The Spanish national identity document (DNI) is one of the most common elements of everyday life. We present it to open an account, sign a contract or even check in at a hotel. But is it lawful for an organisation to ask for a copy of it in all those cases? According to the Spanish Data Protection Agency (AEPD), the answer is clear: not always. The same reasoning applies to the passports and residence cards of foreign residents.
Although the DNI is not among the special categories of data defined by the General Data Protection Regulation (GDPR), its contents, name, photograph, signature, identification number, date of birth, nationality and so on, make it a document with a very high load of personal information. Its use and copying are therefore subject to strict limits that many companies and organisations still ignore.
The applicable legal framework
In Spain, the issue and use of the DNI are governed by Royal Decree 255/2025 of 1 April, which defines it as a personal, non-transferable document protected like any official public document. Neither the GDPR nor Organic Law 3/2018 on the protection of personal data and digital rights (LOPDGDD) contain specific rules on copies of the DNI. The AEPD has therefore taken the leading role in setting the criteria on when a copy may be requested and kept, and when doing so amounts to disproportionate processing.
When a copy may be requested
There are cases in which the law expressly obliges companies or institutions to identify people by means of reliable documents. In those cases a copy may be justified.
Prevention of money laundering and terrorist financing. Sector legislation requires banks, notaries, lawyers and insurers to verify the identity of their clients. Even so, the rules give priority to alternative methods (electronic signature or digital authentication) and reserve the copy of the document for cases where no other viable route exists.
Registration obligations in hotels and tourist accommodation. Organic Law 4/2015 on the protection of public safety obliges tourist accommodation to record certain guest data. But the AEPD has recalled that it is not necessary to keep a copy of the document, only to record the required data (name, surname, document number and type, date of birth, nationality and so on).
In all other cases, if no rule expressly requires it, requesting or keeping a copy of the identity document constitutes excessive and unlawful processing under Article 5(1)(c) GDPR (the data minimisation principle).
When it may not be requested
A photocopy of the document is often requested for mere administrative convenience: to join a gym, make a booking, take out a service or even exercise data protection rights. The AEPD has been categorical: the collection of copies of identity documents cannot be established as a general practice. Each request must be justified case by case, with a clear legal basis, a legitimate purpose and processing proportionate to the risk. The controller must also carry out a risk analysis and document the security measures adopted under Articles 24 and 32 GDPR.
Key principles to be respected
Minimisation: only the data essential for the specific purpose may be processed. Proportionality: no more information than necessary may be collected. Security: the copy must be stored with adequate measures to prevent unauthorised access or leaks. Less invasive alternatives: visual verification, partial scanning (hiding unnecessary data) or electronic identification must be given priority.
The position of the AEPD
In its most recent decisions, the AEPD has stressed that the identity document number is particularly sensitive data, since its misuse can facilitate fraud, identity theft or unauthorised access to digital services. The Agency therefore limits the lawfulness of processing copies of the document to cases in which there is express legal authorisation. In any other scenario, the processing is considered disproportionate and unnecessary. Basing the request on the controller’s legitimate interest is, in practice, difficult to sustain: passing the balancing test between the company’s interests and the rights of the data subject is very complex when the data processed poses a high risk to privacy.
The message is clear: not everything goes when it comes to verifying identity. Organisations must carefully assess whether they really need to keep a copy of the document or whether less intrusive alternatives exist. Respecting the minimisation principle not only avoids sanctions, but strengthens trust in the responsible management of personal information.
If your document has been used without permission
The improper handing over of a copy of an identity document is frequently the first link in an identity theft. If your document has been used to open accounts, take out services or make charges, you are facing identity theft that can be prosecuted, and which is often intertwined with online fraud and other computer crimes. The first hours are decisive: the evidence must be preserved, the charges blocked and the complaint filed with the right documentation.
Foreign residents: passport, NIE and residence card
The criteria of the Data Protection Agency apply equally to the documents used by foreign residents: the passport, the NIE certificate and the residence card (TIE). All of them contain the same categories of personal data, and in the case of the passport also the signature and the nationality, so that copying them without a legal basis is just as disproportionate. In practice, foreign residents are asked for copies more often, because organisations wrongly assume that a foreign document requires more verification. The rule is the same: the organisation may check the document and record the data it needs, but may keep a copy only where a specific rule requires it, as in the case of banks and other entities subject to anti-money-laundering obligations.
How to object and where to complain
When a copy is requested without justification, the person may ask which legal rule requires it and which purpose it serves, and may offer the alternatives accepted by the Agency: showing the document, allowing a visual check or providing a partial copy with the unnecessary data masked. If the organisation insists, it is possible to file a complaint with the Spanish Data Protection Agency, which has sanctioned companies for keeping copies of identity documents without a legal basis. The General Data Protection Regulation allows fines of up to twenty million euros or four per cent of the worldwide annual turnover for breaches of the basic principles of processing, among them data minimisation.
When the copy has already been misused
Where a copy of the document has been used to open bank accounts, take out loans or telephone contracts or make purchases, the person faces a case of identity theft combined with fraud. The steps are: obtaining written confirmation from the entities involved that a contract exists in their name, requesting a copy of the documentation presented, filing a criminal complaint with the National Police or the Guardia Civil with all the evidence, and notifying the credit information files so that the debt is not attributed to them. The criminal complaint is what allows the authorities to trace who used the document and where, and it is the basis for having the fraudulent contracts declared void.
Frequently asked questions
Can a hotel in Spain keep a copy of my passport?
No. The accommodation must record the required guest data, but the AEPD has stated that it is not necessary to keep a copy of the document.
Can a gym or a shop ask for a photocopy of my ID?
Only if a legal rule expressly requires it, which is not the case for ordinary services. Otherwise the request breaches the data minimisation principle.
What should I do if my ID has been used to open accounts or take out services?
Preserve all the evidence, contact your bank to block the charges and file a criminal complaint for identity theft and fraud as soon as possible, with the support of a lawyer.
Does a hotel have to see my passport if I am a foreign guest?
Yes, the accommodation must record the data required by the public safety rules, but that obligation does not include keeping a copy of the passport.
What fines can a company face for keeping copies without a legal basis?
Under the General Data Protection Regulation, breaches of the data minimisation principle may be fined with up to twenty million euros or four per cent of worldwide annual turnover.
Related guides
- Recovering money from an online scam in Spain
- Frequently asked questions on criminal defence in Spain
- Privacy policy
Do you need a criminal defence lawyer in Alicante or Madrid now? Société Juridique provides emergency assistance and 24-hour assistance to detained persons in Alicante, Madrid and throughout Spain.
This article is informative in nature and does not constitute legal advice. For a specific case, consult a lawyer.
Francisco Javier Martín Porras
Abogado penalista, socio de Société de Conseil Juridique et Expert y creador de la metodología LIWARD®. Dirige la defensa en procedimientos penales de alta complejidad, combinando estrategia procesal con análisis pericial y forense. Conozca al equipo →

