Police can share personal information, but only when a specific federal or state law authorizes the disclosure. The default rule treats most data held by law enforcement as confidential. Some records, like daily arrest logs and incident reports, are public by design. Others, especially anything tied to an open case or a vulnerable person, are locked down. And when officers step outside the rules, you have concrete legal remedies that vary depending on which agency did the sharing.
What Police Records Are Public by Default
A significant slice of what police produce is available to anyone who asks. There is no federal Freedom of Information Act right against state or local departments (FOIA covers only federal agencies),1FOIA.gov. Freedom of Information Act – Learn but every state has its own public records law, and they generally presume government records are open unless a specific exemption applies.
The records commonly available through a public records request include:
- Arrest logs, sometimes called the police blotter, listing who was arrested, where, and on what charges.
- Incident reports recording the date, time, location, and nature of a reported crime.
- 911 call recordings, though portions identifying callers are often redacted.
- Booking photographs, though a growing number of jurisdictions restrict their release to prevent exploitation by commercial mugshot sites.
Even when a record is technically public, agencies routinely redact sensitive details before releasing anything. Victim names, witness contact information, and details that could endanger someone get blacked out. You still learn what happened; you don’t learn who to go after.
What Police Cannot Share
Federal FOIA’s law enforcement exemption, and its state equivalents, let agencies withhold records when disclosure could reasonably be expected to interfere with enforcement proceedings, deprive someone of a fair trial, invade personal privacy, reveal a confidential source, expose investigative techniques, or endanger physical safety.2U.S. Department of Justice. FOIA Guide – Exemption 7 In practice, the same categories come up again and again:
- Active investigation files. Anything tied to an open case stays confidential, because releasing it could tip off suspects or taint witnesses.
- Confidential informant identities. This protection often survives even after a case closes.
- Victim information, especially in sexual assault and domestic violence cases, is shielded in virtually every state.
- Juvenile records. Records involving minors are sealed or otherwise restricted from public access.
Federal Laws That Restrict Police Disclosure
Two federal statutes set the floor for how law enforcement handles your personal data. Which one applies to your situation matters, because they cover very different ground.
The Driver’s Privacy Protection Act
The Driver’s Privacy Protection Act (DPPA) prohibits state DMVs and their employees from releasing personal information from motor vehicle records unless a specific exception applies. Personal information under the DPPA includes your name, address, phone number, Social Security number, photograph, and medical or disability data, but not your driving violations or accident history.3Office of the Law Revision Counsel. 18 U.S. Code 2725 – Definitions Your photo, Social Security number, and medical data sit in a more protected tier called “highly restricted personal information,” which requires your express consent before release in most situations.
The permitted exceptions are narrow. DMV data can be shared for vehicle safety and recall purposes, insurance claims investigations, and use by any government agency (including law enforcement) carrying out its official functions.4Office of the Law Revision Counsel. 18 U.S.C. 2721 – Prohibition on Release and Use of Certain Personal Information From State Motor Vehicle Records Outside those categories, the information stays locked.
The DPPA has real teeth. Anyone who knowingly obtains, discloses, or uses DMV personal information for an unauthorized purpose faces a civil suit by the affected individual. Courts can award actual damages with a floor of $2,500 in liquidated damages, punitive damages for willful or reckless violations, and reasonable attorney fees.5Office of the Law Revision Counsel. 18 U.S. Code 2724 – Civil Action
The Privacy Act of 1974
The Privacy Act restricts how federal agencies collect, maintain, and disclose records about individuals. Important limitation: it applies only to federal agencies. It does not cover state or local police departments.6U.S. Department of Justice. Overview of the Privacy Act – Definitions If your city police officer leaks your address, the Privacy Act is not the statute you’d sue under.
For federal law enforcement agencies like the FBI, DEA, or ATF, the Privacy Act prohibits disclosing your records to third parties without your written consent, with exceptions for law enforcement purposes, court orders, and certain routine uses. Federal employees who willfully disclose protected records face a misdemeanor conviction and a fine of up to $5,000. If you’re harmed by a willful or intentional violation, you can sue with a guaranteed minimum recovery of $1,000 in damages plus attorney fees.7Office of the Law Revision Counsel. 5 U.S.C. 552a – Records Maintained on Individuals
Sharing Between Law Enforcement Agencies
Information passed from one law enforcement agency to another is not public disclosure. It’s a controlled exchange, governed by federal rules about who can see what.
The National Crime Information Center, run by the FBI’s Criminal Justice Information Services (CJIS) Division, connects criminal justice agencies across all 50 states, U.S. territories, and select foreign countries. Authorized users query records on wanted persons, stolen property, missing individuals, and criminal histories. Access is limited to criminal justice agencies and specific authorized noncriminal justice entities.8Federal Bureau of Investigation. Privacy Impact Assessment for the National Crime Information Center The CJIS Security Policy sets the guardrails: access controls, encryption, audit trails, and personnel screening for everyone who handles the data.9Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy
Criminal intelligence databases sit under a separate federal regulation. Agencies can only collect intelligence on an individual when there is reasonable suspicion of criminal activity, and the information must be relevant to that activity. Intelligence cannot be gathered based on political views, religious beliefs, or social associations unless those directly relate to criminal conduct. Dissemination requires both a “need to know” and a “right to know,” and every disclosure gets logged with recipient, reason, and date.10eCFR. 28 CFR Part 23 – Criminal Intelligence Systems Operating Policies
When an investigation wraps up, the case file moves to the prosecutor’s office. Once the information enters the court system through a judicial proceeding, it generally becomes accessible through public court records, though judges can seal sensitive material.
Where the Rules Are Thinnest: Digital Data
The framework above was built for paper files and radio dispatches. Modern policing generates volumes of digital data that fit awkwardly into the older rules.
Body-worn camera footage sits between public record and private surveillance. Recordings tied to active investigations are generally exempt from public disclosure. Footage captured inside a home gets stronger protection than footage from a public street. The subjects of a recording, their attorneys, and in many states the parents of recorded minors can typically request copies even when the footage is exempt from broader public release.
Automated license plate readers capture millions of scans daily and build a detailed record of vehicle movements. No federal law specifically governs retention or sharing of this data, and agency policies range from purging within days to keeping years of searchable history that other agencies can query.
Facial recognition regulation lags further still. Congress has introduced legislation to restrict law enforcement use of the technology but has not passed it. As of late 2024, roughly 15 states had enacted some limits; four require a warrant, probable cause, or court order before a facial recognition search, and six restrict the technology to investigations of serious crimes. Most states impose no limits at all.
Then there’s the data broker gap. Federal law prohibits phone and internet companies from selling customer data directly to government agencies. But those companies can sell it to a data broker, and the broker can sell it to law enforcement. Legislation to close that loophole has been introduced in Congress but had not been enacted as of early 2026.
What to Do If Police Shared Your Information Improperly
Your remedy depends on which agency shared what. Getting this right at the outset saves time and money.
Internal Affairs Complaint
Filing a complaint with the department’s internal affairs division is the simplest first step. Unauthorized disclosure of personal information falls squarely within their mandate. This costs nothing and can result in officer discipline. It won’t get you monetary damages.
DPPA Lawsuit
If someone improperly accessed or disclosed your DMV-related personal information, the DPPA gives you a direct cause of action in federal court. You don’t need to prove a constitutional violation or a departmental policy failure. The statute guarantees at least $2,500 in liquidated damages even without proof of specific financial harm, plus punitive damages and attorney fees if the violation was willful.5Office of the Law Revision Counsel. 18 U.S. Code 2724 – Civil Action
Privacy Act Claim Against a Federal Agency
If the FBI, DEA, or another federal agency improperly disclosed your records, the Privacy Act of 1974 lets you sue in federal district court. Willful or intentional violations carry a guaranteed minimum of $1,000 in damages plus attorney fees, and the responsible employee can face criminal prosecution and a fine of up to $5,000.7Office of the Law Revision Counsel. 5 U.S.C. 552a – Records Maintained on Individuals This route is only available against federal agencies, not your city or county police department.
Section 1983 Civil Rights Suit
For privacy violations by state or local police, the primary federal tool is a civil rights lawsuit under Section 1983. The statute lets you sue anyone who, acting under state law authority, deprives you of rights secured by the Constitution or federal law.11Office of the Law Revision Counsel. 42 U.S. Code 1983 – Civil Action for Deprivation of Rights A disclosure-based claim would typically allege a violation of your constitutional right to informational privacy.
These cases are harder to win than DPPA claims. You have to prove the officer’s action violated a clearly established constitutional right, and officers can raise qualified immunity, arguing the right was not sufficiently defined at the time of the violation. Courts have recognized a right to informational privacy in some circuits, but the contours are not consistent nationwide. The statute of limitations borrows from each state’s personal injury deadline, which runs two to three years in most states.
State Attorney General and Civilian Oversight
Beyond lawsuits, you can complain to your state attorney general’s office or a civilian review board if your city has one. These bodies can investigate patterns of misconduct, impose corrective measures on departments, and in some cases pursue enforcement actions. They are especially useful when the problem is systemic rather than one officer’s bad judgment.
If a Police Department Suffers a Data Breach
Police departments are not immune to cyberattacks, and every state now has a data breach notification law. The majority apply to government agencies, so a department that suffers a breach exposing your personal information generally must notify you within a set timeframe. Roughly 36 states also require the breached entity to report the incident to the state attorney general or another oversight agency, and about 21 states maintain online portals where reported breaches can be checked.
If a notification arrives, treat it like any other breach: monitor your credit, consider a fraud alert or credit freeze, and document everything. The fact that a police department was breached doesn’t change the practical steps you need to take.