Install a camera on a Georgia state road, and you may be routing your city’s movement data into a federal surveillance app-enabled system. Public records and a DEA privacy impact assessment approved December 20, 2024, reveal that local governments can be contractually required to route license plate data into the High Intensity Drug Trafficking Area (HIDTA) program. That requirement can apply simply as a condition of deploying cameras on state transportation rights of way. That data can then travel further, reaching the DEA’s National License Plate Reader Program (NLPRP). The agency that installs the camera and the agency that ultimately searches the data may be located in entirely different jurisdictions.
How the Data Pipeline Actually Works
Three layers separate your local camera from the federal database searching its records.
Local cameras capture plate reads, timestamps, and vehicle images. Vendor systems operated by companies including Flock, Axon, ELSAG, and Vigilant transmit that data to regional HIDTA servers. Those servers aggregate records from multiple agencies and platforms, and selected data can then flow to the DEA’s NLPRP.
According to 404 Media, Flock’s own law-enforcement materials state that agencies installing cameras on Georgia Department of Transportation property must sign a memorandum of understanding with HIDTA. Plate reads from those cameras then become accessible to Georgia users of the HIDTA national system directly through the Flock interface.
The aggregation layer is real infrastructure, not a theoretical concern. A Houston HIDTA contract worth $306,800 was awarded to Recruitful LLC. It described the creation and maintenance of a license plate database designed to combine third-party data from Flock, Axon, ELSAG, and Vigilant systems, according to 404 Media. A city council packet from Brunswick, Georgia, described an agreement requiring the city to facilitate sharing of information from electronic data systems, including ALPRs and systems containing aggregated information from multiple sources.
What the DEA’s Own Assessment Admits
The agency flagged the risk of tracking law-abiding drivers in its own December 2024 filing.
Approved December 20, 2024, the DEA’s own privacy impact assessment states that its NLPRP uses not only DEA equipment but also “non-DEA equipment” accessed through HIDTA and other contributing law-enforcement agencies. Contributing agencies transmit license plate data to regional hub servers. Those agreements may allow the information to be shared with the NLPRP, according to the assessment.
The DEA also warned, in its own language, that integrating large numbers of government and commercial license plate networks could permit ongoing tracking users of individuals’ travels. Records about law-abiding drivers unrelated to any investigation are inevitably collected, the agency acknowledged.
The DEA did include stated safeguards. The assessment said current camera coverage is not extensive enough to enable comprehensive nationwide tracking, and that records not accessed become unavailable after 90 days. Those controls apply to DEA systems specifically. The assessment does not establish the retention or access rules governing every HIDTA regional center or local partner that contributes data upstream.
The Accountability Gap Nobody Wants to Close
Distributed governance makes it genuinely unclear who owns the data or who answers for it.
Ask a local agency who controls the data, and the answer may point toward HIDTA. Ask the DEA, and the answer points away. In court filings, DEA attorneys argued that HIDTA records are not created, possessed, maintained, or controlled by the agency. Those records are also not stored in DEA systems of records, according to 404 Media.
Neither position clearly assigns accountability. The architecture, built across vendor contracts, regional memoranda, and federal grant structures, can move records into systems governed by policies entirely different from those adopted by the collecting agency.
A city can restrict how its police department queries a vendor’s database. Yet if the underlying plate reads are already residing in a HIDTA system, a different participating agency governed by different rules can still search them. Jeramie Scott of the Electronic Privacy Information Center characterized the arrangement as adding another layer of uncertainty about how ALPR data is used and who can access it, according to 404 Media.
One important caveat applies. The total number of jurisdictions currently transmitting ALPR data to HIDTA is not documented in the available records, and claims about a complete nationwide database should be treated cautiously.
Context: A 1980s Drug Program Running 2020s Surveillance Infrastructure
HIDTA’s expansion into license plate aggregation follows a broader pattern of connecting local and federal data systems.
HIDTA was created in the late 1980s to coordinate anti-drug-trafficking efforts. Its 33 regional programs now cover all 50 states. Reporting has documented similar federal data-aggregation patterns in telecommunications through the Hemisphere program, where ONDCP funding supported carrier access to large commercial call-record databases. License plate readers represent the physical-movement equivalent: a distributed network of locally owned sensors feeding centrally searchable records.
Whether more states will condition right-of-way camera access on HIDTA participation remains an open question. So does whether courts will clarify which public-records laws govern HIDTA-held data. The legal status of this pipeline, including what constitutional limits may apply to prolonged location tracking and which disclosure rules govern the records, is not resolved by the available documents. What is documented is the access pathway. Any local government that treats its license plate camera deployment as a purely local tool should read the fine print of its right-of-way permits.




























