Reported / Citable
Background
Digital Recognition Network operates an automated license plate recognition (ALPR) system, which combines cameras, software, and a searchable database to collect and store license-plate information. Guillermo Mata alleged that the company failed to comply with California’s ALPR statute, including requirements concerning security procedures and a public usage-and-privacy policy. He sought to represent a class and obtain the statute’s minimum liquidated damages.
Mata did not identify an unauthorized disclosure, misuse, security breach, financial loss, or other concrete consequence involving his information. Instead, he asserted that collection and storage themselves invaded his privacy and that this subjective concern was enough to sue. The trial court granted summary judgment to the company for lack of statutory standing. After judgment, class member Scott Aker also sought to intervene as a replacement representative, but the court denied that request.
The Court’s Holding
The Fourth District affirmed. Civil Code section 1798.90.54 authorizes suit by an individual who has been harmed by a violation against a person who knowingly caused the harm. Reading those words according to their ordinary meaning, the court held that a statutory violation alone is insufficient: the plaintiff must show actual harm caused by the defendant. The statute’s availability of at least $2,500 in liquidated damages affects the measure of recovery after standing exists; it does not eliminate the threshold harm requirement.
Mata’s belief that the collection and retention of plate data invaded his privacy did not establish the necessary injury on this record. The court distinguished statutes in which the Legislature expressly makes the violation itself actionable. It also affirmed denial of Aker’s intervention request because his appellate briefing failed to challenge both independent grounds supporting the trial court’s order, including untimeliness. Failing to address an independent basis for a ruling forfeits the challenge.
Key Takeaways
- A plaintiff invoking California’s ALPR private right of action must prove actual harm, not merely a technical violation of statutory procedures.
- The statute’s liquidated-damages floor does not create standing where the plaintiff cannot first connect a cognizable injury to the violation.
- ALPR operators still face exposure for unauthorized access, disclosure, security breaches, or other violations that produce demonstrable harm.
- Privacy plaintiffs should investigate and plead the concrete consequence of data collection or misuse, including disclosure, surveillance effects, economic loss, or another recognized injury.
- On appeal, every independent ground supporting an order must be challenged; leaving one unanswered can end the appeal without review of the others.
Why It Matters
The decision narrows a potentially broad source of class-action liability for private ALPR businesses and other entities using plate-reading technology. California’s statute requires specified safeguards and policies, but this opinion separates regulatory noncompliance from a damages claim: a private plaintiff needs an injury caused by the violation. Businesses should not treat that limit as permission to relax compliance, because a breach, misuse, or unauthorized disclosure can supply the missing harm and expose the operator to statutory and other remedies.
For privacy counsel, the pleading and proof strategy now matters more than labeling the practice invasive. The record should establish what happened to the claimant’s information, who accessed it, how the violation changed the claimant’s position, and why the defendant knowingly caused that consequence.