Free guide: How to use AI in compliance
Editorial cover headlined "Court blocks bulk transfer of driver's license data to federal agencies".

A US court blocked a federal demand for driver's license data from a database of 17 million commercial drivers. What it changes for KYC, privacy and vendors.

Table of contents

A federal judge has temporarily blocked the bulk transfer of driver's license data to federal agencies. The order protects the records of twenty-one states and the District of Columbia inside a database covering 17 million commercial drivers. Judge Anthony J. Trenga granted it on 20 August 2026, ahead of a 10 September hearing.

  • The Eastern District of Virginia enjoined the transfer of the plaintiff states' master pointer records out of the Commercial Driver's License Information System (CDLIS), the AAMVA-run database, which holds records on more than 17 million commercial drivers.
  • Each record carries a name, date of birth, Social Security number, sex, license number and state of record, which is why the court treated the demand as a privacy question rather than a records question.
  • The Federal Motor Carrier Safety Administration had threatened to terminate all of AAMVA's federal funding if it did not comply by 17 August.
  • The court held the agency had failed to dispel an inference that it wanted the files for "immigration enforcement, which is not part of its statutory mandate".
  • It also held that the government-use exception in the Driver's Privacy Protection Act does not let one agency pass motor vehicle records to another.

What did the court actually block?

The court blocked two things at once. The American Association of Motor Vehicle Administrators (AAMVA), a non-profit that operates CDLIS for the states, may not transfer the plaintiff states' driver's license data to the federal defendants or any other agency. Separately, the federal defendants may not retaliate for that refusal by cutting contracts or funding.

The second half matters more than it looks. On 11 August 2026 the Federal Motor Carrier Safety Administration (FMCSA) told AAMVA to hand over the full database by 17 August or face immediate termination of its federal funding, including the roughly 10 million dollars that pays for the database. AAMVA argued a shutdown could stop the issuance and renewal of any driver license in the United States. The court agreed that was a real harm and required no security bond from the states.

The government offered a rationale, but a thin one. FMCSA said it wanted the records to conduct routine reviews and data analysis, and to carry out its statutory safety mandates. In court it argued the states' alleged harm was speculative, since it had threatened funding rather than cut it. Judge Trenga answered that FMCSA already runs individual queries and annual program reviews, and could not "point to anything that they cannot already do without this data".

The order in State of Illinois v. US Department of Transportation, No. 1:26-cv-02547 (AJT-IDD) (E.D. Va.), describes the database as holding "limited but highly personalized information" on more than 17 million license holders. It also vacated the earlier administrative stay of 13 August, so one instrument now governs both the data and the funding threat.

Date, 2026Step
Before 11 AugustFMCSA asks AAMVA for the whole database; Homeland Security issues, withdraws, then reissues a subpoena for the same records
11 AugustChief counsel letter sets a 17 August deadline and threatens all federal funding
13 AugustThe court enters an administrative stay in the states' suit
20 AugustAfter a hearing, the court grants the temporary restraining order
27 August, 3 SeptemberStates move for a preliminary injunction; the government responds
10 SeptemberHearing, 10:00 a.m., Courtroom 900, Alexandria Division

Source: order granting the temporary restraining order, 20 August 2026.

How did a pointer system become the CDLIS Data Demand?

CDLIS was never designed as a federal repository. Congress created it in 1986 so states could see whether a commercial driver already held a license elsewhere. It stores a master pointer record saying which state holds the real file, and the states keep the detailed qualification data themselves.

The driver's license data in a pointer record is limited. As the court described it, citing 49 U.S.C. 31309(b), the record holds a name, date of birth, Social Security number, sex, license number and state of record. Federal officials have always been able to query it one person at a time, and to audit state records through program reviews. What changed was the request to take custody of all of it.

The department's own information policy from 2005 says plainly that "the records in CDLIS are not controlled by FMCSA". FMCSA's May 2026 fee rulemaking proposal likewise refers to master pointer records as "owned by each state". The court leaned on both, and noted the agency had never made a request on this scale before, which it read as a policy change requiring consultation with the states. The three shapes below differ only in what sits in one place.

Three panels comparing a CDLIS pointer lookup, a bulk transfer of 17 million records, and a sharded credential where no node holds a complete record.
Analysis by Zyphe, from the 20 August 2026 order and 49 U.S.C. 31309.

What does this change for your KYC obligations?

Nothing in the order changes a bank's duties directly, but it sharpens three of them: the lawful basis for using state license records in verification, the retention floor that builds the store in the first place, and the onward sharing your suppliers may do. The table maps each to its rule, and adds the EU parallel.

ObligationRuleWhat the ruling changesDo this quarter
Non-documentary verification31 CFR 1020.220(a)(2)(ii)(B)Confirms that permissible-use limits follow driver's license data into your vendor chainRecord which permissible use each supplier relies on
Record retention31 CFR 1020.220(a)(3)(ii)Nothing legally, but it prices the store you are obliged to keepDelete copies held above the five-year floor
Onward disclosure18 U.S.C. 2721(b)(1)An agency's own use does not license passing data to a second agencyAdd onward-sharing terms to supplier contracts
Minimisation, EU and UK[GDPR Article 5](https://eur-lex.europa.eu/eli/reg/2016/679/oj)Poses the same question in another regime: a copy, or an answerMap retention against actual verification need

The Driver's Privacy Protection Act at 18 U.S.C. 2721 bars disclosure of personal information from motor vehicle records, and lets the Social Security number in these records out under only four exceptions. The government never showed how any of them covered the Data Demand, and the one it relied on does not authorise passing the records to the Department of Homeland Security for immigration enforcement.

Your suppliers inherit that reasoning. If your Customer Identification Program relies on non-documentary verification under FinCEN's rule at 31 CFR 1020.220, which permits comparing customer-supplied information against a consumer reporting agency, public database or other source, then somewhere in your stack a supplier is likely querying driver's license data. Ask which permissible use they rely on, and whether they receive match flags or underlying records. AAMVA's own Driver's License Data Verification service returns only match or no match indicators against the issuing jurisdiction, a materially different privacy posture from receiving the record.

Retention is the second pressure point. The same rule requires you to keep identifying information for five years after an account closes, and to keep the description of your verification methods and results for five years after the record is made. Those duties are why regulated firms accumulate the sort of concentrated store that became the subject of this litigation. The rule sets a floor for what you must keep, not permission to keep copies of everything you saw.

What is still uncertain, and what could go wrong?

A temporary restraining order is a holding position, not a judgment. The court found a likelihood of success on the statutory, constitutional and contract claims, but the preliminary injunction is briefed over the next fortnight and the merits remain untested.

The federal defendants also argued that exclusive jurisdiction sits with the court of appeals under the Hobbs Act, an argument the court rejected and which is likely to reappear. Homeland Security is a further loose end. It issued a subpoena for the same records, withdrew it, then reissued it. A companion order the same day, in No. 1:26-mc-19, held the states' motion to quash in abeyance and continued AAMVA's time to respond, so the subpoena is paused rather than quashed.

The order leaves most drivers out. AAMVA floated an opt-out mechanism under which it would produce only the records of states that did not object, and the order protects the plaintiff states' records, so only the states that sued are covered. Drivers licensed elsewhere gain nothing from it.

There is a structural risk too. AAMVA sits between contracts with the states and funding from the federal government, and it told the court it "takes no view on most of those legal issues". An entity in that position is a single point of failure whichever way the case goes. The court accepted that losing it could disrupt license issuance across the country, which is a striking amount of dependence on one non-profit's database.

The win is narrower than the headlines suggest. Individual queries continue exactly as before, and the order restrains wholesale custody rather than routine access. It creates no new privacy right for the drivers whose driver's license data sits in the system.

Why does architecture decide the outcome here?

Harm scales with what sits in one place, not with how carefully that place is guarded. A pointer system answers one question per query. A consolidated copy exposes 17 million people in a single transfer, and the court treated that gap as decisive when it weighed irreparable harm.

Compliance teams face the same choice in miniature. Identity verification can be built to obtain an answer, or to obtain and retain the evidence. Every firm that touches driver's license data makes that choice, usually by default.

DesignWhat sits in one placeExposure from one demand or breach
Central pointer databaseIdentifying fields on every license holder in the country17 million records in a single transfer
Match-flag verification serviceNo new copy; the issuing jurisdiction keeps the record1 answer about 1 person
Conventional vendor archiveDocument images, selfies and extracted fields held for yearsEvery customer onboarded through that vendor
Sharded or user-held credential (Zyphe)No reconstructable record on any single node0 complete records recoverable from one node

We have written before about how this plays out when a store is breached rather than subpoenaed, in the AssuranceAmerica case that exposed seven million driver's license numbers, and in our analysis of centralised storage as a standing liability.

How should compliance teams respond?

Start with an inventory. Identify every supplier in your onboarding chain that queries state license records, and record which permissible use each one relies on. Then ask a narrower question: does the supplier return a verification result, or a copy of the record?

Older contracts often describe a verification service without saying what it retains. Where the contract is silent, the data processing agreement and the supplier's retention schedule settle it.

Next, test your retention against the actual rule rather than against habit. Your Customer Identification Program obliges you to keep identifying information and a description of your methods. It does not oblige you to keep every document image and selfie you ever collected, and each surplus copy is a record you would have to disclose, defend or notify on. Review what your vendor keeps on your behalf, since that store is yours in substance even when it is theirs in contract.

Then revisit your government data request playbook. A demand for bulk records, a subpoena and a funding threat are three different instruments with three different responses, and this case involved all three inside a fortnight. Know who signs off, and know what you would be able to hand over if asked.

Zyphe was built for the position these teams now occupy. Verification runs against an NFC chip read to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload. Personal data is sharded across, on Zyphe's own figures, more than 60,000 nodes under a 29-of-100 threshold scheme, and the customer holds the key, so there is no central store to demand and no master key to compel. You can see the design in decentralised PII storage or book a demo.

The bottom line

The order is short lived by design, but the reasoning is the part worth keeping. A regulator asked for a copy of a national store of driver's license data, could not explain what the copy would let it do that a query already allowed, and lost. Apply that same test to your own architecture and to every supplier in your onboarding chain. Concentrated stores of identity data are a compliance liability as much as a breach risk, because they answer to subpoenas, funding leverage and policy shifts that sit outside your control. Holding less is now the cheaper position in both directions.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

It is a clearinghouse Congress created in 1986 so states could stop commercial drivers holding licenses in several jurisdictions at once. It stores a master pointer record for each holder, which identifies the state that keeps the full file. The states retain the detailed licensing data, and AAMVA has operated the system for the states since 1988.

No. Individual queries continue as before, and federal officials can still audit state records through program reviews. The order restrains the transfer of the plaintiff states' records into federal custody, and it bars retaliation against AAMVA or those states for refusing. It is a limit on bulk custody, not on lawful access.

The court found the states likely to succeed on Administrative Procedure Act claims resting on the Commercial Motor Vehicle Safety Act, the Driver's Privacy Protection Act and the Privacy Act, on an arbitrary and capricious claim, on a Spending Clause claim, and on contract claims brought by Illinois, California, Maine and the District of Columbia.

Indirectly. Any firm verifying US customers may rely on a supplier that queries state license records, and the permissible use question applies to that chain wherever the firm sits. For EU and UK firms there is also a read across to GDPR Article 5, whose minimisation and storage limitation principles ask what the court asked: why hold a copy when an answer will do.

The states must move for a preliminary injunction by 27 August 2026, the federal defendants respond by 3 September, and the court will hear argument on 10 September at 10:00 a.m. The restraining order holds until the court rules on that motion.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo