TL;DR: Spain’s data protection authority has sanctioned Yoti over its Digital ID app, while the company disputes the decision and says no user data was breached, according to Yoti. The case puts consent, processing scope, and regulator-facing accountability at the centre of digital identity governance, especially where biometric or identity verification flows are involved.
NHIMG editorial — based on content published by Yoti covering the AEPD sanction and the Digital ID app: Yoti’s statement on recent data-protection findings
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: What breaks when digital identity apps are treated as ordinary consumer apps?
A: The main failure is governance drift.
Q: Why do digital ID platforms create GDPR accountability pressure?
A: Because they sit at the intersection of identity verification, personal data processing, and external trust.
Q: How do security teams know whether privacy controls are actually working?
A: Look for evidence that discovery, classification, DSR routing, and consent enforcement update when the environment changes.
Practitioner guidance
- Map the full personal-data lifecycle Document what the digital ID app collects, why it collects it, where it is stored, who can access it, and when it is deleted.
- Separate security evidence from privacy evidence Maintain one control set for access control, logging, and hardening, and a second set for notices, retention, consent or lawful basis, and minimisation.
- Inventory backend NHIs supporting the identity stack List every service account, API key, certificate, and integration used by the digital identity platform, then assign owners and rotation rules.
What's in the full analysis
Yoti's full article covers the operational detail this post intentionally leaves for the source:
- The company’s framing of the AEPD sanction and its appeal posture.
- The specific data-protection issues Yoti says relate to the Digital ID app.
- The company’s statement that the findings do not apply to all users or clients.
- The Spanish-language access note and original source wording.
👉 Read Yoti's statement on the AEPD sanction over its Digital ID app →
AEPD sanction and digital ID apps: what do identity teams need to review?
Explore further
Digital identity governance is now a compliance control, not a branding exercise. A regulator sanction against an identity app shows that trust in digital identity is built on evidence of lawful processing, not on claims of security. For IAM and privacy teams, the control question is whether the platform can prove collection, purpose, and retention discipline under review. Practitioners should treat identity verification services as regulated processing environments.
A question worth separating out:
Q: Who is accountable when a digital identity app is sanctioned?
A: Accountability usually sits with the organisation operating the service, even if a vendor provides the platform or components. Privacy, IAM, application security, and legal ownership must be explicit because regulators assess the actual processing chain, not just the product label. Shared responsibility does not remove the need for a named control owner.
👉 Read our full editorial: AEPD sanction puts digital ID governance and GDPR accountability in focus