1. Rules that apply everywhere
These rules are enforced in CLICR’s software at the scanning device and at the point where data enters the venue’s database. No venue setting overrides them.
- Four fields, and no more. In every state, the scanner reads and the venue database stores at most name, date of birth, ID number and expiration date. Sex or gender, address, zip code, height, eye color, photograph and every other field are never read, derived, displayed, logged or stored, whatever the state allows.
- CLICR receives counts only. The only data CLICR itself receives from a venue’s operation is in/out headcounts by area and time, recorded from taps in the counting app. Nothing derived from a scan, including an age range, is sent to CLICR in any state.
- Each business leases its own database. Scan records, ban lists and any venue analytics live in a database dedicated to that business, hosted by CLICR, encrypted with a key specific to that business, and partitioned by liquor licensee. CLICR has no standing read path to its contents.
- No ban list is ever shared. A ban list belongs to a single liquor licensee and is never shared between venues, businesses or CLICR customers, including venues under common ownership.
- Unmapped means off. A state not listed as enabled, or newly restricted by a change in law, defaults to “not enabled” until CLICR completes legal review.
- The venue decides. Every election below (retention, ban list, venue analytics) is the venue’s decision under the ID Scanning Addendum, made after the venue has confirmed lawfulness with its own counsel. CLICR provides defaults and ceilings and enforces them; it does not choose for the venue.
2. Tiers
| Tier | What it means | States |
|---|---|---|
| Not enabled | ID scanning is not available. These states prohibit any person from retaining, compiling or maintaining data from an age-verification scan, so hosted storage is not lawful for anyone. | Hawaii, New Hampshire, New Jersey, Oregon, Texas, Virginia |
| Hold | ID scanning is not yet available pending a state-specific build or approval. Venues in these states may use the counting service. | Connecticut, Illinois, South Carolina, Utah |
| Use-limited | Four fields; venue analytics off; counts from taps only; ban list available only in the observation-list configuration (Section 4). The state's law limits how the scanner and its records may be used. | New York, Ohio |
| Verify-and-discard | The scanner reads the ID, shows staff the age result and the validity check, and stores nothing. No scan record, no ban list matching, no venue analytics. The state's law bars retaining or using scan information for any purpose beyond the verification itself, and it has no scan-based statutory defense that a record would support. | California |
| Scanning only after the patron's documented prior informed consent, with a visual-check path for a patron who declines. Four fields after consent; features as stated in Section 3. | Georgia, Florida | |
| Baseline | Four fields; venue analytics available as a venue election; venue observation ban list available; counts from taps; ordinary retention default 21 days. Pennsylvania adds a defense ceiling and a disclosed hosting consideration (Section 3). | Pennsylvania and all other states and the District of Columbia (see Section 3) |
3. State-by-state configuration
Columns: Fields = maximum fields the venue database may hold. Ordinary retention = default period for scan records and the ceiling a venue may elect where a scan-based statutory defense exists. Ban list = whether the venue may enable a ban list and in what configuration ("Observation" means the configuration in Section 4). Venue analytics = whether the venue may enable the age-range report inside its own database. Consent = whether patron consent is required before scanning.
| State | Tier | Fields | Ordinary retention / defense ceiling | Ban list | Venue analytics | Consent | Notes |
|---|---|---|---|---|---|---|---|
| New York | Use-limited | Four | 21 days default / 90 days with recorded defense rationale (ABC Law § 65-b(7)(a)) | Observation only | Off | No | Four fields per § 65-b(7)(b). Scan records used only for the § 65-b(7)(a) defense. Counts from taps only. Residual consideration disclosed: a scan-against-list comparison is arguably a device use beyond age verification under § 65-b(8); venue election. |
| Ohio | Use-limited | Four | 21 days default / 90 days with recorded defense rationale (ORC § 4301.611) | Observation only | Off | No | ORC § 4301.61(D): four fields; information derived from a scan used only for the § 4301.611 defense; device used for no other purpose; no dissemination. Same residual consideration as New York. |
| Pennsylvania | Baseline, with defense ceiling | Four | 21 days default / 90 days with recorded defense rationale (47 P.S. § 4-495(g)) | Observation | Venue election | No | 47 P.S. § 4-495(h) bars a licensee from selling or disseminating transaction-scan information to any third party except the Board, the Bureau or law enforcement. The statute limits dissemination, not use, so the observation ban list and venue analytics inside the venue's own database are available. Residual consideration disclosed: storage in the venue's leased database, hosted by CLICR with no CLICR read path, is not a sale and is not dissemination in the ordinary sense, but no Pennsylvania authority has addressed hosted storage; the venue acknowledges this when it enables scanning. |
| California | Verify-and-discard | None stored | None | Off | Off | No | Cal. Civ. Code § 1798.90.1(a)(1)(A) permits a scan to verify age or the authenticity of the card; § 1798.90.1(a)(3) bars retaining or using the information for any other purpose; violation is a misdemeanor (§ 1798.90.1(c)). The California licensee defense (Bus. & Prof. Code § 25660) turns on having demanded, been shown and relied on bona fide evidence of majority and needs no record, so there is no defense purpose for retention. The device displays the result and discards the fields; nothing is written to any database. |
| Connecticut | Hold | Name and date of birth (point of sale only) until CTDPA build | 21 days default | Off | Off | Yes, for the ID number | Conn. Gen. Stat. § 30-86(d): four fields at point of sale or service; not admission scans. From July 1, 2026 a license or ID number is CTDPA sensitive data (§ 42-515(40)(I)); retaining it requires the consent, assessment and contract build. |
| Utah | Hold | Per DABS verification program | 7 days (Utah Code § 32B-1-407(5)(a)(ii); R82-4-101) | Off | Off | No | Electronic age verification is mandatory for bars and taverns. Information used only to verify age and retained seven days; required records and timestamps differ from the four-field design. Disabled until the Utah configuration is built and approved. |
| Illinois | Hold | Four | Strictly necessary (P.A. 104-0821, eff. Aug. 7, 2026) | Off | Off | Express permission required for any use beyond the transaction | 625 ILCS 5/6-117.1 and 15 ILCS 335/14D limit use to identifying the individual or completing the transaction and bar third-party provision; hosting and express-permission analysis must be completed before enablement. |
| South Carolina | Hold | Four | 21 days default | Off | Off | No | S.C. Code § 61-2-145(F) requires an SCDOR-approved forensic ID system for covered licensees; CLICR is not on the approved list. Do not represent CLICR as satisfying the mandate until approval is documented. |
| Georgia | Four | 21 days default | Observation | Venue election, if disclosed in the consent | Yes: prior knowledge and consent before every scan (O.C.G.A. § 40-5-120(5)) | After documented consent, consented information may be stored and used for any legitimate purpose; the statute lists no fields. Sign at each scanning point, pre-scan device prompt, logged consent record, visual-check path for a patron who declines. Each unlawful act of storage, disclosure or use is a separate misdemeanor. | |
| Florida | Four, only as disclosed in the consent | 21 days default; storage only with consent to disclosed purposes (Fla. Stat. § 322.143(6)) | Observation, if disclosed in consent | Only if disclosed in consent | Yes: informed consent to collect and store; manual collection on request (§ 322.143(6)(b), (7)) | Without consent, an age-verification swipe may not store, sell or share personal information (§ 322.143(3)). The consent screen must state each field and each purpose. | |
| Delaware | Baseline (changes Jan. 1, 2027) | Four | 21 days default | Observation | Venue election | No today; government ID numbers become sensitive data Jan. 1, 2027 (HB 380) | Consent build required before January 1, 2027 for any configuration retaining the ID number. |
| Vermont | Baseline (changes Jan. 1, 2028) | Four | 21 days default | Observation | Venue election | No today; Act 145 effective Jan. 1, 2028 | Sensitive-data treatment of government ID numbers under Act 145 from January 1, 2028; consent build required before then. |
| All other states and D.C. | Baseline | Four | 21 days default | Observation | Venue election | No | Alabama, Alaska, Arizona, Arkansas, Colorado, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Mexico, North Carolina, North Dakota, Oklahoma, Rhode Island, South Dakota, Tennessee, Washington, West Virginia, Wisconsin, Wyoming, District of Columbia. No scanning statute restricting the four-field design was identified in the State-by-State Law Review; state privacy, breach and public-accommodation law continue to apply. |
| Hawaii, New Hampshire, New Jersey, Oregon, Texas, Virginia | Not enabled | None | None | None | None | n/a | Each state bars retention of data from an age-verification scan by any person, and several are criminal statutes (e.g., N.H. RSA 263:12, X; Tex. Transp. Code § 521.126(b)). Verify-and-discard only; no hosted record. |
New York
- Tier
- Use-limited
- Fields
- Four
- Retention
- 21 days default / 90 days with recorded defense rationale (ABC Law § 65-b(7)(a))
- Ban list
- Observation only
- Analytics
- Off
- Consent
- No
- Notes
- Four fields per § 65-b(7)(b). Scan records used only for the § 65-b(7)(a) defense. Counts from taps only. Residual consideration disclosed: a scan-against-list comparison is arguably a device use beyond age verification under § 65-b(8); venue election.
Ohio
- Tier
- Use-limited
- Fields
- Four
- Retention
- 21 days default / 90 days with recorded defense rationale (ORC § 4301.611)
- Ban list
- Observation only
- Analytics
- Off
- Consent
- No
- Notes
- ORC § 4301.61(D): four fields; information derived from a scan used only for the § 4301.611 defense; device used for no other purpose; no dissemination. Same residual consideration as New York.
Pennsylvania
- Tier
- Baseline, with defense ceiling
- Fields
- Four
- Retention
- 21 days default / 90 days with recorded defense rationale (47 P.S. § 4-495(g))
- Ban list
- Observation
- Analytics
- Venue election
- Consent
- No
- Notes
- 47 P.S. § 4-495(h) bars a licensee from selling or disseminating transaction-scan information to any third party except the Board, the Bureau or law enforcement. The statute limits dissemination, not use, so the observation ban list and venue analytics inside the venue's own database are available. Residual consideration disclosed: storage in the venue's leased database, hosted by CLICR with no CLICR read path, is not a sale and is not dissemination in the ordinary sense, but no Pennsylvania authority has addressed hosted storage; the venue acknowledges this when it enables scanning.
California
- Tier
- Verify-and-discard
- Fields
- None stored
- Retention
- None
- Ban list
- Off
- Analytics
- Off
- Consent
- No
- Notes
- Cal. Civ. Code § 1798.90.1(a)(1)(A) permits a scan to verify age or the authenticity of the card; § 1798.90.1(a)(3) bars retaining or using the information for any other purpose; violation is a misdemeanor (§ 1798.90.1(c)). The California licensee defense (Bus. & Prof. Code § 25660) turns on having demanded, been shown and relied on bona fide evidence of majority and needs no record, so there is no defense purpose for retention. The device displays the result and discards the fields; nothing is written to any database.
Connecticut
- Tier
- Hold
- Fields
- Name and date of birth (point of sale only) until CTDPA build
- Retention
- 21 days default
- Ban list
- Off
- Analytics
- Off
- Consent
- Yes, for the ID number
- Notes
- Conn. Gen. Stat. § 30-86(d): four fields at point of sale or service; not admission scans. From July 1, 2026 a license or ID number is CTDPA sensitive data (§ 42-515(40)(I)); retaining it requires the consent, assessment and contract build.
Utah
- Tier
- Hold
- Fields
- Per DABS verification program
- Retention
- 7 days (Utah Code § 32B-1-407(5)(a)(ii); R82-4-101)
- Ban list
- Off
- Analytics
- Off
- Consent
- No
- Notes
- Electronic age verification is mandatory for bars and taverns. Information used only to verify age and retained seven days; required records and timestamps differ from the four-field design. Disabled until the Utah configuration is built and approved.
Illinois
- Tier
- Hold
- Fields
- Four
- Retention
- Strictly necessary (P.A. 104-0821, eff. Aug. 7, 2026)
- Ban list
- Off
- Analytics
- Off
- Consent
- Express permission required for any use beyond the transaction
- Notes
- 625 ILCS 5/6-117.1 and 15 ILCS 335/14D limit use to identifying the individual or completing the transaction and bar third-party provision; hosting and express-permission analysis must be completed before enablement.
South Carolina
- Tier
- Hold
- Fields
- Four
- Retention
- 21 days default
- Ban list
- Off
- Analytics
- Off
- Consent
- No
- Notes
- S.C. Code § 61-2-145(F) requires an SCDOR-approved forensic ID system for covered licensees; CLICR is not on the approved list. Do not represent CLICR as satisfying the mandate until approval is documented.
Georgia
- Tier
- Fields
- Four
- Retention
- 21 days default
- Ban list
- Observation
- Analytics
- Venue election, if disclosed in the consent
- Consent
- Yes: prior knowledge and consent before every scan (O.C.G.A. § 40-5-120(5))
- Notes
- After documented consent, consented information may be stored and used for any legitimate purpose; the statute lists no fields. Sign at each scanning point, pre-scan device prompt, logged consent record, visual-check path for a patron who declines. Each unlawful act of storage, disclosure or use is a separate misdemeanor.
Florida
- Tier
- Fields
- Four, only as disclosed in the consent
- Retention
- 21 days default; storage only with consent to disclosed purposes (Fla. Stat. § 322.143(6))
- Ban list
- Observation, if disclosed in consent
- Analytics
- Only if disclosed in consent
- Consent
- Yes: informed consent to collect and store; manual collection on request (§ 322.143(6)(b), (7))
- Notes
- Without consent, an age-verification swipe may not store, sell or share personal information (§ 322.143(3)). The consent screen must state each field and each purpose.
Delaware
- Tier
- Baseline (changes Jan. 1, 2027)
- Fields
- Four
- Retention
- 21 days default
- Ban list
- Observation
- Analytics
- Venue election
- Consent
- No today; government ID numbers become sensitive data Jan. 1, 2027 (HB 380)
- Notes
- Consent build required before January 1, 2027 for any configuration retaining the ID number.
Vermont
- Tier
- Baseline (changes Jan. 1, 2028)
- Fields
- Four
- Retention
- 21 days default
- Ban list
- Observation
- Analytics
- Venue election
- Consent
- No today; Act 145 effective Jan. 1, 2028
- Notes
- Sensitive-data treatment of government ID numbers under Act 145 from January 1, 2028; consent build required before then.
All other states and D.C.
- Tier
- Baseline
- Fields
- Four
- Retention
- 21 days default
- Ban list
- Observation
- Analytics
- Venue election
- Consent
- No
- Notes
- Alabama, Alaska, Arizona, Arkansas, Colorado, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Mexico, North Carolina, North Dakota, Oklahoma, Rhode Island, South Dakota, Tennessee, Washington, West Virginia, Wisconsin, Wyoming, District of Columbia. No scanning statute restricting the four-field design was identified in the State-by-State Law Review; state privacy, breach and public-accommodation law continue to apply.
Hawaii, New Hampshire, New Jersey, Oregon, Texas, Virginia
- Tier
- Not enabled
- Fields
- None
- Retention
- None
- Ban list
- None
- Analytics
- None
- Consent
- n/a
- Notes
- Each state bars retention of data from an age-verification scan by any person, and several are criminal statutes (e.g., N.H. RSA 263:12, X; Tex. Transp. Code § 521.126(b)). Verify-and-discard only; no hosted record.
4. The observation-list ban configuration
Where this schedule shows “Observation” or “Observation only,” a venue may enable a ban list that works as follows, and only as follows.
Entries are created by venue staff at or about the time of an incident, from their own observation. Staff type the individual’s name and date of birth, or confirm them from the face of the ID, choose a reason from a fixed list of lawful security grounds (violence, threats, theft, sexual misconduct, weapons, fraudulent identification, refusal to comply with staff), and set an expiry that defaults to one year and may run to five years only for violence or weapons. The exclusion is communicated to the individual at the time. No entry is created from, linked to or populated by a scan record.
At the door, the name and date of birth decoded from the ID at the moment of scan are compared in device memory against the venue’s list. On a match, staff see the name, date of birth and “banned,” and a manager confirms before anyone is refused entry. No record of the match is written, the ID number is not used in the comparison, and stored scan records are not read. No photograph or biometric is captured or compared. No persistent identifier is assigned to scanned patrons.
The list is scoped to one liquor licensee, can be reviewed and corrected by the venue at any time, and is never shared. In use-limited states (New York, Ohio) the venue acknowledges the residual consideration noted in Section 3 when it enables the feature. The ban list is not available in California, where the statute bars any use of scan information beyond the verification itself.
5. The venue analytics election
Where this schedule shows “Venue election,” a venue may turn on an age-range report inside its own database. The report groups the venue’s own scans into age ranges by area and time interval, derived only from the date of birth field the venue already holds. No cell is shown unless at least ten scans sit behind it; smaller cells roll up into a coarser bucket. The report is the venue’s, stays in the venue’s database, appears only on the venue’s dashboard, and is not sent to, read by or used by CLICR. It is not available where this schedule shows “Off,” and in consent-gated states only where the venue’s consent disclosure covers it.
5A. Defense-period retention (New York, Ohio and Pennsylvania)
Where this schedule shows a defense ceiling, a venue may keep the four permitted fields beyond 21 days, up to the ceiling, only to preserve a transaction-scan record that supports a statutory defense (New York: ABC Law § 65-b(7)(a); Ohio: ORC § 4301.611; Pennsylvania: 47 P.S. § 4-495(g), which requires the licensee to establish that the card was identified as valid by a transaction scan device and was relied upon in good faith), and only after recording that reason in the Service. The statutes set no retention period; retention is lawful for as long as it is necessary to that purpose and for no other. A proceeding for serving or admitting an underage patron is brought after the event and a venue may not learn of it for weeks, so a record deleted at 21 days cannot support the defense. The 90-day ceiling is set to cover the period in which a charge is most likely to be brought while keeping the record short enough that it serves no other purpose. Records kept under this election are used for nothing else and may be shortened at any time.
6. Change of law
CLICR reviews this schedule quarterly and on any change in law or regulator guidance. CLICR may restrict or disable the feature in a state on notice under Section A-8(c) of the ID Scanning Addendum. Scheduled changes already known: Delaware, January 1, 2027 (government ID numbers become sensitive data; consent build required); Vermont, January 1, 2028 (Act 145). Each version of this schedule is dated and prior versions are archived.