The Biometrics Worked Perfectly. The Legal Basis Didn't.
Yoti just paid nearly a million euros to leave Spain. Specifically, the Spanish AEPD slapped them with a €950,000 fine for the unlawful processing of biometric data. After the dust settled, Yoti pulled its ID app from the market.
This wasn't a data breach. No hackers broke in; no database was leaked onto a forum. The "failure" here was far more fundamental. The company built a technically sophisticated tool but failed to secure a lawful basis for using it.
When firms talk about 'privacy by design', they usually mean they used AES-256 encryption and minimized their logs. That's security by design, not privacy. True privacy by design starts with the question: "Do we actually have the legal right to touch this data?" In Yoti's case, the answer for the Spanish market was no.
The fine was really for a misunderstanding of GDPR Article 9. Biometric data used for identification is a "special category" of data. You don't just need a general reason to process it; you need a specific exemption. Yoti likely banked on consent or some variation of legitimate interest. But under the strict interpretation favored by European regulators, biometric consent must be explicit and truly freely given. If the app is positioned as the primary way to verify identity for certain services, that "choice" becomes illusory.
The control Yoti missed wasn't a technical one. It was a legal gate in the product development lifecycle.
A proper control would have been a Data Protection Impact Assessment (DPIA) that functioned as a kill-switch. Instead of a DPIA being a checkbox exercise performed after the code was written, it should have been the prerequisite for the project's existence. The assessment should have forced a hard stop the moment it became clear that the legal basis for Article 9 processing in Spain was precarious. If the legal team can't sign off on the 'why', the engineers shouldn't be allowed to build the 'how'.
Some will argue that Yoti is being singled out for a common industry practice. Every identity verification provider uses these methods. They’ll say the regulator is moving the goalposts on what constitutes "explicit consent."
That may be true, but it doesn't excuse the gamble. When you process biometrics, you aren't just handling emails or phone numbers; you're handling the immutable geometry of a human face. The risk profile is permanently higher. To deploy that technology across a jurisdiction without an airtight legal mandate isn't "innovation"—it's negligence.
The cost here goes beyond the €950,000 check. Yoti lost its footprint in a major European economy.
There is also a second-order effect for every other IDV provider operating in the EU. This ruling signals that regulators are tired of "global standards" being used as a shield against local law. If you're providing biometric verification, your compliance isn't a global blanket; it's a patchwork of specific national interpretations of the GDPR.
The insurers will be the next to feel this. Many professional indemnity policies cover breaches (the accidental leak), but they are notoriously prickly about "willful" or "structural" non-compliance (processing data you weren't allowed to have in the first place). If a provider can't prove they had a legal basis for their entire dataset, an insurer might decide the rest of the business is an unquantifiable risk.
The industry likes to pretend that technology solves privacy problems. It doesn't. Technology just makes it faster to commit a violation at scale.
I want to know how many other ID apps currently in the app store are relying on a "consent" button that isn't actually legal under Article 9. The AEPD has set a precedent. Now we wait to see which regulator decides to follow their lead and clear out the rest of the market.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) European Data Protection Board
- Irish health service fined after medical records found covered in animal droppings in turf shed - The Independent Data Privacy (Google News)
- Thailand SEC sets Feb. 2027 deadline for crypto Travel Rule compliance - Bitget Compliance Week (Google News)
- SEC proposes overhaul of transfer agent rules to support blockchain, electronic records - | Governance Intelligence Compliance Week (Google News)
- Yoti pulls Spanish ID app after €950,000 fine over processing biometric data - MLex Data Privacy (Google News)
- Thailand’s SEC Tightens Stablecoin Regulation With New Compliance Framework - The Cryptonomist Compliance Week (Google News)
- SEC, CFTC Delay Private Fund Reporting as Filing Pool May Shrink 43% - TradingView Compliance Week (Google News)
- Leaked compliance records shatter anonymity of 291 crypto users by matching names directly to wallet activity - CryptoSlate Data Privacy (Google News)