North Carolina’s Digital Driver’s License Is Coming. Keep the Plastic One

Free ALPR 101 Town Hall — every Tuesday, 7 PM ET. Join us ›  ·  Wilmington is under warrantless AI surveillance — it’s time to act.
← All updates

North Carolina’s Digital Driver’s License Is Coming. Keep the Plastic One.

A driver’s license on your phone is convenient, and the technology can even reveal less than a plastic card. But it changes something quiet and important: a plastic license tells someone who you are; a digital credential can also create data about when, where, and to whom you proved it. North Carolina is launching that machine-readable identity without the basic legal guardrails — starting with the rule other states wrote in, that showing your ID is not consent to search the rest of your phone.

In December 2026, the N.C. Division of Motor Vehicles plans to launch Mobile ID — a digital version of your driver’s license that lives in the state’s NC Wallet app (Apple, Google, and Samsung Wallet versions are expected in 2027). By statute, it is “the legal equivalent of a valid license.” It is genuinely convenient, and the underlying technology can be privacy-protective. But there is a gap between how it is designed to work and how it will actually work on the side of the road — and that gap runs straight through the most protected thing in your pocket.

How it’s supposed to work

Mobile IDs are built on an international standard (ISO 18013-5) meant to minimize what you reveal. In the ideal case, an officer with a compatible reader taps or scans your phone and receives only the credential — and only the fields needed. You could confirm you’re over 21 without showing your address; you would never hand over the device at all. Done right, a digital ID exposes less than a plastic card. But the standard only governs the tap. It can minimize what a reader receives; it does not write North Carolina’s privacy law — ISO itself leaves questions like how consent is obtained, and what happens to any record after the exchange, expressly outside its scope.

Where it breaks down

That protective design depends on something North Carolina cannot yet guarantee: that the readers are actually deployed, and that people know their rights when they aren’t. The DMV’s own guidance is good on this point — it says you do not have to hand your phone to an officer, and that if an officer lacks a compatible reader you can provide the information verbally. That is the safe path, and it is the one to use. The catch is that the whole protection then rests on the driver knowing it and holding to it under pressure. The DMV says not every officer will have a compatible reader right away, and the reflexive move in a traffic stop — the officer asks for your license, and it lives on your phone — is to unlock the device and hand it across. The state’s guidance discourages that; but the guidance only protects a driver who knows it and asserts it.

Why does that one act matter? Because your phone is a device the U.S. Supreme Court has recognized as holding an exceptional concentration of private information. Under its decision in Riley v. California (2014), police generally need a warrant to search the contents of a cell phone — the Court called the modern phone a window into “the privacies of life.” But a warrant is not the only way in: consent and plain view are recognized exceptions. Handing an officer your unlocked phone does not, by itself, hand over the contents — but it can create a later dispute about whether you consented to their handling the device, or about what was visible in plain view while they held it. Riley did not address digital driver’s licenses, and no North Carolina appellate court has yet resolved that scenario. So the honest way to put it is not that showing a mobile ID is a search — it is that it opens a door a plastic card never does, and the cleanest way to keep that door shut is to not hand the phone over at all.

Other states closed the gap. North Carolina didn’t.

This problem was foreseeable, and some states wrote the fix directly into their mobile-ID laws. Indiana’s statute (Ind. Code § 9-24-13-3) states that transmitting a mobile credential “shall not serve as consent or authorization” for a court, a police officer, or anyone else to “search, view, or access any data or application” on the device other than the credential itself — and it goes further, barring an officer from confiscating or downloading the phone to check a credential absent probable cause or a warrant. North Carolina’s enabling law — S.L. 2024-30 — contains no such clause. It made the mobile ID legally equivalent to a plastic license and then merely directed the DMV to study “means by which to prevent unintended violations of an individual’s constitutional rights.” It flagged the problem. It did not solve it. To be clear, the absence of that clause does not hand police new authority — the Fourth Amendment and Riley still apply, and using a mobile ID waives nothing. What the missing clause removes is the bright line. Instead of a statute that settles the question in advance, North Carolina leaves it to be argued encounter by encounter, after the fact, in court. A clear rule up front is worth more than a good argument later. The legislative ask here is simple and non-partisan: North Carolina should adopt the Indiana-style protection — presenting a digital ID is not consent to search the phone — before this goes live.

The practical rule: keep the plastic.

North Carolina’s own law calls the Mobile ID a “supplement to” your license — not a replacement. Until the phone-search gap is closed, keep carrying your physical license and hand that to an officer. If you use the digital version, keep the phone in your own hand and present it through the officer’s reader by tap or QR code — a mobile ID is not just a picture of a license and can’t be verified by eye, so if the officer has no reader, simply provide the license information they ask for. Either way, never unlock and pass your phone across. You are not required to hand your phone to police, and doing so is the one act that can turn a routine ID check into a question about everything else on the device.

The part a defense lawyer cares about most: lock it with a passcode, not your face

There is a stronger reason than consent to keep the phone out of an officer’s hands — and it is the one that turns the digital ID’s convenience into a genuine trade-off. To present the Mobile ID, NC Wallet requires Face ID or a fingerprint. Using it therefore nudges you into leaving biometric unlock switched on — and biometrics are the weaker posture if it ever comes to a fight over your phone.

Here is why. Courts have generally treated a passcode — something you know — as protected by the Fifth Amendment: the state usually cannot compel you to disclose it, because doing so is testimonial. A face or a fingerprint has been treated differently — many courts have allowed police to compel a biometric unlock, sometimes even on a warrant or probable cause, on the theory that your face and finger are physical characteristics, not testimony. The law here is still moving and not uniform, but the prudent conclusion is settled enough to act on: a phone locked with a strong passcode, and biometric unlock turned off, is the hardest to compel open — harder even than a probable-cause search can readily overcome. That is precisely why we recommend disabling biometrics. Our firm’s step-by-step privacy guide walks through turning Face ID or fingerprint unlock off and setting a strong passcode.

So the Mobile ID quietly asks you to do the opposite of the safe thing. Keep the plastic license, and you keep the option to lock your phone the way a lawyer would want it locked — passcode on, face off — without giving that up just to show ID.

And the phone-search question isn’t the only one

Police access is the sharpest concern, but it is not the only one, and a fair accounting names the rest — carefully. The risks a digital credential adds are different, not uniformly greater. A mobile ID can actually be harder to steal or forge than a plastic card: the DMV says it can’t be used just because someone is holding your phone, because presenting it requires Face ID or a fingerprint. What it adds instead are software, device, vendor, and infrastructure risks a laminated card doesn’t have. Enrollment involves two distinct biometric steps worth separating: an identity-proofing step, where a selfie is checked against DMV records when you sign up, and a device-authentication step, where Face ID or a fingerprint unlocks the credential each time you present it. Each raises its own unanswered questions — what becomes of the enrollment selfie, how long it is kept, whether it is shared with a vendor. And a digital credential can be updated or suspended remotely in a way a plastic card cannot; useful for security, but it makes a valid ID depend on the state’s infrastructure, and the governing questions — who can revoke it, on what grounds, with what notice and appeal — are worth a records request.

The larger shift is on the other side of the tap. A physical license is mostly passive — a bartender reads your birthdate and hands it back, and no durable record of the moment has to exist. A machine-readable credential makes that same moment a structured transaction that can be logged, retained, and later searched. That does not mean North Carolina records it: the DMV says its system does not “phone home,” and cannot see where or when you present your ID. But that answers only one question — whether the state watches every use. It says nothing about the verifier, the reader operator, or their service providers. When a bar, a retailer, an airport, or a police reader scans your credential, what identifier is transmitted, what do they log, how long do they keep it, can different verifiers correlate your appearances, and can those logs be subpoenaed? These are not paranoid questions — they are the exact privacy risks the federal government’s own standards body, NIST, tells mobile-ID systems to limit: observability, linkability, and singling out. A record of where you proved your identity is a record of where you were — a gun store, a clinic, a dispensary, a courthouse, a political event. One such fact is mundane. Assembled, they describe a life — which is precisely the lesson of the plate-reader network we already document.

Why we’re writing about a DMV app

Because it is the same pattern we document everywhere else in North Carolina: a convenient new system rolled out with the privacy safeguard left as a footnote — a study to be done later — rather than written into the law up front. It belongs beside the plate readers, facial recognition, drones, and fusion centers we track, not because a digital license is sinister, but because the same shortcut keeps getting taken: build the convenience now, sort out the constitutional protection never. This one is easy to fix while the program is still on the launch pad.

The real question is linkage

That brings the concern into focus, and it is not the science-fiction version. Privacy advocates — the former federal official Catherine Austin Fitts among them, years ago — have warned that a digital ID becomes the keystone of a broader tracking system. You do not need that framing to see the concrete, reportable problem. Picture four ordinary databases: plate readers (plate → place → time), card transactions (account → merchant → time), ID verifiers (credential → verifier → time), and phone location (device → place → time). None holds the whole picture, and today they are not merged. But databases do not have to be formally merged to become revealing — they can be joined by a shared identifier, a matching timestamp, a common location, or a subpoena. So the question worth investigating is not whether North Carolina has already built one master file. It is which agencies, vendors, contracts, or shared identifiers would let these records be linked — and what rule stands in the way.

That is the same civil-liberties problem at the center of our ALPR work: the danger is rarely the single innocuous fact. It is what becomes possible when millions of innocuous facts become structured, persistent, searchable, and linkable. A digital license does not create that risk by itself — but it adds a new stream to it, and it is the stream that ties a name to the rest. That is worth watching, and worth filing records requests about, as the license — and, the DMV says, eventually other government credentials in the same NC Wallet — moves onto the phone. (We take up the movement-and-money half of that question here.)

What North Carolina should do before this expands

The privacy question here is not whether a digital credential exists. It is whether the state writes enforceable limits before use becomes routine. Four commitments would settle most of it:

  • Put in statute that presenting a mobile ID is not consent to search, view, handle, seize, or download the phone beyond the credential itself.
  • Require law-enforcement training and a written statewide policy: a driver may keep the phone and present through a reader, or provide the requested information verbally when no reader is available.
  • Publish binding rules for what verifiers, readers, and vendors may log, how long they may keep it, and with whom they may share it.
  • Guarantee parity for the physical ID — accepted everywhere in practice, not merely in theory: no extra fee, no slower service, no separate line, no denial of any government service, and no private demand for the digital version where a plastic card would do. “Optional” today does not stay optional if the plastic card quietly becomes the slow lane.
  • Publish the record. Release the study S.L. 2024-30 already required, the vendor contract, and the privacy-impact assessment — and answer, on paper, what identifier each presentation transmits and whether verifier logs can be correlated — before adoption becomes routine, not after.

None of that is anti-technology. It is the difference between a credential you control and one that quietly becomes a record of your day — and the time to write those rules is now, before the program leaves the launch pad.

Sources: N.C. Division of Motor Vehicles, NC Mobile ID Program; WRAL and Spectrum News reporting on the NCDMV Mobile ID launch (2026), and idtechwire / mobileidworld reporting on NC Wallet’s selfie-and-biometric enrollment; N.C. Session Law 2024-30 (House Bill 199), adding G.S. 20-7(m1); Riley v. California, 573 U.S. 373 (2014); Indiana Code § 9-24-13-3. This page is general information about North Carolina and federal law, not legal advice, and creates no attorney-client relationship.

New Hanover County’s Commissioners hold the lever that ends Flock here. They need to hear from you.
Your move

You’re not a suspect. So stop being tracked like one.

It takes one minute. Add your name, then tell your county commissioners to cancel the Flock contract.