Spain Ruled Stored Face Templates Unlawful, and the Defence Was Security
Spain's data protection authority has ruled that a facial template held on a provider's servers is special category data under Article 9 of the GDPR, even when it is used only to authenticate the person it belongs to. The Agencia Española de Protección de Datos issued a total of €950,000 in penalties across three separate breaches. The provider, the British identity company Yoti, is contesting the decision before the Audiencia Nacional and withdrew its Digital ID app from Spanish app stores on 10 September 2026 rather than remove the facial step while the appeal runs.
Key takeaways
- The AEPD rejected the argument that a stored template used for one-to-one matching is authentication rather than identification. It held that such a template meets the criteria for special category data regardless.
- The penalty splits across three articles, with the largest component attaching to the biometric processing itself.
- A second finding concerned consent. Users were defaulted into having biometric material used for internal research and had to untick a box to opt out.
- The provider's defence is a security argument: replacing facial authentication with PINs, passwords or one-time codes would weaken protection for the identity documents it stores.
- Both positions can be correct at once, which is what makes the case structurally interesting.
What the regulator decided
The investigation opened on 12 December 2023 and the resolution was published on 10 March 2026. The penalties break down as follows.
| Breach | Article | Penalty |
|---|---|---|
| Unlawful processing of biometric special category data | Article 9 | €500,000 |
| Invalid consent | Article 7 | €200,000 |
| Excessive retention | Article 5(1)(e) | €250,000 |
The Article 9 finding is the one with consequences beyond this company. The provider argued that its facial templates serve authentication rather than identification, a distinction that has historically been used to keep one-to-one matching outside the special category regime. The AEPD did not accept it. In its reading, a template stored on the controller's infrastructure and capable of one-to-one matching during account operations satisfies the criteria for special category status on its own terms, whatever the stated purpose.
The retention finding is more conventional but no less pointed. Geolocation data was held for five years, which the authority treated as excessive against the purposes claimed for it.
The consent finding is the uncomfortable one
Users were defaulted into permitting their biometric material to be used for internal research and algorithm improvement. That material included facial images, video recordings and ethnicity estimates derived from the Fitzpatrick skin tone scale. Opting out required actively unticking a box.
Article 7 requires affirmative opt-in for special category data. A pre-ticked box has not met that standard for some years. The detail worth sitting with is not the mechanism but what was inside it: a dataset of faces and inferred ethnicity, assembled from people who came to the service to prove their age.
The defence deserves to be taken seriously
The company's position is not that the data is harmless. It is that the alternatives are worse. PINs, passwords and one-time codes sent by SMS or email can be shared, stolen or intercepted. Facial authentication binds account recovery to the person rather than to a secret they might lose or hand over. If the app holds a user's identity documents, weakening the lock on that vault has real consequences for the people inside it.
That is a coherent security argument, and it is why the company chose to leave the market rather than ship a version with the facial step removed.
Why both sides can be right
The regulator is applying the law to the data that exists. The provider is defending the mechanism that protects it. Neither is being unreasonable, and the deadlock is not really about biometrics.
It is about the vault. The security argument only becomes necessary because the service holds a store of identity documents that has to be defended. Once that store exists, something strong has to guard it, and anything strong enough will be a biometric, and any biometric held on the provider's servers is now, at least in Spain, special category data carrying a retention obligation the provider cannot easily discharge.
The alternative is not a better lock. It is not having the vault. In an issuer, holder and verifier model, the credential sits with the person rather than in a provider's store, and the recovery problem changes shape because there is no central archive whose compromise would be catastrophic. That does not make the engineering trivial, and device loss remains a genuinely hard problem. It does remove the specific bind this case describes.
What it means for the identity industry
The precedent to watch is the Article 9 reasoning rather than the size of the fine. If a stored template used for one-to-one matching is special category data irrespective of purpose, then a large share of the authentication designs currently in production across European consumer identity services are exposed to the same analysis, and the authentication-not-identification distinction that many of them rely on becomes considerably less load-bearing. Other supervisory authorities are not bound by the AEPD, and the Audiencia Nacional may yet take a different view. But firms holding facial templates on their own infrastructure now have a concrete reason to ask whether the architecture that made those templates necessary is the thing that actually needs revisiting.
Frequently asked questions
What did Spain's AEPD decide about stored facial templates?
It held that a facial template stored on a provider's servers and capable of one-to-one matching during account operations is biometric special category data under Article 9 of the GDPR, rejecting the argument that using it for authentication rather than identification places it outside that regime.
How was the €950,000 penalty divided?
€500,000 for unlawful processing of biometric special category data under Article 9, €200,000 for invalid consent under Article 7, and €250,000 for excessive retention under Article 5(1)(e). The resolution was published on 10 March 2026 following an investigation opened in December 2023.
Why does the authentication versus identification distinction matter?
One-to-one matching confirms that a person is who they previously claimed to be. One-to-many matching searches a population to determine identity. Providers have often argued the former is lower risk and outside Article 9. The AEPD's position is that a stored template capable of matching meets the special category criteria on its own terms, whatever it is used for.
What was the consent violation?
Users were defaulted into allowing biometric material, including facial images, video recordings and ethnicity estimates derived from the Fitzpatrick skin tone scale, to be used for internal research and algorithm improvement. Opting out required unticking a box. GDPR requires affirmative opt-in for special category data, which a pre-ticked box does not provide.
Does this ruling apply outside Spain?
Not directly. The AEPD's resolution binds in Spain and is under appeal before the Audiencia Nacional. Other European supervisory authorities are not obliged to follow it. Its significance is as a reasoned position on a question that has not been settled elsewhere, which makes it likely to be cited in future cases.
Related reading
- Biometric data retention is a liability
- Why biometrics alone are no longer enough
- The case against storing documents
Sources: Agencia Española de Protección de Datos resolution, 10 March 2026; company statement on market withdrawal, 3 September 2026; Biometric Update and MLex reporting, March and September 2026.




.png)