On July 20, 2026, the California Court of Appeal, Fourth Appellate District issued a notable decision in Mata v. Digital Recognition Network, Inc.,[1] which addresses the standing requirements for private claims under California’s Automated License Plate Recognition (“ALPR”) law. At the heart of the decision lies the question whether a violation of the ALPR statute with no articulated resulting harm other than the subjective belief that the plaintiff’s privacy has been invaded confers standing to sue under the ALPR law.  The California Court of Appeal said no.

The Allegations

Mata alleges that Digital Recognition Network (“DRN”) collected and stored license plate images and related date, time, and location information from vehicles in public places. However, it was undisputed by the parties that DRN actually had a ALPR privacy policy in place and made the policy publicly available. Rather, Mata alleged that DRN’s implemented privacy policy was done “to maintain the appearance of adhering” to the law and that DRN “does not really mean what it says in the policy.” It was further undisputed that Mata’s ALPR data was never accessed without authorization, was only ever accessed by his own attorneys in connection with the litigation, and he suffered no physical or monetary harm.  Instead, Mata’s alleged harm theory was what he called a “collection-based invasion of privacy” harm – namely, the harm he suffered arose from the very collection of ALPR data that the ALPR law specifically permits.

The Court’s Conclusion: Actual Harm is Required

Looking to the statutory text and the legislative history of the ALPR law, the Court held that Mata’s alleged harm was not enough to confer standing. In so doing, it agreed with Bartholomew v. Parking Concepts, Inc.,[2] where the Fifth Appellate Division of the California Court of Appeal “rejected the plaintiff’s argument ‘that harm results from any violation of the ALPR law’ and held that standing ‘require[s] harm beyond a mere statutory violation.” Conversely, in dicta it indicated skepticism towards Bartholomew’s holding that the absence of a publicly displayed ALPR policy was sufficient to confer standing under a “right to know” theory of harm at the pleading stage. Significantly, however, the Mata court did not reach that question as one of the key differentiators between the matters was that DRN undisputedly implemented and displayed its ALPR policy, while the defendant in Bartholomew allegedly did not have one posted at all.

Take Aways & Action Items

For companies that operate or use ALPR systems, Mata is a helpful standing decision, but not a catch-all or safe harbor. The ruling solidifies that being able to demonstrate an implemented ALPR privacy policy that is adequately publicly displayed will make it more difficult for plaintiffs to pursue claims under the law. Under Mata, plaintiffs will be forced to allege policy or procedural deficiencies connected to the ALPR law’s requirements. Plaintiffs will also need to demonstrate actual harm resulting from those violations, such as unauthorized access, improper use, inadequate security, over-retention, or other tangible consequences flowing from alleged noncompliance.

Companies using or receiving ALPR information in California should continue to treat ALPR compliance as a priority. Recommended steps include confirming whether the organization is an ALPR operator or end-user; maintaining a current, publicly available ALPR usage and privacy policy; reviewing vendor and customer agreements for appropriate limits on collection, access, use, sharing, retention, security, audit rights, and deletion; and documenting operational compliance through training, access controls, retention schedules, and incident response procedures. These facts may be central to defending future claims following the decisions in Mata and Bartholomew.


[1] Mata v. Digital Recognition Network, 2026 WL 2085579 (July 20, 2026)

[2] Bartholomew v. Parking Concepts, Inc., 118 Cal.App.5th 438 (Feb. 5, 2026)

The handbrake has been pulled on aspects of the EU’s AI Act (Act), with key workplace rules, particularly those on high-risk systems, pushed back from August 2, 2026, to December 2, 2027. 

The delay may feel welcome for multinational employers keeping up with the spread of AI adoption across their organization, but it is an opportunity to get the groundwork done. 

The European Commission in late May published draft guidelines on the classification of high-risk AI systems (Guidelineshttps://bit.ly/4vDtgOV) for the Act. This is the clearest indication yet of how EU workplace AI tools will be treated, using many real examples.

 To function efficiently across borders, business must incorporate these rules into their global compliance framework for legal, HR, talent acquisition, procurement, IT, data, compliance and operations. 

The extra months are useful runway, because HR, recruitment, performance management and workforce allocation tools will require the full gamut of “high-risk” systems compliance. Global employers need time to work this into a matrix of other global rules — including in multiple US jurisdictions (e.g., California, Colorado, Connecticut, New York), Canada, Korea’s Basic AI Act, the updated UK GDPR and emerging rules elsewhere. 

Below is a pragmatic look at what use cases trigger the Act, and what global employers need to do from governance, procurement, data protection and employee relations perspectives. 

Continue Reading Workplace AI — How Employers Should Prepare for the New EU AI Act Deadline

Automated License Plate Reader (ALPR) technology is facing increasing legal scrutiny as courts, regulators and individuals attempt to examine and expose the various ways in which license plate data is captured, collected, shared and used. Recent disputes over ALPR technology have shifted away from issues of public safety and toward whether the private sector businesses and governmental organizations, among others, that utilize ALPR adequately disclose its use and sharing, as well as implement proper safeguards around this potentially sensitive, location-based personal information.

1. Private Sector’s Failure to Disclose Use of ALPR Technology Can Be Sufficient to Constitute Harm to Consumers

The private sector’s use of ALPR technology is facing challenges and possible legal exposure. In February of this year, California’s First Appellate District addressed the requirements imposed by the state’s ALPR Law in Bartholomew v. Parking Concepts, Inc., and in particular addressed what constitutes sufficient “harm” under the law to state a claim.1,2 In that matter, the plaintiff alleged that a parking garage owned and operated by Parking Concepts collected his license plate data without making a privacy policy regarding the collection publicly available. First, the Court determined that the parking garage camera system constituted a ALPR system under the law – that is, that it was “a searchable computerized database resulting from the operation of one or more mobile or fixed cameras combined with computer algorithms to read and convert images of registration plates and the characters they contain into computer-readable data.” But more importantly, the Court concluded that using ALPR technology without a publicly disclosed privacy policy stating when and how ALPR is collected and used violates an individual’s “right to know” of the activity, which is sufficient to allege harm under the law.

Continue Reading Automated License Plate Reader Technology Raises Concerns Over Private Sector Compliance and Government Overreach

When Colorado enacted the first comprehensive state AI law in 2024, it imported the conceptual architecture of the EU AI Act: a risk-based regime built on duties of care, risk management programs, and impact assessments. Two years later, and within a matter of weeks, the state has dismantled that legislation. On May 14, 2026, Governor Jared Polis signed Senate Bill 26-189, which repeals SB 24-205 and replaces it with a disclosure-and-rights framework focused on automated decision-making technology (“ADMT”). The new framework takes effect January 1, 2027.

The substance of the rewrite has been well-covered already. Less examined is how Colorado got here, and what the speed and direction of the pivot signal for the rest of the state AI regulatory landscape. The new bill was introduced and signed within two weeks of its introduction. The Governor’s AI Policy Working Group did the heavy lift in advance: roughly six months of stakeholder consultation produced the draft framework released on March 17, 2026. But the final two-week sprint reflects pressure to land the rewrite before the original AI Act’s June 30, 2026 effective date and amid escalating federal headwinds.

Continue Reading Colorado’s AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model

Software procurement has become a central feature of modern business operations. Organizations increasingly rely on third‑party tools to support internal workflows, manage data, and deliver products and services to customers. As a result, vendor due diligence is no longer a purely procurement or contracting function. It is a core risk management exercise.

Despite this shift, many organizations still approach software procurement in a linear way. The business identifies a tool, procurement advances the deal, and Legal is brought in late to review contract terms. That approach assumes software presents a uniform level of risk.

It does not.

The legal and regulatory risk associated with software depends heavily on how the tool is used, what data it processes, and how much the business or its customers rely on its outputs. Understanding those factors early is essential to allocating risk appropriately and drafting contracts that reflect operational reality.

Continue Reading Rethinking Vendor Due Diligence: Software Procurement Starts Before the Contract

Legal500 featured an article by Seyfarth partners Kathleen McConnell and Lauren Gregory Leipold, and associate Daniel Riley“AI Governance In (and Beyond) Privacy: Regulatory Tensions in Automated Decision‑Making, the Digital Authenticity Crisis, and Restrictions on Professional Use.

The piece, published as a part of the Legal500 Country Comparative Guides, examines the rapidly evolving legal landscape governing artificial intelligence and its intersection with privacy, consumer protection, employment law, and professional responsibility.

The article highlights how US AI regulation is emerging through a fragmented mix of state privacy laws, AI‑specific statutes, ethics rules, and intellectual property doctrines, creating significant compliance challenges for organizations deploying AI at scale. The authors outline three key regulatory fronts—automated decision‑making, synthetic content and digital authenticity, and profession‑specific governance—and emphasize the need for proactive, enterprise‑wide AI governance strategies that extend beyond traditional privacy compliance.

As McConnell, Leipold, and Riley explain:

“Organizations cannot rely on any single legal regime, whether privacy, cybersecurity, or professional ethics, to define the boundaries of responsible AI use.”

The full article is available here.

When the California Privacy Protection Agency (“CalPrivacy”) announced a $1.35 million settlement in September 2025 – the largest CCPA penalty to date – one of the itemized grievances stood out for any practitioner who has wrestled with a vendor redline: the company had failed to amend or enter into third-party data protection vendor contracts by regulatory deadlines.

This hints at where state privacy enforcement is heading. The consumer-facing side of privacy compliance – notices, opt-out links, cookie banners – is visible and testable. But the back-end architecture of a compliant privacy program lives at least in part in vendor contracts, and regulators increasingly treat those contracts as evidence of program maturity (or its absence). Nowhere is this more concrete than in California’s 11 CCR § 7051.

Continue Reading The Paper Trail: State Privacy Law Contracting Requirements

The lesson from the PocketOS database deletion is not that agentic AI is dangerous. It’s about governance and controls.

You have probably seen some version of the headline by now: “AI Agent Deletes Company’s Entire Database in 9 Seconds.” It is a compelling story. But the headline, while technically accurate, obscures the far more important lesson buried in the details.

So what actually happened? PocketOS, a small SaaS company that makes software for car rental businesses, was using a popular AI-powered code editor running on Anthropic’s Claude Opus 4.6 model. The AI agent was tasked with resolving a routine issue in a staging environment. When it hit a credential mismatch, the agent decided on its own initiative to “fix” the problem by deleting a volume on Railway, the company’s cloud hosting provider. The agent found a password in an unrelated file and used it to execute a deletion command. Because of permissions made available to the agent and the way access to the infrastructure was configured, that single command using a password which was valid across all systems wiped both the production database and all associated backups.  

The agent, when asked to explain itself, produced what multiple outlets described as a “confession,” acknowledging it had violated its own safety instructions. The story has gone viral. The framing in most coverage puts the AI squarely at the center of the narrative: the agent “went rogue,” it “confessed,” it acted autonomously and destroyed a business. But the reports are not entirely accurate and usually miss the point.

Continue Reading The AI Didn’t Go Rogue. Guardrails Were Never There.

As another piece of harmonization legislation, the AI Act is unsurprisingly reminiscent in regulatory philosophy to the GDPR. Many of the same data principles (transparency, accuracy, security) are present, as is an explicit risk-based approach. Understanding precisely where there is overlap with your existing GDPR program is a head start in your AI Act compliance program design. But it is also important to recognize where the two frameworks diverge. The GDPR regulates what happens to personal data, the legal basis for collection, how it is used, how long it is kept, who can access it. The AI Act generally regulates the AI system itself – namely, how it is designed, tested, documented, governed, and deployed. While that difference in regulatory object creates structural differences in inputs and outputs, the framework itself does have a lot of commonalities.

This post suggests a strategy for efficiently building a unified compliance framework for both regimes.

Continue Reading One Compliance Program for Two Frameworks: Aligning the EU AI Act and GDPR for Efficiency

Episode 14 is now live. In this episode of Consumer Counterpoint, we sit down with Chicago partner Jay Carle to discuss the launch of Seyfarth’s new D.A.T.A. Law practice group. Jay shares insights into the group’s multidisciplinary approach and how it’s designed to help clients stay ahead of emerging data and technology challenges.

Watch Episode 14 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.