The Part Nobody Asks About
Most conversations about door scanners stop at whether the card reads. The more interesting question starts a second later: the scanner now holds your name, your date of birth, your address, and the time you arrived. What happens to that record is rarely explained to the person handing over the card, and it varies enormously between venues.
This guide covers what a scan actually captures, the range of retention practices, and why handing over a card is a privacy decision as well as an age check. It sits alongside the practical guidance in where to use ID safely.
What a Scan Captures
A door scanner reading the barcode does not extract only an age. It decodes the whole record, because the barcode is a single block of fields that come together. In one read the device receives your full name, date of birth, address, card number, issue and expiry dates, and usually height, eye colour, and sex.
Then it adds context the card never carried: a timestamp, the device identifier, and often the door or venue name. The result is a far richer record than the yes-or-no answer the venue actually needed. What the barcode holds is set out in what is encoded in a licence barcode.
The Range of What Happens Next
There is no single answer, and the spread is wide:
- Some devices compute an age, display a result, and discard everything immediately.
- Some keep a local log on the device for a period, so an incident can be reconstructed.
- Some upload to a venue system, building a customer record across visits.
- Some feed a shared network operated across multiple venues, where a flag at one door follows you to another.
- Some are configured to retain indefinitely, simply because nobody changed the default.
That last case is more common than people expect. Retention is usually a configuration setting rather than a considered policy, and defaults tend to favour keeping data rather than deleting it.
Why Venues Keep It
The reasons are mostly mundane and mostly defensive. A venue facing a regulator wants to demonstrate that it checked. A venue facing an incident wants to know who was present. A venue running a members scheme wants to recognise returning customers. None of these motives require your address, but the scan captured it anyway because the barcode does not offer a partial read.
That is the structural problem. The technology was designed to deliver a complete record, so a venue that only wants an age still ends up holding everything else by default.
What This Means Practically
The useful takeaway is not alarm, it is awareness of the asymmetry. A visual check reveals your details to one person for a few seconds and leaves no record. A scan converts the same interaction into a database row that may outlive your visit by years and may be shared beyond the venue.
Neither is avoidable at a door that scans, and refusing a scan generally means not entering. What you can control is knowing which is happening, and recognising that venues differ. Somewhere that scans every entrant into a shared network is a materially different environment from somewhere that glances at a card. That distinction is worth weighing in the same way as the practical considerations in the risks hub.
Where the Rules Are Heading
Some jurisdictions have started restricting what venues may retain from a scan, typically limiting storage to what is needed to prove a check occurred, and setting time limits. The direction of travel is toward minimisation, because regulators recognise that an age check does not require an address database.
Digital credentials point the same way. A mobile licence can answer a yes-or-no age question without transmitting the underlying record at all, which removes the retention problem rather than regulating it. That model is described in how mobile driver licences work.
Frequently Asked Questions
What does a venue actually capture when it scans an ID?
The full barcode record, not just an age: name, date of birth, address, card number, issue and expiry dates, and usually height, eye colour, and sex. The device then adds a timestamp and its own identifier.
How long do venues keep scan data?
It varies from not at all to indefinitely. Some devices discard immediately, some keep a local log, some upload to a venue system, and some feed a network shared between venues. Retention is often a default setting rather than a deliberate policy.
Why does a venue need my address to check my age?
It does not. The barcode delivers every field in a single read, so a venue that only wants an age receives the rest as a side effect. That is a limitation of the format rather than a choice by the venue.
Is a scan different from someone just looking at my card?
Substantially. A visual check leaves no record and ends when you walk away. A scan creates a database row that can persist for years and may be shared across a network of venues.
Can I refuse to be scanned?
You can decline, but a venue that scans as policy will usually decline entry in return. The realistic choice is deciding in advance which venues you are comfortable being scanned at.
Do digital IDs solve this?
They can. A mobile credential is designed to answer whether you are over an age threshold without handing over the underlying record, which removes the retention question rather than regulating it after the fact.
