On July 20, 2026, the California Court of Appeal (Fourth Appellate District, Division One) issued its decision in Mata v. Digital Recognition Network, Inc., No. D084781, holding that standing to sue under California’s Automated License Plate Recognition (ALPR) statute (Civ. Code §§ 1798.90.5–1798.90.55) requires a showing of actual harm arising from a statutory violation instead of a bare technical violation or a plaintiff’s subjective privacy concerns.
The ALPR Statute’s Private Right of Action
California’s ALPR Law requires operators and end-users to maintain reasonable security procedures and to implement and publicly post a usage and privacy policy addressing various topics. Section 1798.90.54 of the ALPR authorizes a private right of action for “an individual who has been harmed by a violation” to recover actual damages or at least $2,500 in liquidated damages, plus punitive damages, attorney fees, and injunctive relief.
What the Plaintiff Alleged
The plaintiff alleged that Digital Recognition Network tracked his license plate and maintained a privacy policy only as “lip service.” Critically, his own ALPR data was never breached, accessed without authorization, or misused. The trial court granted summary judgment, and the Fourth District affirmed.
The court reasoned that Section 1798.90.54(a)’s text—“harmed by a violation”—requires more than a bare statutory violation. The statute identifies, but plaintiff could not establish, any of the three illustrative harms (unauthorized access, unauthorized use, or a breach of security).
The court distinguished Bartholomew v. Parking Concepts, Inc., 118 Cal.App.5th 438 (1st Dist. 2026), a decision we discussed in a prior article, on the basis that the defendant’s complete failure in that case to post any ALPR policy satisfied the requisite harm. Comparatively, in Mata, the defendant maintained a policy and plaintiff’s theory that the policy was insincere, or that mass collection itself invades privacy, was insufficient.
Practical Significance
Mata highlights a potential, though likely factual, standing defense for ALPR defendants if plaintiffs cannot identify an actual misuse, breach, or unauthorized access of their specific data. However, it also does not appear to disturb Bartholomew’s holding that a complete failure to post a compliant policy remains actionable.
Businesses that operate or use ALPR systems should have a compliant, publicly posted usage and privacy policy that matches what they actually do. If a business says one thing in its policy but does another in practice, that gap could still expose it to liability, even under the Mata decision.