Forecourt Video Analytics and LPR: Get the Law Right First

Known errors in this article have been corrected.
A full claim-by-claim review is still pending. Confirm any figure with your state program before acting on it. Last verified 2026-09-08. Not legal advice.
Start with the statute, not the camera
A camera above pump three that only records is governed by ordinary premises surveillance rules. The moment it reads a plate, converts it to text and stores it, you are operating an automated license plate reader, and a different body of law applies — state law, which is not uniform, and which in at least one state does not permit a private operator to run one at all.
This is the part of a forecourt analytics project that gets skipped, and it is the only part that can make the whole deployment unlawful rather than merely disappointing. So it comes first here. Identify the statute that governs plate capture where your sites are, by name, with counsel, before you specify hardware or sign anything. Then read the operational half of this guide.
Three states, three genuinely different regimes
The following are examples chosen because they sit far apart, not a survey. There is no national rule, no majority position you can safely assume, and several states have amended their plate-reader laws recently. Nothing below tells you what your own state does.
| State | Governing law | What it means for a private operator |
|---|---|---|
| California | Civil Code 1798.90.5 et seq. (Title 1.81.23) — in the Civil Code, not the Vehicle Code | Private ALPR operators and end-users may run a system, but carry duties: maintain reasonable security procedures, implement and post a usage and privacy policy, and log access to the data. The statute imposes no fixed retention cap on private operators; the shorter purge added by AB 1463 runs to public agencies. |
| New Hampshire | RSA 261:75-b | Operation of a number plate scanning device is restricted to local, county and state law enforcement officers. This is a restriction on who may operate one, not a retention rule — a private forecourt LPR deployment is not a matter of configuring it correctly. |
| Utah | Automatic License Plate Reader System Act, Utah Code 41-6a-2001 et seq. | The Act's restrictions run to governmental entities: 41-6a-2003(1) bars a governmental entity from using an ALPR system except for the listed purposes, and 41-6a-2004(2)(a) bars a governmental entity from selling captured plate data. A private forecourt operator is a "nongovernmental entity" under 41-6a-2002(5) and is not the subject of those prohibitions — but the Act does condition how a governmental entity may obtain plate data from you, so a law enforcement request for your data arrives with statutory strings attached. Confirm with counsel whether your specific use falls inside or outside the Act. |
Notice what the three do differently, and who each one binds. California regulates the conduct and paperwork of a private operator directly. New Hampshire regulates eligibility, restricting ALPR operation to law enforcement. Utah's Act runs to governmental entities rather than to you, but governs how they may obtain plate data from a private holder. A compliance posture built for one of them fails in the other two, and a vendor's boilerplate "privacy-compliant" claim addresses none of them specifically. The first question for counsel is not what the statute requires but whether it binds you at all.
What counsel needs to answer before you buy
- May a private operator run a plate reader here at all? If the answer is no, the project ends.
- What is the governing statute, by name and section? Get the citation in writing. A general reference to "state privacy law" is not an answer, and plate-reader rules do not always live where you would expect — California's are in the Civil Code.
- What may be transferred, and to whom? Sharing with law enforcement, with a vendor's cloud, with a regional watchlist, and with an insurer are four separate questions, and a state may treat them differently.
- Is there a retention limit, and does it apply to private operators or only to agencies? Conflating the two is the most common error in published summaries of this area.
- What notice must be posted, and where? Surveillance-notice rules vary by state and locality. Confirm yours rather than assuming a general rule.
- Do any of your sites sit in a different state? A multi-state operator needs the answer per state, not per company.
Governance you should adopt regardless
Whatever your state permits, put the following in writing before go-live, because these are also what a plaintiff's counsel will ask for. A documented retention period and an automatic deletion mechanism that actually runs. A named person accountable for the system. An access log. And a watchlist policy setting out how a plate is added, who reviews it, on what evidence, and how it comes off. Pre-authorization locking driven by an undocumented, informally maintained watchlist is the configuration most likely to generate a discrimination claim, and your written process is the first thing standing between you and one.
What the systems actually detect
With the legal question settled, here is the operational picture. Modern forecourt analytics is three layers: IP cameras with local or attached inference hardware; a software engine running on a local server or in the cloud where plate recognition, object detection and behavioural analysis happen; and an integration layer connecting that engine to the site controller and point of sale.
| Detection | How it works | How reliable |
|---|---|---|
| Plate recognition | Optical character recognition on the camera feed, matched against an internal or third-party list | Vendor-claimed only. No independent benchmark exists for forecourt conditions, and read rates vary with plate condition, state plate design, approach angle, speed and lighting. |
| Drive-off correlation | Matches a plate read against transaction status at the dispenser | Reliable within its own terms — it can only be as good as the plate read that feeds it |
| Person-down detection | Pose estimation flags abnormal body position or motionlessness | Emerging; heavily camera-angle dependent, with no published outdoor benchmark |
| Spill detection | Pixel-level change detection at the dispenser base | Moderate; degraded by weather, shadow and surface staining |
| Loitering and perimeter | Dwell-time thresholds on detected persons or vehicles in defined zones | Reliable in well-defined zones |
Vendors selling plate recognition into retail environments include Genetec, Milestone Systems, Rekor (OpenALPR) and Plate Recognizer. Motorola Solutions sells the Vigilant line, acquired in January 2019 as part of VaaS International Holdings, the parent of Vigilant Solutions and Digital Recognition Network. Do not assume any of them ships a connector for your site: make each vendor name the fuel point-of-sale platforms and software versions it is certified against, in writing.
Drive-off: measure your own baseline first
Fuel theft is the use case that sells these systems, and it is genuinely site-specific. The only number that belongs in your case is your own: pull twelve months of point-of-sale exception reports and total the loss before you take a demo. A system that repays itself at a high-loss site may never repay itself at a low-loss one, and no published figure tells you which you have.
Integrated plate recognition runs in two modes. In pre-authorization mode the camera reads the plate on approach and the dispenser stays locked pending prepayment if the plate is on a watchlist. In post-transaction mode the system logs every plate that fuels, flags departures without a matching transaction, and packages the plate image, timestamp and vehicle description for a police report. The first mode is operationally stronger and legally heavier — it acts on a person before any transaction, which is exactly why the watchlist governance above is not optional.
If your sites run Gilbarco Encore dispensers or Wayne dispensers, confirm with Invenco by GVR or Dover Fueling Solutions, and with the analytics vendor, that a supported interface for pre-authorization locking exists on your specific site controller and software version. Integration usually needs a middleware appliance on site and coordination between two vendors. Ask each to quote integrator hours against your actual configuration.
Safety and environmental monitoring: what video is, and is not
The forecourt carries real slip, fall and medical-emergency exposure, and detection that alerts inside staff to a person down at a remote island late at night is worth having. Its value in litigation is documentary: time-stamped evidence that staff responded promptly. Be precise about what it is not. OSHA's medical services and first aid standard, 29 CFR 1910.151, protects employees. It requires ready availability of medical personnel for advice and consultation, and, where no infirmary, clinic or hospital is in near proximity, a person adequately trained to render first aid plus adequate supplies. It says nothing about customers and nothing about video. Footage is evidence in a civil claim, not a compliance record under that standard.
Spills are similar. 40 CFR 280.30 requires that releases from spilling or overfilling do not occur; the reporting duty sits in 40 CFR 280.53, which requires a spill or overfill of petroleum resulting in a release to the environment of more than 25 gallons — or another reasonable amount specified by the implementing agency — to be reported to that agency within 24 hours. A smaller spill contained and cleaned up within 24 hours need not be reported, but must still be contained and cleaned up. Video-based spill detection does not substitute for under-dispenser containment, spill buckets or shear valves from suppliers such as OPW and Morrison Bros. What it adds is a time-stamped record of when a spill started and how fast it was addressed, which is useful precisely because the reporting clock is short. Our guide to release reporting timelines and agency procedures covers the downstream obligations.
On fire, NFPA 30A is the code framework for motor fuel dispensing facilities, adopted in the edition your authority having jurisdiction has taken up. Camera-based smoke and flame-flicker detection exists in enterprise platforms, but it is a supplemental tool and never a substitute for listed fire detection equipment. Treat it that way in your fire plan.
Deployment: placement, lighting, and the questions to ask
Plate recognition accuracy is dominated by physical setup, not software. Resolution of at least 1080p, higher where one camera covers multiple lanes. Frame rates high enough to hold a moving vehicle. Infrared or supplemental illumination for overnight reads. And a shallow capture angle — steep downward mounting degrades character recognition badly, which is why the tidiest canopy position is often the worst. Lighting feeds directly into this: if yours is due for work, coordinate our guide to canopy maintenance and LED lighting upgrades with the camera plan rather than after it.
Put these to every vendor, and require an on-site pilot under your own lighting and layout rather than a demo reel:
- What read performance do you achieve at night and in my climate's weather, demonstrated at my site?
- Which fuel point-of-sale platforms and versions are you certified against?
- Where is plate data stored, in which jurisdiction, and what is the contractual deletion timeline?
- Do you operate a shared regional watchlist, who governs it, and can I opt out of contributing to it?
- What happens to detection and to the dispenser lock if your service is unreachable?
- Will the system work over my existing camera cabling, or is a re-cable in scope?
Analytics belongs on top of a working physical foundation — lighting, containment, emergency shutoffs, signage and trained staff. It augments human awareness rather than replacing it, and it sits alongside the rest of your loss and safety programme, including robbery prevention and threat response training. Because these systems put plate data and video on a network, they also enlarge your attack surface: fold them into your station cybersecurity review rather than treating them as isolated appliances.
The sequence that keeps you out of trouble: identify the governing statute by name, confirm a private operator may run the system at all, write the retention and watchlist policies before go-live, measure your own drive-off baseline, then buy. Reversing those steps is how a loss-prevention project becomes a legal one.
Sources
Citations in this article were checked against the following primary sources on 2026-09-08.
- California Civil Code 1798.90.5 et seq. — collection of license plate information
- California AB 1463 (2023-24) — ALPR retention and use of information
- New Hampshire RSA 261:75-b — use of number plate scanning devices regulated
- Utah Code 41-6a-2001 et seq. — Automatic License Plate Reader System Act, published by the Utah Legislature at le.utah.gov
- 29 CFR 1910.151 — medical services and first aid
- 40 CFR 280.30 — spill and overfill control
- 40 CFR 280.53 — reporting and cleanup of spills and overfills
- NFPA 30A, Code for Motor Fuel Dispensing Facilities and Repair Garages — consult the edition adopted by your authority having jurisdiction, at nfpa.org
- Motorola Solutions — acquisition of VaaS International Holdings, parent of Vigilant Solutions and Digital Recognition Network, January 2019, at motorolasolutions.com
- Invenco by GVR — Gilbarco Veeder-Root retail solutions business rebranded, July 2023, at invenco.com