Seven changes, in the order we would make them.
1
Define "independent," and make conflicts disqualifying
Define an independent auditor as one that does not receive a substantial share of its business from law enforcement, whose employees and board members have no affiliation with any agency it audits, and that has no other business relationship with the audited agency. Require every audit to open with a signed conflict-of-interest disclosure. Better still, take auditor selection out of the audited agency’s hands: the Office of the State Auditor already performed the State Patrol’s 2022 audit under AICPA attestation standards, so a state-run model exists today.
What the record shows
The statute requires an “independent” audit but never defines the word, and the audited agency picks and pays its own auditor. MNSec’s five-member board includes the police chief of Elko New Market, whose department retains MNSec for its statutory audits, and the technology director of the City of Woodbury, whose ALPR program MNSec has audited twice and cleared twice. LOGIS supplies CAD and records software to many of the same departments whose ALPR programs it audits, and is governed by its member cities. Several other auditors are retired law enforcement auditing former colleagues. Two firms produced 54% of every audit we have reviewed. These arrangements arguably violate the existing statutory word; defining it makes that enforceable.
2
Set minimum standards for what an audit must test
Require, at minimum: direct auditor access to the live system rather than agency-supplied screenshots; a sample of actual queries tested against the written authorizations the statute requires; a direct database query verifying that data past the retention limit is gone; and testing of export and audit-trail behavior.
What the record shows
Only 10 of the 68 audits we have reviewed tested a live system. Only one examined data exports, and that one audit found there is no mechanism whatsoever enforcing the 60-day retention limit once data is exported from Flock: exports leave no audit-trail entry at all. One high-volume auditor states in its own reports that it reviews screen prints provided by the agency. A statute that does not say what the audit must test gets policy read-throughs, and the reports show it: they run two to nine pages.
3
Enforce the filing requirement
Designate one mandatory repository for every audit, set the filing deadline from the audit’s completion date, flag any agency that misses its biennial deadline on the BCA’s public LPR list, and suspend reader operation after a grace period. Today no one is responsible for noticing a missing audit.
What the record shows
61 of the roughly 118 Minnesota agencies known to run license plate readers have no locatable audit at all, a decade into the biennial mandate. Columbia Heights had an audit conducted and presented to its city council that was never filed with the state; we found it in a council packet. The State Patrol’s 2017 audit was filed three years late. Nothing happened in any of these cases, because nothing in the statute makes anything happen.
4
Record every problem found, including the fixed ones
Require that any deficiency the auditor observes be recorded as a finding, with its remediation status noted. An agency that fixes a problem mid-audit should get credit for the fix in the record, and the legislature should still learn the problem existed.
What the record shows
We have documented 6 audits that describe statutory problems in their own narrative while recording zero findings, a pattern we call ghost findings. Olmsted County’s audit notes the office was not maintaining the required public Log of Use, and passed the item. Oakdale’s says the department came into compliance “as a result of this audit,” then recorded nothing. Reports to the legislature that say nothing happened are how an oversight regime goes quiet.
5
Audit the auditors
Give the commissioner of administration authority to review audit quality, reject a deficient audit, and order a re-audit at the auditor’s expense. Publish which auditors have had audits rejected.
What the record shows
The statute’s only enforcement mechanism, suspension of an agency’s readers under subdivision 6(b), triggers off audit findings. 82% of the audits we have reviewed record zero findings, so the mechanism has never had anything to fire on. No one currently grades the audits themselves, which is why a two-page checklist and a live-system test carry identical statutory weight.
6
Keep audit logs long enough to audit
Set a minimum two-year retention requirement for system audit logs, access records, and written authorizations, and state explicitly that these oversight records are not ALPR data subject to the 60-day destruction rule. The 60-day limit protects the public’s location data; it was never meant to erase the records of who searched it.
What the record shows
Minneapolis deletes its ALPR audit logs every 60 days, on the same schedule as the plate data, a practice its own auditor flagged because it leaves almost nothing to examine and destroys exactly the records a misuse investigation would need. Some agencies appear to believe the 60-day maximum requires this. A biennial audit of a system whose logs only reach back 60 days can only ever sample 8% of the period it is supposed to cover.
7
Close the shared-network loophole
Clarify that the existing prohibition on a central repository of ALPR data covers vendor-hosted shared networks, require that any cross-agency sharing be affirmative, individually logged, and publicly listed, and address the commercial resale of privately collected plate data to law enforcement.
What the record shows
Flock’s cross-agency lookup functions as a central repository at national scale: a single search of St. Louis Park’s cameras reached 25,263 networks, and the one auditor who examined the platform flagged that cross-agency search may amount to a prohibited central repository. Meanwhile InsightLPR is selling access to privately collected plate data to Minnesota agencies, reportedly offering Duluth a free trial this year with access to 26 million scans collected last year. The statute regulates data agencies collect; the market has moved to data agencies buy.