Yoti today said it will remove its Digital ID app from the Apple and Android app stores in Spain from September 10, 2026, choosing to leave the market rather than strip the facial biometric step that Spain's data protection authority ruled unlawful in March.
The British identity company set out the decision in a statement issued today, six months after the Agencia Española de Protección de Datos published a resolution imposing a total of €950,000 in penalties across three separate breaches of the General Data Protection Regulation. Yoti is contesting that resolution before the Audiencia Nacional, Spain's High Court, and the withdrawal is framed as a consequence of that appeal rather than a settlement of it.
According to Yoti, the company examined what it would need to change to satisfy the regulator and concluded the required change went to the core of the product. "We have concluded that to do so would require us to remove the biometric protections that sit at the heart of our app," the company said. Those protections, it added, are essential to safeguarding users' personal data and to maintaining the integrity of the identity and age verification services that businesses rely on when using its Digital ID.
The reasoning is unusual in its directness. Companies facing a national regulator normally adjust a setting, add a disclosure, or accept a fine and continue trading. Yoti has instead concluded that the adjustment the AEPD appears to require would produce a product it does not want to ship. "Offering a version of our app in a country without biometric authentication would mean delivering a service that falls short of the global guarantees we stand behind, and that is not something we are prepared to do," the statement said.
What changes on September 10
The removal covers the app stores, not the installed base. From Thursday, September 10, 2026, the Yoti ID app will no longer be downloadable from Apple's App Store or from Android app stores in Spain. Anyone who already holds an account can carry on using the version currently on their device.
What existing Spanish users lose is the update channel. According to Yoti, the company hopes to republish the app in the Spanish stores once the appeal concludes, after which it expects updates to become available again to existing users. Until then, accounts in Spain sit on a frozen build. The company recommends that users in Spain who continue with the app store a recovery file, which it says would help them regain access if they hit problems updating to a new version should the app return.
Account deletion runs the other way. Yoti says it cannot remove Spanish accounts on users' behalf even if asked. "Due to the privacy and security controls built into the Yoti ID app, we can't delete existing Spanish users' app accounts for them," the statement said, describing this as a consequence of a privacy-by-design architecture in which only the individual account holder can reach and erase the account. Deletion is available from inside the app at any time, and the company points users who need help to its customer support team.
That detail carries a small irony. The AEPD's third finding concerned retention: biometric templates held for the life of an account, geolocation data derived from IP addresses kept for five years, images of documents flagged as fraudulent held for up to two years. The architecture Yoti cites as the reason it cannot delete accounts centrally is the same architecture that leaves data in place unless a user acts.
The decision Yoti is appealing
The March resolution, published under file reference EXP202317887 and signed by AEPD president Lorenzo Cotino Hueso, broke the €950,000 total into three parts. Spain fined Yoti €950,000 across unlawful biometric processing, invalid consent and excessive retention: €500,000 under Article 9 for processing biometric special category data without a valid legal basis, €200,000 under Article 7 for consent obtained through a pre-ticked box covering research and development use, and €250,000 under Article 5.1(e) for holding data longer than the stated purposes required. The authority also ordered three corrective measures, to be implemented within six months of the resolution becoming final.
The Article 9 finding is the one that produced the impasse. Yoti argued during the investigation that its facial scan authenticates rather than uniquely identifies, and therefore falls outside the special category regime. The AEPD rejected that reading, finding that the scan generates a stored biometric template and that a later scan is matched one-to-one against it when a user changes a PIN or recovers an account. The authority described the company's position as reflecting particular negligence, and treated the involvement of minors as an aggravating factor, on the basis that an age verification product is by its nature used heavily by people under 18.
Yoti's public statement now accepts the classification while contesting its consequences. "A retained facial template is classed as special category data under Article 9 of GDPR. Consent to process it must be freely given," the company said, adding that it agrees with the principle and already requires any organisation offering its Digital ID as an access route to provide a non-biometric option alongside it, so that use of the Yoti app remains voluntary.
The dispute is therefore narrower than it first appears. It is not about whether facial templates are sensitive. It is about whether a company that stores such a template can make the biometric step the only way to reach the account that holds it.
Why Yoti says a password will not do
According to Yoti, the app requires a face scan at four points: adding an identity document, recovering an account after a phone is lost, stolen or replaced, deleting an account, and changing a PIN. Each is a moment at which control of an identity credential changes hands, and each is a moment at which an attacker who has taken over a device would want to act.
The company's argument is that the alternatives the AEPD's decision would push it toward are weaker at exactly those moments. "Biometric facial authentication offers the strongest security to protect tens of millions of Digital ID users," the statement said, contrasting facial biometrics with passwords, hardware devices, and SMS or email one-time passwords on the ground that a face cannot be handed to another person. Yoti's list of the alternatives it would have to offer runs to a PIN, a password, or an SMS or email one-time password, and it concludes: "There are no credible, cost-effective alternatives to biometric authentication that offer equivalent high security, assurance and customer convenience."
That list is notable for what it omits. It does not mention passkeys, the device-bound cryptographic credentials that have displaced passwords across large consumer platforms and that Google Ads made mandatory for sensitive account actions from July 15, 2026. The omission is defensible on its own terms, since a passkey is typically unlocked by a fingerprint, a face scan or a device screen lock, which returns the question of whether a non-biometric path exists rather than answering it. It is still the case that the company's published reasoning addresses a 2015 menu of alternatives rather than a 2026 one.
Where the two positions diverge
The AEPD has been circling this question for more than a year, and not only in the Yoti file. In February 2026 the authority issued a formal warning to Tools for Humanity over its iris-scanning operation, and rejected an argument structurally identical to Yoti's: that processing designed to verify uniqueness rather than to identify a person sits outside Article 9. In the same warning, the authority set out the test that matters here. Where several equally effective measures exist, a controller must select the least intrusive, and that assessment includes evaluating whether a non-biometric alternative could do the job.
Yoti's answer is that no non-biometric alternative is equally effective, which is why it treats the least-intrusive test as a demand to degrade the product. The regulator's answer, implicit in the resolution, is that a service holding identity documents and facial templates cannot make the collection of a further biometric the price of reaching them.
Neither position has been tested in court. The Audiencia Nacional appeal is the venue in which it will be, and the withdrawal removes the product from the Spanish market while that runs. There is no published timetable for the hearing.
European practice offers no settled answer either. The UK's Information Commissioner's Office, which ran Yoti through its regulatory sandbox, previously accepted that facial age estimation used purely for categorisation is not biometric processing in the Article 9 sense. Spain has taken a different view of the same underlying templates once they are retained and matched. The GDPR binds identically across the European Economic Area, yet the classification of a facial template still turns on which supervisory authority is asked.
Spain's enforcement record
The AEPD is among the more active supervisory authorities in Europe on biometric questions, and the Yoti file sits inside a run of decisions. The authority fined FC Barcelona €500,000 in March 2026 over a deficient impact assessment covering facial and voice data from roughly 143,000 members. It imposed €1.8 million on airport operator AENA in November 2025 for inadequate assessments before deploying facial recognition. In May 2026 it fined Amadeus IT Group €14.4 million over passenger data profiling, and it penalised Bankinter €240,000 as successor to EVO Banco for a breach exposing 1.27 million records.
That output is not simply a function of resources. With 189 staff supervising a population of 49.1 million, Spain's ratio of regulators to residents is comparable to Portugal's, whose authority issued two fines in the whole of 2025. The difference is posture.
Yoti's exit is the first case in which a vendor has responded to an AEPD biometric ruling by pulling a product from the Spanish market rather than reconfiguring it. Whether that reads as principle or as pressure depends on where one sits; what it establishes as a matter of record is that a national data protection decision can now remove an identity product from a member state's app stores.
Why this matters for the marketing community
Age assurance has moved from an option to an obligation across a widening set of European surfaces, and the vendors supplying it are a short list. Reddit locked teen chat and ad personalisation in the EU when its age checks began on June 24, 2026, removing granular targeting eligibility from an entire cohort of accounts in one of its larger advertising markets. X built age assurance behind a verification flow in 2025 to meet UK and EU requirements. The UK's Online Safety Act regime drove a documented surge in VPN signups when adult content checks took effect. France approved an under-15 social media ban in July 2026 after cutting the age verification clause from the text.
Each of those deployments rests on a third-party verifier. The Yoti case shows that the verifier carries compliance risk of its own, separate from the platform that hires it, and that this risk can crystallise as market withdrawal rather than as a fine a large vendor absorbs. A publisher or advertiser that has built an age gate around a single supplier now has a worked example of what happens when that supplier and a national regulator cannot agree.
The supply side is also thinner than the demand side. The European Commission adopted a recommendation on April 29, 2026 urging member states to deploy a privacy-preserving age verification app by December 31, 2026, having contracted Scytales and T-Systems to build open-source software and declared it feature-ready on April 15, 2026. The instrument is a recommendation, not a regulation, and carries no penalty for a member state that misses the date. Spain is one of the frontrunner countries expected to move first. Documents released in July 2026 in response to a freedom-of-information request showed the Commission held no privacy impact assessment written specifically for that app, arguing the future publisher carries that responsibility.
So Spanish users lose a private-sector digital identity option in September while the public-sector replacement remains undeployed, undated in practical terms, and short of the documentation the same regulator demands of commercial vendors. That asymmetry is the part of this story with the longest tail.
The legal direction of travel, meanwhile, is toward more verification rather than less. The Court of Justice of the European Union ruled on June 16, 2026 in Joined Cases C-188/24 and C-190/24 that member states can compel age verification from platforms established elsewhere in the bloc, subject to the procedural conditions in Article 3(4)(b) of the e-commerce directive. The European Data Protection Board's Statement 1/2025, adopted on February 11, 2025, set ten principles for GDPR-compliant age assurance, among them that the method chosen must be the least intrusive available and that retention periods must be short.
Those two requirements are the ones Yoti and the AEPD read differently. The company treats strong authentication as a security floor that a regulator is asking it to breach. The authority treats a mandatory biometric as a ceiling on user choice that a controller may not impose. Until the Audiencia Nacional rules, the practical effect is that Spanish residents cannot download the app, and every age assurance vendor operating in the market has a precedent to price in.
"We look forward to bringing it back once we have legal clarity and confidence that we can offer the most secure version of our app in Spain," the company said.
Timeline
- July 2018 - Yoti creates the first version of its data protection impact assessment for age verification services.
- December 12, 2023 - The AEPD opens preliminary investigations into Yoti under file EXP202317887.
- May 14, 2024 - The authority issues a second information request covering methods used in Spain, geolocation data and retention periods.
- February 11, 2025 - The EDPB adopts Statement 1/2025, establishing ten principles for GDPR-compliant age assurance.
- November 2025 - The AEPD fines AENA €1.8 million over airport facial recognition failures.
- February 2026 - The AEPD warns Tools for Humanity over its iris-scanning operation, rejecting the verify-uniqueness framing.
- February 24, 2026 - The UK ICO fines Reddit £14.47 million for children's data failures including the absence of age assurance.
- March 4, 2026 - The AEPD fines FC Barcelona €500,000 over a deficient biometric impact assessment.
- March 10, 2026 - The AEPD publishes its resolution fining Yoti €950,000 across three GDPR violations, ordering corrective measures within six months.
- April 29, 2026 - The European Commission adopts a recommendation urging member states to deploy age verification apps by December 31, 2026.
- June 16, 2026 - The CJEU Grand Chamber rules in Joined Cases C-188/24 and C-190/24 that member states can compel cross-border age checks.
- June 24, 2026 - Reddit begins EU age checks, locking teen chat and ad personalisation.
- July 18, 2026 - Released documents show the Commission holds no dedicated privacy impact assessment for the EU age verification app.
- September 3, 2026 - Yoti states it will remove the Yoti ID app from Apple and Android app stores in Spain, citing its appeal before the Audiencia Nacional.
- September 10, 2026 - The removal takes effect. Existing accounts remain usable on the installed version; no new downloads are available in Spain.
Related PPC Land coverage
- Spain fines Yoti €950,000 over biometric data and consent failures - The March 2026 resolution, its three penalties, and the AEPD's reasoning on facial templates, pre-ticked consent and retention.
- Spain's data regulator warns World's iris-scan operator over GDPR risks - The February 2026 warning in which the AEPD rejected the same verify-uniqueness argument and set out the least-intrusive-alternative test.
- Spain fines FC Barcelona €500,000 for failing biometric data protection assessment - The March 2026 decision on an impact assessment covering biometric data from around 143,000 members.
- Spain's AENA receives €1.8 million fine for airport facial recognition failures - The November 2025 ruling establishing that valid consent does not excuse a missing assessment.
- European data regulator details new age verification rules for digital services - The EDPB's ten principles for age assurance under the GDPR, adopted February 11, 2025.
- EU spent millions building an age verification app nobody has to use - The Commission's April 2026 recommendation, its December 31, 2026 target and the absence of any enforcement mechanism.
- EU age-check app: 9 files released, no privacy review, claims unproven - What a freedom-of-information request revealed about the documentation behind the Commission's app.
- EU court rules states can force age checks on foreign porn sites - The June 2026 Grand Chamber judgment on cross-border age verification obligations.
- Reddit locks EU teen chat and ads as age checks start June 24 - How a platform-level age check removed targeting eligibility from a cohort of EU accounts.
- France bans under-15s from social media but cuts age verification clause - The July 2026 law and the verification provision removed before adoption.
- Portugal's data watchdog issued just 2 fines in all of 2025 - Comparative staffing and enforcement output across European supervisory authorities, including Spain.
- Explaining passkey - How device-bound cryptographic credentials work and where platforms have made them mandatory.
Summary
Who: Yoti Ltd, the British digital identity and age verification company, and the Agencia Española de Protección de Datos, Spain's national data protection authority. The dispute is before the Audiencia Nacional, Spain's High Court.
What: Yoti will remove the Yoti ID app from Apple and Android app stores in Spain. Existing accounts continue to work on the installed version, but no new downloads will be available and updates pause until the appeal concludes. Only individual users can delete their own accounts; the company says its architecture prevents it from doing so on their behalf. The withdrawal follows the AEPD's March 10, 2026 resolution imposing €950,000 in penalties: €500,000 for unlawful processing of biometric special category data under Article 9, €200,000 for invalid consent under Article 7, and €250,000 for excessive retention under Article 5.1(e).
When: Announced September 3, 2026, taking effect Thursday, September 10, 2026. The underlying resolution was published on March 10, 2026, following an investigation opened on December 12, 2023.
Where: Spain. The app remains available in other markets, and Yoti says its global service is unaffected.
Why: Yoti states that aligning with the AEPD's decision would require offering a non-biometric route into the app - a PIN, a password, or an SMS or email one-time password - alongside the face scan used for adding documents, account recovery, account deletion and PIN changes. The company says no such alternative offers equivalent security and that it is not prepared to ship a reduced version in one country. The AEPD holds that a retained facial template matched one-to-one is special category data requiring a valid Article 9 basis, and that controllers must select the least intrusive effective measure, which includes assessing whether a non-biometric option would suffice.
Discussion