Is it safe to send my ID for identity verification (KYC)?
It depends who's asking. Banks and regulated entities must verify your identity and usually require the full document inside their official app. The rule: verify inside the entity's app, redact whatever the process doesn't require, and mark every copy you send by email or web form.
Why they ask for it
Anti-money-laundering rules require banks, fintechs and investment platforms to verify their customers' identity (KYC, "know your customer"). It's the process with the least room for redacting.
The problem starts outside the official apps: verifications by email, third-party forms, or shady services asking for "a photo of both sides of your ID", no questions asked.
The real risk
Fake KYC checks are a direct route to identity theft: someone registers you on real services with your document. And copies emailed to legitimate services sit outside their secure verification systems.
How to send it with Ofuska
- 1
Store
Your DNI encrypted on your phone. For KYC inside an official app, use the app's own flow.
- 2
Redact
If they ask for a copy by email or form, cover only what the process doesn't require — ask which fields they verify — and send it in color if they need it.
- 3
Trace
An "Entity X — KYC — date" mosaic plus the invisible signature. If that copy ends up somewhere else, you'll know exactly which verification it came from.
In KYC: mark, don't hide
Here the law works the other way around: Law 10/2010 (anti-money-laundering) requires banks, fintechs and insurers to keep a complete copy of your document. If you cover fields, they'll reject it.
The right protection isn't hiding, it's marking: the security mosaic with the entity and the date ("Bank X KYC · date"), a black-and-white copy and the invisible signature. The copy is still valid for the verification, but it stops being useful for anything else — and if it ever leaks, you'll know which verification it came from.
Legal basis and sources
- Law 10/2010 (anti-money-laundering) — obligation to keep a complete copy of the document
Frequently asked questions
- Can a bank reject my redacted ID?
- Yes: regulated KYC checks usually require the full, legible document. In that case use the entity's official app — not email — and if you have no choice but to send a copy, at least mark it with the recipient mosaic.
- How do I know a KYC check is legitimate?
- Check that the entity is registered (Bank of Spain, or CNMV for investment), that the verification happens on their official domain or app, and distrust any KYC that arrives via a messaging link. If in doubt, send nothing.