Verification record · Standard v1.0

Cambridge, Massachusetts

Cambridge has a surveillance-technology ordinance, a municipal facial recognition ban, and terminated its Flock deployment in 2025. It is among the better-governed cities in the country on this issue. It still does not currently qualify, because the City indicated it planned to continue evaluating ALPR technology — which is not the forward-looking rejection of persistent mass tracking the standard requires.

This is not a Verified Unsurveilled designation. This jurisdiction has been assessed and does not currently qualify.

Status
Does not currently qualify
Standard
v1.0
Last reviewed
Aug 14, 2026
Criteria met
2 of 12
DOES NOT CURRENTLY QUALIFYEVIDENCE UNDER REVIEW

Disqualifying findings

  • The City publicly indicated it planned to continue evaluating ALPR technology after terminating its Flock contract. The standard requires a forward-looking rejection of persistent mass tracking, and an open evaluation is not that.

Why a good city does not qualify

Cambridge is genuinely strong on this issue. It has a surveillance-technology ordinance. It has a municipal facial recognition ban. It removed its Flock cameras and terminated the contract in 2025. On most privacy scorecards it would place near the top.

It does not currently meet the Verified Unsurveilled standard, and explaining why is more useful than adding another name to a list of good actors.

“Ended Flock” is not “ended mass ALPR surveillance”

After terminating the contract, the City indicated it planned to continue evaluating ALPR technology.

The standard asks whether a community has rejected persistent, indiscriminate tracking of the general public. A city actively considering a replacement has not answered that question — it has deferred it. A designation issued inside that window would either have to be withdrawn at the next procurement vote, or survive it dishonestly.

That is the entire reason the standard is written in the forward tense.

What Cambridge is useful for

Cambridge is the clearest illustration of a distinction this project has to draw constantly: the difference between a vendor decision and a policy decision.

A resident who reads “our city cancelled Flock” should immediately ask the second question — and what is the city’s position on the next one? Cambridge answered that question publicly and honestly, which is why we can assess it at all.

Most cities have simply never been asked.

The rubric, criterion by criterion

All 12 criteria of the published standard, including the 9 not yet examined. A criterion that has not been assessed is shown as unexamined rather than omitted — otherwise a record could look complete by leaving out the awkward questions.

  1. 01

    No persistent mass ALPR program

    Not met

    The municipality does not operate a persistent automated license plate reader program that routinely records ordinary traffic and builds a searchable history of people’s movements.

    The Flock deployment was removed and the contract terminated in 2025, which settles the present tense. But the City publicly indicated it planned to continue evaluating ALPR technology. The standard requires a forward-looking rejection of persistent mass tracking, not a pause between procurements, so the available evidence does not establish this criterion.

    City of Cambridge, Massachusetts — checked Aug 14, 2026

  2. 02

    No vendor workaround

    Not yet examined

    The municipality has not simply replaced one platform with another providing substantially equivalent dragnet capability.

    Cannot be resolved while the city is openly evaluating replacement ALPR technology.

    What would resolve it Procurement records across all vendors, not only the one that attracted public attention.

  3. 03

    No routine access to another agency’s dragnet

    Not yet examined

    The municipality does not evade the standard by routinely querying regional, private, vendor, or neighbouring ALPR databases as a substitute for operating its own network.

    Not yet examined.

    What would resolve it Mutual-aid agreements, regional fusion or task-force participation, vendor account access, department policy.

  4. 04

    Targeted investigative exception only under defined lawful authority

    Not yet examined

    Short-term or case-specific use is tied to individualized legal justification, a warrant or court order where required, or a tightly defined exigent circumstance documented by policy.

    Not yet examined.

    What would resolve it Written department policy, authorization logs, ordinance text.

  5. 05

    No persistent facial recognition or biometric identification of the public

    Met

    No persistent facial-recognition or biometric identification system aimed at the general public.

    Cambridge has a municipal facial recognition ban.

    City of Cambridge, Massachusetts — checked Aug 14, 2026

  6. 06

    No purchase of sensitive historical location data from data brokers

    Not yet examined

    The municipality does not purchase sensitive historical location data to circumvent warrant or court-order requirements.

    Not yet examined.

    What would resolve it Procurement records, purchase orders, department policy.

  7. 07

    Democratic control of new surveillance technology

    Met

    New systems capable of identifying, tracking, or profiling the public require advance public notice, an impact and use policy, and approval by the elected legislative body or an equivalently accountable process.

    Cambridge has a surveillance-technology ordinance governing adoption of new systems.

    City of Cambridge, Massachusetts — checked Aug 14, 2026

  8. 08

    Public surveillance technology inventory

    Not yet examined

    The municipality publishes what surveillance technologies it uses and for what purpose.

    Not yet examined.

    What would resolve it Published inventory, currency of the most recent version.

  9. 09

    Retention and deletion limits

    Not yet examined

    Personally identifying surveillance data is minimized and deleted on defined schedules unless legitimately tied to a specific investigation or legal obligation.

    Not yet examined.

    What would resolve it Written retention schedule, department policy, contract terms.

  10. 10

    Sharing controls

    Not yet examined

    Sensitive data is not casually pooled, sold, or made broadly searchable by outside agencies; sharing rules and legal standards are public.

    Not yet examined.

    What would resolve it Sharing configuration, data-sharing agreements, published policy.

  11. 11

    Annual transparency reporting

    Not yet examined

    The municipality publishes meaningful annual reports covering use, sharing, complaints, audits, policy violations, costs, and material changes.

    Not yet examined.

    What would resolve it Published reports and whether they are current and substantive.

  12. 12

    Function-over-brand protection

    Not yet examined

    Policies apply to capabilities rather than vendor names, so future technology cannot bypass the spirit of the standard by changing product labels.

    Not yet examined.

    What would resolve it Ordinance and policy text — how the scope clause is written.

Evidence

  • Statement on the Flock Safety ALPR contract terminationCity of Cambridge, MassachusettsThe city's own statement. Establishes termination of the Flock deployment. Critically, it also indicates the City planned to continue evaluating ALPR technology — which is why Cambridge does not meet the forward-looking no-dragnet requirement despite otherwise strong protections.Agency release

Not yet obtained

  • Has Cambridge concluded its evaluation of ALPR technology, and with what outcome?Council agenda
  • Does Cambridge access any regional or state ALPR database operated by another agency?Public-records request

Verified as of

Change log

  1. status change

    Record opened at status NOT QUALIFIED, with the disqualifier stated explicitly.