Technology

Digital Driver’s Licenses Face Privacy Tests as States Go Mobile

What mobile driver's licenses reveal—and what they keep private

Arizona became the first jurisdiction to support Apple Wallet driver’s licenses in March 2022. Maryland, Colorado, Georgia, California, Utah, Iowa, and Ohio later launched state ID support across Apple and Google platforms, while the Transportation Security Administration began deploying Credential Authentication Technology Phase 2 (CAT-2) readers at U.S. airport security checkpoints.

Advertisement

CAT-2 units accept ISO 18013-5 compliant credentials through contactless readers. Major hubs using the technology include Phoenix, Baltimore, Atlanta, Reagan National, and Los Angeles. The expansion is taking place as state motor vehicle agencies move physical identification credentials into smartphone digital wallets.

ISO/IEC 18013-5 governs the technical standards for mobile driver’s licenses (mDLs). The International Organization for Standardization and the International Electrotechnical Commission officially published the standard in September 2021, establishing cryptographic protocols that let a mobile device present digitally signed identity data directly to an electronic reader.

Under that architecture, standard transactions use “device retrieval”: encrypted identity data moves directly from a smartphone to a verification terminal over short-range channels such as Near Field Communication (NFC) or Bluetooth Low Energy (BLE). A different framework, “server retrieval,” requires a verifier to query an issuing authority’s remote database in real time.

The American Association of Motor Vehicle Administrators (AAMVA), which standardizes technical guidance for motor vehicle departments across North America, established formal rules in 2025 prohibiting server-retrieval systems for digital licenses. AAMVA maintained that position in its Mobile Driver License Implementation Guidelines, published in July 2026.

Digital rights advocates, including the Center for Democracy & Technology (CDT), have warned that server retrieval could create audit logs of physical movements and commercial transactions, a concern often described as a “phone home” risk. The AAMVA prohibition targets centralized verification models that could allow state agencies or third parties to record every time and location a citizen presents an ID card.

Unlike traditional laminated cards, which display a holder’s full legal name, date of birth, home address, physical attributes, and driver’s license number simultaneously, ISO 18013-5 supports selective disclosure controls. An electronic reader can request only the data fields needed for a particular interaction.

For an age-restricted purchase, a compatible terminal can ask whether a holder is at least 21 years old and receive a cryptographically verified confirmation without obtaining the exact birth date, address, or document number. In the European Union, Google has expanded digital wallet ID tools under the eIDAS 2.0 regulatory framework, where platforms are implementing age-verification methods that confirm age limits while withholding full legal names and residential addresses.

Apple stores credentials inside the device’s Secure Enclave. Before data is transmitted, the system requires active local biometric validation through Face ID or Touch ID, or an applicable accessibility authorization. Apple Wallet displays the specific fields requested by a verifier so cardholders can review what will be transmitted before approving the exchange.

Google uses hardware-backed execution environments, including Trusted Execution Environments (TEE) and StrongBox key management modules, on compatible Android hardware. Mobile IDs in Google Wallet are encrypted and stored locally on the physical handheld device rather than uploaded to central Google Account cloud infrastructure.

Android systems also prompt users to authenticate with biometric scanning or device screen lock credentials and display a readout of requested data fields before transmission. On both platforms, data exchanges occur wirelessly, so users do not need to physically hand an unlocked smartphone to an inspector or law enforcement officer.

State legislatures have begun setting legal limits for law enforcement handling and data retention. In New Jersey, statutory protections say that presenting a digital driver’s license does not constitute legal consent for officers or third parties to search or inspect other contents on the mobile device. The law also clarifies that citizens are not required to hand physical custody of their mobile phones to inspecting authorities.

Those protections do not control what happens after information leaves a phone. Software wallets cannot police how third-party recipients process or store shared data, although Apple Wallet and Google Wallet provide interface indicators showing whether a requesting verifier intends to retain the shared attributes.

The American Civil Liberties Union (ACLU) has highlighted risks tied to the broader normalization of digital credentials. The group has cautioned that widespread infrastructure could lead commercial platforms to require verified government IDs for online browsing activities that were previously conducted anonymously.

Device status creates another limitation. Depleted batteries, broken screens, or software system freezes can prevent a digital wallet from communicating with readers, and a digital ID cannot be displayed without device power and operational screen hardware.

A lost physical card leaves its printed information readable to any finder. A digital ID on a secured smartphone, by contrast, requires bypassing device encryption and authentication locks. If a phone is stolen or lost, users can issue remote wiping commands through Apple’s Find My network or Google’s Find My Device account portal, revoking stored wallet passes and credentials remotely.

Because of those operational limits, state motor vehicle departments and transportation authorities maintain that digital licenses serve as a companion credential rather than a complete replacement for standard physical plastic cards.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *