How Flock Safety's Three Lawsuit Tracks Create Exposure
This tracker consolidates every major Flock Safety ALPR lawsuit across three litigation tracks—Fourth Amendment, California state-law class actions, and product-liability misread claims—providing a cross-referenced, source-cited record for assessing Flock-related risk exposure.
- Jurisdiction
- US Federal and State
- Court
- Multiple U.S. Federal and State Courts
- Judge
- Judge Davis
- AI tool named
- Flock Safety
- Ruling date
- Jun 29, 2026
- Source document
- View primary court order ↗
- Last verified
- Jul 27, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Last verified: July 27, 2026. This is a litigation-risk tracker, not legal advice. In a Flock camera privacy lawsuit legal analysis, the first cut is not whether automated license plate readers are lawful in the abstract; it is which exposure track is actually in front of you. A suppression motion, a California statutory-damages demand, and a mistaken-stop claim do not move on the same facts.

The current record separates into three tracks: Fourth Amendment challenges to ALPR collection or querying; California state-law class actions against private deployers and related entities; and product-liability or civil-rights claims after alleged plate misreads and wrongful enforcement encounters. Some surrounding events—undisclosed data sharing, state legislation, procurement reversals, and FTC pressure—do not fit neatly into those tracks, but they change the settlement and renewal environment around them.
| Matter or event | Track | Jurisdiction or forum | Theory or risk hook | Current posture | Source status and caveat |
|---|---|---|---|---|---|
| Schmidt v. Norfolk | Fourth Amendment | Federal litigation arising from Norfolk, Virginia; appeal pending in the Fourth Circuit | ALPR use challenged as unconstitutional surveillance; Judge Davis reportedly held on Jan. 27, 2026 that the system did not violate privacy while flagging a possible future tipping point | Adverse ruling for privacy challengers at trial-court level; appellate risk remains open | Reported by WHRO; primary appeal materials were not available for this tracker [1] |
| Commonwealth v. Church | Fourth Amendment / criminal procedure | Virginia Court of Appeals | Whether law enforcement needed a warrant for ALPR data | On Oct. 14, 2025, the court reportedly reversed a warrant requirement | Source is Flock’s own blog, useful for posture but not neutral legal characterization [2] |
| Institute for Justice San Jose litigation | Fourth Amendment / civil constitutional challenge | San Jose, California | Challenge presses the broader argument that ALPR networks enable unconstitutional dragnet tracking | Active litigation according to reporting | NBC News reporting available; several IJ.org pages were inaccessible during verification [3] |
| Chatrie v. United States | Fourth Amendment analogy, not an ALPR holding | U.S. Supreme Court | Warrantless acquisition of Google Location History data held to be a Fourth Amendment search in a 6-3 decision dated June 29, 2026 | Creates a live analogy debate for ALPR databases; does not itself decide Flock ALPR legality | Analysis relies on The Record and related reporting; the full slip opinion was not reviewed for this tracker [4] |
| Bartholomew v. Parking Concepts | California private-entity statutory class action | California First District Court of Appeal | Reported holding that absence of a compliant ALPR privacy policy can itself be actionable harm, with statutory damages described as $2,500 per person per violation | Decision dated Feb. 5, 2026; review denied May 13, 2026 | Secondary analysis from Rain Intelligence and Global Privacy Watch; primary Justia opinion was inaccessible and should be checked before quoting exact statutory language [5][6] |
| Follow-on California class actions naming Simon Property Group, Flock Group, Sunset Development / Bishop Ranch, and related private deployers | California private-entity statutory class action | California state-law class-action environment | Alleged noncompliance with California ALPR privacy-policy obligations after Bartholomew | At least four follow-on class actions reportedly filed within six weeks, with at least eight additional plaintiff investigations recruiting as of May 2026 | Reported by Rain Intelligence; individual complaints should be pulled before valuing any specific demand [5] |
| Mountain View data-sharing incident | Data-sharing / municipal renewal risk adjacent to California track | Mountain View, California | Flock allegedly enabled nationwide mode, leading to 600,000 unauthorized searches by more than 250 agencies | Discovered in January 2026 according to ACLU reporting | Not itself listed as a private class action in the available materials, but material to notice, consent, and procurement-risk analysis [7] |
| Ventura County vendor-error incident | Data-sharing / immigration-enforcement risk adjacent to California track | Ventura County, California | Vendor error allegedly enabled 364,000 queries, including 299 for immigration enforcement | Reported in 2026 | ACLU reporting; relevant to controls and sharing representations, not automatic proof of damages in another matter [7] |
| Upchurch v. Toledo | Product-liability / mistaken enforcement | Toledo, Ohio | Alleged misread contributed to wrongful police encounter and police dog mauling | Settled for $35,000 | Business Insider reported the settlement; settlement is an operational signal, not an admission of liability [8] |
| Burkleo v. Atherton | Product-liability / mistaken enforcement | Atherton, California | Alleged wrongful enforcement following plate-read error | Settled for $45,000 | Business Insider reporting; settlement value should not be treated as a verdict benchmark [8] |
| Gonzales v. Española | Product-liability / mistaken enforcement | Española, New Mexico | Alleged wrongful enforcement after ALPR-related error | Settled | Business Insider reporting; amount was not provided in the available materials [8] |
| Business Insider / IJ wrongful-encounter record | Product-liability / mistaken enforcement | Multiple jurisdictions | More than 12 documented wrongful enforcement encounters; IPVM 2021 testing reportedly found about a 10% state-misidentification rate, and Coralville officials described accuracy as “around 90%” before that statement was later disclaimed | Investigative and advocacy record, not a single docket | IPVM testing was behind a paywall and is cited here through Business Insider’s secondary reporting [8] |
| California AG v. El Cajon | Government enforcement / data-sharing | California | California Attorney General Rob Bonta sued El Cajon for allegedly illegal ALPR data sharing with out-of-state agencies | Filed Oct. 3, 2025 | Official California Attorney General press release; government enforcement is distinct from private statutory damages [9] |
| Washington SB 6002 | Statutory operating constraint | Washington | Prohibits stops based solely on an ALPR match | Effective March 30, 2026 | MRSC legislative summary; state-specific and not a national rule [10] |
| Washington public-records ruling | Records and transparency risk | Washington | Public-records litigation affecting access to ALPR-related materials | Reported in November 2025 | EFF reporting; relevant to discoverability and municipal disclosure exposure [11] |
| Sen. Wyden FTC investigation letter | Regulatory pressure | Federal | Request for FTC scrutiny of Flock-related practices | Letter dated November 2025 | Source link was not available for this tracker; treat as a regulatory signal, not an enforcement outcome [12] |
| Oshkosh, Wisconsin contract rescission | Procurement / disclosure risk | Oshkosh, Wisconsin | Contract rescinded over undisclosed heat-mapping capabilities | April 2026 | Source link was not available for this tracker; use as procurement-risk context rather than litigation precedent [13] |
The table is deliberately mixed. A city attorney deciding whether to renew a Flock contract cares about Mountain View, Ventura County, El Cajon, Washington, and Oshkosh even if none of those items is the same thing as Bartholomew. A criminal defense lawyer drafting a suppression motion cares about Schmidt, Church, San Jose, and Chatrie even if none supplies a clean nationwide ALPR rule. A plaintiff lawyer evaluating a mistaken-stop claim cares less about database theory and more about the chain from plate read, to officer reliance, to detention, force, or search.
The California damages track is the sharpest multiplier
Bartholomew matters because it is reported as a damages-mechanics case, not merely another privacy objection. Rain Intelligence and Global Privacy Watch describe the California First District as recognizing actionable harm from the absence of a compliant ALPR privacy policy, without requiring a separate showing that the plate data was misused. They also describe the statutory exposure as $2,500 per person per violation, a figure plaintiffs can model at scan or collection scale if the violation attaches to the collection event [5][6].
That distinction changes negotiation posture. A claim that requires proof of downstream misuse usually forces plaintiffs to spend early money identifying who accessed what, why the access was improper, and how the individual plaintiff was harmed. A no-misuse-required theory shifts attention to deployer compliance: whether a private entity had the required policy, whether it was public, whether it contained the required content, and whether the entity collected ALPR information during the noncompliant period. If those facts are common across a class, the damages conversation moves before anyone proves stalking, identity theft, or a bad search.
The caveat is not cosmetic. The Bartholomew opinion text on Justia was inaccessible due to authentication. Before a demand letter quotes the court’s statutory interpretation, or before a defense memo concedes the no-misuse premise, counsel should pull the primary opinion and the review-denial docket. The secondary sources are strong enough to flag exposure; they are not a substitute for exact language when a reserve number is being set.
The follow-on pattern is what makes Bartholomew more than a one-off parking case. Rain Intelligence reports at least four class actions filed within six weeks against Simon Property Group, Flock Group, Sunset Development / Bishop Ranch, and related defendants, plus at least eight additional plaintiff investigations recruiting as of May 2026 [5]. The legal theory may be California-specific, but the business fact pattern is common: private sites adopted ALPR infrastructure for parking, security, or access control, and the statutory question turns on privacy-policy compliance before anyone reaches the usefulness of the cameras.
That is why data-sharing incidents belong near the California class-action file even when they are not the same claim. Mountain View’s reported 600,000 unauthorized searches by more than 250 agencies after nationwide mode was enabled, and Ventura County’s reported 364,000-query vendor-error incident with 299 immigration-enforcement queries, are not Bartholomew holdings. They do, however, put pressure on representations about who can search a network, who approved sharing, and whether the written policy matched operational reality [7].
The El Cajon suit adds a public-enforcement version of the same problem. California Attorney General Rob Bonta filed suit on Oct. 3, 2025 alleging illegal ALPR data sharing with out-of-state agencies [9]. A private Bartholomew-style plaintiff still has to prove the elements of the private statutory claim. But a municipal client defending a renewal will now face the obvious question: if sharing limits are written into the program, who verifies that the software settings and agency permissions actually enforce them?
| California issue | Why it affects exposure | Immediate document set to pull |
|---|---|---|
| Privacy-policy compliance | Potential common proof for statutory class treatment after Bartholomew | Published ALPR policy, revision history, notices, board approvals, vendor templates |
| Collection volume | Drives damages modeling if plaintiffs press a per-person or per-scan statutory theory | Scan counts, unique plate counts, retention logs, time period of alleged noncompliance |
| Sharing settings | Connects statutory notice questions to Mountain View, Ventura, and El Cajon-style facts | Agency permission logs, nationwide-mode settings, audit logs, vendor-change notices |
| Vendor role | Separates deployer liability, vendor conduct, and indemnity fights | Master services agreement, data-processing terms, indemnity provisions, support tickets |
The Fourth Amendment track is unsettled, and Chatrie does not settle it
The Fourth Amendment cases ask a different question from Bartholomew: not whether a private deployer missed a state-law privacy-policy requirement, but whether government collection or querying of plate-location data is a search, whether a warrant is required, and whether evidence should be suppressed. The consequence is different too. A defendant may care less about statutory damages than about excluding evidence; a city may care less about one suppression ruling than about whether its network design has crossed a constitutional line.
Schmidt is presently the main reported defense-side marker. WHRO reported that Judge Davis ruled on Jan. 27, 2026 that Norfolk’s ALPR system did not violate privacy, while also indicating that ALPR surveillance could reach a future tipping point [1]. That is not the same as a permanent safe harbor. A trial-court ruling on the current record, with an appeal pending in the Fourth Circuit, gives defense counsel language to cabin a suppression analogy. It does not answer how a different network scale, retention period, sharing arrangement, or query practice will look on a fuller record.
Commonwealth v. Church points in a similar direction for law enforcement, but the source posture matters. Flock’s own October 2025 blog says the Virginia Court of Appeals reversed a warrant requirement for ALPR data on Oct. 14, 2025 [2]. The case is still useful for identifying a state appellate ruling favorable to warrantless access. But a vendor blog is not where counsel should stop before telling a prosecutor the issue is safe or telling a city council the constitutional problem is over.
The San Jose litigation presses the opposite direction. NBC News reported on the Institute for Justice lawsuit challenging San Jose’s ALPR network as an unconstitutional surveillance system [3]. Its value is not that it has already produced the controlling ALPR rule; the available materials do not support that. Its value is that plaintiffs are now pleading ALPR networks as systemic dragnet searches rather than isolated database lookups.
Chatrie then enters as an analogy fight. The Record reported that the Supreme Court’s June 29, 2026 decision in Chatrie held, 6-3, that warrantless acquisition of Google Location History data was a Fourth Amendment search [4]. That fact is important for ALPR lawyers because it gives challengers fresh language about database-wide location searching. It does not automatically convert every ALPR query into a Chatrie violation.
Flock’s July 9 response reportedly argues that Chatrie does not control ALPR systems, while IJ attorney Robert Soyfer and Professor Andrew Ferguson have argued that Chatrie’s reasoning has force against ALPR dragnets [2][4]. Those are interpretive positions around a new Supreme Court decision. The next useful holding will turn on record facts: density of cameras, duration of retention, whether officers searched a named plate or mined a database, sharing scope, auditability, and whether the person challenging the search can establish standing and suppression consequences.
| Fourth Amendment source | Helpful to whom | What it can support | What it does not prove |
|---|---|---|---|
| Schmidt v. Norfolk | Municipal defendants and prosecutors | An argument that the current ALPR record before that court did not establish a privacy violation | A nationwide rule that all ALPR networks are constitutional at any scale |
| Commonwealth v. Church | Prosecutors and law-enforcement agencies | A Virginia appellate ruling against a warrant requirement for ALPR data | A neutral source summary or a final answer outside its jurisdiction |
| San Jose IJ litigation | Civil-rights plaintiffs and suppression movants by analogy | A developed dragnet-surveillance theory against ALPR network design | A decided merits holding |
| Chatrie v. United States | Both sides, depending on the factual comparison | Fresh Supreme Court language for database-location-search arguments | An automatic ALPR rule |
Misread claims are smaller on doctrine and harder on operations
The mistaken-enforcement track does not need a grand theory of surveillance to create liability pressure. It needs a bad read, officer reliance, and a concrete injury. Upchurch v. Toledo reportedly settled for $35,000 after an alleged misread contributed to a wrongful encounter involving a police dog mauling; Burkleo v. Atherton reportedly settled for $45,000; Gonzales v. Española also reportedly settled [8]. Those are not class-action multipliers. They are case files a risk manager can understand in one page.
Business Insider’s March 2026 reporting, combined with Institute for Justice documentation, identified more than 12 wrongful enforcement encounters tied to ALPR errors or reliance problems [8]. The same reporting cited an IPVM 2021 test finding about a 10% state-misidentification rate, and noted that Coralville officials described Flock accuracy as “around 90%” before that statement was later disclaimed [8]. Because the IPVM material is paywalled, the exact test design should be checked before anyone treats the percentage as an admissible expert point.
The legal significance is more practical than theoretical. If a policy allows an officer to stop a car based only on an ALPR alert, a single transposed state, stale hotlist entry, or ambiguous plate image can become the first domino in a detention, search, use-of-force event, or arrest. Washington’s SB 6002, effective March 30, 2026, addresses that operational hinge directly by prohibiting stops based solely on an ALPR match [10]. Even outside Washington, that law will be cited in policy debates because it names the failure mode that misread plaintiffs have been litigating.
| Operational fact | Why it matters in a misread claim | Risk-control question |
|---|---|---|
| Alert source | Shows whether the hit came from a live hotlist, old list, shared agency list, or vendor system | Who owned the list and when was it last updated? |
| Image quality and plate-state confidence | Connects the error to product performance or officer interpretation | Was the state, character string, and vehicle description independently confirmed? |
| Officer reliance | Determines whether the ALPR alert was treated as a lead or as probable cause | Was there corroboration before the stop, search, or force? |
| Training and written policy | Goes to municipal fault, negligent operation, and foreseeability | Did the agency forbid sole-reliance stops or merely recommend caution? |
| Audit trail | Controls the after-the-fact proof problem | Can the agency reconstruct the query, alert, image, hotlist match, and user action? |
Procurement and disclosure facts now feed the litigation file
Some of the most damaging facts in a Flock dispute may never appear first in a complaint. They appear in council packets, public-records responses, audit logs, and vendor settings. The Washington public-records ruling reported by EFF matters for that reason: public-records fights can expose deployment details, sharing arrangements, and internal assumptions that later become litigation exhibits [11].
Sen. Wyden’s November 2025 FTC investigation letter and Oshkosh’s April 2026 contract rescission over undisclosed heat-mapping capabilities sit in the same risk environment [12][13]. Neither is a damages award. Neither decides the Fourth Amendment issue. But both make undisclosed capability a legal-management problem: if a feature affects tracking, sharing, heat mapping, or search scope, counsel will want the procurement record to show who knew about it, who approved it, and how the public description matched the product configuration.
This is where company-scale claims should be handled carefully. The available materials note that Flock’s 90,000-to-100,000 camera count comes from the company’s own marketing materials, not an independent audit. That does not make the number useless, but it changes how it should be cited. For constitutional scale, class numerosity, or damages modeling, the better evidence is the deployer’s own camera inventory, scan logs, retention schedule, and sharing-audit export.
Exposure matrix
| Track | Primary claimant or movant | Core evidence | Main remedy or consequence | Current risk level to watch | What changes the analysis fastest |
|---|---|---|---|---|---|
| Fourth Amendment | Criminal defendant, civil-rights plaintiff, advocacy plaintiff | Camera density, retention period, query scope, sharing network, standing facts, warrant status | Suppression, injunction, declaratory relief, policy change | Unsettled; defense-favorable rulings exist, but Chatrie gives challengers new analogy material | Fourth Circuit ruling in Schmidt, merits ruling in San Jose, or a post-Chatrie ALPR appellate decision |
| California statutory class actions | Private plaintiffs and class counsel | Privacy-policy compliance, collection dates, scan or unique-plate counts, private-entity role, notice and sharing terms | Statutory damages and class settlement pressure | High multiplier risk if Bartholomew’s reported no-misuse damages logic is confirmed against the primary opinion | Primary Bartholomew language, certification rulings, settlement values, and new follow-on complaints |
| Misread / product-liability and wrongful enforcement | Stopped driver, arrestee, injured person, civil-rights plaintiff | Plate image, hotlist source, officer corroboration, training, audit trail, injury record | Individual settlement, damages, policy revision, insurance notice | Concrete and recurring, though usually not class-scale on current materials | A severe injury case, evidence of repeated uncorrected errors, or statutes barring sole reliance on ALPR alerts |
| Data-sharing and procurement overlay | Attorney general, city council, public-records requester, regulator, contract counterparty | Sharing permissions, vendor configuration, public representations, feature disclosures, audit logs | Enforcement action, rescission, nonrenewal, disclosure orders, reputational leverage in litigation | Rising because it supplies facts to all three tracks | Unauthorized-search audit, vendor-error incident, undisclosed feature, or public-records production |
The practical point is separability. Flock-related risk cannot be priced as one generic privacy lawsuit category. Constitutional admissibility, California statutory liability, and mistaken-enforcement injury each depend on different records, different sources, and different timelines.
References
- WHRO report on Schmidt v. Norfolk — WHRO, Feb. 11, 2026.
- Flock Safety blog posts on Commonwealth v. Church and Chatrie — Flock Safety, Oct. 2025 and July 9, 2026.
- NBC News report on Institute for Justice San Jose ALPR lawsuit — NBC News.
- The Record analysis of Chatrie v. United States and ALPR implications — The Record, July 2026.
- Rain Intelligence analysis of Bartholomew v. Parking Concepts and California ALPR class actions — Rain Intelligence, 2026.
- Global Privacy Watch California ALPR compliance analysis — Global Privacy Watch, June 2026.
- ACLU reporting on Mountain View and Ventura County ALPR data sharing — ACLU, 2026.
- Business Insider reporting on Flock ALPR misread incidents and IPVM testing — Business Insider, March 2026.
- Attorney General Bonta Sues City of El Cajon for Sharing Automated License Plate Reader Data — California Attorney General, Oct. 3, 2025.
- MRSC summary of Washington SB 6002 — MRSC, April 2026.
- EFF report on Washington public-records ruling involving ALPR records — Electronic Frontier Foundation, November 2025.
- Sen. Wyden FTC investigation letter regarding Flock Safety — U.S. Senate, November 2025.
- Report on Oshkosh, Wisconsin Flock contract rescission — April 2026.
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →