Storing your driver's license in a smartphone wallet is quickly moving from novelty to necessity. Apple and Google have both opened the door for drivers in participating U.S. states to add their official digital licenses to Apple Wallet and Google Wallet, respectively. States including Arizona, Iowa, Colorado, Georgia, Maryland, and others have already rolled out the feature, with more expected in coming months. On paper, the convenience is undeniable: no more fumbling through a physical wallet at a police checkpoint or liquor store, and instant verification through NFC tap technology.
But privacy advocates and cybersecurity researchers are raising alarms about what happens to that data once it leaves your physical card and enters a digital ecosystem controlled by tech giants and state motor vehicle departments alike.
One of the most significant concerns is the amount of data that can be extracted from a digital license during a scan. Unlike a physical card, where an inspector sees only what they look at, a digital credential transmitted via NFC can include your full name, date of birth, address, license number, photo, and even contactless transaction history — depending on how the issuing state has configured the data fields. Some states have built in privacy-preserving features that limit what information is shared, but these vary widely and are not guaranteed across jurisdictions.
There is also the question of Apple and Google's role. When you store a digital ID in either wallet, your phone must be unlocked — typically through Face ID, Touch ID, or a passcode — before the credential can be shared. That adds a layer of security that a physical card, which can be picked up and misused by anyone who finds it, does not provide. However, the very act of using Face ID or Touch ID means biometric data is processed locally on the device, and while neither Apple nor Google stores your biometric information on their servers, the infrastructure that verifies and validates the digital license sits within their respective ecosystems. Critics argue this creates a dependency that could be exploited or breached.
Location tracking is another flashing red flag. Every time you use your phone to verify your age or identity, your device may log that interaction. If law enforcement or other agencies obtain a subpoena or warrant for your phone's data, those transaction records could potentially be uncovered — something far less likely with a paper license that leaves no digital trail.
State officials have pushed back on some of these concerns, noting that digital licenses are encrypted and that the same data protection standards apply whether the credential is stored digitally or on a physical card. Many states also emphasize that the user must actively authenticate each time they share the license, and that there is no continuous background tracking happening in real time.
Still, legal scholars point out that the regulatory framework around digital IDs lags behind the technology itself. There is no federal law specifically governing how digital driver's license data must be protected, who can access it, or what penalties exist for misuse. The Physical Driver's License Act of 2016 established some baseline security standards for plastic cards, but no equivalent legislation currently exists for their digital counterparts.
For now, experts recommend that drivers who choose to adopt digital licenses do so with eyes open — understanding which states participate, what data fields are enabled, and keeping their physical card as a backup until the digital system matures and stronger privacy safeguards are codified into law.



