What Happens to ID After It has been scanned?

By | September 6, 2026
ID Scanning Report

Last Updated on September 6, 2026 by Craig Allen Keefner

What happens to an ID after it is scanned?

Modern ID scanning has moved far beyond reading a barcode or checking a date of birth. Many systems now capture high-resolution document images, perform visible/IR/UV authentication, transmit data to cloud identity-verification platforms, perform biometric comparisons, and potentially retain the resulting records.

Current event —  IDScan sued over alleged data breach affecting 153 million drivers. Brian Krebs originally reported on September 1 that a dark-web identity-theft service called “Nexus” advertised access to more than 153 million U.S. and Canadian driver’s license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards.

That creates a new procurement question: Is the system simply verifying an identity—or creating a permanent identity-data archive?

This 2026 research report examines 26 vendors across the ID scanning and identity-verification ecosystem, from edge reader hardware and venue-operated systems to cloud IDV and visitor/check-in platforms.

What the Report Covers

The report compares vendors across four technology tiers:

  • Edge reader and document-scanning hardware
  • On-premise + cloud ID verification systems
  • Cloud identity-verification (IDV/eKYC) platforms
  • Visitor management and check-in platforms

For each vendor, the research examines architecture, document-image handling, retention posture, published security certifications, transparency, and relevant incident history.

The report also includes:

  • 26-vendor comparison
  • Retention Transparency Scorecard
  • Document-image and cloud-storage analysis
  • Known incident and exposure history
  • Root-Cause Taxonomy
  • State-Law Retention Gap Table
  • Edge vs. cloud architecture analysis
  • Eight-question procurement screen

Key Finding: Scan Does Not Have to Mean Store

One of the clearest findings is that long-term retention of scanned identity documents is an architectural and policy choice—not an inherent requirement of ID verification.

Some platforms can authenticate documents locally, tokenize the resulting information, operate within customer-controlled infrastructure, or discard identity data after verification.

Others can upload and retain document images in centralized cloud environments.

That distinction matters.

A database containing millions of driver’s-license or passport images represents a fundamentally different risk than a system retaining only a result such as “identity verified” or “age 21+ confirmed.”

Security Certification Is Not the Same as Data Minimization

ISO 27001, SOC 2 and other security certifications remain important, but they answer a different question.

Security asks: How well is the data protected?

Data minimization asks: Why is the data being retained at all?

This report examines both.

Why This Matters Now

ID scanning is expanding across:

Retail • Cannabis • Casinos • Hospitality • Financial Services • Visitor Management • Kiosks • Age Verification • Transportation • Self-Service

At the same time, age-assurance mandates, biometric privacy laws and cybersecurity risks are increasing scrutiny of how identity information is collected and retained.

The result is a new requirement for buyers: evaluate the complete data lifecycle, not simply the scanner.

Scan → Extract → Authenticate → Verify → Retain or Delete

Who This Report Is For

Designed for technology buyers, retailers, hospitality and casino operators, dispensaries, kiosk deployers, security and compliance teams, procurement professionals, integrators, consultants, and identity-verification providers.

The Procurement Principle

Scan what you need. Verify what you need. Store only what you can justify.

26 vendor profiles — TokenWorks, Thales, HID Global, E-Seek, Card Scanning Solutions, DESKO, Regula, IDScan.net, Patronscan/Servall, Veridocs, GBG/Acuant, Intellicheck, Mitek, Jumio, Onfido/Entrust, Veriff, Sumsub, AU10TIX, Persona, Incode, Socure, IDEMIA, Envoy, iLobby, Clearwave, Phreesia.

Independent research and analysis from The Industry Group (TIG) / Retail Systems Research — 2026.

Linkhttps://keefner3.gumroad.com/l/jbgzf?layout=profile

Author: Craig Allen Keefner

Craig Allen Keefner is an industry analyst, content strategist, and longtime authority on self-service kiosks, digital signage, unattended payment systems, and interactive technology. He manages content and industry strategy for Kiosk Industry and The Industry Group, with a focus on kiosk software, hardware-software integration, accessibility, payment compliance, healthcare kiosks, restaurant self-service, and emerging AI automation. Craig has covered the self-service and kiosk industry since the 1990s, tracking how public-facing terminals move from concept to field deployment. His work combines industry research, vendor analysis, operator conversations, standards tracking, trade show coverage, and practical experience with the real-world constraints of kiosk deployments. https://www.linkedin.com/in/kiosk