Research Summary
Three Facts That Separate a Legal Lookup From a Federal Crime
Reading a plate off a car in traffic is not regulated. Pulling the owner’s name and address from a DMV database is what triggers federal law.
Federal law lists exactly 14 permitted purposes. Anything outside that list — including simple curiosity — is a federal violation, no matter who is searching.
Having system access isn’t the same as having a lawful reason. Officers who run plates for personal reasons have paid settlements from the tens of thousands to $585,000.
The Driver’s Privacy Protection Act: The Law That Controls Every Answer
A license plate is a public identifier, bolted to a vehicle and displayed openly on every public road in the country. The alphanumeric sequence itself carries no legal protection — anyone can see it, photograph it, or write it down. What the law protects is what happens next: the moment that sequence is typed into a state Department of Motor Vehicles database and converted into a name, an address, and a driver’s license number.[1] That conversion — a database query linking a public plate to a private person — is exactly what the federal Driver’s Privacy Protection Act of 1994 (DPPA) regulates, codified at 18 U.S.C. §§ 2721–2725.[2] Under that statute, running a license plate to obtain personal information is illegal unless the person doing the search has one of 14 specific, legally authorized reasons.[4]
Why Congress Wrote This Law: A Murder, a Harassment Campaign, and a Burglary Ring
Before 1994, state DMVs sold driver records to nearly anyone willing to pay a small fee — direct marketers, private investigators, and members of the public alike, generating steady state revenue in the process.[9] That open access produced a documented pattern of abuse. In 1989, an obsessed fan hired a private investigator who obtained actress Rebecca Schaeffer’s home address directly from the California DMV using her license plate; the fan traveled to her home and murdered her.[9] In the early 1990s, opponents of abortion copied license plate numbers of patients and staff outside women’s health clinics and used DMV records to track them down for sustained harassment — physician Susan Wicklund faced a month of protests at her private residence after her address was obtained this way.[1] Separately, burglary rings in Iowa used the plates of expensive cars parked in public to find owners’ addresses and rob their homes while they were out.[9]
Representative Jim Moran of Virginia introduced the Driver’s Privacy Protection Act in 1992 in direct response to this pattern, and it passed as Title XXX of the Violent Crime Control and Law Enforcement Act of 1994.[1] The Supreme Court unanimously upheld the statute against a constitutional challenge in Reno v. Condon(2000), ruling it a valid exercise of Congress’s power to regulate interstate commerce.[9] A follow-up law in 2000, the Shelby Amendment, tightened the rule further: states must now obtain a driver’s express written opt-in consent before selling personal motor vehicle records to marketers, replacing the earlier opt-out system.[9]
Two Tiers of Protected Data
The statute does not treat every piece of data linked to a plate the same way. It splits protected information into two tiers, and the second tier requires a stricter justification to access.
Personal information, defined at 18 U.S.C. § 2725(3), covers anything that identifies the vehicle owner: full name, home address, telephone number, and driver’s license or ID number.[6] Notably excluded from protection are accident and violation history, license status (valid, suspended, or revoked), and the five-digit ZIP code, which remains available for broad statistical use.[13]
Highly restricted personal information, defined at 18 U.S.C. § 2725(4), is a narrower and more sensitive category: the owner’s photograph or digital image, Social Security number, and any medical or disability information the state holds.[15] Because the risk of identity theft is far higher, this tier can be released under only a narrow subset of the 14 permissible uses, or with the individual’s express written consent.[15]
The 14 Permissible Uses: The Only Legal Reasons to Run a Plate
Section 2721(a) of the statute starts from a flat prohibition: a state DMV, and anyone acting on its behalf, may not disclose personal information from a motor vehicle record to any person or entity.[2] Congress then carved out exactly 14 exceptions in Section 2721(b) to keep essential government, insurance, and legal functions running. If a search does not fit cleanly into one of these 14 categories, it is not legal — regardless of how the requester obtained access to the data.[4] States are also free to adopt fewer than all 14 exceptions or impose tighter rules; Arkansas and Wyoming, for example, restrict access primarily to the licensee, law enforcement, and anyone with the licensee’s written permission.[9]
| # | Category | Scope |
|---|---|---|
| 1 | Government & Law Enforcement | Any government agency, court, or law enforcement agency carrying out its official functions, including contractors acting on its behalf. |
| 2 | Safety, Theft & Emissions | Motor vehicle or driver safety, theft, emissions compliance, product recalls, and manufacturer performance monitoring. |
| 3 | Business Verification & Fraud | Legitimate businesses verifying information a person submitted, or correcting it to prevent fraud or recover a debt. |
| 4 | Court & Legal Proceedings | Civil, criminal, administrative, or arbitral proceedings, including service of process and litigation investigation. |
| 5 | Research & Statistics | Research and statistical reporting, provided the data is never published or used to contact individuals. |
| 6 | Insurance Activities | Claims investigation, anti-fraud work, rating, and underwriting by insurers and insurance support organizations. |
| 7 | Towed & Impounded Vehicles | Providing legal notice to the owners of towed or impounded vehicles. |
| 8 | Private Investigators | Licensed investigative or security agencies, but only when the underlying purpose independently qualifies under another exception. |
| 9 | Employer CDL Verification | Employers verifying commercial driver’s license information as required under Title 49. |
| 10 | Toll Facilities | Normal operation of private toll transportation facilities, including billing vehicle owners. |
| 11 | General Express Consent | Any requester, when the state has obtained the individual’s express written consent to release their record. |
| 12 | Bulk Marketing Consent | Bulk distribution for surveys or marketing, but only with the individual’s express opt-in consent. |
| 13 | Specific Written Consent | Any requester who can document the individual’s written consent to the specific request. |
| 14 | State-Authorized Public Safety | Any other use a state specifically authorizes, if directly related to vehicle operation or public safety. |
Full statutory text: 18 U.S.C. § 2721(b).[2]
An authorized recipient does not gain the right to freely redistribute what they legally obtained. Section 2721(c) permits resale or redisclosure only to another party that independently has a permissible use, and anyone who resells or rediscloses the data must keep records — identifying every recipient and their stated purpose — for a minimum of five years.[2] That record-keeping requirement exists precisely to stop protected data from being laundered through an authorized user to reach someone with no legitimate reason to have it.
Law Enforcement Access Is Not an Unlimited Privilege
Most license plate lookups in the United States happen during a traffic stop, a crash investigation, or an active criminal inquiry — squarely inside Exception 1, government and law enforcement functions.[4] But an officer’s access to the National Crime Information Center and state DMV databases is not a blanket privilege. It runs through the FBI’s Criminal Justice Information Services (CJIS) Security Policy, which sets the technical and operational rules for handling that data and derives its authority from the Federal Information Security Management Act of 2002.[18]
The core CJIS rule is purpose limitation: the system may only be used for official criminal justice work. Checking on a neighbor, an ex-spouse, or anyone else for a personal reason is expressly prohibited and carries serious penalties.[22] To catch misuse after the fact, every query generates a transaction log; agencies must designate a security officer to review those logs at least weekly, and audit records must be kept for at least one year.[22] Many state laws back this with criminal penalties of their own — Massachusetts General Law Chapter 266, Section 120F, for example, makes an officer’s unauthorized access to a computer system for non-law-enforcement purposes a punishable offense carrying fines and incarceration.[22]
A standard lawful query returns a large amount of data at once: registration status, the registered owner’s name and address, physical descriptors, license status, and safety flags such as an outstanding warrant, a missing-person alert, or an active protective order.[9] That breadth is exactly why abusing the access is treated so seriously — a single curious lookup can expose nearly everything the government knows about a person.
The “Curiosity Lookup” Cases: When Officers Cross the Line
The clearest evidence that access alone does not equal legality comes from a wave of federal lawsuits against police departments, mostly out of Minnesota, that established a single controlling principle: even an officer with fully authorized system credentials commits a federal privacy violation by running a plate or a name search for a purely personal reason.
The pattern surfaced in 2009, when St. Paul police officer Anne Marie Rasmusson discovered that colleagues were pulling up her driver’s license photo and personal data on patrol-car computers. A state audit found that 104 officers across 18 different agencies had accessed her file 425 times over four years with no legitimate law-enforcement reason.[26] Rasmusson sued under the DPPA and ultimately secured settlements totaling more than $1 million.[26]
That litigation triggered a wave of independent audits by other officers and private citizens. Fellow Minnesota officer Amy Krekelberg requested her own audit and found that 58 colleagues had searched her driver’s license data 87 times without a lawful purpose; court records showed her looks and marital status had generated workplace gossip that drove the searches.[27] A federal jury awarded her $585,000 in damages.[27]
The abuse extended past internal department gossip and reached private citizens directly. In Heglund v. Aitkin County, two women discovered their records had been accessed a combined 480 times over ten years, often by officers investigating one woman’s ex-husband’s new relationships.[29] In the related Mallak v. Aitkin County case, a local attorney found her information had been repeatedly pulled by multiple agencies with no legitimate justification.[30] And in the Eighth Circuit case Orduno v. Pietrzak, a municipal police chief used his official credentials to illegally look up a motorist’s personal information six times for private reasons; a federal jury awarded her $85,000 in punitive damages, $15,000 in liquidated damages, and more than $141,000 in attorney’s fees. The court held the chief’s municipality vicariously liable, reasoning that his official government access made the violation possible in the first place.[31]
The Controlling Principle
An officer running a plate to identify a robbery suspect’s vehicle is exercising a lawful, permitted use. That same officer running that same terminal to find out where an attractive coworker lives, or to track an ex-spouse’s new relationship, is committing a federal crime — the legality turns entirely on the officer’s actual purpose, not on whether their badge grants them technical access.[6]
Maracich v. Spears: The Supreme Court Narrows the “Litigation” Exception
In 2013, the Supreme Court took up the boundaries of Exception 4 — the litigation exception — in Maracich v. Spears. A group of South Carolina trial lawyers used the state’s public-records law to obtain the names and addresses of thousands of recent car buyers from the state DMV, then sent mass mailings marked “ADVERTISING MATERIAL” to more than 34,000 people, soliciting them to join a proposed class action against several car dealerships.[7] When several recipients sued the lawyers for violating their federal privacy rights, the lawyers defended themselves by pointing to Exception 4, which permits disclosure for use in a legal proceeding, including “investigation in anticipation of litigation.”[7]
In a 5–4 decision written by Justice Anthony Kennedy, the Court rejected that defense. It held that soliciting clients is fundamentally commercial advertising, not litigation investigation, and established a “predominant purpose” test: if the main reason for accessing the data was to drum up business rather than to build an existing case, the litigation exception does not apply.[32] Kennedy noted that the statute already addresses mass solicitation directly, in Exception 12, which requires the driver’s express opt-in consent — letting lawyers bypass that requirement by relabeling their marketing as litigation prep would gut the law’s structure entirely.[33] Four justices dissented, arguing the lawyers were organizing a concrete legal proceeding against identified defendants and that the mailings directly served that case. The majority ruling stands as the governing national standard regardless: running plates to build a marketing list is illegal without express consent, even for a licensed attorney preparing a lawsuit.[33]
Senne v. Village of Palatine: Does a Parking Ticket Violate Your Privacy?
A separate line of litigation, decided by the Seventh Circuit Court of Appeals, tested one of the most common plate lookups of all: a municipal parking ticket. In August 2010, Jason Senne parked overnight on a Palatine, Illinois street in violation of a local ordinance. An officer ran his plate, printed a $20 ticket, and placed it under his windshield wiper — and the ticket itself displayed his full name, home address, driver’s license number, date of birth, sex, height, and weight for anyone walking by to read.[8] Senne filed an $80 million class-action lawsuit, arguing that leaving that much personal data exposed on a public windshield was an illegal disclosure under the DPPA.[8]
The case turned on two questions. First: does printing data on paper and placing it in public view count as a “disclosure” at all? Sitting en banc, the Seventh Circuit said yes, reversing a district court that had said no.[8] Second: was that disclosure legal anyway? After years of appeals, the court ultimately ruled for the municipality, holding that placing a ticket on a windshield is the conventional, recognized method of serving process for a parking violation and that including the owner’s details serves a genuine administrative function — for instance, letting an officer confirm that a person standing near the car matches the registered owner.[8] Judge Richard Posner dissented sharply, warning that broadcasting so much personal data on a public ticket meant “only a sucker would park legally.” Legal risk experts now advise municipalities to strip unnecessary personal data from citation printouts to avoid the exposure this case revealed.[8]
Automated License Plate Readers: The Law Meets a Camera
Officers manually typing a plate into a mobile terminal are increasingly being supplemented by Automated License Plate Readers (ALPRs) — high-speed camera systems mounted on patrol cars, bridges, and street poles that photograph and read thousands of plates per hour without a human typing anything.
The raw output of an ALPR — a plate image, a timestamp, and GPS coordinates — is not, by itself, protected personal information; it simply records that a plate existed at a place and time.[23] The moment that raw capture is queried against a hotlist, the National Crime Information Center, or a state DMV database to attach a name, face, or address, it crosses into the same protected territory as a manual lookup.[23] Any cloud vendor storing that linked data for a police department must comply with the same CJIS security framework, including a formal Security Addendum approved by the FBI Director and the principle of least privilege — giving cloud administrators only the minimum access their job requires.[23]
What an Illegal Lookup Actually Costs
Under 18 U.S.C. § 2722, knowingly obtaining or disclosing personal information for a use the statute does not permit — or lying to obtain it — is unlawful, and Section 2723 attaches criminal fines to that violation, up to $5,000 per violation plus a permanent federal criminal record.[3] If the U.S. Attorney General finds that a state DMV has a policy or practice of substantial noncompliance, the state itself can face a civil penalty of up to $5,000 for each day the noncompliance continues.[4]
The statute’s sharpest enforcement tool is the private right of action in 18 U.S.C. § 2724, letting any victim sue the violator directly in federal court.[4]
| Remedy | Who Pays / Who Collects | Amount |
|---|---|---|
| Criminal fine (violator) | Federal government prosecutes the violator | Up to $5,000 per violation |
| State noncompliance penalty | U.S. Attorney General v. a noncompliant state DMV | Up to $5,000 per day of continued noncompliance |
| Liquidated damages floor | Victim, via private civil suit | No less than $2,500 per violation, no proof of harm required |
| Punitive damages | Victim, upon proof of willful or reckless conduct | Case-by-case; can exceed liquidated damages |
| Attorney’s fees & costs | Victim’s legal team | Reasonable fees and litigation costs |
Source: 18 U.S.C. §§ 2723–2724.[4]
What This Means the Next Time You’re Curious About a Plate
Looking at a plate, photographing it, or reporting it to police for a hit-and-run or reckless-driving complaint is not regulated by the DPPA at all — the statute only reaches the database query that turns that plate into a name and address. If you are the one being looked up rather than doing the looking, the same statutory concerns overlap with how a plate itself is displayed and read: our companion research on license plate frames obscuring parts of the plate and on driving without a front license plate covers the equipment side of the same public identifier this report addresses from the data side.
For a private citizen without an official function, the safest course is straightforward: license plate lookup websites and DMV record requests generally cannot be used to satisfy simple curiosity, and doing so exposes the requester to the same liquidated-damages floor discussed above. Suspicion of a specific crime belongs with police, not a private database query.
Frequently Asked Questions
Is it illegal to run a license plate?
It depends entirely on who is running it and why. The federal Driver's Privacy Protection Act makes it illegal for anyone to obtain a vehicle owner's personal information from a plate lookup unless the search fits one of 14 specific permitted purposes, such as an official law-enforcement function, an insurance investigation, or a court proceeding. A private citizen running a stranger's plate out of curiosity, to stalk someone, or to settle a personal score has no permitted purpose and is committing a federal crime.
Can a private citizen legally run a license plate?
Rarely, and only through channels that require a documented reason. A private citizen cannot walk up to a DMV counter or a license-plate-lookup website and pull a stranger's name and address just to satisfy curiosity. Licensed private investigators can request the data, but only for a purpose that independently qualifies under one of the Driver's Privacy Protection Act's 14 exceptions, such as investigating a specific civil claim.
Can a police officer get in trouble for running a license plate?
Yes. Federal courts have repeatedly held that an officer commits a federal privacy violation by running a plate or a name for a purely personal reason, even with fully authorized system access. Minnesota officer Anne Marie Rasmusson's data was accessed 425 times by 104 officers with no law-enforcement purpose, producing settlements exceeding $1 million; officer Amy Krekelberg was separately awarded $585,000 after 58 officers looked her up out of curiosity.
What information does a license plate lookup reveal?
A standard law-enforcement plate query returns the registered owner's name, address, vehicle description, registration status, and driver's license status, plus safety flags such as an outstanding warrant or a protective order. A more sensitive category — the owner's photograph, Social Security number, and medical or disability information — is separately shielded as "highly restricted personal information" and requires an even narrower justification to release.
Can I sue someone for illegally running my license plate?
Yes. The Driver's Privacy Protection Act creates a private right of action in federal court. A proven violation carries a statutory floor of at least $2,500 in liquidated damages per violation without proving financial harm, plus potential punitive damages for willful conduct and recovery of attorney's fees.
Does running a plate to issue a parking ticket violate federal privacy law?
No, according to the Seventh Circuit Court of Appeals in Senne v. Village of Palatine. The court ruled that printing an owner's name, address, and physical description on a ticket left on a windshield is a "disclosure" under the statute, but held that a parking ticket is a legally recognized method of serving process for a parking violation, placing it within the law's permitted exceptions.
Are automated license plate readers illegal?
Not by themselves. The raw image, timestamp, and location an ALPR camera captures is not protected personal information on its own. The Driver's Privacy Protection Act and FBI CJIS security rules apply once that captured plate is queried against a database to attach a name, face, or address to it — the same point at which a manual officer lookup becomes regulated.
Legal Disclaimer
This content is provided for informational and educational research purposes only. It does not constitute legal advice and does not create an attorney-client relationship. Federal and state privacy statutes, agency policies, and court rulings are subject to change. Verify current requirements with the applicable federal statute, your state’s DMV, and a qualified attorney in your jurisdiction before taking any action based on this research.
Primary Source Directory
- Driver’s Privacy Protection Act — Wikipedia: Overview of the statute’s legislative history, including the 1989 murder of Rebecca Schaeffer and the 1992 introduction of the bill by Rep. Jim Moran.
- 18 U.S.C. § 2721 — Prohibition on Release and Use of Certain Personal Information From State Motor Vehicle Records: Official U.S. Code text setting the disclosure prohibition, the 14 permissible uses, and resale/redisclosure recordkeeping rules.
- Title 18 — Crimes and Criminal Procedure — GovInfo: Official U.S. Code Title 18 Part I, Chapter 123 text, including the resale, redisclosure, and penalty provisions of the DPPA.
- Drivers Privacy Protection Act, 18 U.S.C. § 2721 et seq. — New York State eJustice Portal: State-published summary of the statute’s prohibitions, permissible uses, and civil/criminal penalty structure.
- Drivers Privacy Protection Act, 18 U.S. Code § 2721 — Federal Criminal Defense Attorney: Legal-practice summary of protected personal information categories and enforcement exposure.
- Maracich v. Spears, 570 U.S. 48 (2013) — Justia Supreme Court: Full opinion establishing the “predominant purpose” test narrowing the DPPA’s litigation exception.
- Senne v. Village of Palatine: The Seventh Circuit’s Parking Ticket Payout — Saint Louis University Law Journal, Scholarship Commons: Law review analysis of the en banc Seventh Circuit ruling on plate-derived data printed on parking tickets.
- The Drivers Privacy Protection Act (DPPA) and the Privacy of Your State Motor Vehicle Record — Epic.org: Electronic Privacy Information Center overview of the DPPA’s history, Reno v. Condon, the Shelby Amendment, and typical law-enforcement query results.
- Driver Privacy Protection Act — Florida Department of Highway Safety and Motor Vehicles: State agency summary confirming which data categories (accident/violation history, ZIP code) fall outside DPPA protection.
- 18 U.S.C. § 2725(4) — “Highly Restricted Personal Information” — Law.Cornell.Edu: Cornell Legal Information Institute definition of the statute’s narrower, more sensitive data category.
- Criminal Justice Information Services (CJIS) Security Policy — FBI: Official FBI security policy governing law-enforcement access to criminal justice information, including motor vehicle record queries.
- Criminal Justice Information System (CJIS) Policy — Williamstown Police Department: Municipal department policy implementing CJIS purpose-limitation, authentication, audit, and training requirements.
- Vigilant LEARN CJIS Security Compliance Guide — Motorola Solutions: Industry compliance guide describing when raw ALPR camera captures cross into CJIS-protected data and required cloud-vendor safeguards.
- What’s On Your (License) Plate? — lgit.org: Local government insurance trust analysis of the Anne Marie Rasmusson curiosity-lookup litigation and resulting settlements.
- Jury Awards $585K To Minneapolis Cop Over License Lookups — CBS Minnesota: News coverage of the federal jury verdict in Amy Krekelberg’s DPPA lawsuit against fellow officers.
- Heglund v. Aitkin County — U.S. District Court, District of Minnesota (via Epic.org): Federal court memorandum opinion documenting repeated unauthorized DPPA lookups of two private citizens.
- Mallak v. Aitkin County et al., No. 0:2013cv02119 — Justia: Federal district court docket record documenting a related unauthorized-lookup DPPA claim.
- Privacy — Americans for Effective Law Enforcement (AELE), Civil Liability Law Digest: Case digest summarizing Orduno v. Pietrzak, including jury damages and the municipality’s vicarious liability.
- Supreme Court Decides Maracich v. Spears — Faegre Drinker Biddle & Reath LLP: Law firm client alert summarizing the majority opinion’s reasoning and the predominant-purpose standard.
- Maracich v. Spears — Oyez: Case summary and oral argument archive from the Oyez Supreme Court database, including the dissent’s reasoning.