Why Yoti Was Pulled From Spanish App Stores

Yoti, one of the most widely used age assurance and identity verification apps in Europe, is disappearing from Spanish app stores. There was no data breach behind the move, and no failure in the technology itself. Instead, a Spanish regulator's interpretation of a single GDPR article made the product legally unshippable in that country. For a service that many websites and apps relied on to confirm a user's age before granting access to restricted content, that regulatory reading was enough to force a market exit almost overnight.

This is not a story about hackers or leaked databases. It is a story about how fragile the legal footing under age verification services can be, and how quickly a compliant, functioning product can become unusable simply because one jurisdiction changes its mind about how a privacy law applies. That fragility is exactly what makes this case worth paying attention to, even if you have never heard of Yoti before today.

What Happens to Identity Data When an Age-Check Vendor Exits a Market

Here is the uncomfortable part. Every person who verified their age through Yoti to access a website, app, or online service did so by handing over some form of identity data, often a scanned ID document, a selfie, or both. That data did not stay with the website the user was trying to access. It was routed through Yoti's systems and stored there, because that is how third-party age assurance works: the vendor becomes the holder of the verification record, not the platform requesting it.

When a vendor like Yoti is forced out of a country, the legal argument for removing the app from stores is comparatively simple. The harder question is what happens to the identity records already collected from users in that market. Does the data get deleted? Migrated to another entity? Left in storage while the company sorts out its regulatory status elsewhere? For the people whose ID documents are sitting in that database, there is often no clear, immediate answer, and very little visibility into which outcome actually occurs. The verified user base effectively becomes orphaned, sitting in a vendor's infrastructure that is no longer operating in the country where the data was originally collected.

GDPR Data Portability Rights and Their Limits in Practice

GDPR gives individuals a right to data portability and, in many cases, a right to request deletion of their personal data. On paper, that sounds like a safety net for exactly this situation. In practice, portability and deletion rights depend on the data subject knowing where their data is, understanding which company legally controls it after a market exit, and successfully submitting a request that gets honored on a reasonable timeline.

Most users who verified their age through a third-party app never expected to need any of that. They were not told, at the moment of verification, that the vendor's ability to operate in their country could change with a single regulatory decision. When that happens, the theoretical right to request your data back or have it deleted collides with the practical reality that most people do not track which vendors hold their identity documents, or how to reach them once the vendor's app is no longer even available for download in their region.

How Age Verification Mandates Are Pushing Users Toward VPNs

Episodes like this are part of why age verification mandates keep generating friction between regulators, platforms, and users. Laws requiring ID checks before accessing certain content have already sparked pushback in multiple jurisdictions, including efforts in the United States where some lawmakers want to ban VPNs specifically to prevent people from using them to sidestep age verification requirements. That legislative reaction is itself a signal that a meaningful number of users would rather route around identity checks entirely than hand documents to a third-party verification vendor, especially one whose long-term data handling practices and market stability are impossible to guarantee in advance.

The broader pattern is familiar to anyone who has watched governments tighten control over what citizens can access online. Just as expanding internet restrictions have made VPNs more essential for people trying to preserve normal access to the web, age verification mandates are nudging privacy-conscious users toward tools that avoid centralized identity checkpoints in the first place.

What This Means For You

If you have ever completed an age check that required uploading a government ID or taking a selfie for facial matching, that data lives in a vendor's database, not on the website you were trying to visit. The Yoti case in Spain demonstrates that these vendors can lose their legal standing in a given country for reasons that have nothing to do with security failures, yet your previously submitted identity data does not automatically disappear when that happens. The core age verification vendor data risk is not that the company will be hacked. It is that the arrangement between you, the platform, and the vendor was never built with a clear, guaranteed process for what happens to your data when that arrangement ends.

Takeaways for Protecting Your Identity Data

Before submitting ID documents to any age verification service, check whether the vendor publishes a clear data retention and deletion policy, and confirm how long your data is stored after verification is complete. Where possible, favor services that use privacy-preserving age estimation methods that do not require storing a copy of your government ID at all. If you already verified your age through a service that has since faced regulatory action in your country, consider submitting a formal data deletion request under applicable privacy law rather than assuming the data was automatically purged. And if avoiding centralized ID collection matters to you, understand that the same regulatory pressure driving mandates like these is also fueling pushback against privacy tools that let users bypass such checks altogether, so know your local rules before relying on any workaround.