An age-verified vending machine should keep the result of each age check and almost nothing else. Record that a check passed or failed, why, when and on which machine. Leave out the document image, the name and the licence number unless a specific rule requires them. A full ID scan is a store of personal data that must be secured, disclosed, retained to a schedule and deleted. This page explains what an ID scan actually captures, what the main privacy laws require, and how to write the record into a machine specification.
Quick answer
- Store the outcome, not the identity. Pass or fail, the reason, the check type, the time, the machine and the transaction ID are enough to show that a check happened.
- A licence barcode holds much more than a date of birth. Name, address, licence number, height and eye colour are mandatory elements in the AAMVA barcode. Keeping the raw scan keeps all of them.
- The GDPR and UK GDPR require minimisation and storage limits. Personal data must be “limited to what is necessary” and kept “no longer than is necessary”.
- Some US laws target this exact case. California limits what a business may do with scanned licence data. Illinois regulates face geometry scans with written consent, a published retention schedule and statutory damages.
- Face matching raises the bar. Biometric data used to identify someone is special category data under the GDPR.
- Tell people at the machine. A short notice before the scan, with a link to the full privacy notice, covers the transparency duty in most regimes.
This is a summary for planning, not legal advice. Rules change; confirm with the regulator where the machine will stand. Facts are as of October 2026.
What an ID scan actually captures
The ID scanner guide covers how each document is read. The privacy question starts with how much comes back from that read.
| Source | What the machine receives | Needed for an age check? |
|---|---|---|
| US or Canadian licence barcode (PDF417) | Mandatory elements under the AAMVA standard include family and given names, date of birth, sex, eye colour, height, street address and the customer ID number | Only the date of birth, and the expiry date if expired documents must be refused |
| Passport machine-readable zone | Name, document number, nationality, date of birth, sex and expiry | Date of birth and expiry |
| ePassport chip | The same data plus the holder’s facial image | Date of birth; the image only if a face match is required |
| Document image (visible, UV, IR) | A picture of the whole document | Only for an authenticity check, and only while the check runs |
| Live camera image for a face match | The buyer’s face | Only while the comparison runs |
| Mobile driver’s licence age request | A signed yes or no to “over 21” (or another age) | Yes, and nothing more |
The AAMVA card design standard also states that “all mandatory and optional data must be unencrypted”. Any reader can parse the whole barcode, so the software has to choose to discard what it does not need. A machine that saves the raw barcode string has saved the person’s home address.
The last row is the privacy-friendly end: a check that never receives the identity is easier to defend than one that receives it and then deletes it.
The minimum record: what to log and what to leave out
| Field | Keep? | Why |
|---|---|---|
| Check result (pass or fail) | Yes | The evidence that a check preceded the sale |
| Failure reason (under age, expired, unreadable, not verified, service unavailable) | Yes | Shows the machine refused for the right reason, and helps fault-finding |
| Check type (barcode, MRZ, chip, face match, staff release, code) | Yes | Shows which control was in force |
| Timestamp, machine ID, transaction or receipt ID | Yes | Links the check to the sale |
| Verification service reference | Yes, if a service is used | Lets an auditor trace the decision back to the provider |
| Date of birth | Usually no | Once compared, the yes or no is the useful fact |
| Name, address, licence or passport number | No, unless a rule requires it | High value to a thief, low value to the operator |
| Document image | No, unless a rule requires it | The richest record of all |
| Face image or face template | No | Biometric data; see below |
Every KioskForce machine already writes the same transaction record: items, quantities, machine, location, time, order state and receipt ID. The age check adds a few fields to that record. The design choice is how much identity, if any, is attached.
The age-verified vending hub sets out why the public health programs we supply work the other way round. Registration happens on a separate web portal, the machine sees only a token or an access code, and quotas are tracked against that token. No personal data lives on the machine. The same pattern works for an age gate when the check can happen before the user reaches the machine.
EU and UK: the GDPR principles that decide the design
The UK kept the GDPR’s principles in the UK GDPR, so the same design rules apply in both. Four provisions matter most for a vending machine:
- Data minimisation, Article 5(1)(c). Personal data must be “adequate, relevant and limited to what is necessary”. Saving a document image to prove a date of birth was checked fails this test unless something else requires the image.
- Storage limitation, Article 5(1)(e). Data must be kept “for no longer than is necessary for the purposes”. That means a deletion date, not an open-ended log.
- Data protection by default, Article 25(2). Only data “necessary for each specific purpose” is processed by default. The text says this applies to “the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility”. Those four items are, in effect, the record specification.
- Transparency, Article 13. At the time of collection, people must be told who the controller is, the purposes and legal basis, any recipients, and “the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period”.
Face matching and biometric data
A face match compares the buyer’s face with the portrait on the document. That stops someone using an older friend’s licence, and it is the most privacy-sensitive thing an age-verified machine can do.
Under the GDPR, biometric data means data from “specific technical processing” of physical characteristics “which allow or confirm the unique identification” of a person, “such as facial images”. Article 9(1) prohibits processing “biometric data for the purpose of uniquely identifying a natural person” unless an exception applies, such as explicit consent for specified purposes.
The ICO’s biometric recognition guidance makes three points that apply directly:
- “Not all biometric data is automatically special category biometric data. It only becomes this if you use it to uniquely identify someone.”
- “It is highly likely that you will trigger the requirement to complete a DPIA if you are using biometric recognition systems.”
- “You must adopt a data protection by design and default approach.”
Facial age estimation is a different technology from face matching. It guesses age from a face without a document. In its April 2022 Regulatory Sandbox report on Yoti’s age estimation tool, the ICO concluded that the tool “will not result in the processing of special category data”, because it categorises people by age rather than identifying them. The image is still personal data, and that conclusion was about one product as described to the regulator. The accuracy evidence and the regulatory acceptance of age estimation are covered in biometric and facial age estimation on vending machines.
United States: state laws that reach a vending machine
There is no single US privacy law for age checks. Three state laws show the range.
California: scanning is allowed, keeping is not
California Civil Code 1798.90.1 lets a business “scan or swipe a driver’s license or identification card” for listed purposes, including verifying age or authenticity and complying with a legal requirement to record or retain the information. It then says the business “shall not retain or use any of the information obtained by that electronic means for any purpose other than as provided herein”. A violation is a misdemeanour, punishable by up to one year in jail, a fine of up to $10,000, or both.
Separately, the California Consumer Privacy Act applies to businesses above its thresholds. The statute sets them at annual gross revenue over $25 million, buying, selling or sharing the personal information of 100,000 or more consumers or households, or earning half of revenue from selling or sharing personal information. A covered business must give notice “at or before the point of collection”, disclose how long it keeps each category of personal information, and keep collection “reasonably necessary and proportionate”. Licence numbers and biometric processing for unique identification are both “sensitive personal information” under the Act.
Illinois: biometric scans need a written policy and a release
The Illinois Biometric Information Privacy Act defines a biometric identifier to include a “scan of hand or face geometry”. Photographs themselves are excluded. A face match that builds a face template from the camera and the document portrait falls inside the Act. Before collecting one, a private entity must:
- inform the person in writing what is being collected, why, and for how long, and receive “a written release executed by the subject” (section 15(b))
- publish a written retention policy and destroy the data “when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual’s last interaction with the private entity, whichever occurs first” (section 15(a))
- not “sell, lease, trade, or otherwise profit from” the data (section 15(c))
Section 20 gives anyone aggrieved a private right of action. Liquidated damages are $1,000 for each negligent violation and $5,000 for each intentional or reckless one, or actual damages if greater, plus legal fees. Subsection 20(b) now limits repeated collection of the same identifier from the same person by the same method to a single recovery. For an unattended machine, collecting a signed written release at the screen is awkward. That is a strong reason to avoid face matching in Illinois unless the legal path is clear.
Australia
The Privacy Act’s Australian Privacy Principles apply higher standards to the collection of sensitive information (APP 3), require notification of collection (APP 5), and require entities to destroy or de-identify personal information in certain circumstances once it is no longer needed (APP 11). Whether a face template counts as sensitive information, and whether your business is covered by the Act at all, are questions for your adviser.
The laws side by side
| Jurisdiction | Rule | What it means for the record |
|---|---|---|
| EU (GDPR) and UK (UK GDPR) | Art. 5(1)(c) minimisation, 5(1)(e) storage limitation, 13 transparency, 25 by default; Art. 9 for biometric identification | Store the outcome; set a deletion period; notice at the machine; DPIA and explicit consent or another exception for face matching |
| California | Civil Code 1798.90.1 | Scan a licence for an age check, then do not keep or reuse the data for other purposes |
| California (covered businesses) | CCPA, Civil Code 1798.100 | Notice at or before collection; disclosed retention period; proportionate collection |
| Illinois | BIPA, 740 ILCS 14 | Written notice and signed release before a face scan; published retention schedule; destruction within 3 years at most; statutory damages |
| Australia | Privacy Act, APPs 3, 5 and 11 | Higher standard for sensitive information; notification; destroy or de-identify when no longer needed |
Retention: set the number before the build
A licence condition or an audit cycle may set a minimum period; privacy law sets a maximum. Write down both, and the reason for each, before the build.
A workable specification looks like this:
- Check outcome records (pass or fail, reason, time, machine, transaction): kept for the period your licensing authority or auditor requires, then deleted or aggregated.
- Identity fields: not stored, unless a named rule requires them. If one does, state the rule and its period.
- Document and face images: held in memory only for the duration of the check, never written to storage, unless a named rule requires otherwise.
- Verification service logs: governed by your contract with the provider. Ask what the provider keeps, where and for how long, because their record is part of your compliance picture.
- Access: name who can read each record (site staff, head office, auditor, regulator) and through which interface.
Signage and notices at the machine
Most regimes need the key facts before the scan, with the full notice one step away. A short panel or start screen should cover:
- who operates the machine and how to contact them
- what is checked (for example “your date of birth is read from your ID”)
- what is recorded (for example “we record that a check passed or failed, not your ID details”)
- how long the record is kept
- a URL or QR code to the full privacy notice
- for a face match, the legal basis and, where required, the consent step
On a screen-free cabinet the notice is printed on the front panel. On a touchscreen it can be a start screen that the user accepts before the scan begins.
What to specify if you are buying one
Send these with an enquiry:
- The check your regulator accepts and the layers it needs. The options are compared on the age-verified vending hub.
- The record fields, using the table above as a starting point, and any rule that requires more.
- Retention and deletion for each record type, with the reason.
- Who can read the records, and how exports are made.
- The verification service, if one is used, and its data-handling terms.
- The notice text for the panel or start screen.
- Failure behaviour: what is logged when a check fails or cannot be made.
KioskForce designs the hardware and software in-house, so the record a machine writes is ours to change rather than a third party’s. Our kiosk platform is Android-based and open, and barcode scanners, RFID readers and passport scanners are already integrated on kiosks we build for transport operators. For age checks we integrate the reader and the verification service you nominate. Release methods can be enabled or disabled per machine from the cloud dashboard. We build to the requirement you state and write it into the quotation; we do not certify compliance with any privacy or age-restriction law. For budgets, see vending machine cost. Code and QR release options are on payments.
Where an ID scan is the wrong privacy answer
- Where a pre-verified account would do. If age can be checked once at enrolment by a person, the machine only needs a card or a code. No identity reaches the cabinet.
- Where the check can happen off the machine. An app, web or SMS check that sends the machine a yes or no keeps identity data where it already lives. The SMS2Vend external validation project shows the pattern.
- Where face matching would need consent you cannot collect at a machine, as in Illinois.
- Where nobody will own the records. A log with no owner, no retention period and no deletion job is a liability. If you cannot staff that, choose a check that does not create one.
Frequently asked questions
What should an age verification vending machine record?
The minimum that proves a check happened: whether it passed or failed, the reason for a failure, the type of check used, the time, the machine and the transaction ID. That record lets an operator show a licensing officer that every restricted sale was preceded by a check, without holding anyone’s identity. Keep a name, licence number or document image only where a law or licence condition specifically requires it, and write that requirement into the specification so the retention period and deletion are set from the start.
Is it legal for a vending machine to scan a driver’s licence?
Generally yes, but some places limit what happens to the data. California Civil Code section 1798.90.1 allows a business to scan a California licence or ID card to verify age or authenticity, and says the business shall not retain or use the information for any other purpose except as the section provides. A violation is a misdemeanour. In the EU and UK the scan is personal data, so the GDPR principles of data minimisation, storage limitation and transparency apply. Check the rules where the machine will stand before deciding what to keep.
Does a face match on a vending machine need consent?
Often, yes. Under the GDPR, biometric data processed to uniquely identify a person is special category data, which is prohibited unless an exception such as explicit consent applies. In Illinois, the Biometric Information Privacy Act requires a private entity to tell the person in writing what is collected, why and for how long, and to receive a written release before collecting a face geometry scan. A face match against an ID portrait is exactly that kind of processing, so settle the legal basis before specifying a camera.
How long should age verification records be kept?
No longer than the purpose needs, and the period should be written down. The GDPR says personal data must be kept for no longer than is necessary, and a privacy notice must state the storage period or the criteria used to set it. The CCPA requires businesses it covers to disclose how long each category of personal information is kept. Illinois requires biometric data to be destroyed when the purpose is met or within three years of the last interaction, whichever comes first. A licence condition may set a minimum. Your regulator or legal adviser sets the number, not the machine.
Is facial age estimation biometric data under the GDPR?
It depends on the purpose. The UK regulator, the ICO, says biometric data only becomes special category data if it is used to uniquely identify someone. In its 2022 Regulatory Sandbox report on Yoti’s age estimation tool, the ICO concluded that the tool would not result in the processing of special category data, because it estimates an age rather than identifying the person. The image is still personal data, so data minimisation and transparency still apply. A face match against an ID portrait is different, because it identifies.
What signage does an ID-scanning vending machine need?
Enough for the user to know what happens before they scan. Under the GDPR, information must be given when data is collected, including who the controller is, the purpose, the legal basis, recipients and how long the data is kept. The CCPA requires a notice at or before the point of collection for businesses it covers. On a machine that usually means a short panel or screen notice naming the operator, what is checked and recorded, how long it is kept, and a link or QR code to the full privacy notice.
Does KioskForce store ID data on its vending machines?
Only if the customer’s requirement says to. Every machine writes a transaction record of items, quantities, machine, location, time, order state and receipt ID. What identity is attached to it is specified per project. On the public health programs we supply, the machine sees only a token or access code and no personal data lives on the machine. For an ID scan we integrate the reader and the verification service the customer nominates. We build to the stated requirement and do not certify compliance with any privacy law.
References
- GDPR text (Regulation (EU) 2016/679) — Articles 4, 5, 9, 13, 25 and 35, as reproduced at gdpr-info.eu (accessed 3 October 2026). https://gdpr-info.eu/art-5-gdpr/
- Information Commissioner’s Office — “Biometric data guidance: Biometric recognition” (under review following the Data (Use and Access) Act; accessed 3 October 2026). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/
- Information Commissioner’s Office — “Regulatory Sandbox Final Report: Yoti” (April 2022). https://ico.org.uk/media2/migrated/4020427/yoti-sandbox-exit_report_20220522.pdf
- California Legislative Information — “Civil Code section 1798.90.1” and “Civil Code sections 1798.100 and 1798.140” (accessed 3 October 2026). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.90.1
- Illinois Biometric Information Privacy Act, 740 ILCS 14/10, 14/15 and 14/20, via FindLaw (accessed 3 October 2026). https://codes.findlaw.com/il/chapter-740-civil-liabilities/il-st-sect-740-14-15/
- AAMVA — “DL/ID Card Design Standard (2020)”, Annex D, Table D.3 mandatory data elements (accessed 3 October 2026). https://www.aamva.org/getmedia/99ac7057-0f4d-4461-b0a2-3a5532e1b35c/AAMVA-2020-DLID-Card-Design-Standard.pdf
- Office of the Australian Information Commissioner — “Australian Privacy Principles quick reference” (accessed 3 October 2026). https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-quick-reference
Related
- Age-verified vending machines: the hub for this cluster
- Vending machines that scan ID: how ID verification works
- Biometric and facial age estimation on vending machines
- Which age-restricted products can you sell from a vending machine?
- How to start a vape vending machine business
- Public health vending: identity-lite verification in production
Talk to us about age verification records
Send the product, the jurisdiction, the check your regulator accepts and what you must record and for how long. We will specify the check, the record, the retention and the notice, and write them into the quotation.
Project brief · 60 seconds
What are we building together?
Three quick steps. Your brief goes straight to the engineers who design, build and support KioskForce systems.