On July 20, 2026, the California Court of Appeal (Fourth Appellate District, Division One) issued its decision in Mata v. Digital Recognition Network, Inc., No. D084781, holding that standing to sue under California’s Automated License Plate Recognition (ALPR) statute (Civ. Code §§ 1798.90.5–1798.90.55) requires a showing of actual harm arising from a statutory violation instead of a bare technical violation or a plaintiff’s subjective privacy concerns.

The ALPR Statute’s Private Right of Action

California’s ALPR Law requires operators and end-users to maintain reasonable security procedures and to implement and publicly post a usage and privacy policy addressing various topics. Section 1798.90.54 of the ALPR authorizes a private right of action for “an individual who has been harmed by a violation” to recover actual damages or at least $2,500 in liquidated damages, plus punitive damages, attorney fees, and injunctive relief.

What the Plaintiff Alleged

The plaintiff alleged that Digital Recognition Network tracked his license plate and maintained a privacy policy only as “lip service.” Critically, his own ALPR data was never breached, accessed without authorization, or misused. The trial court granted summary judgment, and the Fourth District affirmed.

The court reasoned that Section 1798.90.54(a)’s text—“harmed by a violation”—requires more than a bare statutory violation. The statute identifies, but plaintiff could not establish, any of the three illustrative harms (unauthorized access, unauthorized use, or a breach of security).

The court distinguished Bartholomew v. Parking Concepts, Inc., 118 Cal.App.5th 438 (1st Dist. 2026), a decision we discussed in a prior article, on the basis that the defendant’s complete failure in that case to post any ALPR policy satisfied the requisite harm. Comparatively, in Mata, the defendant maintained a policy and plaintiff’s theory that the policy was insincere, or that mass collection itself invades privacy, was insufficient.

Practical Significance

Mata highlights a potential, though likely factual, standing defense for ALPR defendants if plaintiffs cannot identify an actual misuse, breach, or unauthorized access of their specific data. However, it also does not appear to disturb Bartholomew’s holding that a complete failure to post a compliant policy remains actionable.

Businesses that operate or use ALPR systems should have a compliant, publicly posted usage and privacy policy that matches what they actually do. If a business says one thing in its policy but does another in practice, that gap could still expose it to liability, even under the Mata decision.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Anthony Q. Le Anthony Q. Le

Anthony has a broad array of experiences assisting with compliance issues, regulatory and enforcement matters, internal investigations, and individual and class litigation. His diverse practice helps him achieve the most efficient and practical results for his clients spanning the financial services, technology, automobile…

Anthony has a broad array of experiences assisting with compliance issues, regulatory and enforcement matters, internal investigations, and individual and class litigation. His diverse practice helps him achieve the most efficient and practical results for his clients spanning the financial services, technology, automobile, and retail sectors.

Photo of Alicia A. Baiardo Alicia A. Baiardo

Ali, a partner in the San Francisco office of McGuireWoods, is a commanding commercial litigator trusted by three of the largest U.S. banks and numerous Fortune Global 500 companies to defend high-stakes, multimillion-dollar class actions and other complex litigation. Her practice spans nationwide…

Ali, a partner in the San Francisco office of McGuireWoods, is a commanding commercial litigator trusted by three of the largest U.S. banks and numerous Fortune Global 500 companies to defend high-stakes, multimillion-dollar class actions and other complex litigation. Her practice spans nationwide consumer class actions involving millions of class members, California-wide cases alleging unfair competition, fraud, violation of various consumer protection statutes, complex Ponzi-scheme matters brought against financial institutions, and the rapidly evolving landscape of mass arbitrations. She has a strong track record of successfully representing clients through trial, including defending major national banks in multidistrict class action litigation and individual class actions, skillfully navigating the regulatory implications that often accompany such matters.

Photo of Payam Khodadadi Payam Khodadadi

Payam graduated from law school in the top 3% of his graduating class. Payam practices in the areas of data privacy and security, restructuring and insolvency, and complex litigation. In each year from 2013 through 2020, Payam was selected by the prestigious Super…

Payam graduated from law school in the top 3% of his graduating class. Payam practices in the areas of data privacy and security, restructuring and insolvency, and complex litigation. In each year from 2013 through 2020, Payam was selected by the prestigious Super Lawyers publication as a “Rising Star.”

Photo of Christian Hochhausler Christian Hochhausler

Christian is an associate in the Financial Services & Securities Enforcement Department. His practice includes both financial services litigation and white-collar litigation. He represents a wide range of clients, including large financial institutions, startups, fintech companies, and aerospace companies. He defends clients at…

Christian is an associate in the Financial Services & Securities Enforcement Department. His practice includes both financial services litigation and white-collar litigation. He represents a wide range of clients, including large financial institutions, startups, fintech companies, and aerospace companies. He defends clients at all stages of litigation in individual plaintiff actions, mass arbitrations, consumer class actions, and government investigations.