Select Page

Identity theft as an impact on rights

by | Identity Verification

The public debate around identity theft tends to focus on the financial dimension: fraud, scams and quantifiable financial loss. This framing, however, is incomplete.

When a third party takes someone’s name, image, voice or biometric data in order to act on their behalf, whether to enter into a contract, publish content or pass an identity verification process, it is not only their assets that are affected. Also at stake is a person’s ability to control how their identity is presented to others.

Under Spanish law, this ability is not protected as an autonomous right with a specific name. Instead, protection is provided through different rights, and the consequences can go far beyond an emptied bank account or an invoice for a service we never signed up for.

The inadequacy of the existing criminal offence

The Spanish Penal Code does not provide for a specific offence of digital identity theft. The closest provision is Article 401 of the Penal Code, which criminalises the usurpation of civil status and carries a prison sentence of between six months and three years.

The difficulty is that this provision is designed around the comprehensive and lasting appropriation of another person’s identity. According to established case law, its application requires a complete and sufficiently prolonged assumption of another person’s identity, with the intention of replacing them in their legal affairs.

Digital identity, however, no longer needs to be completely usurped.

Today, taking just one element may be enough: creating a fake profile, using someone else’s photographs, cloning a voice with artificial intelligence or using certain personal data to complete a digital onboarding process. Such conduct can cause real harm without necessarily falling within the traditional concept of usurpation of civil status.

Using another person’s identity document

 Article 400 bis of the Penal Code

A particularly common situation is the use of another person’s national identity document to pass a digital verification process. Article 400 bis of the Penal Code criminalises the use of an authentic identity document by someone who is not entitled to use it, by referring to the penalties applicable to the offences of document forgery under Articles 392, 393, 394, 396 and 399 of the Penal Code.

It is not, however, an autonomous offence. The Spanish Supreme Court has clarified that the provision does not turn a genuine document into a forged one, but creates a functional equivalence with document forgery in order to close a gap in criminal liability. It also requires harm to a third party, as required by the forgery offences to which it refers. The Court has applied this provision to another person’s physical identity document, such as a brother’s driving licence presented during a police check (STS 152/2026, 23 February).

Other criminal law provisions

The legal system also provides two further avenues. Article 172 ter.1.3ª of the Penal Code, within the offence of stalking, applies to anyone who, through the misuse of another person’s personal data, acquires products, enters into contracts for services or causes third parties to contact that person. However, this conduct is subject to the general requirement in paragraph 1, which requires it to be carried out persistently and repeatedly to the point of altering the victim’s normal daily life. A single, isolated use may therefore fall outside its scope.

Paragraph 5 of the same article takes a different approach. It criminalises the use, without the person’s consent, of their image to place advertisements or create fake profiles on social networks, dating sites or any other means of public dissemination, where this causes a situation of harassment, intimidation or humiliation. Unlike paragraph 1.3ª, its wording does not expressly require repetition, although it does require such a situation of harassment or intimidation to arise. In practice, this leaves some room for interpretation as to whether a single act may be sufficient.

In other words, Spanish legislation does penalise different forms of identity theft. The problem is that there is no single response to a reality that is not itself uniform.

A fragmented legal framework

The result is a fragmented framework. Depending on the circumstances, digital identity theft may fall under Article 401 of the Penal Code, Article 172 ter, Article 400 bis, fraud under Article 248 or the discovery and disclosure of secrets under Article 197 where there has been unauthorised access to data or communications.

Recourse to civil law

Where none of these provisions applies, the response may shift to the civil sphere through the Organic Law on the Civil Protection of the Right to Honour, Personal and Family Privacy and Own Image. This legislation provides civil protection against unlawful interference with these rights and covers, among other forms of conduct, the use of a person’s name, voice or image in certain circumstances.

An example of civil protection

According to legal press reports, this was the approach taken in a case involving a fake Tinder profile created using a friend’s name and photographs. The case was treated as unlawful interference with the person’s honour and own image and resulted in a civil award, rather than being considered an offence of usurpation of civil status. It is included here as an illustrative example of the type of response that may arise in practice.

The underlying issue is precisely that, when identity theft does not fit within another legal category, the legal system still faces difficulties in recognising it as an autonomous infringement of a person’s identity.

The constitutional basis: recognised rights and the value that reinforces them

The absence of a specific criminal offence for digital identity theft does not mean that the conduct is without constitutional protection.

Article 18.1 of the Spanish Constitution

Article 18.1 of the Spanish Constitution recognises three fundamental rights directly related to this issue: honour, personal and family privacy, and own image. Identity theft may affect all three where someone, without consent, uses another person’s identifying attributes to create a representation of them before third parties that does not reflect their wishes.

On this basis, certain forms of identity theft may affect recognised fundamental rights.

The constitutional value of Article 10.1

The role of Article 10.1 of the Spanish Constitution is different. It recognises human dignity and the free development of personality. Here, particular precision is needed. The Spanish Constitution does not recognise a “right to identity” by that name, with its own autonomous scope.

Article 10.1 operates as a constitutional value that informs and guides the interpretation of fundamental rights. The Constitutional Court has understood it in this way since STC 53/1985 of 11 April (FJ 8), which describes dignity as a “fundamental legal value” linked to the rights inherent to the person and to their free development. This doctrine was reaffirmed more recently in STC 81/2020 of 15 July (FJ 11).

The Constitutional Court has also linked personal identity, dignity and the free development of personality in decisions such as STC 99/2019 of 18 July (FJ 4.a), concerning the legal recognition of sex, which states that “establishing one’s own identity… places the individual in a position to develop their own personality”, and STC 67/2022 of 2 June (FJ 3.b and FJ 4), concerning discrimination in employment on grounds of gender identity, which links gender identity to “respect for human dignity (Article 10.1 of the Spanish Constitution)” and to the free development of personality.

Neither of these decisions concerns a case of digital identity theft: both deal with gender identity, not with impersonation by a third party. However, they do support the view that, in connection with the rights recognised under Article 18, personal identity forms part of an individual’s sphere of autonomy and deserves protection against certain forms of interference by third parties.

And this raises a particularly important question in the digital environment: who gets to decide how our identity is presented to others?

When a third party uses our image, voice or data to impersonate us, they are not simply using information. They are interfering with how our identity is projected to others.

AI regulation and synthetic content

Artificial intelligence has added a new dimension to the problem.

A photograph can be manipulated until it becomes difficult to distinguish from a real image. A voice can be cloned from an audio sample. A video can show a person doing or saying something they never did or said.

The problem is no longer simply that someone obtains our data. They can use it to build an increasingly convincing representation of us.

It is important to distinguish between identity itself and the attributes we use to represent it. Our name, image, voice or biometric data are elements that can be used to identify us, but they can also be copied or manipulated.

The difficult part is proving that these attributes are being used by their true owner.

The response under Article 50 of the AI Act

The European framework has already begun to respond to this reality. Article 50 of the Artificial Intelligence Act establishes specific transparency obligations for certain AI systems and content generated or manipulated using AI, including deepfakes.

In particular, Article 50 includes obligations to mark or label certain content generated or artificially manipulated, as well as information requirements in certain cases involving interaction with AI systems. The European Commission has also published specific guidance to clarify the scope of these obligations for providers and deployers.

However, it is important to understand what this regulation is intended to achieve.

Labelling does not prevent someone from creating a deepfake for fraudulent purposes, nor does it make such content lawful in itself. Its purpose is transparency: allowing people to identify certain content generated or manipulated using AI and reducing the risks of deception and manipulation.

It is an important step, but knowing that content is synthetic is not always enough to prevent identity theft.

Sometimes we need more than simply identifying that an image has been generated by AI. We need to be able to establish who is actually behind an identity.

GDPR and LOPDGDD

The legal basis for processing personal data

Identity theft often involves the processing of personal data without a valid legal basis under Article 6 of the GDPR.

In most cases, this lack of a legal basis is not merely theoretical. The person processing the data is not dealing with the genuine data subject, but acts on the assumption, or pretence, that they are. The impersonator may provide their own consent, but not that of the actual data subject, who is the person whose consent would be relevant under Article 4.11 of the GDPR.

Nor does the mere existence of an apparent contractual relationship or legitimate interest, in itself, legitimise the processing where that relationship has been built on an impersonated identity, because these Article 6 legal bases are intended for genuine relationships between the controller and the data subject.

The enhanced protection of biometric data

Where biometric data are involved, the enhanced protection under Article 9 of the GDPR also comes into play. This provision includes biometric data intended to uniquely identify a natural person among special categories of personal data, unless one of the circumstances allowing their processing applies.

Not every photograph or voice recording is, in itself, biometric data in this strict sense. To fall within this enhanced category, the processing must be technically intended for unique identification, rather than for any use of the image or voice.

Where they do qualify as biometric data, there is a fundamental difference compared with a password. If a password is compromised, we can change it; our face or our voice do not work in the same way.

For this reason, biometric data protection should not be understood solely as a privacy issue. It is also part of protecting a person’s identity.

This enhanced protection does not constitute a parallel protection of a right to identity, but rather one of the ways in which the legal system protects identifying attributes. This raises the question of who can use certain attributes belonging to a person, for what purpose and under what conditions.

The challenge is to strike a balance: using only the data necessary for a specific purpose and with appropriate security measures, without turning the technology used to protect users’ identities into a new source of risk.

Biometric verification as a prevention tool, not just a risk

There is a recurring narrative that presents the collection of biometric data solely as a privacy risk.

It is understandable that there is concern. Any processing of biometric data must be proportionate, secure and respectful of data protection principles. But focusing only on this side of the story would be incomplete.

A properly designed digital identity verification system using biometrics can help prevent someone from using a photograph, recording or synthetic content to impersonate another person.

The difference lies in what we are trying to establish. For example, a password proves that someone knows something, while a document proves that someone possesses something.

Identity verification seeks to answer a different question:

Is the person carrying out this transaction really who they claim to be?

This is where biometrics, combined with liveness detection and appropriate security and privacy measures, can become a tool for protecting identity rather than simply something that needs to be protected.

It is not simply about checking whether certain data match. It is about adding a check on the person behind those data.

In these terms, identity verification does not necessarily have to come into conflict with the rights at stake. When properly designed and applied, it can help prevent certain forms of identity theft.

It is therefore not a question of choosing between privacy and security, but of using the right technology to protect both.

Determining who the genuine identity holder is requires comparing the biometric data captured at the time with a reliable source.

In practice, this means matching that capture against a verified reference belonging to the individual, whether their identity document, an authorised database or a previously verified biometric record, rather than simply accepting the identity the person claims to have.

This makes it possible to answer, with a reasonable degree of certainty, the question of who is actually behind a transaction and to help prevent identity theft.

Two approaches compared: specific criminalisation and dynamic burden of proof

Comparative law shows that countries have not all responded to this issue in the same way. Two recent examples illustrate different approaches to identity theft: taking action against the impersonator and strengthening the obligations of the party carrying out the verification.

France and the focus on the impersonator’s unlawful conduct

France introduced a specific criminal offence as early as 2011. Article 226-4-1 of the French Penal Code criminalises the usurpation of a third party’s identity or the use of data of any kind that makes it possible to identify them, where this is done with the aim of disturbing their peace or that of another person, or harming their honour or reputation.

The difference compared with Article 401 of the Spanish Penal Code is that the French provision does not require a complete and lasting substitution of the victim’s civil status. It is enough to use identifying data together with one of the harmful purposes specified in the provision.

This makes it possible to address certain forms of identity theft that are more closely associated with the digital environment, such as fake profiles, fraudulent use of personal data or certain conduct carried out online.

Colombia and the responsibility of those in a position to determine identity theft

Statutory Law 2573 of 2026 introduces measures to protect people whose identities have been impersonated in relation to telecommunications operators, financial and credit institutions and certain commercial establishments.

Among its principles, Article 2 includes the dynamic burden of proof: the obligation to prove a claim falls on the party best placed to do so and, in cases of identity theft, telecommunications operators and financial and credit institutions must provide the information and documentation they received when approving the relevant product or service.

The law also requires these entities to adopt sufficient and reasonable digital security measures to verify the identity of their customers and, upon request, provide the claimant with the information and documentation used to approve the product or service.

The French model focuses on pursuing the conduct of the impersonator. The Colombian model, by contrast, strengthens the obligations of the party carrying out the identity verification and places the burden of proof on whoever is in the best position to provide the evidence needed to establish how the identity theft occurred.

Faced with the same problem, one puts the focus on the impersonator; the other on the party best placed to detect and establish how the impersonation took place.

What this means for digital identity

Identity theft can affect different rights and legal interests, but the Spanish legal system responds in a fragmented way because there is no autonomous and unified protection of digital identity.

From there, a question becomes increasingly relevant.

If identity can be attacked through technology, we also need technological tools such as MobbScan capable of verifying who is really behind a transaction.

Need to prevent identity theft on your platform? Our anti-fraud mechanisms can detect altered, forged or stolen identity documents, as well as presentation attacks using photos, screenshots, masks, deepfakes and content generated or manipulated with artificial intelligence.

Talk to our team →

DOSIER PRODUCTO

Descubre nuestra solución de verificación de identidad

Verifica la identidad de tus clientes en segundos a través del escaneo y validación de documentos de identidad y matching biométrico facial con prueba de vida. 

mobbeel
Cookies policy summary

We use first-party and third-party cookies to make our website work, analyse how users use the website in order to improve our services and create a profile of your browsing and content viewed in order to show you personalised advertising. Find out more by reading our Cookies policy.

Reject cookies

What is a cookie?

Cookies are files sent from a web server that obtain information from users’ devices, for example, about their preferences and browsing patterns.

Cookies are essential for the functioning of the Internet, as they offer technical solutions that allow the user to browse the different websites; they cannot damage the user’s equipment/device and can be used to identify and resolve possible errors in the functioning of the Website. They may also be used for advertising or analytical purposes.

Use of cookies by Mobbeel

Specifically, MOBBEEL uses its own cookies generated directly by this domain and third-party cookies generated from other websites outside MOBBEEL, belonging to third party companies, for the specific purposes described below. If in the future MOBBEEL uses other cookies for the purpose of providing more and better services, the user will be informed of this.