Automated License Plate Recognition (ALPR) policy

Policy owner: Parking and Transportation Services
Official custodian: Director of Parking and Transportation Services
Effective date: September 25, 2026
Review cycle: Annually and upon a material legal, technical, or operational change.

1. Purpose and scope

California State University, Long Beach (CSULB) uses Automated License Plate Recognition (ALPR), also known as License Plate Recognition (LPR), to administer virtual parking permits and support parking management and enforcement. This policy governs CSULB's collection, access, use, maintenance, security, retention, sharing, and destruction of ALPR information and is intended to protect privacy and civil liberties while supporting legitimate University operations.

This policy applies to all CSULB employees, contractors, vendors, and other people who operate an ALPR system for CSULB or access CSULB ALPR information. It applies to mobile and fixed ALPR equipment, associated databases, parking-management integrations, exports, backups, and vendor-hosted services.

A business unit may not deploy a new ALPR system or materially expand an existing use without written approval from the Vice President for Administration and Finance or designee, consultation with the Information Security Officer, Human Resources, University Counsel, and any public process required by law.

2. Definitions

ALPR information. Information or data collected through the use of an ALPR system, including a plate image or number and associated date, time, location, camera, or system metadata.  Information or data collected through the use or operation of an automated license plate recognition system, as defined in CA Civil Code §1798.90.5, is considered Level 1 Confidential Information.

ALPR system. A searchable computerized database resulting from one or more mobile or fixed cameras and algorithms that read registration plates and convert their characters into computer-readable data.

Authorized user. A person whose job duties require access, who has written authorization from the official custodian or designee, and who has completed required training.

Raw ALPR information. Identifiable ALPR information that has not been aggregated or de-identified.

De-identified information. Information processed so it cannot reasonably be linked to a plate, vehicle, parking account, or individual. Reversible pseudonymization alone is not de-identification.

Official custodian. The Director of Parking and Transportation Services, or a formally designated administrator, responsible for implementing this policy.

3. Governance and responsibilities

The official custodian owns day-to-day administration of the ALPR program, maintains the authorized-user roster, approves role-based access, ensures training and audits, manages retention and destruction, coordinates records requests and disclosures, and keeps this policy conspicuously available to the public.

  • Parking and Transportation Services administers parking operations, validates business need, and documents procedures.
  • The Information Security Officer advises on data classification, security controls, vendor risk, incident response, and periodic review.
  • The designated Custodian of Records and campus Public Records Act coordinator manage subpoenas, compulsory process, legal holds, and California Public Records Act requests.
  • University Police Department (UPD) requests are evaluated under Section 10 and do not create routine or direct access unless separately authorized in writing and permitted by law.
  • Vendors and contractors must comply with this policy, applicable CSU security requirements, and written contractual restrictions.

4. Authorized purposes

ALPR systems and information may be used only for the following legitimate University purposes:

  • Verifying virtual parking permits, paid parking sessions, vehicle eligibility, and parking privileges for the location in which a vehicle is parked.
  • Enforcing campus parking rules and applicable vehicle laws, including citation issuance, time-limit enforcement, scofflaw administration, towing support, and adjudication of citation appeals.
  • Managing parking facilities through occupancy, utilization, turnover, and operational analytics, using aggregated or de-identified information whenever identifiable information is unnecessary.
  • Investigating suspected fraud, misuse, or a specific system-security incident involving CSULB parking services.
  • Responding to a documented, legally valid request described in Section 10.

5. Prohibited uses

  • Tracking or monitoring a person or vehicle without a documented authorized purpose.
  • Monitoring employee attendance, work hours, performance, union activity, protected speech, religious activity, political activity, or other First Amendment-protected activity.
  • Targeting a person based on race, color, ethnicity, national origin, religion, disability, sex, gender, gender identity or expression, sexual orientation, immigration status, or any other protected status.
  • Personal, commercial, retaliatory, discriminatory, or other non-University use.
  • Creating or using predictive profiles of individuals, travel patterns, associations, or behavior.
  • Selling ALPR information or using it for advertising, marketing, debt collection unrelated to campus parking, or commercial data brokerage.
  • Uploading CSULB ALPR information to, or enabling default access by, a national or shared ALPR database unless specifically approved in writing after legal and security review and permitted by law.
  • Accessing another entity's ALPR information through a vendor platform unless separately authorized and legally permitted.
  • Vendors are explicitly prohibited from using ALPR data for analytics, product development, AI model training, marketing, or any secondary purpose/use unrelated to CSULB services.

6. Information collected and accuracy

The system may collect a vehicle license-plate image; the alphanumeric plate number; issuing state or jurisdiction when available; date and time; location; and limited camera, patrol, or transaction metadata necessary for an authorized purpose. The parking-management system may link a plate to a permit or patron account for parking administration. ALPR does not itself identify a driver or establish that a registered owner was operating or occupying a vehicle.

Because automated plate translation can be inaccurate, no citation, tow, disciplinary referral, law-enforcement response, or other adverse action may be based solely on an ALPR alert. Before action, an authorized user must visually compare the plate and vehicle with the source image and relevant records, confirm the applicable rule or request, and document material discrepancies. Users must promptly report errors; the custodian will correct University-controlled records when appropriate and escalate software issues to the vendor.

7. Authorized users and access controls

Role/designationPermitted accessPurpose
Director of Parking and Transportation Services; designated parking managersAdministrative and searchableProgram administration, approvals, audits, enforcement oversight, disclosures, and retention.
Parking enforcement officers and designated citation/appeal staffOperational or case-specificPermit verification, parking enforcement, citation processing, and appeals.
Parking support staffCase-specific, least privilegeIssue and verify permits, as well as assist customers with their citations and appeals.
Designated parking systems/technical administratorsMinimum technical accessConfiguration, integration, troubleshooting, security, retention, and audit support.
Authorized vendor support personnelTime-limited and supervisedContracted maintenance or support; no independent use or secondary purpose.

Access requires unique credentials, supervisory approval, annual training, least-privilege role assignment, and prompt removal when duties change or employment or the contract ends. Shared accounts are prohibited. Multifactor authentication shall be required for administrative, remote, and vendor access.  

Vendor access must be logged, time-limited, and disabled when not in use.   Vendors shall conduct access validation, remediate stale accounts, and document approval for privileged access and support on an annual basis.

8. Training

Before receiving access, and at least annually thereafter, authorized users must complete role-appropriate training covering:

  • Authorized and prohibited purposes; privacy, civil liberties, and nondiscrimination requirements.
  • System operation, alert verification, accuracy limitations, and correction procedures.
  • Access logging, records retention, legal holds, sharing restrictions, and public-records routing.
  • Credential security, phishing awareness, secure handling and export, and incident reporting.
  • Applicable CSU and CSULB information-security and responsible-use requirements.

The custodian will retain training completion records and suspend access when required training is overdue.

9. Security, monitoring, and audits

CSULB and its service providers must maintain reasonable administrative, technical, operational, and physical safeguards against unauthorized access, destruction, use, modification, or disclosure. The program will use encryption in transit and at rest, unless the Information Security Office documents that encryption is technically unavailable and approves compensating safeguards; role-based access; secure configuration; logging; supported software; vulnerability and patch management; backup protections; vendor security requirements; and a documented incident-response path.

CSULB will maintain an auditable record of every access to or provision of access to identifiable ALPR information, including searches, views, exports, and disclosures. ALPR systems must log access to identifiable information. For disclosures (see Section 10), the log must record the date and time, plate number or other query element, username, user's organization when applicable, a specific purpose, and a case, citation, appeal, request, or incident number when available. Generic purposes such as 'official business' are insufficient.

At least annually, the custodian or designee will review user access and system, the authorized-user roster, vendor access, retention settings, sharing configuration, training status, incidents, and compliance with this policy. An audit sample of access logs will be conducted at least quarterly for unauthorized activity. Findings and corrective actions will be documented.

10. Sharing and disclosure

CSULB will not sell, share, or transfer ALPR information except when required by law. Requests for records via subpoena, California Public Records Act, or other legal process must be referred to University Counsel and the designated records office. Requests for identifiable ALPR information must be submitted to the official custodian or designated records office and approved in writing before disclosure; no disclosure may occur until the University has documented the applicable legal authority.  The approval must identify the requester, legal authority, specific data requested, purpose, time period, and any case or incident number. University Counsel, the Public Records Act coordinator, Information Security, or UPD Records will be consulted as appropriate. Disclosures will be limited to the minimum information legally authorized and necessary, transmitted securely, and recorded in the access log.

A vendor may access, receive, process, host, transmit, or store ALPR information only as necessary to provide services expressly authorized by a written agreement with CSULB. The vendor acts solely on CSULB’s behalf and is not an independent user or owner of the ALPR information.  Vendor access must be limited to the minimum information and duration necessary to perform the contracted service. CSULB remains responsible for authorizing the purposes for which ALPR information is accessed and for ensuring that vendor access is consistent with this policy and applicable law. The vendor may not disclose ALPR information to another person or entity except as expressly authorized in writing by CSULB.

Law-enforcement requests must be for a documented official purpose and supported by lawful authority. CSULB will not disclose information for federal civil immigration enforcement except when required by a judicial warrant, court order, or other binding legal obligation, as determined by University Counsel. Recipients may not further disclose the information unless authorized by law and the written approval.

Requests from the public, media, private litigants, or non-law-enforcement entities will be processed under the California Public Records Act with applicable exemptions, subpoenas, court orders, and University records-release procedures. Nothing in this policy promises confidentiality where disclosure is required by law.

11. Retention and destruction

Raw ALPR information that is not associated with a parking citation, appeal, enforcement action, documented investigation, security incident, public-records request, subpoena, court order, or legal hold will be retained for no longer than 35 days and then automatically and securely destroyed, including from searchable production systems. The custodian will verify the automated deletion setting at least quarterly.

Information associated with a specific business or legal record will be segregated or linked to that record and retained only for the period required by the applicable CSU records retention and disposition schedule, legal hold, law, or court order. When that need ends, the information will be securely destroyed. Backups must expire under documented backup schedules and may not be restored for routine searching after the source record's retention period ends.

Aggregated operational statistics may be retained longer only if they are de-identified and cannot reasonably be re-linked to a plate, vehicle, account, or individual. Parking and Transportation Services will document the de-identification method and prohibit re-identification.

12. Security incidents and complaints

Anyone who knows or suspects any privacy incidents, unauthorized surveillance, or if ALPR information has been lost, improperly accessed, disclosed, altered, or misused must immediately stop further disclosure when safe to do so, preserve relevant records, notify a supervisor and the CSULB Information Security Office, and follow the CSULB Security Incident Reporting and Breach Notification Procedure. After business hours, reports may be made to UPD. CSULB will investigate and provide notifications as required by law and University policy.

Vendors that access, process, store, transmit, or otherwise handle Automatic License Plate Reader information on behalf of CSULB must be contractually required to promptly notify the CSULB of any actual or suspected security incident involving ALPR information.

Vendor contracts must require:

  1. Initial notification: Written notice to the CSULB Information Security Office (ISO) without undue delay and no later than 48 hours after the vendor discovers or reasonably suspects the incident.
  2. Required content: The notice must include, to the extent known, the nature and time of the incident; affected systems and information; geographic and operational impact; containment actions; and a primary point of contact.
  3. Ongoing updates: Regular status updates, at least daily during active response or as otherwise requested, until containment and recovery are substantially complete. The vendor must promptly notify the ISO of any material change in scope, impact, or risk.
  4. Investigation cooperation: The vendor must fully and promptly cooperate with the ISO’s investigation and response, including preserving relevant evidence; providing logs, records, and forensic findings; supporting interviews and technical inquiries; permitting reasonable audits or assessments; and assisting with root-cause analysis, risk assessment, remediation, and required notifications.
  5. Coordination of communications: The vendor may not notify affected individuals, regulators, law enforcement, or the public about an incident involving the CSULB’s ALPR information without the CSULB’s prior written approval, unless legally required. If disclosure is legally required, the vendor must provide advance notice when legally permitted and coordinate with the ISO.
  6. Remediation and prevention: The vendor must promptly implement corrective actions approved or reasonably required by the organization and provide a written post-incident report describing the incident, response actions, root cause, affected information, and measures taken to prevent recurrence.

Failure to meet these notification and cooperation requirements constitutes a material contractual breach and may result in corrective action, suspension of access, termination, indemnification obligations, or other remedies available under the contract and applicable law.

Questions, privacy concerns, access complaints, or suspected policy violations may be sent to Parking and Transportation Services at ParkingGeneral@csulb.edu or 562-985-4146. Security incidents may be reported to security@csulb.edu. Questions, privacy concerns, requests to correct ALPR information, and suspected policy violations may be submitted to Parking and Transportation Services at parkinggeneral@csulb.edu. Reports involving suspected information-security incidents will be handled under the CSULB Security Incident Reporting and Breach Notification Procedure.

13. Compliance and enforcement

Unauthorized operation, access, search, use, disclosure, alteration, or destruction of ALPR information is prohibited. Violations may result in suspension of access, corrective or disciplinary action consistent with applicable collective bargaining agreements and University policy, contract remedies, referral to law enforcement, and civil or criminal liability. The University may preserve records and suspend system access while reviewing a suspected violation.

14. Transparency and policy review

This policy will be available to the public in writing and posted conspicuously on the CSULB Parking and Transportation Services website. Material changes to purpose, collection, access, sharing, or retention require documented review by the official custodian, Information Security, University Counsel, Records Management, and other stakeholders as appropriate. The policy will be reviewed at least annually and promptly updated when law, CSU policy, technology, contracts, or University practice materially changes.  An annual management review will be conducted.

15. References

Appendix A. Required access-log fields

  • Date and time of access or query.
  • Plate number or other data element used to query.
  • Unique username and, if applicable, affiliated organization.
  • Specific authorized purpose stated in plain language.
  • Citation, appeal, case, request, incident, or other reference number.
  • Disclosure recipient, legal authority, approving official, data scope, and transmission method, when information is shared.