Biometric Privacy Act Fight: Yoti Quits Spain Over Fine

Here's a sentence that should stop you mid-scroll: a company just pulled its entire identity app out of a country rather than remove one security check. Not because of a hack. Not because of a data breach. Because a regulator asked it to make biometric authentication optional, and the company said doing that would break the whole system for everyone else using it. That company is Yoti, the country is Spain, and the story underneath it teaches something almost nobody understands about how digital identity actually works.
TL;DR: Biometric privacy and app security aren't the same fight, a face scan can confirm you're a real, live person without ever proving your ID, account, or credential is genuine, current, or still under your control.
Most of us assume a selfie-plus-ID check is basically one big security blanket. Take a picture of your face, take a picture of your driver's license, app says "match!", done, secure, move on with your life. That assumption is exactly the gap that got exposed in Spain, and it's a gap that biometric privacy laws, biometric data rules, and biometric information privacy act cases keep exposing again and again. And once you understand why it's wrong, you'll never look at an ID-verification prompt the same way again.
Why biometric privacy rules and biometrics privacy law in Spain forced an ID app to leave the country
Yoti's app uses a face check at several exact moments: when someone adds a new identity document, recovers their account on a new or lost phone, deletes their account, or changes their PIN. Spain's data protection regulator, the AEPD, hit Yoti with a fine of roughly €950,000 and effectively told the company its facial authentication couldn't be mandatory, users needed a non-biometric opt-out. Yoti's response was to pull the app from Spanish app stores entirely rather than build that opt-out. The dispute is a clean example of how biometric data and personal information rules can force a company to choose between a market and its security architecture.
Why would a company choose "leave the market" over "just add a workaround"? Because in security engineering, an optional lock isn't a lock. It's a note that says "or don't." If even one user can skip the face check during account recovery, that becomes the exact door a fraudster tries first, and it doesn't just put that one user at risk, it puts every other person and business trusting that verified account, and every piece of personal information tied to it, at risk too.
96% vs 61%
AI-based liveness systems catch face spoofs at 96% accuracy, human reviewers catch them at 61%
Source: Mitek Systems research on biometric spoof detection This article is part of a series, start with Illinois Bipa Court Says A Recorded Voice Is Now A Face Scan.
What is the difference between biometric privacy, biometric information, and biometric security?
Biometric privacy is about who controls your face, voice, or fingerprint data and whether you consented to its storage, that's the legal, consent-driven side. Biometric information covers the actual data points collected, the templates, scans, and characteristics themselves. Biometric security is about whether the system checking your face can actually stop an impostor. Spain's regulator was fighting the privacy battle. Yoti was defending the security one. That collision, protect data on one side, keep the door locked on the other, is exactly why this case matters.
The three hidden layers behind every biometric system, and why one biometric characteristic alone isn't enough
Here's the part almost nobody outside the industry knows: when an app checks your face, it's not running one test. A properly built biometric system runs at least three separate checks, in sequence, like three locks on the same door. Each layer relies on a different biometric characteristic or piece of biometric information, and skipping any single layer weakens the other two.
Layer one is liveness detection. Before the system even asks "does this face match," it asks "is this a real, live human being right now, or a photo, video, or mask held up to the camera?" This runs through computer vision, motion analysis, texture checks, and depth mapping, looking at things like whether light bounces off skin the way it should, or whether the image has that flat, printed quality where skin appears too smooth under close inspection. It's the first gate, and it's the one most people don't even know exists.
Layer two is the actual face matchyour live face compared against a stored template (basically, a mathematical map of your facial features, not a photo). This is the part everyone thinks of as "the security check." It's actually the middle step, and it depends entirely on accurate biometric data being captured correctly the first time.
Layer three is credential validationchecking that the document behind the face (your ID, your passport, your account) is real, current, issued by a trusted authority, and hasn't been reported stolen or reassigned. A face match only answers "does this face match the template." It says nothing about whether the credential attached to that template, or the personal information linked to it, is still good.
Allowing users choice to avoid biometric authentication removes that global high-security rule and architecture, leaving those users vulnerable to bad actors taking control of their accounts, which would then leave other Yoti ID app users and businesses vulnerable to interacting with impostors abusing verified users' accounts.
Biometric Update
That quote is the whole story in one sentence. A security architecture that only works when every single person participates is exactly why Yoti wouldn't bend on this, one opt-out breaks the guarantee for everybody.
The ATM analogy that makes biometric privacy and identity security finally click
Picture your bank's ATM. It's not running one check when you insert your card and scan your fingerprint. It's running three, back to back. First, the camera confirms a real person is standing there, not a photo taped to a stick. Second, your fingerprint gets compared to what's on file, using stored biometric data much like Yoti's system does. Third, and this is the one people forget, the bank checks that the account tied to that fingerprint is still active, still yours, and hasn't been frozen or flagged. Previously in this series: Clearview Ai Opt Out What A School Deepfake Case Proves.
Now imagine a regulator walked in and said: "Some customers find the fingerprint scanner uncomfortable. Let them skip it and use a PIN instead." Sounds reasonable for privacy, right? Except now every fraudster who steals a PIN has a direct path around the one check that actually confirms it's really you. That's the trade Spain asked Yoti to make. Yoti said no.
How biometric identifiers and biometric data get treated differently under privacy laws across Europe
Here's where it gets genuinely strange: the exact same facial templatethe same mathematical map of your face, gets classified completely differently depending on which country's regulator you ask. The UK's Information Commissioner's Office has accepted that facial age estimation used purely to guess someone's age category isn't full biometric processing under privacy laws. Spain's AEPD looked at similar templates and drew a stricter line, treating them as sensitive biometric data the moment they're stored and matched. Same technology, same underlying identifier, two different legal answers, even though GDPR is supposed to apply the same way across the whole European Economic Area, and neither answer resembles how BIPA handles biometric information back in the US.
| What a face match confirms | What a valid credential confirms | Status |
|---|---|---|
| A live person is in front of the camera right now | The ID or account is real, current, and issued by a trusted source | Biometric data check enforced |
| The face resembles the stored template closely enough to pass a threshold | The credential hasn't been stolen, revoked, or transferred to someone else | Personal information verified |
| Liveness checks defeated a printed photo or video replay attempt | Consent and ownership history still trace back to the rightful holder | BIPA-style consent recorded |
| Answers: "does this person match the enrolled face?" | Answers: "is this identity still trustworthy right now?" | Biometric information reviewed |
What You Just Learned About Biometric Privacy And Biometric Data
- 🧠 A face match is one gate, not the whole gate systemliveness, matching, and credential checks are three separate steps, and skipping any one weakens the rest
- 🔬 AI beats humans at spotting fakes96% accuracy for AI-based liveness detection versus 61% for human reviewers, according to research cited by Mitek Systems
- 💡 Consent rules and security rules can conflicta regulator protecting your privacy by making a check optional can accidentally hand fraudsters an easier way into personal information
- ⚖️ Regulators don't always agreethe UK and Spain treat the same biometric templates and biometric data differently under laws meant to apply identically
Why do biometric privacy laws sometimes weaken security instead of protecting it?
It sounds backwards, but it happens when a rule designed to protect consent ends up creating an optional bypass around a check meant to stop impostors. Privacy laws generally assume the biggest risk is a company misusing your data. But in identity verification, the bigger risk can be a stranger pretending to be you. When a law forces a company to offer a weaker, non-biometric path "for privacy," it can open the exact hole an attacker wants, protecting one right while quietly undermining another, all while the underlying biometric data sits in the same database either way.
The misconception almost everyone has about biometric systems and biometric data allows consumers to feel secure
Here's the mistake, and it's a completely understandable one: people see an app ask for a selfie and a photo of their ID, watch some AI compare the two, and think "well, that's got to be secure, it checked my face AND my document." It feels thorough. Three elements, one process, done. Believing that biometric data allows consumers to skip worrying about the rest of the system is exactly the misconception this article is trying to correct.
But a 99% confidence match score on a face doesn't tell you anything about whether the ID behind it is stolen, expired, or was issued to someone else entirely. Scale that across a database with millions of people, and even a system that's right 99% of the time can generate hundreds of thousands of false matches. The face check and the credential check are answering two completely different questions, and a system that only asks one of them is only half-secure, no matter how confident that one answer sounds.
Why do people miss this? Because the selfie step is the most visible, most "high-tech feeling" part of the process. You watch your own face get scanned. It feels like the security is happening right there, in that moment. The credential check, is this document real, current, still owned by you, happens quietly in the background, or sometimes doesn't happen at all. The flashy part may not be the credential check. This is the same principle worth understanding whenever facial recognition intersects with real-world stakes, whether it's an app verifying your identity, a company evaluating footage, or a regulator weighing biometric information against a fraud report, the match score is never the whole story on its own.
Key Takeaway
Biometric privacy and identity security are two different jobs, a face scan can confirm a live person is in front of the camera without ever confirming that the credential, account, or ID behind that face is genuine, current, or still under the rightful person's control. Up next: Illinois Bipa Court Says A Recorded Voice Is Now A Face Scan.
How does biometric privacy compare to US laws like the Illinois Biometric Information Privacy Act?
In the US, the closest equivalent fight plays out under the Illinois Biometric Information Privacy Act (BIPA)a state law that requires companies to get written consent before collecting biometric identifiers like fingerprints or face scans, and allows individuals to sue for damages when companies skip that step. BIPA is one of the strictest biometric law frameworks in the country, and it's forced major tech companies to change how they store facial templates and other biometric data. It shares Spain's underlying concern, protecting people's personal information from being collected without permission, but the biometric information privacy act doesn't force companies to make security checks optional the way Spain's ruling did.
So here's the real aha moment, the one worth remembering the next time an app asks for your selfie: the question isn't "did my face match?" The question is "what else did this system just check, and what did it skip?" A face match proves presence. It doesn't prove ownership, and it doesn't prove the credential attached to that face is still trustworthy. Spain's regulator tried to protect people by making one lock optional. Yoti's answer was that a lock everyone can skip isn't protecting anyone, it's just protecting the paperwork, and the personal information behind it.
biometric privacy: Frequently Asked Questions
What does biometric privacy actually protect if it doesn't guarantee security?
Biometric privacy laws generally protect your control over sensitive personal information, your face, fingerprints, or voice, by requiring companies to get consent before collecting biometric data, explain how it's stored, and disclose their biometric-data practices upon request. Laws like the biometric information privacy act focus on data ownership and misuse prevention, not on whether the verification system itself can stop impostors. That's a separate engineering problem, which is exactly what tripped up the Yoti case in Spain.
Can biometric data allow consumers to control how companies use their face scans and personal information?
Yes, under many privacy laws, biometric data allows consumers real rights: they can demand to know what's stored, request deletion, and in places like Illinois under BIPA, sue for damages if a company collected biometric identifiers without written consent. These protections shape how companies design their systems, sometimes creating tension between what protects your privacy and what keeps a security system airtight, which is the exact conflict at the center of the Yoti-Spain dispute.
Do payment methods use the same biometric systems and biometric characteristic checks as digital ID apps?
Many payment methods now use face or fingerprint checks to let you access their app or approve a transaction, but they typically layer this with additional checks, like device recognition and transaction pattern analysis, precisely because a single biometric characteristic alone can pose challenges if used as the only safeguard. A stolen phone with a spoofed fingerprint sensor is a real attack path, which is why serious payment systems never rely on biometrics as a single point of failure.
Why can biometric systems pose challenges for both privacy and security teams at once?
Because the two goals sometimes pull in opposite directions. Security teams want mandatory, layered checks like liveness detection plus credential validation to stop fraud. Privacy teams and regulators, sometimes citing BIPA or a biometric information privacy act, want individuals to have choices about whether their biometric data gets collected at all. When a law forces an optional path around a security check, it can pose challenges for the whole system, which is exactly the bind Yoti found itself in in Spain.
What happens to biometric templates and biometric data if someone deletes their account?
Under most privacy laws, including GDPR-style frameworks and BIPA, companies are required to delete stored biometric data and biometric information within a defined window after account closure, unless a legal obligation requires retention. Yoti's system specifically triggers a face check at the moment of account deletion, precisely because that's a high-risk moment where an impostor might try to hijack and close someone else's account rather than their own.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Facial Recognition Privacy Concerns: MSG Fined $30,000
A liquor authority dropped its case against Madison Square Garden over facial recognition but still issued a $30,000 fine — and the reason why teaches a lesson everyone should know before their own face gets scanned somewhere.
facial-recognitionFacial Recognition Bias: 34% Error Rate for Some Faces
A "99% accurate" facial recognition system can still be wrong 34% of the time for certain faces — and the score never tells you which group you're in. Here's how to read a match score like an expert.
digital-forensicsUK Digital Identity: 275 Firms Face One New Rulebook
A green checkmark that says "verified" doesn't mean much on its own. Here's what the UK's new digital identity rulebook actually forces companies to prove—and what it teaches you about trusting any identity check.
