TL;DR: Complying with the Spanish Data Protection Agency’s decision would require dropping biometric protections that are central to account integrity and identity assurance, according to Yoti. The case underscores how biometric authentication, GDPR consent, and identity verification governance intersect when digital ID providers must balance security, legality, and user choice.
NHIMG editorial — based on content published by Yoti: the Yoti ID app pause in Spain and its biometric authentication rationale
Questions worth separating out
Q: How should identity teams handle biometrics when legal requirements limit their use?
A: They should treat biometrics as one control in a broader assurance model, not as the only acceptable design.
Q: Why do weaker fallback methods create risk in digital identity systems?
A: Because fallback methods often become the easiest path for impersonation, interception, or social engineering once the primary factor is removed.
Q: Where do identity verification programmes most often lose assurance?
A: They most often lose assurance during recovery, document changes, PIN resets, and account deletion, because those workflows are designed for exception handling.
Practitioner guidance
- Map biometric use to high-assurance events only Restrict biometric authentication to events where impersonation risk is highest, such as onboarding, recovery, document changes, PIN resets, and account deletion.
- Re-test fallback paths against assurance requirements Review every PIN, password, SMS OTP, and email OTP fallback to see whether it still satisfies the relying party’s required confidence level.
- Align consent, retention, and template handling Confirm that biometric templates are processed under a clear legal basis, with explicit consent where required, defined retention periods, and user-facing controls for deletion and recovery.
What's in the full article
Yoti's full post covers the operational detail this post intentionally leaves for the source:
- The company’s explanation of why biometric protections sit at the centre of its Digital ID assurance model.
- The specific account events that require face scan authentication, including recovery and deletion.
- The legal and privacy reasoning behind its position on non-biometric alternatives in Spain.
- The user-facing guidance on account access, deletion support, and recovery file storage.
👉 Read Yoti’s explanation of the Spain app-store pause and biometric ID controls →
Biometric identity verification in Spain: what does it mean for IAM teams?
Explore further
Biometric assurance is now a governance issue, not just an authentication choice. The Spanish case shows that identity services cannot treat biometric factors as a simple product feature because removing them can alter the entire assurance posture. For IAM and identity verification teams, the key question is whether the remaining control stack still satisfies the trust level that relying parties need. The practitioner conclusion is that biometric policy, legal basis, and assurance design must be governed together.
A question worth separating out:
Q: How do GDPR-style privacy rules affect digital ID authentication design?
A: They force teams to think about lawful basis, consent, retention, minimisation, and user rights at the same time as security design. If biometric templates are retained, the service must explain why, how long, and under what safeguards. That means privacy and IAM teams need shared control ownership for identity proofing, recovery, and deletion flows.
👉 Read our full editorial: Biometric authentication and digital ID governance after Spain’s Yoti ruling