🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

Home Depot Is Running a Secret License Plate Surveillance Network For ICE

TL;DR

  • Home Depot operates 233 California stores and, primarily through vendor Flock Safety, has installed license plate cameras at store entrances and exits that photograph every vehicle, log the timestamp and location, and feed the data into a searchable, nationwide law-enforcement database.
  • Home Depot’s own posted ALPR privacy policy is missing at least three elements California’s ALPR Privacy Act requires: it names no accountable custodian, sets no defined data-retention period, and places no real limits on which agencies can access the data.
  • Public records show the same Flock network architecture Home Depot uses has been tapped by ICE, the ATF, Air Force installations, and a federal inspector general’s office, and has been searched using terms tied to protests and immigration enforcement.
  • A Mountain View, California police chief shut down his department’s entire Flock network in February 2026 after learning out-of-state and federal agencies had been accessing local data without authorization; a Ventura County audit found similar unauthorized access more than 364,000 times.
  • Five California shoppers are now suing Home Depot for statutory damages of at least $2,500 per person, punitive damages, and an injunction, arguing the company knew about these failures and never fixed them.

Keep reading to see the exact three words Home Depot used in its official policy to justify keeping your data indefinitely.

The Non-Financial Ledger

This isn’t about money first. It’s about what it feels like to learn that pulling into a hardware store parking lot to buy lumber or a garden hose quietly put your license plate into a federal surveillance system. The complaint documents that Home Depot posted no signage at its camera-equipped entrances, so none of the plaintiffs had any way of knowing their vehicle data was being captured, stored, and made searchable to agencies as far away as an Ohio Air Force base.

For immigrant communities and day laborers who shop at Home Depot for work supplies, the stakes documented in this case are sharper. Community members in multiple California cities reported that the same camera network is connected to systems accessible to ICE, and the underlying Flock network has logged searches explicitly tagged “immigration” and “criminal alien.” The lawsuit also cites reporting that the network has been searched in connection with an abortion investigation and Border Patrol monitoring of a driver who made an obscene gesture at a patrol vehicle.

The same Flock technology Home Depot deploys has, elsewhere in the country, produced at least twelve documented cases of people stopped at gunpoint, jailed, or attacked by a police dog because of a camera misread. Home Depot’s own policy commits only to “periodically” checking for errors, with no defined frequency and no way for a misidentified shopper to ever find out why.

Legal Receipts

“We will retain ALPR Information for as long as necessary for the Authorized Purposes.”
  • This is Home Depot’s own retention language, quoted directly from its posted ALPR policy.
  • California’s ALPR Act requires operators to state a defined retention period and a process for destroying data; “as long as necessary” defines nothing.
  • The complaint calls this circular language the exact kind of non-answer the statute was written to prohibit.
“…cooperating with law enforcement related to enforcement of laws and regulations.”
  • This is the entire limiting language Home Depot’s policy uses to describe when it will share shopper data with police.
  • It contains no restriction on out-of-state agencies, federal agencies, or immigration enforcement.
  • The complaint calls this “not a restriction on data sharing, it is an absence of any restriction.”
“Collecting and maintaining individuals’ ALPR information without implementing and making public the statutorily required policy harms these individuals by violating this right to know.”
  • This is the California Court of Appeal’s holding in Bartholomew v. Parking Concepts, Inc., decided February 5, 2026.
  • The court ruled that a company doesn’t need to misuse the data to cause legal harm; failing to post a compliant policy is the harm.
  • Home Depot did post a policy, just one missing three of the seven elements the law requires, a scenario the same court left unresolved in a later modification order.
“The existence of access by out-of-state agencies, without the City’s awareness, that circumvented the protections we purposefully built and believed were in place is frankly unacceptable to me and to the dedicated people of the MVPD.”
  • Mountain View Police Chief Michael Canfield said this after learning federal agencies had accessed his department’s Flock data without permission.
  • His department shut down its entire ALPR network in response.
  • Home Depot runs the same vendor’s network across 233 California stores and, per the complaint, has announced no comparable suspension or audit.

What You Were Told vs. Reality

Home Depot’s published ALPR policy makes specific commitments. Public records and government audits, cited throughout the complaint, describe a different operational reality.

Policy Claims vs. Documented Reality WHAT THE POLICY CLAIMS WHAT THE RECORD SHOWS
Data is retained “for as long as necessary for the Authorized Purposes.”
No defined retention period exists at all; California law requires operators to state one.
Data is shared with law enforcement only for “enforcement of laws and regulations.”
The same national network has been accessed by ICE, the ATF, Air Force installations, and a federal inspector general’s office, with no agency restriction in place.
Access records will be maintained and “periodically” checked for compliance.
A Mountain View, CA audit found Flock itself failed to retain records for months, making it “impossible to determine” whether data was shared.
Flock markets the underlying camera network as a “digital neighborhood watch.”
EFF analysis of 12 million searches found over 50 agencies ran searches tied to protest activity, using terms including “protest” and “No Kings.”

Regulatory Gray Zones

California’s ALPR Privacy Act sets a floor, not a ceiling, and Home Depot’s policy language shows how much room a company can find inside that floor.

  • The statute requires a policy to state “restrictions on” data sharing under Cal. Civ. Code § 1798.90.51(b)(2)(D). Home Depot’s policy authorizes sharing for “enforcement of laws and regulations,” language broad enough to cover essentially any law enforcement request, which the complaint argues is the absence of a restriction dressed up as one.
  • The statute requires “the length of time ALPR information will be retained” under § 1798.90.51(b)(2)(G). Home Depot substituted the standard “as long as necessary,” open-ended language that functions as indefinite retention while technically answering the question the statute asked.
  • The California Court of Appeal’s February 27, 2026 modification order in Bartholomew explicitly declined to rule on whether a policy that omits mandatory elements, rather than posting no policy at all, causes the same legal harm, leaving exactly the gap Home Depot’s policy sits inside.

Legal Minimalism: The Letter but Not the Spirit

Home Depot did post an ALPR usage and privacy policy, satisfying the bare requirement that one exist. The complaint documents how that policy fails the purpose the law was written to serve.

  • California Civil Code § 1798.90.51(b)(2)(E) requires naming “the title of the official custodian, or owner, of the ALPR system.” The rule exists so someone is accountable when something goes wrong. Home Depot’s policy names no title at all.
  • Section 1798.90.51(b)(2)(B) requires describing specific job titles and training requirements for anyone with system access. The rule exists so access is limited to trained, identifiable personnel. Home Depot’s policy names general departments, security, IT, legal, but no titles, no curriculum, no frequency, no duration.
  • The statute’s overall purpose, according to the Legislature’s own 2015 bill analysis, was to protect the fact that plate, location, and timestamp data “over multiple time points can identify not only a person’s exact whereabouts but also their pattern of movement.” A policy that technically exists but omits the custodian, retention period, and sharing limits leaves that pattern of movement exposed exactly as before the law was passed.

Supply Chain Complicity

Home Depot didn’t build its own surveillance system. It procured one, and the complaint documents how that vendor relationship let responsibility slip through the cracks while the surveillance kept running.

  • Home Depot entered an enterprise vendor relationship with Flock Safety to install and operate ALPR cameras across its store portfolio, connecting California shopper data to Flock’s national network of more than 20 billion license plate reads per month.
  • Oversight of that vendor was documented as absent: audits at Mountain View Police Department and Ventura County Sheriff’s Office both found that Flock had quietly re-enabled nationwide or statewide data-sharing settings without the customer’s knowledge or authorization.
  • Home Depot’s own complaint response anticipates the standard corporate deflection, blaming the vendor, but the pleading states plainly that Home Depot “cannot disclaim responsibility by pointing to Flock’s conduct” because it bears the statutory obligation directly.
  • Downstream, shoppers, including non-customers whose route to an adjacent shopping plaza cuts through a Home Depot lot, were exposed to data capture with no disclosure that a private retailer’s parking lot had become a node in a federal surveillance network.
How the Data Flows: Vendor to Federal Access
The Home Depot, Inc.
Parent corporation, sets enterprise ALPR policy
operates through
Home Depot U.S.A., Inc.
Operates 233 California store locations
contracts & procures cameras from
Flock Safety
ALPR vendor; audits show it re-enabled nationwide access without client authorization
grants queryable access to
Law Enforcement Agencies
Confirmed: ICE, ATF, Air Force installations, GSA Office of Inspector General, out-of-state agencies
captures & tracks
California Shoppers
No signage, no notice, no way to know before entering the lot

This Is the System Working as Intended

Nothing about Home Depot’s conduct required breaking the law outright. It required doing the statutory minimum, and betting that the cost of getting caught would stay smaller than the cost of full compliance.

  • Home Depot reported approximately $164.7 billion in fiscal 2025 sales and $14.2 billion in net earnings. The ALPR Act’s statutory damages start at $2,500 per person, individually meaningful but, as the complaint itself notes, “modest individually,” which is precisely why the law relies on class actions rather than regulators to make enforcement bite.
  • The gap the Bartholomew court’s February 27, 2026 modification order left open, whether a policy that omits mandatory elements causes the same harm as no policy, gave a company with “experienced legal and compliance departments” room to publish something that looked compliant without functioning that way.
  • Public disclosure of the underlying vendor’s unauthorized data-sharing pattern began no later than August 2025. As of the May 1, 2026 filing of this complaint, Home Depot had announced no suspension of California ALPR operations, no policy remediation, and no notice to affected shoppers.
Nine Months of Public Warnings, No Public Response
Aug 5, 2025
404 Media/EFF names Home Depot’s Flock use in Texas records
Feb 3, 2026
Mountain View PD shuts down its entire Flock network
Feb 26-27, 2026
Bartholomew ruling issued; Javorsky v. Flock filed
Mar 9, 2026
Business Insider documents 12 wrongful-detention cases from Flock misreads
Mar 19, 2026
Companion suit filed against Simon Property Group
May 1, 2026
This class action filed against Home Depot
Editorial analysis

What a Legitimate Fix Looks Like

This case exposes a core structural failure: a private company can satisfy the letter of a privacy statute while providing none of the accountability the statute was designed to guarantee, and can outsource the surveillance infrastructure itself to a vendor with a documented pattern of unauthorized access.

Regulatory Track

  • State privacy regulators should require ALPR operators to file their usage and privacy policy for compliance review against all seven statutory elements before deployment, not rely on after-the-fact litigation to catch omissions.
  • As a general industry standard, regulators overseeing any company that procures surveillance technology from a third-party vendor should require mandatory independent audits of that vendor’s access logs, rather than allowing the vendor to self-report as Flock currently does.
  • Enforcement agencies should be empowered to require immediate network suspension, not just future compliance, when a documented pattern of unauthorized data sharing is found, following the model Mountain View’s own police department set voluntarily.

Legislative Track

  • Close the “as long as necessary” loophole by requiring a fixed maximum retention period in the statute itself, rather than allowing operators to satisfy the disclosure requirement with open-ended language.
  • Require that any law enforcement sharing clause name the specific categories of agencies authorized to receive data, explicitly excluding federal immigration enforcement absent a judicial warrant, closing the gap Home Depot’s “enforcement of laws and regulations” language exploited.
  • Resolve, by statute, the exact question the Bartholomew court’s modification order left open: that a policy omitting mandatory elements causes the same legal harm as no policy at all.

Corporate Governance Track

  • Home Depot’s board should require the company to name and publicly identify the ALPR custodian the statute already requires, with that role reporting on compliance status to the board on a fixed schedule.
  • Vendor contracts for surveillance infrastructure should require Home Depot, not Flock, to independently maintain the access audit logs the statute requires, so a vendor failure to retain records can never again make it “impossible to determine” who accessed shopper data.
  • Any renewed or continued vendor relationship with a company that has a documented pattern of unauthorized data-sharing, as Flock does across multiple California agencies, should require contractual, verifiable safeguards against nationwide access being silently re-enabled.

What Now?

Home Depot U.S.A., Inc. and its parent, The Home Depot, Inc., are the named defendants; direct organizing energy at the corporate entities and the regulators positioned to act.

  • California Attorney General’s Office: has already sued at least one other California entity, the City of El Cajon, for illegal out-of-state ALPR data sharing, and can bring similar enforcement action here.
  • The courts hearing the companion cases Javorsky & Mayor v. Flock Group, Inc. and Linder & Hoffert v. Simon Property Group, Inc., since rulings in either case will shape Home Depot’s own liability.
  • Support the Electronic Frontier Foundation’s ongoing public records work auditing Flock’s national search logs, the same methodology that first surfaced this pattern.
  • Push your own city council to follow Mountain View’s example: audit, then suspend, any Flock network found granting unauthorized outside access.
  • Check the “Have I Been Flocked?” public records project cited in the complaint to see what searches have been run in your area.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2001