Seems like this company got fined recently for breaching GDPR: https://www.ictrecht.nl/en/blog/leeftijdsverificatie-online-...
>The Spanish privacy regulator (hereinafter: AEPD) recently imposed a fine of €950,000 on age verification service YOTI
>For the unlawful processing of biometric personal data in violation of Article 9 of the GDPR, YOTI was fined €500,000. In addition, a fine of €200,000 was imposed for obtaining invalid consent in violation of Article 7 of the GDPR. Finally, the company was fined €250,000 for exceeding retention periods in violation of Article 5 of the GDPR