Use of Cl@ve by third parties: strengthening the restrictive approach of the Public Administration and its impact on digital intermediation models
The objective of this Informative Note is to present the considerations raised by the State Agency for Tax Administration ("AEAT") regarding the personal and non-transferable nature of the Cl@ve systems and the need to prevent intermediation practices or use by third parties, published last April titled "Personal Use of Cl@ve and Prevention of Unauthorized Intermediation Practices".
I. BACKGROUND FRAMEWORK
Before addressing the specific content of the statements made by the AEAT, it is worth situating its publication in the context of the current regulatory framework.
Cl@ve is a system of identification, authentication, and electronic signature established by the General Administration of the State to facilitate electronic relations of citizens with public administrations. According to Cl@ve's own definition:
It is a common platform for identification, authentication, and electronic signatures, an interoperable and horizontal system that saves public administrations the need to implement and manage their own identification and signature systems, and saves citizens the need to use different identification methods to interact electronically with the administration.
It is important to highlight that these systems are the result of the entry into force of the relevant legislation, which aims to promote digital transformation and regulate the mechanisms of identification and electronic authentication of citizens in their relations with public administrations.
In this context, Articles 9 and 10 of the LPACAP establish the different electronic identification and signature systems allowed for citizens to interact with public administrations, including Cl@ve. For its part, the eIDAS Regulation expressly recognizes the role of trust service providers, defined as those natural or legal persons who provide one or more trust services, whether qualified or unqualified.
Once clarified, it is important to note that this is not the first time that public authorities have pronounced on this issue. In fact, as early as 2022, the Ministry of Economic Affairs and Digital Transformation published the "Clarification Note on the Use of Electronic Certificates for Persons Other than the Holder or Signatory", in which it was expressly stated that:
In conclusion, it is reiterated that electronic certificates are for personal and non-transferable use, and the possibility that the holder or signatory of an electronic certificate issued in their name transfers possession and communicates their access keys to third parties is not in accordance with current legislation on trust electronic services. (emphasis added)
This position is entirely coherent with the provisions established both in the Frequently Asked Questions (FAQ) about the Cl@ve PIN and in the informational documents published by the AEAT itself and by the General Administration of the State, which repeatedly highlight its personal and non-transferable nature.
However, given that the Administration has defended this principle for years, a fundamental question arises: what new insight does the recent declaration of the AEAT bring?
II. CONTENT OF THE RECOMMENDATIONS
The AEAT's declaration should be interpreted as an explicit warning against certain business models based on acting as intermediaries in accessing public data, particularly those that rely on the user's or client's consent to operate with their credentials, replicate "practical delegation" schemes of authentication, or allow third parties to directly access personal information on online portals.
However, currently, in the context of the digitization of public services and the information sharing models of "Open Data", intermediation solutions have been developed through which the service provider acts as a technical intermediary between the citizen and the Administration, effectively carrying out the authentication process on behalf of the citizen.
Although the vast majority of these models are generally based on the user's consent and aim to simplify the user experience, the AEAT is unequivocal on this matter.
Although the AEAT's communication does not itself introduce legal prohibitions, it does consider certain practices a misuse; these should be interpreted as recommendations or administrative guidelines.
Below, we summarize the practices referred to:
- Cl@ve is a mechanism for identification, authentication, and electronic signature for personal, direct, and non-transferable use;
- third parties are not permitted to use a citizen's Cl@ve authentication mechanisms to access public administration electronic services on their behalf;
- it is considered a misuse to access services using a citizen's credentials, even if the citizen has given their consent;
- it constitutes a misuse to use technical intermediation systems that capture, reuse, or automate authentication processes, or that display or manage QR codes or similar elements through intermediary systems;
- it constitutes an improper use to store, process, or reuse passwords, one-time passwords (OTPs) and other elements intended to authenticate the citizen.
In summary, the AEAT considers any use of the Cl@ve system that involves intermediation, that is, that a third party access public administrations using a citizen's credentials, as improper use.
Ultimately, although the AEAT's criteria do not introduce an express legal prohibition, they do represent a clear tightening of the administrative interpretation regarding the use of electronic identification systems. From a practical perspective, this does not automatically invalidate existing models, but significantly increases their exposure to regulatory compliance risks, oversight, and medium-term business continuity.
Furthermore, the AEAT itself explicitly warns that it may implement the technical and organizational measures it deems necessary to protect citizens and ensure the integrity of the identification and authentication mechanisms, reinforcing the idea of a clearly restrictive approach and foreshadowing potential future limitations, through regulatory or technical developments, regarding intermediation models based on the use of third-party credentials.
Finally, it should be noted that in these systems, actions performed through Cl@ve are fully attributed to the account holder, even when a third party is involved, thereby increasing the risk associated with its shared or delegated use.