Flock cameras are not deployed in the UAE, and an honest treatment of this topic starts by saying so. What the Flock story actually teaches is that any networked plate-reader system turns into a tracking tool the moment the wrong person can run a query, and the UAE operates some of the densest vehicle-monitoring infrastructure anywhere: toll gates, police ANPR, mall parking cameras and community gate barriers all record the same thing Flock records. A plate, a time, a place. The stalking threat lives in who can search those records, how that access is governed, and whether anyone reviews the lookups.
What Flock cameras actually are
Flock Safety sells small, often solar-powered ALPR cameras to police departments, homeowner associations and retailers, mostly in the United States. Each camera photographs passing vehicles and extracts the plate together with what the vendor calls a vehicle fingerprint: make, colour, body type and distinguishing details such as roof racks or dents. Every read is timestamped, location-tagged and written into a searchable database. Many customers opt into shared networks, so one query can sweep cameras across an entire region.
The camera is not the interesting part. Plate cameras have existed for decades. What changed is scale and retention: thousands of fixed collection points feeding one searchable history means a plate query no longer returns a sighting, it returns a pattern of life. Home street, office car park, gym, school pickup, Friday routine. That is a surveillance dossier, and the system builds it automatically for every vehicle that passes, not just vehicles under investigation.
How a plate-reader network becomes a stalking tool
The documented abuse path is not hacking. It is authorised users running personal queries. US reporting has repeatedly surfaced cases of officers and other insiders using ALPR lookups to track ex-partners and people they had no lawful reason to search, and those cases usually came to light through lookup audit logs. That detail tells you the two things that matter most: the abuse genuinely happens, and logging is what catches it.
Three access paths cover nearly every realistic scenario:
- Insider misuse. Someone with legitimate query rights searches a plate for personal reasons. This is the most common documented pattern and needs no technical skill.
- Over-broad sharing. Shared networks multiply the number of people who can query a given plate. Every partner agency, community account and analyst seat widens the pool.
- Account compromise. A phished or reused credential inherits everything its owner could search. A lookup portal is just another web application, and attackers treat it as one.
The UAE picture: same capability, different owners
The UAE has no Flock network, but it has the underlying capability many times over.
State systems
Toll gates in Dubai and Abu Dhabi log every crossing against a registered vehicle. Police ANPR reads plates at scale for traffic enforcement and investigations. These systems are tightly held, access is restricted, and misuse carries serious consequences under UAE law. They are not where the practical stalking risk concentrates.
Private-sector plate databases
This is the softer target. Ticketless mall parking, hotel valet systems, gated community entry barriers, office tower car parks and fleet telematics platforms all run plate recognition or continuous location tracking. Each one holds movement data about identifiable people, and the governance varies from professional to nonexistent. A community management company running ANPR on its gates rarely has a lookup audit trail, a purpose limitation policy or an offboarding process for the contractor who installed the system.
Under the UAE Personal Data Protection Law, plate reads tied to an identifiable person are personal data, and movement history is exactly the kind of data that causes real harm when it leaks. Assessors reviewing these systems expect evidence of access control, retention limits and query logging. In my experience, most operators of small ANPR deployments cannot produce any of the three.
What actually protects individuals
The advice that circulates online for this threat is mostly wrong, and some of it is illegal in the UAE.
GPS blockers do nothing here: a plate camera is optical and never touches GPS, and jamming equipment is in any case restricted in the UAE. Plate covers and obscuring sprays are traffic offences, and driving with an unreadable plate attracts exactly the attention a person at risk does not want.
What genuinely helps is duller:
- Treat your plate as public information, because it is. Anyone standing near your car can read it. The goal is not hiding the plate but limiting what a plate query can return.
- For people at higher risk, such as public figures, executives and those leaving abusive relationships, vary routes and timing. Pattern-of-life tracking works because routines repeat. Predictability, not the camera, is what enables an ambush.
- Keep plates out of social media photos and car sale listings. Linking a plate to a name is the step an attacker needs, so do not hand it over.
- Ask your community or building operator what their cameras retain and who can search the records. The question alone often triggers the first governance review the system has ever had.
- Escalate real concerns to the police rather than self-help. Stalking and privacy violations are criminal matters in the UAE, and plate-lookup records make strong evidence precisely because these systems log so much.
What UAE organisations should take from this
If your organisation operates ANPR, parking recognition or vehicle telematics, you are holding stalking-grade data whether you think of it that way or not. The controls that matter are the ones that govern any sensitive lookup system:
- Least privilege on query access. Most ANPR misuse traces back to accounts that never needed search rights in the first place. Treat plate lookup as a privileged operation and manage it with the same discipline you would apply to privileged access management: named accounts, individual accountability, periodic review of who holds query rights.
- Log every lookup with a reason. A reason field plus a monthly sample review deters the casual personal query, which is most of the problem. Audit logs are how every published ALPR abuse case was caught.
- Watch for abnormal query behaviour. A user searching the same plate weekly, querying outside working hours, or searching with no case reference is a detectable pattern. This is a textbook use case for user and entity behaviour analytics applied to application logs rather than endpoints.
- Retention limits. Movement data ages into risk. If your parking system does not need reads older than 90 days, delete them, and the damage from any future compromise shrinks with them.
- Third-party scope. If a facilities vendor runs the cameras, their access governance is your exposure. Put lookup logging and access review into the contract.
A decision rule for anyone holding plate data
If a system in your estate can answer the question "where has this vehicle been", treat it as a sensitive system from that moment. Apply named accounts, logged queries, retention limits and a quarterly access review. If you cannot say who can search it, assume the answer includes someone who should not be able to, because in every published abuse case, it did.