When a store or rental scans your driver's license, who keeps the photo?

Updated Corrections

September 17, 20268 min read

Usually the scan is an age or identity check, and it reads the barcode on the back rather than photographing your license. Your photo is never in that barcode. Some counters do image the card itself, and then the business, its ID-verification vendor, or both can hold that picture. What they may keep depends on the business and your state, and those copies are separate from your DMV record and from the people-search profiles that publish your address and phone number.

A free Delist scan looks at the open web we check for listings about you. It does not tell you whether a copy of your license sits in a particular company's system or in a particular leaked file.

Sources

Why stores and rentals scan your license

Age gates, fraud checks, and rental contracts. A bar or dispensary is confirming you're old enough and the ID is genuine. A car rental or hotel is tying a contract to a verified identity. A pharmacy may be logging a regulated purchase. None of that is unusual, and refusing the scan often means not completing the transaction.

The scan is quick because most of the time it isn't taking a picture. Every US license carries a PDF417 barcode on the back, and under the AAMVA card standard that barcode holds your name, address, date of birth, sex, height, eye color, license number, and issue and expiration dates. The standard requires all of it to be unencrypted, so any scanner can read it in one pass. Your photograph is not in there.

Imaging is the other kind of scan, and it's the one worth asking about. Some systems photograph the front and back of the card, sometimes under infrared and ultraviolet light to check for forgery. That's where a copy of your picture comes from.

Who can keep a copy

Two parties, and you rarely see either one.

The business keeps whatever its point-of-sale or check-in system stores. That might be a yes-or-no age result, or the fields it read, or images of the card.

The ID-verification vendor behind that scanner keeps its own records. These companies sell scanning hardware and software to thousands of venues at once, so the data flows to them too, not only to the counter in front of you. You never signed anything with that vendor and usually never learn its name.

You almost never get a receipt for any of it, which is why the honest answer to "who has my license photo" is often "the business, its vendor, and whoever they share it with."

What your state may require

Retention rules are a patchwork, and many of them are specific to one industry rather than to ID scanning in general.

A few states limit what a business may hold onto. New Hampshire bars businesses from electronically scanning, recording, retaining, or storing license data at all without state authorization (RSA 263:12). New Jersey lets retailers scan for a short list of reasons and forbids keeping anything scanned purely to check age or authenticity (PIPPA). California allows a scan to verify age or authenticity and then bars the business from retaining or using the data for anything else (Civil Code 1798.90.1). Nebraska lets alcohol, tobacco, and lottery sellers store only your age and ID number, requires a sign telling you so, and caps retention at 18 months (60-4,111.01).

Others limit use rather than retention. Illinois says data taken from your license in a transaction may be used only for that transaction and may not be sold or given to a third party (625 ILCS 5/6-117.1). Connecticut restricts what a liquor permittee may record from a scan (30-86).

Cannabis regulators are sometimes the strictest. Oregon says age-verification data may not be retained after the check (ORS 475C.109), and New Jersey rules say a cannabis retailer "shall not keep a copy of the consumer's photographic identification."

Plenty of states have no rule of this kind, and where a rule exists it usually has exceptions for fraud prevention and for records the business is separately required to keep. So the practical answer stays the same: ask, and don't assume the copy disappears.

When those copies turn up in the news

Two 2026 incidents show that these copies exist well beyond the counter.

An identity-verification company, IDScan.net, confirmed unauthorized access to customer data in its cloud platform after a marketplace advertised scans of more than 153 million driver's licenses for sale. Krebs on Security reported that the samples included six image files per license, front and back plus infrared and ultraviolet versions, which is what an imaging scan produces. The 153 million figure is a seller's claim, not a confirmed count of affected people, and the company has not said how many people are involved. The detail that matters here is that images were sitting in a cloud system long after the verification they were taken for.

Separately, Florida's motor vehicle agency confirmed that its DAVID driver database was breached using a police login stolen from an officer's personal device. Attackers later published a large set of files, including license images.

Read both as evidence that license data is held in places you didn't choose, not as a statement about your own records. Neither page tells you whether your license is in either set, and neither do we.

What this has to do with what's findable about you

License data and people-search profiles travel on separate tracks. A leaked ID copy doesn't create your Whitepages listing, and removing that listing doesn't reach the leaked copy.

They matter to each other anyway. Someone holding ID details still needs your current address, phone number, and relatives to impersonate you convincingly or to pass a support agent's questions, and people-search sites publish exactly that, openly and for free. That's the part you can actually change.

If you also got a breach notice in the mail, what to do when a company emails you about a breach covers the letter itself. For an ID uploaded to an app rather than scanned at a counter, see when a vendor has your ID documents or your home address. For how leaked data differs from published profiles, see dark web data versus data brokers.

What you can do

  • Ask what happens to the scan. "Do you scan the barcode or photograph the license, and do you keep it?" is a fair question, and a business that can't answer is telling you something.
  • Skip the scan where it's optional. Some venues will accept a visual check.
  • Expect targeted phishing after any ID-related incident. A message that quotes your real license number or address is still a message you should verify by calling the company yourself.
  • Freeze your credit if a notice you received names your Social Security number or financial account details. Freezes are free at all three bureaus, and IdentityTheft.gov is the reference if something has already happened.
  • If an SSN was named, our data breach recovery guide has the longer checklist.
  • Check what's already published about you, since that's the piece that stays fixable.

See what's listed, free

What Delist does here

Delist scans the open web for listings that publish your personal details, people-search sites, public records, data brokers, and breach-source signals (signals are not live listings, and this is not removing you from a dump), and shows you what's there. The free scan is the look. A paid plan files the removals we're authorized to file and re-checks them afterward, because brokers repost profiles.

What Delist does not do is remove your license photo from a breach dump, from an ID vendor's systems, or from a state motor vehicle database. Nobody can do that, and a service that says otherwise is selling you something that doesn't exist.

Frequently asked questions

When a store scans my driver's license, who keeps the photo?

Nobody keeps the photo from a barcode scan, because your picture isn't encoded in the barcode. If the counter photographs your license, then the business and the ID-verification vendor behind its scanner can both hold that image. What's allowed depends on the business and your state, and you usually aren't told which kind of scan happened.

Do car rentals and bars keep a copy of my ID?

Often yes, in some form. A rental company ties your license to the contract and typically keeps that record. A bar or dispensary scanning for age may keep only a pass-or-fail result, or may retain the details it read. Asking at the counter is the only reliable way to find out.

What's the difference between a DMV record and a store ID scan?

Your DMV record is the state's file about you and your vehicles, and who may obtain it is governed by the federal Driver's Privacy Protection Act. That law covers the DMV's records; it doesn't govern a bar or rental counter reading the card you hand over. Those are separate systems with separate rules, and a breach of one says nothing about the other.

Did the IDScan or Nexus story mean my license photo is public?

No. A marketplace advertised a large set of license scans, and IDScan confirmed unauthorized access to customer data in its cloud platform. Neither the seller's claim nor the company's notice tells you whether your license is in that set. If you're affected, the notice comes from the company, not from a news story.

Can Delist remove my driver's license photo from a dump or a DMV database?

No. We don't have access to leaked files, ID-verification vendors' systems, or state motor vehicle databases, and neither does anyone selling that promise. What we remove is the open-web listings that publish your name, address, phone number, and relatives.

Can I ask a business to delete a copy of my ID?

You can ask, and in California residents have a formal right to request deletion under the state privacy law, though it only applies to businesses above certain size thresholds and doesn't override records a business is legally required to keep. Elsewhere it depends on your state and the company's own policy. Asking before the scan is usually more effective than asking after.

How do I check what's easy to find about me after an ID-related breach?

Start with the published sources, since those are the ones that stay fixable: people-search sites, data brokers, and public-record aggregators. A free Delist scan shows what we find on the open web, and is my information public walks through checking by hand.

Related

More guides

Find out what data brokers know about you

A free scan shows which sites are exposing your name, phone, address and email, and Delist files the removals for you.

Start your free scan No card required