From 10 September, Yoti will remove its Digital ID app from the Apple and Android stores in Spain. People who already have the app can keep using it. New downloads stop. Yoti says it wants to republish after its appeal is decided.

Why this is happening: Spain’s data protection authority (AEPD) fined Yoti €950,000 over the Digital ID app. The fine breaks down roughly as €500k for biometric processing under GDPR Article 9, €200k for invalid consent for R&D use (including pre-ticked boxes), and €250k for keeping data longer than the stated purpose allowed. Yoti is appealing at the Audiencia Nacional. It says matching the AEPD’s view would mean offering a non-biometric login option (PIN, password, SMS or email codes) that it considers easier to share or steal. Rather than ship that version, it is pausing Spanish store distribution.

This is a GDPR case about consent, biometrics and retention. It is not a new AI Act storyline. Yoti’s CEO post also draws a useful line: the fine concerns the Digital ID app where Yoti is the controller. Age-check services Yoti runs as a processor for business clients sit outside that decision. That does not mean your stack is automatically fine. It means you need to know which product you actually use.

For Spanish shops and agencies running age-gated goods (alcohol, nicotine, adult content, or anything else that needs an age check before Black Friday), the practical question is dependency. Does your Shopify app, checkout plugin or agency integration rely on the consumer Digital ID app path, or on a separate B2B age token / facial age estimation setup? AEPD has taken a strict view that face templates used for matching can be special-category biometric data, even when the marketing story is “age estimate, not identity.” Treat that as the Spain baseline when you review vendors.

What to do this week:

  1. List every tool in checkout or onboarding that mentions Yoti.
  2. Ask the vendor (in writing) whether you are on Digital ID, processor age assurance, or both.
  3. Check the legal basis they claim for any face scan, whether a non-biometric fallback exists, and how long templates are kept.
  4. If Spanish customers need a working age gate after 10 September, confirm a documented fallback before peak traffic.

Existing Spanish users of the app are not cut off overnight. The risk for merchants is silent dependency on a download path that is about to close for new users, plus any biometric design AEPD has already rejected in this ruling.