Spain kills the plastic id: your phone is now your legal passport
From 2 April, leaving home without your physical DNI is no longer a punishable oversight; it is a conscious, state-backed choice. Spain’s Policía Nacional has flipped the switch on MiDNI, an app that turns any smartphone into a biometrically sealed, fully legal identity card.
The paper cut that started a digital revolution
Hotel receptionists who used to photocopy your document in indelible black-and-white, bar bouncers who bent the laminate under UV light, traffic cops who fined you €100 for «olvido de documentación»—all of that becomes folklore overnight. The app spits out a dynamic QR that reveals only the data the moment demands: age at a club gate, full ID at a bank desk, nothing at all if you prefer a Bluetooth handshake. The Royal Decree 255/2025, quietly published last spring, quietly equated the pixelated version with the plastic one; the police tweet last Sunday simply told citizens to stop being afraid of their own law.
Behind the scenes, the Ministry of the Interior migrated the DNI’s chip logic into a sandboxed Secure Element inside Android and iOS. Result: offline verification, zero cloud storage, and a kill switch that bricks the virtual card the instant the phone is rooted or jailbroken. The forgery window that haunted Greek, French and Italian digital IDs—screenshots, PDF exports, AirDropped clones—has been welded shut.

Planes, booze and bank accounts: where it works today
Renfe ticket inspectors already scan the QR on the Madrid–Seville AVE. Ryanair gate agents at Barcelona T1 have been briefed. CaixaBank’s app will open an account in three minutes if the MiDNI handshake returns a green tick. Even the gruff mom-and-pop tabacos that still sell €1.30 stamps have a 50-euro contactless reader that blinks «ID OK» when you buy your weekend bonoloto.
What you cannot do yet: cross a border. The ICAO travel standard still demands the physical chip for e-gates. And online authentication—filing taxes, signing a mortgage—still routes through Cl@ve PIN, a separate war that Finance keeps fighting.

The privacy trade no one reads
Every scan logs a hash on the citizen’s device and another on the verifier’s terminal. The two match, or they don’t; no central database tallies how many beers you ordered at 3 a.m. in Salamanca. Yet the verifier does keep an anonymised hash. Aggregate that across 150,000 bars and you have a heat map of nightlife density that Big Data firms are already bidding for. Spain’s data protection agency (AEPD) green-lit the model because, technically, it is no different from the bar owner remembering your face—just far more efficient.

What happens to the plastic?
It lingers, like the 100-euro note you still tuck into your phone case for emergencies. Renewals remain every ten years; the chip embeds your fingerprint, the app does not. Lose your phone and you can freeze the virtual card in 12 seconds, but the plastic still gets you on a plane tonight. Police sources admit the next iteration—2027 at the earliest—will make the physical card optional, not mandatory. By then, the vending machine that sells you a packet of Marlboro will probably ask for a QR, not a birth certificate printed in 2005.
The countdown is on: 48 hours until Spain joins the tiny club of countries—South Korea, Denmark, Singapore—where the smartphone is the state. The rest of Europe watches, wallets half-open, wondering who scraps the paper next.