secure-os.org
All guidesQubes OSTailsWhonixHardened LinuxDisk encryptionThreat model
surveillance

License Plate Reader Surveillance: What ALPR Records (2026)

secure-os· Updated September 3, 2026· 4 min read #surveillance#privacy#alpr#location-privacy#threat-model
Four white box cameras mounted at different heights on a rusty metal pole, each pointing a different way, against a clear blue sky

An automatic license plate reader, usually shortened to ALPR, is a camera paired with software that turns a photograph of a passing car into text. It is often described as a tool for finding stolen vehicles, and it is used that way. But that description leaves out the part that matters for privacy: the reader does not photograph only the cars it is looking for. It photographs all of them.

That single design choice is what turns a lookup tool into a location history, and it is the subject of this page.

What a single reading actually contains

A reader that sees your car generally records four things: the plate as text, the time, the location of the camera, and usually the photograph itself, sometimes including a wider shot of the vehicle.

None of those is sensitive on its own. A plate seen once at one junction says almost nothing.

The sensitivity comes from accumulation. The same plate seen at the same junction every weekday at the same hour describes a commute. Seen outside a clinic, a place of worship, a lawyer’s office or a protest, it describes something a good deal more personal, and it does so without anyone having been suspected of anything.

Two women stand against a brick wall covered in dozens of identical surveillance cameras arranged in a grid, both looking up at them

Two women stand at the foot of a brick wall covered with dozens of identical surveillance cameras arranged in a regular grid, heads tilted back to look up at them. The wall makes the point visually that a plate reader network makes numerically: the density is the story, not the single camera.

Why retention is the setting that matters

Discussions about plate readers often focus on where cameras are placed. The more consequential number is how long the readings are kept, because that is what decides whether the system answers “is this car stolen right now” or “where has this car been over the past two years”.

A short retention window, measured in days, supports the first question and makes the second one impossible. A long window supports both. The camera hardware is identical in either case, which is why the retention policy, and not the camera count, is the real privacy setting.

⚠️ Retention periods vary widely between operators and jurisdictions, and they change. We do not publish a figure here, because a number that is right for one network is wrong for the next, and a stale figure is worse than none. If it matters to you, the operator’s own published policy is the source to check.

Who holds the data, and why that is the harder question

Plate readings are not held in one place. Depending on the network, they may sit with a police force, a local authority, a private operator running cameras on commercial property, or a commercial database that aggregates readings from many sources and sells access.

That last category is the one people underestimate. A private aggregator is not bound by the rules that constrain a public body, and access to its database may be a commercial matter rather than a legal one.

What you can realistically do

This is the part where honesty matters more than reassurance, so here is the blunt version.

You cannot opt out of being read. A plate is designed to be legible from a distance, by law. Obscuring it is an offence in most places, and devices sold to defeat readers tend to be both illegal and ineffective.

What you can do is act on the data rather than the camera. In jurisdictions with data protection rights, plate readings held about you are usually personal data, which means you may be able to ask who holds them, request a copy, and in some cases ask for deletion. That right is the practical lever, and it works on the aggregators as well as the public bodies.

And you can treat vehicle travel as observable in your threat model. If a journey would be sensitive if logged, the realistic mitigations are not technical ones applied to the car. Our page on building a threat model covers how to decide which of your activities actually need that treatment, rather than defending everything equally.

What this is not

ALPR is not facial recognition, and the two get conflated. A plate reader identifies a vehicle, and links to a person only through registration records. That is a weaker link, and it is also a real one.

It is also not the same as a toll or congestion camera, which typically reads plates for a single stated purpose with its own retention rules. The distinction matters because the purpose limitation is what keeps a narrow system narrow.

The short version

  • ALPR photographs every passing vehicle, not only flagged ones.
  • Each reading holds plate, time, place and usually the image.
  • One reading is harmless; accumulation is what creates a location history.
  • Retention length, not camera count, is the real privacy setting.
  • Readings may sit with private aggregators, not only public bodies.
  • You cannot avoid being read; data protection rights are the usable lever.