Privacy Class Actions beyond CIPA: Emerging Trends in PTFA and Automated License Plate Tracking (ALPR)
Authors
Myriah V. Jaworski , Michael J. Laszlo , Chirag H. Patel , Christian W. Allan
While ample attention has been paid to the California Invasion of Privacy Act (CIPA) and related digital tracking cases, a new wave of privacy class actions is emerging of which businesses should take note.
Enterprising plaintiffs’ firms appear to systematically identify older statutes that have laid dormant for years, with little or no caselaw developed, but which contain (i) private rights of action; and (ii) statutory damages and/or fee shifting provisions. A wave of filings then follows to test the outer boundaries of these old laws’ application to new technologies and business use cases.
Of recent note are the Colorado Prevention of Telemarketing Fraud Act (PTFA) and California’s Automated License Plate Recognition (ALPR), each of which have seen a large uptick in filings against business these collect, use, or disclose regulated information.
1. Colorado PTFA Litigation Update
A little-known 2005 Colorado statute has become one of the most active fronts in privacy class-action litigation. As Clark Hill first framed it in its overview, PTFA Privacy Claims: Is a Little-Known Colorado Statute the New Right to Publicity?, the plaintiffs’ bar has repurposed Colorado’s Prevention of Telemarketing Fraud Act (“PTFA”) into a vehicle for statutory-damages class actions against companies they claim publish or sell cell phone numbers. In the past year, plaintiffs’ firms have filed dozens of putative PTFA class actions, and the pace is accelerating rather than slowing.
What Is the PTFA “Listing Provision”?
The Colorado Prevention of Telemarketing Fraud Act is a state consumer-protection law. A 2005 amendment, codified at Colo. Rev. Stat. § 6-1-304(4)(a)(I), makes it an unlawful telemarketing practice to knowingly list a cellular telephone number in a directory for a commercial purpose unless the number’s owner has given affirmative consent through written, oral, or electronic means. This is the provision (that went essentially unused for nearly two decades) that is now driving the litigation.
What makes the Colorado statute attractive to plaintiffs is the remedy. Under Colo. Rev. Stat. § 6-1-305(1)(c), a PTFA violation carries statutory damages of $300 to $500 for a first offense and $500 to $1,000 for a second or subsequent offense, plus court costs and attorney’s fees. Aggregate those penalties across a putative statewide class, and the exposure climbs quickly, which is precisely the pressure these suits are designed to create.
The typical PTFA complaint targets a familiar business model: a company that displays “teaser” contact data, sometimes a partial or masked phone number, in response to a search or within a subscription database, with an option to purchase the full record. Plaintiffs argue that this practice is an impermissible “listing” of a cell number in a “directory” for commercial gain. Defendants counter that a query-driven platform returning individualized results is not a “directory” in any ordinary sense and that the statute’s real target was abusive telemarketing, not the lawful commercial handling of already-public information.
The State of PTFA Play in 2026
The cases are being pressed by a growing group of plaintiffs’ firms against a widening set of defendants. What began as a campaign against people-search sites has moved distinctly upmarket, now reaching data brokers, credit-reporting agencies, and mainstream B2B “sales intelligence” companies as well. The filings are concentrated in California and Colorado but span at least eight states, in both federal and state court. Several developments define where things stand:
Early motions to dismiss are being denied, but the core questions remain open.
- In Gargus v. Uplead (C.D. Cal., January 13, 2026), the court denied both a motion to transfer to Colorado and the motion to dismiss. It read the statute’s plain language to cover a searchable “people search” platform, rejected the argument that a data broker is not a “telemarketer” subject to the Act, treated the listings as commercial speech (and found the defendant’s strict-scrutiny argument too cursory to succeed), and concluded, at the pleading stage, that the PTFA’s penalties may be sought on a classwide basis.
- In Adinoff v. RELX dba LexisNexis (Denver County District Court, March 23, 2026), the court likewise denied dismissal and upheld standing, but it declined to reach the First Amendment challenge because the defendant had not served the Colorado Attorney General as required, and it deferred the pivotal question of whether classwide statutory penalties are available, calling the interplay of Sections 6-1-113(2.9) and 6-1-305 “a matter of first impression.” In the Whitepages litigation (USDC Western District of Washington, April 2026), the federal court denied a motion to strike class allegations, holding that classwide treatment turns on facts to be developed in discovery.
- Most recently, the U. S. District Court of the ED of Illinois in Byer v. Buildout Inc. denied a facial First Amendment challenge to the PTFA, holding that the law did not “flunk” a four-part intermediate scrutiny framework for cases involving commercial speech at the outset, but appeared to suggest that further factual development and an as-applied challenge may be sustained. The Byer court similarly rejected Buildout’s request to dismiss classwide statutory damages at the motion to dismiss juncture.
The first classwide PTFA settlement has now been preliminarily approved. Cochrane v. People Data Labs (USDC N.D. Cal.) is the first PTFA case with figures on the record, and on June 30, 2026, Judge Rita F. Lin granted preliminary approval. The settlement establishes a non-reversionary fund (a fixed pool of money) of $6,362,167 for an estimated 908,881-member class (about $7 per class member, before fees and administration), together with prospective relief limiting future disclosure of class members’ numbers. A final-approval hearing is set for November 17, 2026, with an objection and opt-out deadline of September 29, 2026. Whatever its ultimate fate at final approval, the deal is the first public data point on how these claims are being valued at an early, pre-merits-ruling posture, well below the statutory maximums plaintiffs invoke.
A legislative fix is not on the horizon. Colorado’s General Assembly adjourned its 2026 session in May without amending the Listing Provision, defining “directory,” clarifying consent, or addressing classwide penalties, and the next regular session does not convene until January 2027. More tellingly, the State is currently defending the statute: Colorado and a coalition of other states filed an amicus brief urging that the provision is constitutional. With the Attorney General litigating to uphold the broad reading, any near-term “clarification” is more likely to come from the courts, through a merits ruling or a question certified to the Colorado Supreme Court, than from the legislature. Companies should also be mindful that if lawmakers do act, the change could just as easily strengthen the plaintiffs’ reading as narrow it.
2. California sees surge in Automated License Plate Recognition (ALPR) filings
As with the PTFA, California’s ALPR has been on the books for over a decade with little litigation activity in that time. That all changed recently, with an uptick in filings following a recent Court of Appeal’s decision reinstating a ALPR class action and broadly interpreting the laws provisions.
What is ALPR technology and how is it regulated?
California’s Automated License Plate Reader Privacy Act was enacted in 2015. ALPR is defined broadly to regulate companies that use, access, or operate automated systems capturing license plate images and converting them into searchable, machine-readable text.
You’ve probably seen cameras near traffic lights or on patrol cars or in parking garages that quickly scan license plates. These are ALPRs. Every day, they collect millions of plate scans to help law enforcement find stolen vehicles, enforce tolls and parking flow, and support investigations.
The law requires that every ALPR operator implement a usage and privacy policy. That policy—which must be made publicly available in writing—must address seven elements:
(1) the authorized purposes for using the ALPR system
(2) a description of how the ALPR system will be monitored to ensure security and compliance
(3) the purposes of, process for, and restrictions on the sale or sharing of ALPR information
(4) the length of time ALPR information will be retained
(5) the process for auditing and ensuring compliance with the policy
(6) the designation of the official custodian of the ALPR system responsible for implementation of the policy
(7) reasonable measures to ensure the accuracy of the ALPR information; the law also provides that companies must implement reasonable security measures to protect the data
California’s ALPR statute provides for remedies ranging from actual damages, liquidated damages not less than $2,500 per violation, punitive damages and attorneys’ fees, along with injunctive relief, which means the potential exposure for businesses operating ALPR systems is significant.
Court of Appeals Endorses Broad Reading of ALPR in Bartholomew: No Data Misuse Required
In Bartholomew v. Parking Concepts, Inc., the plaintiff parked his vehicle in a San Francisco parking garage owned and operated by Parking Concepts, Inc. on multiple occasions. The plaintiff alleged that Parking Concepts automatically collected his license plate information without implementing or making publicly available the usage and privacy policy required by Section 1798.90.51(b). The trial court dismissed the claim after concluding that the plaintiff had not alleged harm, an essential element for a claim. But the Court of Appeal disagreed by concluding that the customer had adequately alleged harm based on the defendant’s failure to implement and publicize the policy.
On appeal, the Court of held;
- ALPR System Broadly Defined. The court held that Parking Concepts’ system—which used cameras to read license plates, converted the images into computer-readable data, and stored that data in a searchable database—constituted an “ALPR system.”
- No Actual Harm Required. The court held that the failure to implement and publicly display the required policy constitutes “harm” within the meaning of the statute. No data misuse, breach, or measurable monetary injury need be alleged.
- No Pre-Suit Cure Notice Required. The ALPR law does not require plaintiffs to provide pre-suit cure notice, meaning businesses can be sued without any prior warning.
The court rejected the contention that every violation of the law is per se actionable and instead held that the law requires “harm beyond a mere statutory violation.” The court also left open whether incomplete ALPR policies—or policies that are published but not implemented (or vice versa)—are actionable.
Post-Bartholomew Uptick in Filings
Following the decision, plaintiffs’ firms began filing a growing number of putative class actions against businesses that use ALPR systems in connection with ordinary commercial activities. The targets have extended well beyond traditional law-enforcement applications of ALPR and include shopping malls and retail centers, hotels and hospitality properties, office parks, medical centers and hospital systems, parking operators and garage companies, big-box retailers and grocery stores, and ALPR technology vendors.
The breadth of these cases is significant because many of the targeted businesses may not have viewed themselves as “ALPR operators” in the traditional sense. A business may use cameras primarily for parking management, security, access control, loss prevention, or other operational purposes, while a third-party vendor provides the technology that captures and converts license-plate information into searchable data. The recent litigation suggests that plaintiffs may nevertheless seek to impose liability based on the business’s role in operating or using the system.
The claims also illustrate a potentially important distinction between how a business uses ALPR information and whether the business has complied with the statute’s procedural requirements.
At the same time, Bartholomew did not resolve every issue that will determine the ultimate viability of these cases. The Court of Appeal expressly rejected the proposition that every technical violation of the ALPR statute is automatically actionable and held that the plaintiff must establish harm beyond a mere statutory violation. The decision also leaves open important questions concerning what constitutes a sufficient ALPR policy, whether an incomplete policy is sufficient, and whether a policy that is published but not actually implemented satisfies the statute. These issues are likely to become central as the newer cases progress beyond the pleading stage.
Strategies to Reduce Emerging Privacy Litigation Risk
The recent PTFA and ALPR filings illustrate a broader trend that businesses should expect to continue: Plaintiffs’ firms are increasingly looking beyond the statutes that have historically driven privacy litigation and identifying older or underutilized laws that can be applied to modern data practices. Businesses that collect, use, disclose, or make available information potentially covered by these statutes may consider taking the following steps:
- Determine whether the laws apply to your business. Identify whether your business collects, uses, discloses, sells, or otherwise makes available information that could fall within the scope of emerging state privacy statutes, including cellular telephone numbers, license plate information, or other regulated data.
- Audit data disclosure and sharing practices. Map where regulated information comes from, how it is used, who receives it, and whether it is displayed or made searchable to customers or the public. Particular attention should be paid to practices that may have been designed without these older statutes in mind.
- Review statutory notices and policies. For ALPR operators, for example, the statute imposes specific requirements concerning the content and implementation of an ALPR usage and privacy policy. A policy that exists on paper but does not accurately reflect actual practices may create additional risk.
- Evaluate consent and authorization. Businesses should identify where affirmative consent is required and determine whether existing collection and disclosure practices can demonstrate that consent. This is particularly important where a statute contains a specific consent requirement that may differ from requirements under more familiar privacy laws.
- Monitor developments in emerging litigation. Because many of these statutes have little historical caselaw, a small number of decisions can materially change the litigation landscape. Companies operating in potentially affected industries should monitor decisions addressing statutory interpretation, standing, First Amendment defenses, class certification, and the availability of statutory damages on a classwide basis.
As the PTFA and ALPR litigation demonstrate, plaintiffs may find substantial exposure in relatively obscure provisions that were enacted long before the technologies at issue existed. Companies should therefore look beyond their traditional CCPA, CIPA, and cybersecurity compliance reviews and periodically assess whether newer uses of data create risk under less familiar state laws.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author(s) only and are not necessarily the views of Clark Hill PLC or Clark Hill Solicitors LLP. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.