Skip to content

Spain Fines Yoti €950K — Biometric Enforcement Is Tightening Under GDPR

March 20, 20262 minute read

Spain’s data protection authority, AEPD, has fined Yoti €950,000 over its facial age-verification technology — a clear signal that biometric compliance is now under intense regulatory scrutiny.

Key GDPR Breaches Identified
• Unlawful processing of biometric data (special category data)
• Invalid consent (not sufficiently informed, specific, or freely given)
• Excessive data retention beyond necessity

Notably, regulators rejected “weak or bundled consent”, especially where users may feel compelled to use the service (e.g. platform access).

What This Means
Biometric technologies — from age verification to digital identity — are now firmly in regulators’ crosshairs. Authorities across the EU are emphasizing:
• DPIAs are mandatory for high-risk use cases
• Necessity & proportionality must be demonstrable
•  “Privacy by design” must be operational — not theoretical

Key Takeaway
Biometric innovation is colliding with GDPR’s strict safeguards — and enforcement is accelerating.

For companies deploying AI & biometric solutions:
• Ensure explicit, granular consent (or a solid alternative legal basis)
• Enforce data minimization & strict retention policies
• Conduct and document DPIAs & risk assessments

How S8fe.ai Supports
S8fe.ai helps organizations operationalize GDPR requirements across AI and biometric use cases. We enable automated DPIAs, consent governance, and data lifecycle management, reducing regulatory risk while accelerating innovation.

Source: https://ppc.land/spain-fines-yoti-eu950-000-over-biometric-data-and-consent-failures/

Share this article

Back To Top