Skip to content
Constaia

ID card copies and the Spanish DPA: verify without keeping

What Spain's data protection authority says about collecting ID card copies (PS-00138-2025), what it means for sports clubs, and how to verify without storing.

By Constaia team7 min read

Also in: Español, Português, Français

"Please upload a photo of both sides of your ID card" is almost a reflex in race registrations, club memberships and sports licences. It is convenient: the image sits in a folder and, if a question ever comes up, there it is. The problem is that this folder is exactly what the Spanish Data Protection Agency (AEPD) considers, as a general rule, excessive.

This article covers the data minimisation principle, what the AEPD decided in the Diputación de Pontevedra case, and how a club, federation or event organiser can check identity without piling up copies of documents.

The case concerns the Spanish national identity card, the DNI (Documento Nacional de Identidad), but the underlying principle comes from the GDPR and applies across the EU.

Not legal advice

This article is for general information. Every processing activity has to be assessed on its own facts: talk to your data protection officer or a lawyer before changing your processes.

The principle: adequate, relevant and limited

Article 5(1)(c) GDPR requires personal data to be "adequate, relevant and limited to what is necessary" for the purpose. That is data minimisation.

Applied to ID cards, the question is not "do I need to know who this person is?" but "do I need to keep an image of the document to know it?". An ID copy contains far more than is usually needed: photo, card serial number, signature, machine readable zone (MRZ), and on the Spanish DNI even the address and parents' names.

The case: PS-00138-2025, Diputación de Pontevedra

Resolution PS-00138-2025 (file EXP202413234) is a good example because the facts are so ordinary:

  • On 17 July 2024, a person went to a registry office of the Diputación de Pontevedra (a Spanish provincial council) to file an appeal against a fine.
  • To register the document, staff asked for the DNI to scan it, or for a photocopy, which was attached for the department handling the fine.
  • The person complained to the AEPD.

The AEPD found that the council infringed Article 5(1)(c) GDPR (data minimisation). According to the resolution, the obligation to establish identity could be met without requiring or storing a photocopy or image of the DNI: an official checking the original was enough. The council acknowledged this and, from 19 August 2025, changed its protocol: visual check of the DNI, validation in the application and a record of that confirmation.

Two details matter to avoid wrong conclusions:

  1. There was no fine. Under Article 77 of Spain's data protection act (LOPDGDD), public bodies such as local authorities receive a declaration of infringement instead of a financial penalty. A private entity, such as a club or an event company, is not covered by that regime.
  2. Corrective measures did not erase the infringement. The AEPD welcomed them but noted they do not remove liability for what had already happened.

The texts the resolution relies on

  • The EDPB Guidelines 01/2022 on the right of access (paragraphs 74 and 76): using a copy of an ID document to authenticate someone creates a risk for the security of personal data and should be considered inappropriate unless necessary, suitable and in line with national law. Data such as the photo or the machine readable zone can be blacked out when not needed.
  • The AEPD Legal Office report 0048/2023: requesting the DNI and taking a copy would, in principle, be excessive processing that cannot become systematic practice; the legal basis, risk and proportionality must be assessed case by case.

The resolution sums it up: copying the DNI should be an exceptional measure, reserved for situations where no less intrusive means exist. Commentary (in Spanish) is available from Iberley and PwC.

What this means for clubs, federations and organisers

The resolution concerns a public authority, but Article 5(1)(c) GDPR applies to every controller. If you run registrations or licences, these questions help you review your process.

1. Why do you ask for the document?

Write down the concrete purpose. "Check that the licence holder is who they claim to be", "verify age for the under-16 category" and "comply with a rule that requires identifying the participant" are different purposes needing different data. If you only need the date of birth, the full image is too much.

2. Does a rule require you to keep the copy?

The EDPB guidelines accept a full copy where national law requires it. If your federation rules or a sector regulation require it, identify exactly which provision. If you cannot find one, you probably do not need to keep the image.

3. Can you check without keeping?

At the council office, looking at the original and recording the check was enough. The online equivalent is:

  • the user uploads the document,
  • it is checked (document type, expiry, name matching the registration),
  • the result is recorded ("identity checked on day X"),
  • and the image is not kept.

4. What do you keep as evidence?

Keep the minimum that shows the check happened: date, result and who or what system performed it. You do not need the ID photo for that.

5. For how long, and who has access?

If you decide to keep something, set a retention period and restrict access. A shared folder with hundreds of scanned ID cards is a risk even if nobody ever opens it.

Minimising is not the same as not processing

Even if you do not keep the image, analysing it is processing personal data. You still need a legal basis, you still need to inform people and, if you use a provider, you need a processor agreement (Art. 28 GDPR).

How Constaia does it

Constaia is built for the "check without keeping" pattern. By default storage is "none": the file is deleted as soon as the analysis finishes. If you also send keep_results: false, the extracted fields are not stored either; only what is needed for billing remains. Processing happens in the EU (Hetzner, Mistral OCR and AWS Bedrock in eu-central-1).

Your system receives the response once and decides what to keep. To minimise, store only verdict.status, the analysis id and the date.

curl https://api.constaia.com/v1/analyze \
  -H "Authorization: Bearer $CONSTAIA_API_KEY" \
  -F file=@dni_valid.jpg \
  -F 'options={
    "expect": "es_dni",
    "checks": {
      "not_expired": true,
      "holder": { "full_name": "María García López" }
    },
    "storage": "none",
    "keep_results": false,
    "language": "en"
  }'

A few honest caveats:

  • With keep_results: false you cannot fetch the analysis later with GET /v1/analyses/{id}: whatever you do not store at that moment is gone. That is the point.
  • A review verdict means a person should look at it (low quality, insufficient confidence). Ask the user to retake the photo or check manually; you do not need to keep the image to do that.
  • Constaia is not a biometric KYC system and does not prove a document is authentic. It checks type, expiry, the NIF check letter, the MRZ and the match with the data you provide; warnings are signals, not guarantees.
  • If you need to keep the file (because a rule requires it), there are temporary and persistent modes. In that case the file is stored, encrypted, until it expires or you delete it.

More in Storage and privacy and Checks.

Summary

  • The AEPD considers that requesting and keeping ID copies should not be routine; in PS-00138-2025 it found an infringement of Article 5(1)(c) GDPR because identity could be checked without keeping the image.
  • For a club or federation, the key question is whether you need the image or only the result of the check.
  • A "check and discard" flow (analyse, record the verdict, delete the file) fits data minimisation better than a folder of scanned IDs.

If you want to try this flow, create a free account: it includes 250 credits a month and test keys that do not consume credits.

Sources

  1. 01AEPD — Resolution PS-00138-2025 (Diputación de Pontevedra), in Spanish
  2. 02AEPD — Legal Office report 0048/2023 (use of data and copies of the DNI), in Spanish
  3. 03Regulation (EU) 2016/679 (GDPR), EUR-Lex
  4. 04EDPB — Guidelines 01/2022 on data subject rights: right of access
  5. 05Iberley — The AEPD finds a provincial council infringed the GDPR by asking for a DNI copy (Spanish)
  6. 06PwC NewLaw Pulse — Proportionality when requesting a copy of the DNI (Spanish)