The Spanish National Police's advice for sharing your ID
The Spanish National Police recommends never sending a faithful copy of your DNI (Spanish national ID): limit the visible data, turn the copy black and white, write the purpose and the date on the image, and add watermarks. Here are the six recommendations — and how Ofuska automates them. The guidance is Spanish, but the principles apply to any identity document.
Source: recommendations published by the Spanish National Police and cybersecurity experts (2024) on how to share your ID document.
-
1 Hide the data that isn't needed
Cross out or pixelate everything the process doesn't need: signature, support number, date of birth or the MRZ (the lines on the back).
With Ofuska: The editor gives you a brush, rectangles, pixelation and blur, plus preset quick zones per document type to cover it all in one tap.
-
2 Send the copy in black and white
A black-and-white copy is harder to reuse in verifications that expect the document in color.
With Ofuska: One checkbox when you generate the copy. Done.
-
3 Write the purpose and the date on the image
If the copy says what it's for and who it's for, it can't be used for a different process.
With Ofuska: The security mosaic repeats the recipient and the date diagonally across the whole image, without covering the data that is actually needed.
-
4 Add a watermark
A visible mark deters; an invisible one lets you trace the copy if it leaks.
With Ofuska: Every copy carries the visible mosaic plus an invisible signature (steganography) unique to each recipient.
-
5 Store and send the document encrypted
An unprotected gallery or a badly configured cloud leaks documents more often than any hacker.
With Ofuska: Your documents live encrypted with AES-256 on your phone, behind PIN and fingerprint. The optional Google Drive backup is zero-knowledge: not even Google can read it.
-
6 Track the recipient and ask for deletion afterwards
Note down who you gave each copy to and ask them to delete it once the process is over.
With Ofuska: Your history keeps the exact photos of every send, with recipient and date. And "Verify copy" tells you which send a leaked copy came from.
All of this, inside the app
Ofuska does not just list the recommendations: it tells you what to show and what to hide for each procedure, and applies the marks for you.
Two golden rules before you cover anything
The MRZ repeats everything
The lines of characters on the back (the MRZ) repeat the number, the date of birth, the expiry date and the name. Covering a printed field while leaving the MRZ visible is covering nothing.
The CAN and the signature are almost never needed
The CAN (the 6 digits on the front) gives NFC access to the DNI's chip; the signature makes forgeries possible. Cover them by default: almost no process needs them.
What to show and what to hide, process by process
Every process has its own legal basis and its own list of data. You'll find both, with their show/hide table, in each use case:
Following these recommendations by hand — editing the photo, adding marks, logging sends — takes several minutes per copy. Ofuska applies them all in three taps.
How it works →