privacysecurity

Storing Your ID in Apple Wallet or Google Wallet: What It Reveals

States are rolling out mobile driver's licenses through Apple and Google Wallet. Here's what your digital ID reveals and who can request access to that data.

Digital ID wallet privacy is worth understanding before you add your driver’s license to Apple Wallet or Google Wallet. Mobile driver’s licenses — abbreviated mDL — are now accepted at TSA checkpoints in dozens of US airports, and state programs are expanding. The convenience is real. So is the data trail that identity verification creates.

The shift from physical ID to digital ID isn’t just a format change. It’s a change in who mediates the act of verification, what gets logged when your identity is checked, and where records of those verification events are stored. For most people, the practical difference will be invisible for years. For some, it will matter in ways they didn’t anticipate.


How Mobile Driver’s Licenses Work

The mDL standard — ISO 18013-5 — defines a technical protocol for mobile identity documents. The basic model works like this:

  1. Your state DMV issues a digital credential, cryptographically signed by the state, stored on your phone inside a secure enclave.
  2. When a verifier (TSA, a bar, an age-gated retailer) requests your ID, they present a request specifying what they need.
  3. Your phone shares only the specific attributes the verifier requested — date of birth if age verification is the purpose, or name and license status for a traffic stop — rather than the full contents of your license.

The selective disclosure design is a genuine privacy improvement over a physical license, which reveals your full address, full name, ID number, exact date of birth, and organ donor status even when someone just needs to know you’re over 21. An mDL implementation that works as designed only shares what’s asked for.

The gap between how the standard is designed and how implementations actually work is where the privacy questions live.


What Apple Actually Does With Your Digital ID

Apple’s wallet implementation stores the mDL credential in the Secure Enclave — the isolated cryptographic chip in iPhone hardware — and processes identity presentations locally on the device.

Apple’s published position is that it does not see the identity information shared during a verification transaction. The presentation happens on-device; Apple’s servers aren’t in the verification path.

This aligns with Apple’s broader “privacy as a product feature” positioning. Apple doesn’t have an advertising business model that creates incentives to see your verification events.

What Apple does collect:

  • The fact that an mDL was added to your wallet (for activation and troubleshooting)
  • Technical metadata about wallet state (not the contents of verification transactions)
  • Standard account information about your Apple ID

What this means in practice: Apple’s mDL implementation is relatively privacy-protective in terms of transaction data. The larger question is the state DMV’s data and the verifier’s data.


What Google Wallet Does With Your Digital ID

Google’s wallet implementation follows a similar architecture: on-device credential storage, on-device presentation, without Google seeing the contents of individual verification transactions.

Google’s advertising-driven business model creates more surface area for concern than Apple’s, but the technical architecture of the mDL implementation separates verification transactions from Google’s data collection. The mDL credential is handled by a secure element; it’s not processed through Google’s standard app infrastructure in ways that would make the verification contents available for ad targeting.

What Google does retain: activation events, wallet state metadata, and the standard Google account data associated with your device and account.

The practical distinction between Apple and Google for mDL privacy is less significant than the shared concerns about state DMV data and third-party verifier logging.


The State DMV Data Layer

Your mobile driver’s license is issued by your state DMV. The state is the root of trust in the credential chain — the entity that signs the cryptographic credential and maintains the identity record it’s based on.

States vary significantly in how they handle mDL issuance data:

What states know: Your identity information, the fact that you requested and received an mDL, and your device’s technical identifiers provided during enrollment.

Verification event logging: Some state implementations log when a credential is presented for verification — meaning the DMV knows that your license was checked at a specific location at a specific time. Whether states retain this data, for how long, and under what disclosure conditions varies by state program.

Law enforcement access: Unlike a physical license check, which leaves no central record beyond what the officer files, a logged digital verification event creates a retrievable record. Law enforcement requests to the state DMV could surface a log of every time your digital ID was presented for verification — at airports, bars, dispensaries, retailers, or traffic stops — if the state retains that data.

This isn’t hypothetical exposure in a worst case. It’s the straightforward operation of a verification logging system under existing law enforcement data request frameworks.


The Verifier Data Problem

When a verifier — a TSA agent, a bartender, a dispensary, an age-gated online service — checks your digital ID, they receive the attributes you’ve shared. What happens to that data on the verifier’s side is outside Apple’s or Google’s control.

TSA at Airports

The TSA has disclosed that it logs verification events for digital IDs. This is distinct from how physical license checks work at checkpoints: a physical check involves visual inspection without creating a central record. A digital check may create a logged event in TSA’s verification system.

TSA’s position is that this logging is for system security and operational purposes. The same legal frameworks that apply to TSA physical records — Freedom of Information Act requests, law enforcement inquiries, government data retention policies — apply to these logs.

Third-Party Verifiers

For verifiers outside of government (retailers, bars, venues, age-gated websites), the mDL technical standard defines what gets shared. It doesn’t define what the verifier logs after the transaction completes.

A bar that checks your digital ID receives your date of birth (or a confirmation that you’re over 21). Whether the bar logs that verification event, retains your identifying information, or links it to other in-venue data is governed by the bar’s own practices and applicable privacy law — not by Apple’s, Google’s, or the state DMV’s policies.

Age verification services that integrate digital IDs at the software layer — for online content, cannabis delivery, adult platforms — may log verification events in ways that create a persistent record of your identity check across multiple platforms, because a third-party identity service handles the verification for multiple clients simultaneously.


What the mDL Standard Gets Right

The ISO mDL standard’s selective disclosure design is genuinely better than a physical license for many common use cases. A few specifics worth noting:

Selective attribute sharing: You share date of birth for age verification, not your home address. This is a real improvement over handing someone a physical license.

Offline verification: The standard supports offline verification — a verifier can confirm the credential’s cryptographic validity without connecting to an external server. This prevents real-time network-based tracking of verification events by the credential issuer during the transaction itself.

Consent model: The presentation should be initiated by the holder, not captured by the verifier. A compliant reader can’t harvest your mDL data without your phone displaying the confirmation and you approving the presentation.

These design decisions matter. When implementations follow the standard correctly, the privacy properties are meaningful. The concerns arise in implementation gaps, post-transaction logging, and the legal frameworks that govern the records created.


Practical Considerations Before Adding Your ID

Ask your state’s DMV what they log. Many states have FAQ pages on their mDL programs that describe data retention practices. The answer varies significantly — some states explicitly discard verification event logs; others retain them. Knowing your state’s policy is the starting point.

Review the verifier’s practices before use. Using your digital ID with TSA is governed by federal policy. Using it at a dispensary, a bar, or an online platform means that verifier’s privacy policy applies to what happens after the presentation. When the verification service is a third party (not the venue itself), that third party’s data practices are the relevant consideration.

Understand the difference between wallet and physical ID trails. A physical license check at a traffic stop is logged in the officer’s report. A digital license check may additionally create a log at the DMV system level. The digital option isn’t necessarily more surveillance-prone than physical — but it may create a different kind of record, maintained in a different system, accessible through different legal mechanisms.

Use selective disclosure deliberately. The mDL standard allows you to share only what a verifier actually needs. If an age-check only requires confirming you’re over 21, share that attribute rather than your full date of birth. In compliant implementations, this choice is presented to you during the verification flow.


Storing Sensitive Documents Privately

The broader context here is personal identity documents in digital form. Scans of your passport, insurance cards, Social Security cards, birth certificates, and similar materials represent a category of highly sensitive personal data that many people now store digitally.

When that storage happens inside a major platform’s wallet or cloud drive — with the convenience they offer — the data exists under that platform’s terms, accessible through that platform’s legal process. When it happens in a purpose-built private storage service with server-side encryption and no data sharing, the exposure profile is different.

The question isn’t whether to go digital with important identity documents. For most people, some digital copy is practical and necessary. The question is where those copies live, under whose terms, and with whose access.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts