Relating to swiping driver licenses.
SB 1005 regulates when private entities and governmental entities may swipe, meaning electronically read, a driver license or identification card in Oregon. The bill defines key terms such as “swipe,” “personal information,” “private entity,” and “financial institution,” and then limits swiping to specified purposes. For private entities, permitted uses include verifying identity for non-cash transactions, returns, or refunds; verifying age for age-restricted goods or services; fraud prevention in certain return/refund situations; check verification and payment processing; loan or deposit account applications at financial institutions; and pharmacy-related reporting for pseudoephedrine or ephedrine sales. The bill also creates a narrow exception for certain national commercial radio service providers that may swipe with permission for contract-related purposes.
The bill generally prohibits private entities that swipe a license or ID for the allowed identity or age-verification purposes from storing, selling, or sharing the collected personal information. For fraud-prevention and payment-related uses, it allows retention and limited sharing of only certain data elements, and restricts how recipients may use that information. It also limits governmental swiping to situations where the individual knowingly presents the card, the card is lawfully confiscated, emergency assistance is being provided, or a court rule requires swiping for accurate record matching.
SB 1005 also creates a private right of action. An individual may sue an entity that violates the swiping, storage, sharing, sale, or use restrictions and recover actual damages or $5,000, whichever is greater, plus equitable relief, costs, and attorney fees. Courts may treble the award for willful or knowing violations. Any waiver of the statute’s protections is void as against public policy.
The bill’s impact is to tighten privacy rules around driver license and ID card scanning, especially in retail, financial, fraud-prevention, and pharmacy contexts, while preserving certain operational uses. It amends ORS 807.750 and increases potential civil liability for misuse of electronically read identification data, affecting private businesses, financial institutions, pharmacies, and government agencies that scan IDs.
The overall sentiment appears strongly favorable, with broad support in both chambers and only limited opposition. The Senate passed the bill 26-1, the House passed it 41-10, and the Senate concurred 26-2 after House amendments. The available vote history suggests the bill was generally viewed as a consumer privacy measure with a relatively narrow set of exceptions rather than a controversial overhaul.
SB 1005 amends ORS 807.750 to restrict when driver licenses and identification cards may be swiped and to limit the collection, retention, sharing, and sale of the personal information obtained from those swipes. It creates enforceable privacy rules for private entities and governmental entities, while preserving specific exceptions for identity verification, age verification, fraud prevention, financial services, pharmacy reporting, and certain contract-related telecommunications uses. It also increases civil penalties by raising the statutory minimum recovery from $1,000 to $5,000 and authorizes attorney fees and treble damages for willful or knowing violations.
The bill appears to have enjoyed broad bipartisan support, with large margins in both chambers and no recorded committee opposition in the available vote history. The pattern of votes suggests legislators generally supported the bill as a privacy-protection measure with targeted exceptions for legitimate business and government uses. The House margin was somewhat narrower than the Senate’s, indicating some reservations, but the overall sentiment was clearly positive.
The main points of contention appear to be the scope of the exceptions and the strength of the enforcement provisions. Businesses that rely on ID scanning for returns, fraud prevention, payment processing, financial account opening, or age verification may have concerns about operational limits and liability exposure, while privacy advocates likely favored the restrictions on storage, sharing, and sale of scanned data. The House vote, which was less lopsided than the Senate’s, suggests some members may have been concerned about the breadth of the private right of action, the increased damages amount, or the practical burden on retailers, financial institutions, pharmacies, and service providers.