# ASP HIDTA Governance Terms and Administrator Duties This message preserves the onboarding package sent to ASP for Houston HIDTA participation: a blank fourteen-page MOU, five-page LPR policy, March 2024 member-agency list, and blank point-of-contact workbook. Later ASP correspondence establishes that a signed ASP/Houston HIDTA MOU was transmitted, but the attachment here is a template with an empty execution page, not that signed copy. ## Onboarding message Houston HIDTA LPR Coordinator [[Elizabeth Reyes]] described the program as a no-cost conduit and storage service for participating agencies and wrote: > "a signed MOU must be on file with the HIDTA in order for your agency to have access to the HIDTA LPR sever [sic]." (`FW_ HIDTA LPR MOU Signature Request - Arkansas State Police_ AR.msg`, forwarded 2025-05-08). She said the MOU had to be accepted "as is," required a member-agency LPR administrator, and required introductory and administrative training before access. ## Custody, sharing, and audit terms The blank MOU template states: - data are shared only to authorized users with a need and right to know; a member agency is not required to contribute data; withdrawn data and replications must be deleted by hosts within 48 hours (`HHIDTA LPR MOU 11.15.22 _Secure.pdf`, p. 5); - the origin agency remains the official custodian and information requests are referred to it (`...MOU...pdf`, p. 6: "Member Agencies shall retain control of, and remain the official custodian of, all information they contribute"); - an access audit log is maintained for at least twelve months (`...MOU...pdf`, p. 6); - only the origin agency or official custodian may release database information under a court order or public-records request (`...MOU...pdf`, p. 10); and - state law controls retention; if state law is silent, the ceiling is two years, subject to evidentiary preservation (`...MOU...pdf`, p. 11). The template's broad recitals encompass records-management, CAD, ALPR, intelligence, jail-management, and other law-enforcement data-sharing systems (`...MOU...pdf`, p. 2). The ASP package documents the terms proposed to ASP, not that ASP actually contributed every named data class. ## Administrator and query controls The member administrator must conduct monthly user/access audits, approve and audit all agency hot lists, report camera additions/removals, and enforce training (`...MOU...pdf`, p. 8; `Houston HIDTA LPR Policy 11.15.22_Secure.pdf`, pp. 4-5). The MOU says a query request must include: > "the purpose of the request, the agency's incident or report number (physical record number), the requestor's name, the requestor's agency and requestor's contact information." (`...MOU...pdf`, p. 11). After evidentiary LPR information is disseminated, the completed report enters a searchable internal database for future analysis and auditing (`...MOU...pdf`, p. 12). ## Retention and centralized storage The policy says participating agencies can eliminate local storage while retaining round-the-clock access, and that data are stored by HHIDTA (`Houston HIDTA LPR Policy 11.15.22_Secure.pdf`, pp. 1-2). Its default is two years, but: > "If a Member Agency is in a state where LPR data retention is regulated by state law, all data received from the Member Agency will be retained for the period designated in the legislation." (`...Policy...pdf`, p. 2). The policy also says all user activity is logged and that the HHIDTA administrator performs random monthly query/usage audits (`...Policy...pdf`, pp. 2-3). Its statement that LPR data are "not open to the public" is the template drafter's legal position; the document does not decide Arkansas disclosure law. ## Blank supporting files - `Agency Point of Contact Form_blank.xlsx` contains only the title and columns for agency/name/title/address/phone/email, followed by blank rows. No completed ASP contact data appear. - `Attachment A - Member Agencies - 03.13.24_by_state.Pdf` predates ASP's documented 2025 execution sequence and does not list Arkansas State Police. ## What this resolves and does not resolve The recovered template resolves the earlier absence of the governing **form terms**. It does not supply the executed ASP signature page, prove which revisions governed ASP, or establish that every template duty was performed. Current administrator rosters, monthly user audits, hot-list audits, query logs, dissemination records, and purge evidence remain unproduced.