What mobile driver's licenses actually collect and share
The plastic card in your wallet is quietly being replaced. According to a recent commentary published by Federal News Network, more than 20 states now offer mobile driver's licenses (mDLs), and the federal government is pushing agencies to modernize legacy identity verification systems to keep pace. The piece frames this as a tipping point for digital identity in the United States, one that requires balancing citizen privacy with practical needs like frontline safety checks at airports, traffic stops, and age-restricted purchases.
An mDL stores your driver's license data directly on your smartphone, typically through a dedicated state app or a digital wallet. Unlike a physical card that simply displays your name, photo, and address to anyone who looks at it, a mobile ID can be programmed to share only specific pieces of information. For example, a bartender scanning your mDL to confirm you're over 21 might only receive a yes or no answer rather than your full birth date and home address. That selective disclosure is often marketed as a privacy improvement over the plastic card model.
But the flip side is that mDLs are built on digital infrastructure that plastic cards never had. That means data can be logged, transmitted, and potentially stored in ways a physical card never allowed. Understanding exactly what gets recorded, and by whom, is the first step before deciding whether to add a digital ID to your phone.
The tracking and surveillance risks of going digital-ID
The core tension with mobile IDs isn't just what data they collect, it's what they're technically capable of transmitting back to issuing authorities. Digital credentials rely on verification protocols that can, depending on implementation, notify a central system every time your ID is checked. That creates the possibility of a record showing when, where, and by whom your identity was verified, information a laminated card physically cannot generate on its own.
This is the same concern that has driven scrutiny from privacy researchers and digital rights groups: an mDL system that isn't carefully designed could turn routine identity checks into a surveillance trail. Even if no single check reveals much on its own, a pattern of checks over time (a bar tonight, a pharmacy tomorrow, an age-gated website next week) can paint a detailed picture of someone's movements and habits. For advocates and everyday users alike, the worry isn't hypothetical hacking so much as the built-in plumbing of how these systems are supposed to work.
There's also the more familiar risk of device compromise. Your mDL lives on your phone, which means anyone who gains unauthorized access to that device, through malware, a stolen phone, or a phishing attack, could potentially misuse your digital identity. That risk sits alongside the broader reality that digital credentials, like any data-bearing system, are attractive targets. The kind of large-scale extortion campaigns detailed in the CISA and FBI warning about Gunra ransomware illustrate how attackers increasingly go after sensitive data wherever it's stored, government systems included, and why any database holding identity credentials needs strong defenses from day one.
How agencies and apps are supposed to safeguard your data
The Federal News Network commentary frames the current push as agencies needing to modernize legacy verification systems specifically so they can handle mobile IDs securely, rather than bolting new technology onto old, unprepared infrastructure. That modernization effort matters because the safeguards built into an mDL system determine whether it delivers on its privacy promise or simply digitizes existing risks.
In practice, well-designed mDL systems are supposed to limit data sharing to only what's necessary for a given transaction, avoid unnecessary logging of verification events, and give users control over what information gets transmitted during each check. Agencies issuing these credentials are also expected to secure the backend systems that support verification, since a breach there could expose far more than any single physical wallet ever could.
However, implementation varies by state, and the pace of rollout doesn't always match the pace of security hardening. That gap between ambition and infrastructure is precisely what the commentary highlights as the central challenge: agencies need to move fast enough to meet mobile-first expectations while making sure the plumbing underneath is trustworthy.
What This Means For You
If your state offers a mobile driver's license, adoption is optional in almost every case right now, and it's worth treating it as a choice rather than an inevitability. Before enabling an mDL, it's reasonable to ask how your state's system handles verification logging, whether it shares more data than necessary during routine checks, and what happens if your phone is lost or compromised. These are the same questions privacy researchers have been raising as mDL programs expand nationwide.
For now, most states still allow you to carry a physical license alongside or instead of a digital one, so you're not forced to choose. Treating your phone's digital ID with the same caution you'd apply to your banking apps, meaning a strong passcode, biometric lock, and prompt reporting if the device is lost, is a reasonable baseline.
Actionable takeaways
- Keep a physical driver's license as backup, even if you enable a mobile version.
- Check your state's specific mDL privacy policy before opting in, particularly around data logging and sharing.
- Secure your phone with strong authentication, since your digital ID is only as safe as the device holding it.
- Stay alert to broader digital identity risks; the same threat actors targeting sensitive databases in incidents like the Gunra ransomware campaign have every incentive to target identity systems too.
- Revisit your choice periodically as mDL systems mature and security practices around them evolve.
Mobile driver's licenses aren't going away, and the convenience they offer is real. But convenience and privacy don't always move in the same direction, and understanding the tradeoffs now puts you in a much better position than discovering them after the fact.




