What this report is — and is not
The July 30 notice is requester-authored correspondence asserting apparent policy-compliance deficiencies and asking the County to cure or explain them. It is not a court ruling, County admission, or independent legal determination that a violation occurred. This report separates the notice’s position from what the cited statutes, Policy 473, and released records establish on their face.
Executive summary
A saved email dated July 30, 2026 documents electronic transmission of the notice to two Sheriff’s Office addresses with County officials copied. The email carried four exhibits: Policy 473; a requester-created compilation of California ALPR statutes; a screenshot of the July 28 unified CPRA response; and an administrative activity CSV covering August 2023 through December 2024.
The notice requested a substantive written response by close of business August 7, before the August 11 Board of Supervisors meeting. The materials supplied to this archive do not include a substantive County response specifically addressing the July 30 notice. The separate August 10 County Counsel letter archived elsewhere responds to the July 28 focused CPRA request and is not treated here as a response to this notice.
Four principal issues raised
| Issue | Source record / law | Notice position | Archive status |
|---|---|---|---|
| Public guidelines and procedures | Policy 473.3.1 assigns the Administrative Captain responsibility for developing guidelines and procedures and for conspicuous posting of the policy and related procedures. | The notice states that separate public guidelines or procedures were not identified in the released records. | Open question Whether separate procedures exist, are incorporated elsewhere, or are publicly posted is not resolved by the records in this package. |
| Periodic system audits | California Civil Code § 1798.90.53(b)(2)(C) expressly includes a process for periodic system audits in an end-user ALPR policy. Policy 473.6(c) says ALPR system audits should be conducted regularly. | The notice argues that Policy 473 states an audit expectation but does not itself describe the periodic audit process. | Open question Exhibit D contains 150 administrative create/update/delete events and is not labeled on its face as a periodic compliance-audit report or findings record. |
| Accuracy and data-error correction | Civil Code §§ 1798.90.51(b)(2) and 1798.90.53(b)(2) require reasonable measures to ensure accuracy and correct data errors. Policy 473 also contains an operational safeguard directing CLETS verification when practicable before enforcement based solely on an alert. | The notice argues that the released policy does not set out an explicit process for correcting inaccurate ALPR information or data errors. | Archive analysis The released policy’s CLETS-verification language is visible, but the archive does not make a legal-sufficiency determination about whether the policy as a whole satisfies the statutes. |
| Retention and destruction | The cited statutes require a retention length and destruction process. Policy 473.5 says ALPR data downloaded to “the server” should be stored for a minimum of one year; the agency’s July response says Flock-captured images are retained 30 days by default and may be retained longer if flagged or downloaded. | The notice asks the County to clarify which data categories and storage layers each retention statement covers and how destruction occurs. | Open question The existing records still do not reconcile the 30-day and minimum-one-year language by category and storage location. |
What the notice requested
The notice asked the County to identify the policy basis it believes satisfies California ALPR requirements; point to the exact compliance language; identify any separate public guidelines; revise and publish them if necessary; document the periodic audit process; identify procedures for inaccurate data; clarify retention and destruction; explain interim compliance measures; and preserve relevant records. It also asked the Clerk of the Board to distribute the notice and attachments to the Board and preserve them as official correspondence.
What Exhibit D shows
The attached CSV contains 150 administrative events from August 16, 2023 through December 8, 2024: 93 update events, 52 create events, and 5 delete events involving roles, users, and one organization-level entry. That makes it useful evidence of administrative account activity. On its face, however, it is not labeled as a periodic compliance audit and does not itself contain audit findings, misuse determinations, or corrective-action conclusions.
Questions remaining
- Did ACSO maintain separate ALPR guidelines or procedures beyond the three-page Policy 473 excerpt, and if so, where were they posted?
- What is the documented periodic audit process, who performs it, how often, and what findings or corrective actions are retained?
- What written process governs correction of inaccurate ALPR information or data errors?
- What data is subject to 30-day deletion, what data is retained a minimum of one year, where is each category stored, and what destruction process applies?
- Did the County issue a substantive response to the July 30 notice or take any policy action in response?
Revision history
- Initial publication based on the July 30 notice package and independently verified statutory text.