compliance
Drivers License Scanning Visitor Management: Privacy Guide
A driver's license barcode holds more than most front desks realize, and scanning it pulls you into privacy rules most SMB lobbies don't need to touch. Here's what's on the card, what the law says, and when a scanner is overkill.
By InstaCheckin Team Updated September 23, 2026

A driver’s license barcode holds a full data record: name, date of birth, address, license number, expiration date, height, eye color. All of it in plain text, readable by any barcode scanner app on a phone. Before you put a scanner at your front desk, it’s worth knowing what you’d actually be pulling off that card and what obligations come with holding it.
That’s the honest first question about drivers license scanning visitor management: does your lobby need it, or does looking at a photo ID and typing a name into a kiosk get you the same result with none of the downside?
This post covers what’s actually encoded on the card, which privacy rules apply when you scan it, and where scanning earns its keep versus where it’s just extra liability for no extra security.
This post describes general practice and product capabilities, not legal advice. ID-scanning and data-privacy rules vary by state and change over time — verify your specific obligations with counsel before adopting a scanning policy.
What’s actually on the barcode
Nearly every U.S. driver’s license carries a PDF417 barcode on the back. The AAMVA DL/ID Card Design Standard defines exactly what goes in it: full legal name, date of birth, address, license or ID number, issue and expiration dates, and physical descriptors like height, weight, and eye color.
None of that data is encrypted or signed. It’s plain text, laid out in fixed fields, built to be read fast by any scanner — including a five-dollar barcode-reader app. Scan the card and you’ve captured the full record, not just the name and photo a receptionist would have noted anyway.
That gap between “what a human glances at” and “what a scanner extracts” is the whole reason this deserves a policy decision, not a default purchase.
Drivers license scanning visitor management: what you’re actually allowed to keep
A few states regulate driver’s license scans directly, and the rules are narrower than most people expect. New York’s General Business Law § 391-oo is a clear example: it permits retail scanning of the barcode only for specific purposes such as age verification, limits what can be recorded to four fields (name, date of birth, ID number, expiration date), and bans reselling or disseminating the scanned data to any third party, with civil penalties for violations.
Statutes like that were written for a narrow transaction — checking age at a register — not for logging office visitors. If your state has one, it likely doesn’t list “visitor sign-in” among the permitted purposes at all, which means scanning at your front desk sits in a gray zone rather than a clearly authorized one.
The FTC’s data-minimization guidance states the general principle plainly: don’t collect personal information you don’t need, and don’t hold it longer than you have a legitimate business reason to. A barcode scan captures an address and a physical description your front desk almost certainly has no use for.
Where BIPA does and doesn’t apply
Illinois’ Biometric Information Privacy Act gets raised often in this conversation, usually incorrectly. BIPA’s definition of “biometric identifier” covers a retina or iris scan, fingerprint, voiceprint, or a scan of hand or face geometry — and it explicitly excludes photographs.
A driver’s license barcode scan reads text fields, not a biometric measurement. It’s closer to typing in a name than to capturing a fingerprint. That puts routine barcode scanning outside BIPA’s scope in most readings of the statute.
Facial recognition is a different story. A system that matches a visitor’s face against a photo database is scanning biometric geometry, and that’s exactly the kind of feature BIPA was written to cover. InstaCheckin’s kiosk simply captures a photo for the badge and the visit record, the same way a receptionist would with a camera, and nothing more.
When scanning actually earns its cost
There’s a real use case for barcode or OCR scanning: high-volume security checkpoints, watchlist screening against a database, or facilities where a guard needs to verify an ID against a government list in seconds. Manufacturing plants under export controls and secure government sites are the closest fit — see our post on badge access control systems for where that credential layer starts.
A standard office lobby isn’t that. If your receptionist is comparing a face to a photo and typing a name once, a scanner doesn’t make the check more accurate — it just adds a device, a data-retention question, and a line item to your privacy policy for a step the human eye already handled.
What a lighter-weight sign-in captures instead
InstaCheckin’s iPad kiosk skips the barcode entirely. A visitor enters their name, company, and reason for visit, the kiosk takes a photo, and — if your policy calls for it — the visitor signs an NDA or safety waiver on screen before the badge prints. The host gets an email and SMS the moment their guest checks in, and every visit lands in a cloud log you can filter by location, host, or date range and export to CSV or PDF.
That’s enough to answer the two questions an audit actually asks: who was in the building, and who let them in. It’s also enough to keep your data-retention policy to one sentence instead of one that has to account for a driver’s license number and a home address. Our visitor log requirements post covers what ITAR, C-TPAT, ISO, and OSHA expect a record to include if your industry needs more than the basics.
FAQ
Is scanning a driver’s license at check-in legal?
Usually, but it depends on your state. A handful of states put specific limits on what a business may record and keep from a driver’s license scan, and most of those statutes were written for age verification, not lobby sign-in. Check your state’s rules before you buy a scanner, not after.
What does a driver’s license barcode actually contain?
Under the AAMVA card design standard, the PDF417 barcode on the back stores name, date of birth, address, license number, expiration date, and physical descriptors like height and eye color, all as plain, unencrypted text.
Does scanning a license trigger biometric privacy laws like BIPA?
Generally no. Illinois BIPA defines biometric identifier as a retina or iris scan, fingerprint, voiceprint, or a scan of hand or face geometry, and it excludes photographs. The text fields in a license barcode aren’t a biometric measurement, so a barcode scan sits outside BIPA’s definition. A separate facial-recognition or face-matching feature would not.
Do small offices need to scan IDs at all?
Most don’t. If a receptionist can look at the license, compare the photo to the person, and enter a name, that satisfies the actual goal of visitor management: a record of who was in the building and when. Barcode scanning earns its cost in higher-security settings, not a standard SMB lobby.
Start with what your lobby actually needs
Before you shop for a scanner, write down the question you’re actually trying to answer at the door. For most offices it’s “who’s here and who do I call” — and a typed name, a photo, and a host notification answer that without touching a barcode. Start a free trial and run a week of real sign-ins to see whether that’s enough for your front desk. Our visitor policy template and the office visitor management system page cover the rest of the setup.
Frequently asked questions
Is scanning a driver's license at check-in legal?
What does a driver's license barcode actually contain?
Does scanning a license trigger biometric privacy laws like BIPA?
Do small offices need to scan IDs at all?
Related reading
Badge Access Control Systems: Where Visitor Badges End
Badges that open doors and badges that prove who was in the building are two different systems. Here's the line between them, and which one your front desk is actually missing.
Visitor Log Requirements: ITAR, C-TPAT, ISO, OSHA Guide
A consolidated look at what ITAR, C-TPAT, ISO 27001, and OSHA actually require for visitor logs — and where a paper sign-in sheet falls short of each one.
Visitor Policy Template: 9 Sections Every Office Needs
The nine sections a workplace visitor policy needs, a copy-paste skeleton you can drop into your own document, and the parts most offices leave out.