Digital driver's licenses can reveal less, but privacy concerns persist
Standards-based mobile driver's licenses in Apple and Google wallets can share less information than a physical card, but questions remain over tracking, data retention and what happens after a user approves a share. North American motor vehicle agencies have prohibited server-based retrieval, while privacy advocates warn easier digital IDs could expand age and identity checks.
A standards-based mobile driver's license, or mDL, is not a photo of a plastic card saved on a phone. It contains digitally signed information that a compatible reader can verify as coming from the issuing authority. That design can make some interactions more private than showing a physical license, while also protecting access to the ID through the phone's security features. But it raises separate questions about tracking, data retention and what happens if the phone becomes unavailable.
A physical driver's license exposes everything printed on it to whoever checks it. If a verifier only needs to confirm that someone is over 21, for example, that person may also see the exact birth date, home address and license number. An mDL can be more selective. The standard supports broad age statements, such as whether someone is over 21, so a compatible verifier can request that answer without seeing the full date of birth.
Apple and Google have added their own safeguards. Apple says users can review requested information before sharing it, and in-person presentation requires authentication with Face ID, Touch ID or an applicable accessibility method. Driver's license and ID data is encrypted, and users do not need to hand over or unlock their phone. Google says its U.S. driver's licenses and state IDs are encrypted and stored locally on the phone rather than in a Google Account. Google Wallet also shows requested information before it is shared and requires authentication. Engadget reported that these controls do not automatically make a digital license safer than a physical one, but they can give users more control over what they reveal.
Tracking is one of the main concerns. The 2021 ISO/IEC 18013-5 standard supports two ways to provide a digital license. With device retrieval, information is sent directly from the phone to the reader. With server retrieval, the reader gets the information from the authority that issued the license instead. Privacy advocates object to server retrieval because the issuer could potentially learn when or where the ID is being used. The Center for Democracy & Technology calls this the "phone home" problem and argues that a digital ID should not be able to report every use back to the issuing agency. That does not mean Apple Wallet or Google Wallet work that way, according to the report; the concern is about what server retrieval could allow if it were used.
There has been a significant policy change. The American Association of Motor Vehicle Administrators, which sets implementation guidance for motor vehicle agencies across North America, prohibited server retrieval in 2025. Its current Mobile Driver License Implementation Guidelines, published in July 2026, continue that prohibition. Still, the report noted, that does not make every digital ID system untraceable. Privacy depends on the standard, regional rules and the wallet's own design.
Controlling what leaves the phone is only part of the question. Once an organization receives information from a digital ID, the wallet cannot necessarily control what that organization does with it afterward. That makes data retention an important part of the transaction. Before a user approves a share, Apple Wallet tells them what information is being requested and, where applicable, whether the requester intends to retain it. Google Wallet also lets a requester indicate whether it plans to keep particular pieces of information before the user approves the request.
Legal protections vary by location. New Jersey's digital ID law includes specific privacy safeguards: an organization cannot require someone to hand over their device when presenting a digital ID, and presenting one does not amount to consent to search other information on the phone.
The American Civil Liberties Union has raised a broader concern. It argues that easier access to government-backed digital IDs could encourage more online services to demand identity or age checks in situations where people can currently browse anonymously. Engadget described that as an argument about how the infrastructure could be used as adoption grows, not evidence that current digital licenses are tracking people's web activity. The debate is becoming more concrete as Google expands Wallet's digital ID and age-verification features in parts of the European Union, including ways to confirm someone's age without sharing their name, address or full birth date.