Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AEPD sanction and digital ID apps: what do identity teams need to review?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12527
Topic starter  

TL;DR: Spain’s data protection authority has sanctioned Yoti over its Digital ID app, while the company disputes the decision and says no user data was breached, according to Yoti. The case puts consent, processing scope, and regulator-facing accountability at the centre of digital identity governance, especially where biometric or identity verification flows are involved.

NHIMG editorial — based on content published by Yoti covering the AEPD sanction and the Digital ID app: Yoti’s statement on recent data-protection findings

By the numbers:

Questions worth separating out

Q: What breaks when digital identity apps are treated as ordinary consumer apps?

A: The main failure is governance drift.

Q: Why do digital ID platforms create GDPR accountability pressure?

A: Because they sit at the intersection of identity verification, personal data processing, and external trust.

Q: How do security teams know whether privacy controls are actually working?

A: Look for evidence that discovery, classification, DSR routing, and consent enforcement update when the environment changes.

Practitioner guidance

  • Map the full personal-data lifecycle Document what the digital ID app collects, why it collects it, where it is stored, who can access it, and when it is deleted.
  • Separate security evidence from privacy evidence Maintain one control set for access control, logging, and hardening, and a second set for notices, retention, consent or lawful basis, and minimisation.
  • Inventory backend NHIs supporting the identity stack List every service account, API key, certificate, and integration used by the digital identity platform, then assign owners and rotation rules.

What's in the full analysis

Yoti's full article covers the operational detail this post intentionally leaves for the source:

  • The company’s framing of the AEPD sanction and its appeal posture.
  • The specific data-protection issues Yoti says relate to the Digital ID app.
  • The company’s statement that the findings do not apply to all users or clients.
  • The Spanish-language access note and original source wording.

👉 Read Yoti's statement on the AEPD sanction over its Digital ID app →

AEPD sanction and digital ID apps: what do identity teams need to review?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12111
 

Digital identity governance is now a compliance control, not a branding exercise. A regulator sanction against an identity app shows that trust in digital identity is built on evidence of lawful processing, not on claims of security. For IAM and privacy teams, the control question is whether the platform can prove collection, purpose, and retention discipline under review. Practitioners should treat identity verification services as regulated processing environments.

A question worth separating out:

Q: Who is accountable when a digital identity app is sanctioned?

A: Accountability usually sits with the organisation operating the service, even if a vendor provides the platform or components. Privacy, IAM, application security, and legal ownership must be explicit because regulators assess the actual processing chain, not just the product label. Shared responsibility does not remove the need for a named control owner.

👉 Read our full editorial: AEPD sanction puts digital ID governance and GDPR accountability in focus



   
ReplyQuote
Share: