# ASP ALPR Policy, Retention, and FOIA Exemption Proposal
Two newly recovered records place ASP's written policy, live platform configuration, and vendor disclosure strategy side by side. They establish what the records said and how the vendor described the setting; they do not establish the complete purge history or resolve which policy provision governed the 2025 fixed-camera network.
## The configured retention setting
On 2025-06-04, Leonardo/ELSAG Senior Business Development Manager [[Robert Ryan]] told [[Dennis Overton]]:
> "Just confirming for you that I just checked and confirmed that ALL ASP cameras in HIDTA are set to 150 day data retention." (Tier-1 corpus, `RE_ Data Retention.msg`).
That is direct configuration evidence for the ASP/HIDTA camera domain as of the email date. It does not show when the setting began, whether it changed, or whether purges occurred as configured.
## Vendor proposal for an Arkansas FOIA exemption
Ryan followed the configuration confirmation with a policy recommendation:
> "I would recommend that you approach the legislature about listing LPR data as a specific exemption from FOIA records." (Tier-1 corpus, `RE_ Data Retention.msg`).
He described a "pattern of life" concern and pointed to Kansas, Georgia, Texas, and Louisiana disclosure rules. The email is vendor advocacy sent to ASP, not an Arkansas legal determination and not evidence that the cited out-of-state descriptions are complete.
## The policy in ASP's December 2024 manual
The PowerDMS distribution email says the attached manual **"will replace any other policy manuals used prior to today's published manual"** (`_ The ASP Policy Manual has been updated _ NO DOCUMENTS TO SIGN .msg`, 2024-12-02). Its ALPR page is **LE SEC 28**, effective 2011-10-12 (`ASP Policy Manual - Mike Hagar, Director_Secretary (1).pdf`, PDF p. 344).
The policy:
- limits authorized users to current ASP employees allowed to review criminal-history data;
- says ALPR use and captured data are only for assigned law-enforcement purposes;
- requires each hit to be verified and says positive hits should be recorded on ASP 999 forms included with monthly reports; and
- states: **"Image data files captured will only be maintained for an open/active criminal investigation."**
The page was published in the December 2024 manual, but its effective date and patrol-unit/flash-drive language show that it originated in an earlier hardware architecture. The corpus does not yet contain a successor policy expressly reconciling LE SEC 28 with the HIDTA-hosted fixed network.
> [!contradiction]
> LE SEC 28 says image files "will only be maintained for an open/active criminal investigation," while Ryan confirmed that "ALL ASP cameras in HIDTA are set to 150 day data retention" (`ASP Policy Manual ... (1).pdf`, PDF p. 344; `RE_ Data Retention.msg`). [[T037 - ASP Active-Investigation-Only Image Policy vs 150-Day HIDTA Retention|T037]] keeps the scope, successor-policy, and implementation questions open.
## Safety and handling
The 1,202-page manual is an unencrypted, Defender-clean PDF with fourteen form fields, two JavaScript form actions, and five legacy local-document launch actions. No action was executed. PDF page 344 was extracted and visually checked against its render.
## Open questions
- Was LE SEC 28 still the operative policy for the fixed HIDTA system in June 2025, or did an unproduced successor directive control it?
- Did ASP 999 monthly reports continue under the fixed network, and where are they retained?
- What configuration-change and purge logs establish actual compliance with the 150-day setting and case-preservation rules?
- Did ASP pursue Ryan's suggested statutory exemption, and if so, what agency legal or legislative records document that effort?