A US court blocked a federal demand for driver's license data from a database of 17 million commercial drivers. What it changes for KYC, privacy and vendors.
Table of contents
A federal judge has temporarily blocked the bulk transfer of driver's license data to federal agencies. The order protects the records of twenty-one states and the District of Columbia inside a database covering 17 million commercial drivers. Judge Anthony J. Trenga granted it on 20 August 2026, ahead of a 10 September hearing.
- The Eastern District of Virginia enjoined the transfer of the plaintiff states' master pointer records out of the Commercial Driver's License Information System (CDLIS), the AAMVA-run database, which holds records on more than 17 million commercial drivers.
- Each record carries a name, date of birth, Social Security number, sex, license number and state of record, which is why the court treated the demand as a privacy question rather than a records question.
- The Federal Motor Carrier Safety Administration had threatened to terminate all of AAMVA's federal funding if it did not comply by 17 August.
- The court held the agency had failed to dispel an inference that it wanted the files for "immigration enforcement, which is not part of its statutory mandate".
- It also held that the government-use exception in the Driver's Privacy Protection Act does not let one agency pass motor vehicle records to another.
What did the court actually block?
The court blocked two things at once. The American Association of Motor Vehicle Administrators (AAMVA), a non-profit that operates CDLIS for the states, may not transfer the plaintiff states' driver's license data to the federal defendants or any other agency. Separately, the federal defendants may not retaliate for that refusal by cutting contracts or funding.
The second half matters more than it looks. On 11 August 2026 the Federal Motor Carrier Safety Administration (FMCSA) told AAMVA to hand over the full database by 17 August or face immediate termination of its federal funding, including the roughly 10 million dollars that pays for the database. AAMVA argued a shutdown could stop the issuance and renewal of any driver license in the United States. The court agreed that was a real harm and required no security bond from the states.
The government offered a rationale, but a thin one. FMCSA said it wanted the records to conduct routine reviews and data analysis, and to carry out its statutory safety mandates. In court it argued the states' alleged harm was speculative, since it had threatened funding rather than cut it. Judge Trenga answered that FMCSA already runs individual queries and annual program reviews, and could not "point to anything that they cannot already do without this data".
The order in State of Illinois v. US Department of Transportation, No. 1:26-cv-02547 (AJT-IDD) (E.D. Va.), describes the database as holding "limited but highly personalized information" on more than 17 million license holders. It also vacated the earlier administrative stay of 13 August, so one instrument now governs both the data and the funding threat.
| Date, 2026 | Step |
|---|---|
| Before 11 August | FMCSA asks AAMVA for the whole database; Homeland Security issues, withdraws, then reissues a subpoena for the same records |
| 11 August | Chief counsel letter sets a 17 August deadline and threatens all federal funding |
| 13 August | The court enters an administrative stay in the states' suit |
| 20 August | After a hearing, the court grants the temporary restraining order |
| 27 August, 3 September | States move for a preliminary injunction; the government responds |
| 10 September | Hearing, 10:00 a.m., Courtroom 900, Alexandria Division |
Source: order granting the temporary restraining order, 20 August 2026.
How did a pointer system become the CDLIS Data Demand?
CDLIS was never designed as a federal repository. Congress created it in 1986 so states could see whether a commercial driver already held a license elsewhere. It stores a master pointer record saying which state holds the real file, and the states keep the detailed qualification data themselves.
The driver's license data in a pointer record is limited. As the court described it, citing 49 U.S.C. 31309(b), the record holds a name, date of birth, Social Security number, sex, license number and state of record. Federal officials have always been able to query it one person at a time, and to audit state records through program reviews. What changed was the request to take custody of all of it.
The department's own information policy from 2005 says plainly that "the records in CDLIS are not controlled by FMCSA". FMCSA's May 2026 fee rulemaking proposal likewise refers to master pointer records as "owned by each state". The court leaned on both, and noted the agency had never made a request on this scale before, which it read as a policy change requiring consultation with the states. The three shapes below differ only in what sits in one place.

What does this change for your KYC obligations?
Nothing in the order changes a bank's duties directly, but it sharpens three of them: the lawful basis for using state license records in verification, the retention floor that builds the store in the first place, and the onward sharing your suppliers may do. The table maps each to its rule, and adds the EU parallel.
| Obligation | Rule | What the ruling changes | Do this quarter |
|---|---|---|---|
| Non-documentary verification | 31 CFR 1020.220(a)(2)(ii)(B) | Confirms that permissible-use limits follow driver's license data into your vendor chain | Record which permissible use each supplier relies on |
| Record retention | 31 CFR 1020.220(a)(3)(ii) | Nothing legally, but it prices the store you are obliged to keep | Delete copies held above the five-year floor |
| Onward disclosure | 18 U.S.C. 2721(b)(1) | An agency's own use does not license passing data to a second agency | Add onward-sharing terms to supplier contracts |
| Minimisation, EU and UK | [GDPR Article 5](https://eur-lex.europa.eu/eli/reg/2016/679/oj) | Poses the same question in another regime: a copy, or an answer | Map retention against actual verification need |
The Driver's Privacy Protection Act at 18 U.S.C. 2721 bars disclosure of personal information from motor vehicle records, and lets the Social Security number in these records out under only four exceptions. The government never showed how any of them covered the Data Demand, and the one it relied on does not authorise passing the records to the Department of Homeland Security for immigration enforcement.
Your suppliers inherit that reasoning. If your Customer Identification Program relies on non-documentary verification under FinCEN's rule at 31 CFR 1020.220, which permits comparing customer-supplied information against a consumer reporting agency, public database or other source, then somewhere in your stack a supplier is likely querying driver's license data. Ask which permissible use they rely on, and whether they receive match flags or underlying records. AAMVA's own Driver's License Data Verification service returns only match or no match indicators against the issuing jurisdiction, a materially different privacy posture from receiving the record.
Retention is the second pressure point. The same rule requires you to keep identifying information for five years after an account closes, and to keep the description of your verification methods and results for five years after the record is made. Those duties are why regulated firms accumulate the sort of concentrated store that became the subject of this litigation. The rule sets a floor for what you must keep, not permission to keep copies of everything you saw.
What is still uncertain, and what could go wrong?
A temporary restraining order is a holding position, not a judgment. The court found a likelihood of success on the statutory, constitutional and contract claims, but the preliminary injunction is briefed over the next fortnight and the merits remain untested.
The federal defendants also argued that exclusive jurisdiction sits with the court of appeals under the Hobbs Act, an argument the court rejected and which is likely to reappear. Homeland Security is a further loose end. It issued a subpoena for the same records, withdrew it, then reissued it. A companion order the same day, in No. 1:26-mc-19, held the states' motion to quash in abeyance and continued AAMVA's time to respond, so the subpoena is paused rather than quashed.
The order leaves most drivers out. AAMVA floated an opt-out mechanism under which it would produce only the records of states that did not object, and the order protects the plaintiff states' records, so only the states that sued are covered. Drivers licensed elsewhere gain nothing from it.
There is a structural risk too. AAMVA sits between contracts with the states and funding from the federal government, and it told the court it "takes no view on most of those legal issues". An entity in that position is a single point of failure whichever way the case goes. The court accepted that losing it could disrupt license issuance across the country, which is a striking amount of dependence on one non-profit's database.
The win is narrower than the headlines suggest. Individual queries continue exactly as before, and the order restrains wholesale custody rather than routine access. It creates no new privacy right for the drivers whose driver's license data sits in the system.
Why does architecture decide the outcome here?
Harm scales with what sits in one place, not with how carefully that place is guarded. A pointer system answers one question per query. A consolidated copy exposes 17 million people in a single transfer, and the court treated that gap as decisive when it weighed irreparable harm.
Compliance teams face the same choice in miniature. Identity verification can be built to obtain an answer, or to obtain and retain the evidence. Every firm that touches driver's license data makes that choice, usually by default.
| Design | What sits in one place | Exposure from one demand or breach |
|---|---|---|
| Central pointer database | Identifying fields on every license holder in the country | 17 million records in a single transfer |
| Match-flag verification service | No new copy; the issuing jurisdiction keeps the record | 1 answer about 1 person |
| Conventional vendor archive | Document images, selfies and extracted fields held for years | Every customer onboarded through that vendor |
| Sharded or user-held credential (Zyphe) | No reconstructable record on any single node | 0 complete records recoverable from one node |
We have written before about how this plays out when a store is breached rather than subpoenaed, in the AssuranceAmerica case that exposed seven million driver's license numbers, and in our analysis of centralised storage as a standing liability.
How should compliance teams respond?
Start with an inventory. Identify every supplier in your onboarding chain that queries state license records, and record which permissible use each one relies on. Then ask a narrower question: does the supplier return a verification result, or a copy of the record?
Older contracts often describe a verification service without saying what it retains. Where the contract is silent, the data processing agreement and the supplier's retention schedule settle it.
Next, test your retention against the actual rule rather than against habit. Your Customer Identification Program obliges you to keep identifying information and a description of your methods. It does not oblige you to keep every document image and selfie you ever collected, and each surplus copy is a record you would have to disclose, defend or notify on. Review what your vendor keeps on your behalf, since that store is yours in substance even when it is theirs in contract.
Then revisit your government data request playbook. A demand for bulk records, a subpoena and a funding threat are three different instruments with three different responses, and this case involved all three inside a fortnight. Know who signs off, and know what you would be able to hand over if asked.
Zyphe was built for the position these teams now occupy. Verification runs against an NFC chip read to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload. Personal data is sharded across, on Zyphe's own figures, more than 60,000 nodes under a 29-of-100 threshold scheme, and the customer holds the key, so there is no central store to demand and no master key to compel. You can see the design in decentralised PII storage or book a demo.
The bottom line
The order is short lived by design, but the reasoning is the part worth keeping. A regulator asked for a copy of a national store of driver's license data, could not explain what the copy would let it do that a query already allowed, and lost. Apply that same test to your own architecture and to every supplier in your onboarding chain. Concentrated stores of identity data are a compliance liability as much as a breach risk, because they answer to subpoenas, funding leverage and policy shifts that sit outside your control. Holding less is now the cheaper position in both directions.
Cited sources
- Order granting temporary restraining order, State of Illinois v. US Department of Transportation, No. 1:26-cv-02547 (E.D. Va. 20 Aug 2026)
- Policy on Availability of Information From the Commercial Driver's License Information System, 70 Fed. Reg. 2454 (13 Jan 2005)
- Fees for Commercial Driver's License Information System, proposed rule, 91 Fed. Reg. 28514 (18 May 2026)
- Driver's Privacy Protection Act, 18 U.S.C. 2721
- Commercial Driver's License Information System, 49 U.S.C. 31309
- Customer Identification Programs for banks, 31 CFR 1020.220
- Regulation (EU) 2016/679, Article 5
- Order holding the motion to quash in abeyance, State of Illinois v. US Department of Homeland Security, No. 1:26-mc-00019 (E.D. Va. 20 Aug 2026)
- AAMVA Driver's License Data Verification service
- California Attorney General, statement on the temporary restraining order, 20 August 2026
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.