Skip to content

Is it safe to send my ID for identity verification (KYC)?

It depends who's asking. Banks and regulated entities must verify your identity and usually require the full document inside their official app. The rule: verify inside the entity's app, redact whatever the process doesn't require, and mark every copy you send by email or web form.

Why they ask for it

Anti-money-laundering rules require banks, fintechs and investment platforms to verify their customers' identity (KYC, "know your customer"). It's the process with the least room for redacting.

The problem starts outside the official apps: verifications by email, third-party forms, or shady services asking for "a photo of both sides of your ID", no questions asked.

The real risk

Fake KYC checks are a direct route to identity theft: someone registers you on real services with your document. And copies emailed to legitimate services sit outside their secure verification systems.

How to send it with Ofuska

  1. 1

    Store

    Your DNI encrypted on your phone. For KYC inside an official app, use the app's own flow.

  2. 2

    Redact

    If they ask for a copy by email or form, cover only what the process doesn't require — ask which fields they verify — and send it in color if they need it.

  3. 3

    Trace

    An "Entity X — KYC — date" mosaic plus the invisible signature. If that copy ends up somewhere else, you'll know exactly which verification it came from.

Police tips →
DNI copy marked with an entity's name for a KYC verification

In KYC: mark, don't hide

Here the law works the other way around: Law 10/2010 (anti-money-laundering) requires banks, fintechs and insurers to keep a complete copy of your document. If you cover fields, they'll reject it.

The right protection isn't hiding, it's marking: the security mosaic with the entity and the date ("Bank X KYC · date"), a black-and-white copy and the invisible signature. The copy is still valid for the verification, but it stops being useful for anything else — and if it ever leaks, you'll know which verification it came from.

Legal basis and sources

  • Law 10/2010 (anti-money-laundering) — obligation to keep a complete copy of the document
Glossary: MRZ, CAN, CIP and other terms →

Frequently asked questions

Can a bank reject my redacted ID?
Yes: regulated KYC checks usually require the full, legible document. In that case use the entity's official app — not email — and if you have no choice but to send a copy, at least mark it with the recipient mosaic.
How do I know a KYC check is legitimate?
Check that the entity is registered (Bank of Spain, or CNMV for investment), that the verification happens on their official domain or app, and distrust any KYC that arrives via a messaging link. If in doubt, send nothing.
See all use cases →

Get notified when it launches

Ofuska is coming soon to Google Play. Leave your email and we'll let you know on launch day. Nothing else.

Only to tell you about the launch. No spam, unsubscribe in one click.