Skip to content

The Spanish National Police's advice for sharing your ID

The Spanish National Police recommends never sending a faithful copy of your DNI (Spanish national ID): limit the visible data, turn the copy black and white, write the purpose and the date on the image, and add watermarks. Here are the six recommendations — and how Ofuska automates them. The guidance is Spanish, but the principles apply to any identity document.

Source: recommendations published by the Spanish National Police and cybersecurity experts (2024) on how to share your ID document.

  1. 1 Hide the data that isn't needed

    Cross out or pixelate everything the process doesn't need: signature, support number, date of birth or the MRZ (the lines on the back).

    With Ofuska: The editor gives you a brush, rectangles, pixelation and blur, plus preset quick zones per document type to cover it all in one tap.

  2. 2 Send the copy in black and white

    A black-and-white copy is harder to reuse in verifications that expect the document in color.

    With Ofuska: One checkbox when you generate the copy. Done.

  3. 3 Write the purpose and the date on the image

    If the copy says what it's for and who it's for, it can't be used for a different process.

    With Ofuska: The security mosaic repeats the recipient and the date diagonally across the whole image, without covering the data that is actually needed.

  4. 4 Add a watermark

    A visible mark deters; an invisible one lets you trace the copy if it leaks.

    With Ofuska: Every copy carries the visible mosaic plus an invisible signature (steganography) unique to each recipient.

  5. 5 Store and send the document encrypted

    An unprotected gallery or a badly configured cloud leaks documents more often than any hacker.

    With Ofuska: Your documents live encrypted with AES-256 on your phone, behind PIN and fingerprint. The optional Google Drive backup is zero-knowledge: not even Google can read it.

  6. 6 Track the recipient and ask for deletion afterwards

    Note down who you gave each copy to and ask them to delete it once the process is over.

    With Ofuska: Your history keeps the exact photos of every send, with recipient and date. And "Verify copy" tells you which send a leaked copy came from.

All of this, inside the app

Ofuska does not just list the recommendations: it tells you what to show and what to hide for each procedure, and applies the marks for you.

Ofuska's “What to hide?” guide with the Hotel procedure selected and the show/hide lists
The per-procedure guide, inside the editor
Ofuska's safety tips screen with the most common use cases
The tips and their use cases, in Settings

Two golden rules before you cover anything

The MRZ repeats everything

The lines of characters on the back (the MRZ) repeat the number, the date of birth, the expiry date and the name. Covering a printed field while leaving the MRZ visible is covering nothing.

The CAN and the signature are almost never needed

The CAN (the 6 digits on the front) gives NFC access to the DNI's chip; the signature makes forgeries possible. Cover them by default: almost no process needs them.

Glossary: MRZ, CAN, CIP and other terms →

What to show and what to hide, process by process

Every process has its own legal basis and its own list of data. You'll find both, with their show/hide table, in each use case:

Following these recommendations by hand — editing the photo, adding marks, logging sends — takes several minutes per copy. Ofuska applies them all in three taps.

How it works →

Get notified when it launches

Ofuska is coming soon to Google Play. Leave your email and we'll let you know on launch day. Nothing else.

Only to tell you about the launch. No spam, unsubscribe in one click.