For decades, the driver's license check at a dealership meant a photocopy dropped into a deal jacket or a salesperson snapping a photo on a personal phone. Most of the industry conversation about this process has focused on fraud, on the fake IDs slipping past the front desk. That conversation matters, but it skips the step that comes first. Before a dealership can worry about whether a license is real, it must solve a more basic problem: how the license is captured in the first place, and what happens to that data once it is stored. Get that wrong, and verification becomes a feature bolted onto a broken foundation.
The Document Itself Is Changing
The license dealers are trying to capture is no longer a single, stable physical object. Mobile driver's licenses, or mDLs, are now live in roughly two dozen states and territories, with adoption expanding through Apple, Google and Samsung Wallet each quarter, according to tracking from Credence ID. Illinois became the largest state to roll out a statewide Apple Wallet mDL in early 2026, and Arkansas, Connecticut and Arizona have each added or expanded programs this year, according to reporting from Biometric Update.
An mDL cannot be photocopied or photographed the way a plastic card can. It is a cryptographically signed credential that requires a compatible reader and a deliberate tap or scan, and it can selectively disclose only the fields a business actually needs. Dealers without that reader capability are left asking every mDL holding customer to fall back on a physical card, an inconsistent exception that is becoming more common, not less. A capture process built only around a camera and a scanner is already behind.
Storage Is Where the Real Liability Sits
Once a license is captured in either of today’s advanced formats, it has to go somewhere, and that is where compliance exposure actually lives. Because dealerships that arrange financing are classified as financial institutions under the Gramm Leach Bliley Act, the license images, numbers and associated data they store fall squarely under the FTC's Safeguards Rule. The FTC has increased enforcement of that rule throughout 2026, with multi-factor authentication and documented risk assessments now treated as baseline expectations, and violations can carry penalties reaching six figures per instance, according to guidance published by Tekion.
A separate wave of state privacy laws taking effect beginning Janua... adds a requirement that is easy to overlook: formal risk assessments before deploying automated or AI driven decision tools, including any system used to score, scan or store identity documents. A dealership that adopts a scanning tool without a documented retention and access policy behind it has not reduced its risk, it has just moved where that risk sits. This is the part of the process most dealers have not modernized. Many still route scanned license images into a CRM field or a shared drive with no encryption standard, no access log and no defined retention period, which is precisely what a regulator or a breach will test first.
Verification Is the Payoff, Not the Starting Point
Here is where the fraud conversation remains prevalent today. Once a dealership has a capture and storage system built to a real security standard, adding a verification step on top of it is a comparatively small lift, because the infrastructure to move license data securely already exists. Fraud researchers have documented a wave of AI generated identifica... that reproduce holograms, barcodes and fonts convincingly enough to defeat a simple visual check, and IDScan.net's most recent industry data found fraudulent ID presentments at dealerships and rental counters rose 21 percent in 2025.
Despite that, industry survey data puts the share of dealerships that skip a true..., checking a scanned license against DMV records, watchlists and OFAC data, at roughly 95 percent, and a related survey found that fewer than one dealer in a hundred makes that DMV comparison, the check most likely to catch an altered document. That gap exists largely because dealers still think of verification as a separate system to bolt on, rather than the natural next step once capture and storage are handled correctly. In a well-built setup, the dealership sends a secure link to the customer's phone, which walks them through capturing an image of the license along with a live selfie, and the same secure pipeline that stores that data can just as easily run it against fraud databases before the deal moves forward.
Sequence Matters
None of this points to a single fix, but it does point to a sequence. A dealership that tries to layer fraud detection onto an unencrypted photocopy process is solving the wrong problem first. The capture method has to account for a credential that increasingly lives on a phone. The storage behind it has to meet a compliance bar that has gotten measurably stricter this year. Only once those two pieces are in place does verification become the genuine upgrade it is meant to be, rather than a patch on a process that was never built to hold sensitive data in the first place. Dealers reviewing their current setup would do well to start with a different question than the one they usually ask. Not "would this catch a fake ID," but "would this storage process hold up if a regulator, or a breach, asked to see it."
About The Author:
Ken Hill is managing director for 700Credit, the automotive industry's leading provider of credit reports, compliance, soft pull and fraud prevention products. For more information, please visit www.700credit.com. ;
© 2026 Created by DealerELITE.
Powered by
You need to be a member of DealerELITE.net to add comments!
Join DealerELITE.net