← IoT Privacy Database

Motorola Solutions ALPR

Motorola Solutions · ALPR Camera

✓ Reviewed

8.6Surveillance
Index
Policy — what its policy permitsF
Evidence — what research provesF

Motorola Solutions sells automated license plate reader (ALPR) cameras — fixed on poles and mounted on patrol cars — that photograph passing vehicles, read the plate, record make, model and colour, and stamp each sighting with a location and time. The images flow into hosted databases (Vigilant LEARN, PlateSearch, VehicleManager) that police agencies search and share with each other. Motorola bought this business on 7 January 2019 for $445 million when it acquired VaaS International Holdings, whose subsidiaries were Vigilant Solutions (law enforcement) and Digital Recognition Network or DRN (commercial); EFF documents that DRN builds its dataset through partnerships with repossession companies and that police can buy subscription access to it. Nobody consents to being scanned: the California State Auditor found that 99.9 percent of the 320 million images the LAPD stores are of vehicles that were not on a hot list, and that audited agencies were sharing images with hundreds — Sacramento with over a thousand — of other entities across the country. EFF's analysis of that audit identifies Vigilant as the cloud provider behind the audited agencies and counts 230 California agencies deploying ALPRs. Motorola's published privacy statement does not cover any of this: it expressly excludes data the company handles in its capacity as a processor, so the drivers being photographed have no policy granting them notice, access or deletion, and the US LPR product page links no notice for them. The system has also leaked. In January 2025, 404 Media reported that researchers found roughly 170 Motorola ReaperHD cameras streaming unencrypted video and plate data onto the open internet; in June 2024, CISA published seven vulnerabilities in Motorola's fixed LPR hardware, the most serious being hard-coded credentials on a hidden wireless network (CVE-2024-38281, rated 8.6 High by CISA under CVSS v4.0 and 9.8 Critical by NVD under CVSS v3.1). In November 2025, 404 Media reported that an ICE app letting officers scan a plate and pull up a vehicle's nationwide location history is powered by Motorola Solutions and Thomson Reuters.

Why this rating

POLICY 10 = 100 -18 no-opt-out (Motorola's Privacy Statement expressly excludes processor-capacity products — it "does not cover or address how personal data may be processed in connection with the products and services we operate in our capacity as a processor" — so the plate scans, vehicle images and timestamped location trails of the driving public sit outside any Motorola privacy commitment; the US LPR product page links no notice for scanned drivers and offers them no access or deletion route) -15 broker-disclosure (Motorola's own 7 January 2019 press release confirms the $445m VaaS acquisition brought in Digital Recognition Network for "commercial customers" alongside Vigilant Solutions; per EFF, "Vigilant Solutions, through its sister company Digital Recognition Network, offers access to data it has privately collected through partnerships with repossession companies", and "law enforcement can also purchase access to this commercial data on a subscription basis") -14 policy-vagueness (the LPR product page's only retention and sharing statement is that "The data from Motorola Solutions' LPR systems is controlled and managed by the customer. The customer also manages access, data retention and can even decide how the data is shared" — no vendor-side default, no ceiling, no published limit) -12 indefinite-retention (no retention cap is published for scan data anywhere in the product materials; for data Motorola does control as a controller the statement contemplates retaining personal data "until the statutory limitation periods have expired (usually three years, but up to thirty years in some cases)") -11 sensitive-collection (precise geolocation, which Motorola's own statement lists among sensitive categories alongside account credentials and payment card information, plus vehicle attribute search that lets a user "Narrow results by make, model, color, accessories and even unique vehicle features like damage or bumper stickers" — bumper stickers being political and religious speech) -10 law-enforcement-loose (disclosure permitted "to comply with laws or to respond to lawful requests and legal process; to protect the rights and property of us, our agents, customers, and others" — no warrant standard, no user notice, no transparency-report commitment) -5 sells-data (the statement concedes that disclosure of contact, commercial, usage and inference data to ad networks and advertising partners "may qualify as the sale of personal data"; scored lightly and deliberately because this clause governs website and business-customer data, NOT plate scans, and it would be an overreach to score it as though it covered the surveilled public) -5 unilateral-change ("When we make changes to this Privacy Statement, we will change the date at the beginning of this Privacy Statement. If we make material changes to this Privacy Statement, we will notify you by prominent posting on our website" — no consent, no opt-out). Not applied: facial recognition as a standard ALPR feature (the face-scan capability 404 Media documented sits in the ICE-facing Mobile Companion app, not in the published LPR product description, so it is not scored against the ALPR policy); and no deduction either way on whether law-enforcement LEARN data is held separate from DRN commercial data, because no Motorola document making or refuting that commitment was loaded. Framing note: this is an involuntary system — no driver is offered these terms, agrees to them, or can decline capture, so every clause above is a permission the vendor grants itself over people who are not its users. EVIDENCE 18 = 100 -20 law-enforcement-loose (404 Media, 17 Nov 2025: ICE's "Mobile Companion" app, which lets an officer scan a plate and pull a vehicle's nationwide sighting history from "a database of billions of records", is "powered by both Motorola Solutions and Thomson Reuters, the massive data broker and media conglomerate", combining plate data with driver licence, credit header, marriage, vehicle ownership and voter registration records; the California State Auditor found audited agencies sharing images with hundreds of entities and Sacramento with "over a thousand entities across the United States"; California AG Bonta sued the City of El Cajon on 3 Oct 2025 for sharing ALPR data with 27 out-of-state agencies in violation of SB 34, proving the unlawful-sharing pattern is real and not merely alleged; the May 2026 Rojas complaint separately alleges UC Merced PD shared Motorola ALPR data with Customs and Border Protection, IRS Criminal Investigation and the Secret Service) -18 no-opt-out (California State Auditor report 2019-118, released 13 Feb 2020: "99.9 percent of the 320 million images Los Angeles stores are for vehicles that were not on a hot list", confirming capture is untargeted and overwhelmingly of people suspected of nothing, with no deletion route for the public; EFF's analysis of the same audit counts 230 California agencies deploying ALPRs with the majority using Vigilant Solutions to collect, store and analyse the data) -15 indefinite-retention (same audit: Fresno retains one year, Sacramento and Marin two years, and Los Angeles "at least five years"; EFF adds that retention "varies from agency to agency, from as short as mere days to as long as several years, although some entities—including private companies—may retain the data indefinitely") -12 broker-disclosure (EFF Street Level Surveillance confirms the DRN sister-company structure, collection via repossession-company partnerships, and subscription sale of that commercial dataset to law enforcement — an independent confirmation of the brokerage structure, not merely a policy permission; EFF notes one vendor dataset "includes more than 6.5 billion scans and grows at a rate of 120-million data points each month") -10 sensitive-collection (404 Media, 7 Jan 2025: researchers Matt Brown and Will Freeman found roughly 170 Motorola ReaperHD ALPR streams reachable unencrypted on the open internet, exposing colour and infrared video, plate numbers, vehicle make, model and colour and timestamped location, with a proof-of-concept script dumping passers-by into a spreadsheet; separately CVE-2024-38281, hard-coded credentials on a hidden wireless network on the Vigilant Fixed LPR Coms Box — CISA/ICS-CERT rates it 8.6 High under CVSS v4.0 and NVD 9.8 Critical under CVSS v3.1 — one of seven vulnerabilities in CISA advisory ICSA-24-165-19 found by the Michigan State Police Michigan Cyber Command Center, which per EFF also included easy backdoor installation, default username/password access, unencrypted storage of historic licence plate data and unprotected authentication logs) -7 policy-vagueness (EFF, 19 Mar 2019: Vigilant publicly asserted that agencies "do not have the ability in Vigilant Solutions' system to electronically copy this data or share this data with other persons or agencies, such as ICE", yet obtained records showed a La Habra detective sending LEARN scans to ICE as a PDF within hours of a request; Vigilant contracts also carried non-disparagement and non-publication clauses binding agencies to the company's "media messaging" — establishing that vendor assurances here have been demonstrably unreliable). Not applied: no confirmed regulatory penalty against Motorola Solutions itself — the CISA advisory is a coordinated vulnerability disclosure rather than an enforcement action, Rojas v. Motorola Solutions is an unadjudicated complaint whose allegations are not proven, and the California Attorney General's October 2025 ALPR suit targeted the City of El Cajon rather than Motorola; no FTC, state-AG, ICO, CNIL or Garante decision against Motorola on ALPR was located. Absence of a penalty is explicitly not treated as exoneration: the independent evidence base for this vendor is unusually deep, spans a state audit, coordinated CVE disclosure, named investigative journalism and litigation, and is consistently adverse. Unverified and therefore excluded: the "72 deployments across 7 states" figure supplied as a lead, and a figure of roughly 400,000 immediate hot-list matches that does not appear in the audit summary and is not derivable from it.

What it is

Manufacturer
Motorola Solutions
Category
ALPR Camera
Model years
2019-present under Motorola ownership (Vigilant/DRN products predate the acquisition; Motorola states the ReaperHD mobil
Market status
Current
Companion app
Agency-facing platforms: Vigilant LEARN, Vigilant PlateSearch, Vigilant VehicleManager (hosted web). 404 Media reports that ICE's "Mobile Companion" field app is powered by Motorola Solutions together

The evidence 14

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Primary policy · Motorola Solutions

    The statement covers personal data Motorola handles as a controller for its websites and its business and government customer relationships, and explicitly 'does not cover or address how personal data may be processed in connection with the products and services we operate in our capacity as a processor' — the capacity in which ALPR scans are handled. It concedes that disclosure of contact, commercial, usage and inference data to ad networks and advertising partners 'may qualify as the sale of personal data'; authorises disclosure 'to comply with laws or to respond to lawful requests and legal process; to protect the rights and property of us, our agents, customers, and others'; contemplates retention 'until the statutory limitation periods have expired (usually three years, but up to thirty years in some cases)'; lists 'Precise geolocation data' among sensitive categories; and permits amendment by changing the date and, for material changes, 'prominent posting on our website'.

    Why it matters here: Primary basis for the POLICY axis; establishes that the surveilled public is outside the policy's scope entirely

  2. Vendor policy · Motorola Solutions

    The product page states that 'The data from Motorola Solutions' LPR systems is controlled and managed by the customer. The customer also manages access, data retention and can even decide how the data is shared', and invites customers to 'Set your own retention rules according to policy and manage data sharing on your own terms' — publishing no vendor-side retention ceiling or sharing limit. VehicleManager search lets a user 'Narrow results by make, model, color, accessories and even unique vehicle features like damage or bumper stickers.' No privacy notice or contact route for scanned drivers is linked anywhere on the page.

    Why it matters here: Sole vendor source for the retention/sharing and vehicle-attribute-search deductions; also establishes the absence of any driver-facing notice

  3. News · Motorola Solutions · 2019-01-07

    Announces the acquisition of VaaS International Holdings for '$445 million in a combination of cash and equity' on 7 January 2019. VaaS subsidiaries are identified as Vigilant Solutions, serving 'law enforcement users', and Digital Recognition Network (DRN), serving 'commercial customers'. The release describes fixed and mobile license plate reader cameras driven by machine learning; it does not describe how DRN collects its data or to whom it sells.

    Why it matters here: Vendor's own confirmation that Motorola owns both the police-facing and the commercial plate-data businesses

  4. Investigative report · 404 Media (Joseph Cox) · 2025-11-17

    ICE's 'Mobile Companion' app lets officers scan a licence plate and instantly see a vehicle's sightings across the country from a database of billions of records, and supports 'predicting where a car may travel in the future.' The capability 'is powered by both Motorola Solutions and Thomson Reuters, the massive data broker and media conglomerate.' Plate data is combined with driver licence data, credit header data, marriage records, vehicle ownership and voter registrations, and the app can also collect face scans for facial recognition.

    Why it matters here: Directly names Motorola Solutions (not merely Vigilant) as powering a federal immigration-enforcement tracking capability

  5. Investigative report · 404 Media (Jason Koebler) · 2025-01-07

    Security researcher Matt Brown (Brown Fine Security) found Motorola ReaperHD ALPR cameras streaming unencrypted to the open internet; roughly 170 such streams were located, exposing colour and infrared video, licence plate numbers, vehicle make, model and colour, and timestamped location data. Will Freeman of the DeFlock mapping project wrote a proof-of-concept script that scraped the feeds into a spreadsheet, enabling real-time tracking of arbitrary people. Motorola Solutions responded that the ReaperHD is 'a legacy device, sales of which were discontinued in June 2022', that the findings 'do not pose a risk to customers using their devices in accordance with our recommended configurations', and that a firmware update would introduce 'additional security hardening.'

    Why it matters here: Proves real-world exposure of live surveillance data from Motorola-branded hardware, with an on-record vendor response

  6. Regulatory action · California State Auditor · 2020-02-13

    Statutory audit of Fresno Police Department, Los Angeles Police Department, Marin County Sheriff's Office and Sacramento County Sheriff's Office. Found that '99.9 percent of the 320 million images Los Angeles stores are for vehicles that were not on a hot list.' Retention varied widely: Fresno one year, Sacramento and Marin two years, Los Angeles at least five years. On sharing: 'Fresno and Marin have each arranged to share their ALPR images with hundreds of entities and Sacramento with over a thousand entities across the United States.'

    Why it matters here: Government audit quantifying the untargeted nature of ALPR capture, retention sprawl and mass inter-agency sharing

  7. Advocacy report · Electronic Frontier Foundation (Dave Maass and Hayley Tsukayama) · 2020-02-13

    EFF's analysis of the audit reports that 230 agencies in California were deploying ALPRs, 'with the majority using Vigilant Solutions to collect, store, and analyze the data', and that the three agencies storing ALPR data in Vigilant's cloud — Fresno, Marin and Sacramento — 'do not have sufficient data security safeguards in their contracts.' It documents insufficient access controls, minimal audit oversight and excessive retention across the audited agencies.

    Why it matters here: Ties the state audit's findings specifically to Motorola's Vigilant product rather than to ALPRs generally

  8. Advocacy report · Electronic Frontier Foundation

    EFF documents that 'Vigilant Solutions, through its sister company Digital Recognition Network, offers access to data it has privately collected through partnerships with repossession companies', and that 'law enforcement can also purchase access to this commercial data on a subscription basis'. One vendor dataset is described as including 'more than 6.5 billion scans' and growing 'at a rate of 120-million data points each month'. Retention 'varies from agency to agency, from as short as mere days to as long as several years, although some entities—including private companies—may retain the data indefinitely.' No mechanism is described by which a driver can opt out or request deletion.

    Why it matters here: Independent confirmation of the DRN commercial-brokerage structure that Motorola acquired, and of the absence of any driver opt-out

  9. Advocacy report · Electronic Frontier Foundation (Dave Maass) · 2019-03-19

    Vigilant publicly asserted that 'These law enforcement agencies do not have the ability in Vigilant Solutions' system to electronically copy this data or share this data with other persons or agencies, such as ICE.' Records showed the opposite: within hours of an ICE official emailing a La Habra police detective, the detective returned a PDF from Vigilant's LEARN software containing the requested scans, including data originating from Fashion Island mall security. EFF further documents that Vigilant's agreements with agencies include non-disparagement and non-publication clauses binding them to the vendor's 'media messaging', and that Vigilant training materials recommended police omit ALPR references from official reports where possible.

    Why it matters here: Establishes that this vendor's public assurances about data sharing have been demonstrably false, and that contracts suppress agency candour

  10. Cve · NIST National Vulnerability Database / ICS-CERT · 2024-06-13

    'An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.' Affects Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) firmware versions up to and including 3.1.171.9; assigned by ICS-CERT. Two different severity ratings appear on the record: ICS-CERT (the CNA) scores it 8.6 HIGH under CVSS v4.0 (AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N), while NVD scores it 9.8 CRITICAL under CVSS v3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). It is one of seven vulnerabilities in CISA advisory ICSA-24-165-19.

    Why it matters here: Coordinated-disclosure proof of security defects in Motorola-branded fixed ALPR hardware

  11. Security research · Electronic Frontier Foundation · 2024-06-18

    Seven vulnerabilities in Motorola Solutions' Vigilant ALPRs were identified by the Michigan State Police Michigan Cyber Command Center and reported to CISA — five High and two Medium. EFF describes CVE-2024-38281 (CVSS 8.6) as arising because 'every camera sold by Motorola had a wifi network turned on by default that used the same hardcoded password as every other camera'; CVE-2024-38279, where someone with physical access 'could also easily install a backdoor'; CVE-2024-38282, default username and password; CVE-2024-38280, historic recordings stored 'without any kind of encryption'; and CVE-2024-38284, logs containing 'authentication information which could be used to connect to a back-end server'. 'Motorola claims that they have mitigated all of these vulnerabilities.'

    Why it matters here: Independent account of the full seven-vulnerability advisory, cited in place of the CISA page which blocks automated access

  12. Regulatory action · California Department of Justice, Office of the Attorney General · 2025-10-03

    On 3 October 2025 the California Attorney General sued the City of El Cajon in San Diego County Superior Court for sharing ALPR data with 27 out-of-state law enforcement agencies across 26 states in violation of SB 34, the 2015 law barring sharing of ALPR data with federal and out-of-state agencies. A 2023 DOJ bulletin had already advised agencies that 'public agency' does not include out-of-state or federal bodies. The office cited risks of the data being misused to track immigrants, people travelling to California for reproductive care, and protesters. This action targets the agency operating the cameras, not the vendor supplying them.

    Why it matters here: Regulator enforcement proving unlawful out-of-state ALPR sharing is an actual practice, not merely an allegation — though the defendant is a city, not Motorola

  13. News · ClassAction.org · 2026-06-17

    A proposed class action, Rojas et al. v. Motorola Solutions, Inc. (no. 2026-CH-05072), filed 27 May 2026, alleges Motorola 'has violated California law by allowing its automatic license plate reader (ALPR) systems to share identifiable vehicle and location data with the federal government and out-of-state agencies without notice or drivers' consent.' It states that 'The UC Merced Police Department had been sharing ALPR data with several federal agencies, including Customs and Border Patrol, IRS Criminal Investigation, and the United States Secret Service', and contends Motorola 'does not maintain a legally sufficient privacy policy.' The complaint also references a January 2025 report that real-time footage and data from Motorola ALPR cameras could be viewed online without any login. These are allegations that have not been adjudicated.

    Why it matters here: Current, unadjudicated litigation alleging exactly the federal/out-of-state sharing and missing public privacy policy identified on the policy axis

  14. News · Legal Newsline / Cook County Record · 2026-06-09

    Reports that the class action against Motorola Solutions over its ALPR cameras was filed in Cook County Circuit Court on 27 May by named plaintiffs Michelle Rojas and Marissa Barriga, both residents of Merced, California, who are represented by Scott Drury of Drury Legal in Highwood and Joshua D. Arisohn. The plaintiffs drove daily past Motorola-operated ALPR cameras near the entrance to UC Merced.

    Why it matters here: Supplies the court, plaintiff and counsel details for the Rojas action, which the ClassAction.org write-up does not state

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database