Reading the Fine Print: Standing, Harm and California’s License Plate Reader Law
As we discussed in our earlier client alert, “,” the California Court of Appeal’s February 2026 decision in Bartholomew v. Parking Concepts, Inc., 118 Cal. App. 5th 438 (2026), revived California’s dormant law on automated license plate readers (ALPRs) and triggered a wave of putative class actions against businesses that operate license-plate-reading cameras. We are issuing this second alert because the landscape has already shifted—on July 20, 2026, a different panel of the Court of Appeal reached a markedly different conclusion in Mata v. Digital Recognition Network, Inc., creating an appellate split on the threshold question of what a plaintiff must show to sue. This alert focuses on Mata, how it diverges from Bartholomew, and what the emerging split means for California businesses.
A Brief Recap of the Statute
As detailed in our first alert, the California ALPR Privacy Act governs any public or private entity that operates an “ALPR system,” a searchable database created from cameras and algorithms that convert license plate images into computer-readable data. It imposes three duties on an “ALPR operator”: maintaining reasonable security safeguards; implementing a public, conspicuously posted usage and privacy policy covering authorized purposes and personnel, security monitoring, data-sharing terms, the responsible custodian, accuracy measures, and retention and destruction practices; and keeping a record of any access to ALPR information. The statute does not restrict a private entity’s collection or use of ALPR information or require notice or consent, giving operators, as the Bartholomew court put it, “wide leeway to determine what to do with this data.”
The provision now being tested in court is the private right of action. Section 1798.90.54(a) lets individuals who have been “harmed” by a violation to sue for actual and liquidated damages.
Bartholomew and the Litigation Wave
The recent ALPR litigation wave has swept up a wide range of business including parking operators, malls, retailers, grocery chains, hotels, residential communities, and property owners— many of which do not consider themselves to be traditional operators of surveillance technology. The $2,500 per-person liquidated damages floor, paired with the class action posture plaintiffs favor, can produce substantial aggregated exposure, and practitioners have compared the statute to the California Invasion of Privacy Act.
This exposure was largely theoretical while the statute lay dormant, until Bartholomew changed that in February 2026. The court held that a parking garage camera system qualified as an ALPR system and that collecting and maintaining ALPR information without the required usage and privacy policy harms individuals by violating their right to know how their data is used. Read as lowering the threshold for pleading harm, the decision triggered the wave of filings against commercial defendants.
The Mata Decision
Now, on July 20, 2026, the Court of Appeal has affirmed summary judgment for an ALPR operator whose system held more than nine billion historical license plate images. Unlike the Bartholomew defendant, this operator had adopted a usage and privacy policy in late 2015 meeting all seven statutory requirements, hyperlinked on its website homepage as its “California ALPR policy.”
Mata’s putative class action alleged that the posted policy only created the appearance of compliance, was not meaningful or conspicuously posted, and reflected inadequate security. Yet the undisputed facts showed that the named plaintiff’s data had never been breached, accessed, or misused, that he suffered no identity theft, stalking, physical injury, lost wages, or monetary loss, and that only his own attorneys had accessed his data, with his authorization, for the litigation. He had never visited the defendant’s website to review the policy before suing and described his harm only as a subjective “collection-based invasion of privacy.”
The court held that the statute’s plain text requires actual harm arising from a violation, not the violation alone. Among other things, the court noted that the statute’s three examples of harm are all examples of actual rather than abstract injury. And while the $2,500 liquidated damages provision confirms harm need not be measurable in dollars, the court found that it does not authorize a suit based on the abstract harms that Mata asserted.
The Mata court agreed with Bartholomew that a bare violation is not enough, but voiced skepticism about Bartholomew’s holding that a plaintiff has standing based solely on an operator’s failure to, for example, adopt and post a policy. It also distinguished the facts: the Mata defendant, unlike the Bartholomew defendant, had adopted and posted a policy, a scenario Bartholomew expressly left open. Mata’s complaint was not that the defendant’s policy omitted required content, but that the defendant did not mean what it said, and the court doubted that insincerity can constitute a violation where there is literal compliance. It concluded that Mata’s subjective belief of harm was not cognizable, and that he had shown no harm from any alleged violation.
What This Means for Businesses and Future Litigation
Mata creates real tension with Bartholomew at the appellate level: both are Court of Appeal decisions, yet they diverge on whether a mere technical failure alone is enough to sue. Mata gives defendants a strong argument that a plaintiff alleging only a statutory violation and a generalized privacy concern, without misuse, disclosure, breach, or other concrete injury, lacks standing, though other courts may disagree until a higher court resolves the split.
For now, it remains prudent for businesses to reduce exposure regardless of how the appellate tension resolves. As detailed in the , companies should confirm conspicuous, compliant disclosures both at the point of collection and on their website; maintain reasonable security procedures, keep access records, and limit access to those with a genuine need; and confirm that vendor and customer agreements include compliance obligations. These measures should further be harmonized with the businesses’ other data governance and privacy compliance efforts, such as integrating disclosures into its broader privacy policies, observing the principles of data minimization and purpose limitation, and ensuring that personal data collected by ALPR systems is accounted for in compliance with federal, state, and international privacy laws.