Bizum Digital ID: How It Works and What Businesses Must Review
What Bizum Digital ID does and the data, legal-basis, security and retention checks a business needs before integration.
Bizum Digital ID lets a user register or sign in to a website or app with a mobile number and confirmation in the banking app. It is not a payment and should not be presented as a universal public identity credential: it is an authentication service whose availability, attributes and terms depend on the integration offered by Bizum and the relevant bank.
What the business actually receives
Bizum says users can authorise the data needed for registration or access and can review or withdraw permissions. The integrating business must confirm in the technical and contractual documents which attributes it receives, who discloses them, how long they are kept and what withdrawal changes. It should not infer that it receives financial data or identity evidence suitable for every regulatory purpose.
Bank authentication does not remove the company's duties
When a company uses the data to create an account, deliver a service, prevent fraud or retain an access history, it processes personal data. The roles of the merchant, bank, Bizum and technical suppliers follow their actual purposes and means; they are not settled by a generic processor label or blanket consent.
Pre-integration checklist
- Map the flow: data requested, received, stored, shared and deleted.
- Define purpose and legal basis: separate account creation, authentication, contract performance, security and optional uses.
- Update privacy information: identify actors, data, purposes, retention, rights and any transfers.
- Minimise: request only the attributes required for each use case.
- Review contracts and suppliers: document roles, instructions, security, incidents, subprocessors and deletion or return.
- Design security and recovery: protect sessions and accounts, retain proportionate logs and offer a secure fallback method.
- Set retention: distinguish account data from technical or security records.
- Assess risk: using Bizum does not automatically require a DPIA; one is required where the planned processing is likely to create high risk.
Practical decision
Before activation, the company should be able to state in writing which problem the integration solves, which data enters its systems, why it is used and when it is deleted. NRRO can review the flow, contracts and legal notices for an identified integration; technical and security validation must be coordinated with the responsible provider.
Official sources
Reviewed on 26 August 2026. Allocation of responsibility requires the actual integration and contracts to be reviewed.
Practical next step
Apply this information to your situation
Review the relevant service or tell us about the facts before making a tax, legal or business decision.
Tags
2 sources
Documentary sources
References recorded for this publication. Check the current version and date before making a decision.