Spanish data protection authorities are cracking down on companies that request photocopies or photos of the national ID card without a valid reason. Unnecessary collection of DNI data can lead to fines of up to €100,000 and exposes individuals to identity theft risks.
When a courier, shop, or private company asks to photocopy or photograph your Documento Nacional de Identidad (DNI), the request may be more than just an inconvenience—it could be illegal. Spain’s data protection watchdog, the Agencia Española de Protección de Datos (AEPD), has issued a clear warning: demanding copies of the DNI without a solid legal or practical justification can violate privacy laws and result in significant financial penalties.
The DNI remains the primary means of proving identity in Spain. It is mandatory for residents over 14 and must be shown to authorities when requested. However, the AEPD stresses that showing your ID is not the same as allowing a business to keep a copy. According to the agency, companies should only process or store DNI data if a specific law requires it or if there is a proportionate, well-founded reason. Collecting more information than necessary—such as keeping a full copy of the document—can be considered excessive and unlawful.
Legal Boundaries
Spanish law is clear: unless there is a regulation or a justified need, companies cannot routinely demand copies of your DNI. For most administrative procedures, simply presenting the document is enough. Only in cases where there is reasonable doubt about a person’s identity may a business request additional information, and even then, the request must be limited to what is strictly necessary.
The AEPD highlights that, for exercising rights like access, rectification, or deletion of personal data, a copy of the DNI is generally not required. The agency’s guidance aims to prevent the misuse of sensitive personal information, which can lead to identity theft or other forms of fraud.
High-Profile Fines
One of the most notable cases involved the telecommunications company Orange. The AEPD fined Orange €100,000 for violating Article 5.1.c of the General Data Protection Regulation (GDPR), which enshrines the principle of data minimization. The company had required customers to photograph both sides of their DNI to receive packages—a measure the agency deemed excessive. Although the National Court later reduced the fine to €40,000, it upheld the core finding: keeping full images of the DNI was not justified for simple identity verification.
This case set a precedent, making it clear that fines for such violations can be substantial, though not always automatic or identical in every situation. The key factor is whether the company’s actions are proportionate to the legitimate purpose of identification.
What to Do If Asked for a Copy
If a business requests a photocopy or photo of your DNI, you have the right to ask why it is needed, how long the data will be stored, and what legal basis supports the request. Habit or convenience is not enough—if there are less intrusive ways to confirm your identity, such as simply showing the document or verifying specific details, those should be used instead.
The AEPD encourages individuals to challenge unnecessary requests and reminds companies that failing to comply with data protection rules can have serious consequences. As digital security and privacy concerns grow, the risks of mishandling personal data are increasingly in the spotlight. For example, the importance of robust systems to protect sensitive information is also highlighted in other areas, such as the need for coastal alert systems in Spain, as discussed in recent coverage of Mediterranean tsunami risks.
Ultimately, the message from Spain’s data protection authorities is clear: companies must respect the boundaries of privacy law, and individuals should remain vigilant about how their personal information is handled.