The End of Identity-First Fraud Prevention: What Europe’s Privacy Mandate Means for Your Tech Stack

By Dayana Costa, Data Protection Officer at Incognia, the leader in cross-device risk intelligence [ Join Cybersecurity Insiders ]

European regulators issued more than €1.2 billion in GDPR fines in 2025, a 22% year-over-year increase, and fraud teams are finally starting to feel the pressure. For years, the dominant assumption in fraud prevention was straightforward: collect more data on your users, build a more comprehensive picture of who they are and catch more bad actors before damage occurs. In this approach, more personal data equated with more confidence.

That approach is facing growing limitations as fraudsters find new ways to get around traditional identity verification. Regulatory pressure is forcing fraud teams to reconsider how they use identity data and whether the signals they collect are appropriate for the risks they are trying to assess. At the same time, increasingly sophisticated fraud is exposing the limitations of relying on identity data as the primary signal. As fraud evolves, teams may need to incorporate additional signals to understand whether an interaction can be trusted, while still ensuring that the data being processed is necessary and justified for that specific purpose. Having more identity data does not necessarily mean knowing more about who someone claims to be or whether they can be trusted.

GDPR Is a Forcing Function, Not a Compliance Problem

Data minimization and purpose limitation are the core principles of the GDPR. Article 5 sets that personal data must be ‘adequate, relevant and limited to what is necessary’ for the purpose it was collected. For fraud teams, that means finding ways to make better risk decisions without assuming that more personal data automatically results in a better fraud decision.

The pressure is especially relevant as fraudsters find ways to use real identity information against the systems designed to verify it. Synthetic identities can combine legitimate and fabricated information to pass identity checks, while account takeover attacks exploit credentials belonging to legitimate users.

This creates a fundamental problem: an identity can check out while the activity is still fraudulent.

Identity Alone Was Never Enough

The traditional fraud stack was built on direct identifiers, such as name, email, phone number, and government ID. The assumption was simple: verify who the person claims to be, and their risk  can be assessed. But identity verification alone can’t determine whether the activity itself is legitimate.  

But synthetic identities, which are not new, pass those checks. Mule accounts are operated by real people using real credentials. Account takeover exploits legitimate users whose identity data has already been compromised. The identity layer, it turns out, was detecting registration, not fraud.

The cost of architectural assumptions compounds in two directions: Fraud teams layered on more identity signals trying to close the gaps (more direct personal data, document verification, facial recognition and data partnerships), with each addition increasing regulatory exposure while the impact on fraud detection can vary depending on the risk. . Meanwhile, each new layer became one more step a legitimate user had to get through, and one more place for them to drop off. The industry optimized hard for a signal that was, at its core, the wrong signal

What identity-first models miss entirely is the behavioral dimension. Behavioral signals add a different layer of context: rather than focusing solely on who a person claims to be, they can help assess whether the activity itself is consistent with legitimate behavior. However, not all behavioral signals are equally effective. Some approaches require sufficient historical data to establish a reliable baseline, while others may become easier for sophisticated fraudsters to replicate

Looking beyond identity to behavioral signals is the correct instinct, but not all behavioural signals are equally useful for fraud prevention. The most effective signals should be impossible to fake at scale, support continuous verification, match the user from day one and operate without adding friction to the legitimate user experience. 

What Location Behavioral Signal Models Actually Look Like

The next layer beyond identity-first detection is anchored to a more durable signal. In addition to asking “who is this person”, the operationally useful question is “is this behavior in the physical world consistent with how this person has  behaved before?”

Location behavior adds a pattern layer: not a snapshot of where someone is, but a history of where they’ve consistently been. This context surfaces anomalies that credentials alone would never catch: the account accessed from three countries in six hours, the cluster of new registrations all resolving to the same physical place, the transaction initiated from an environment never previously associated with that account. None of this asks the legitimate user to do anything. No extra prompt, no second factor, no step-up. The system gets more confident the more normally someone uses the product, not less.

The model earns its keep precisely against the fraud types that identity verification handles the worst. Account takeover is caught because the device, location, and behavioral pattern diverge from the account’s history, regardless of whether the attacker holds valid credentials. Mule account handovers surface as abrupt behavioral discontinuities: same credentials, completely different usage behavior. Fake account creation at scale is detectable because fraud rings, however sophisticated, cannot manufacture the organic, consistent location and device history that legitimate users accumulate naturally over time.

While location behavioral signals may still constitute personal data under the GDPR, they can be processed through pseudonymous identifiers and without being directly linked to traditional identity attributes. This allows fraud systems to derive meaningful risk signals while reducing reliance on directly identifying information and limiting the amount of identity data required for the decision.

The Shift is Underway

Regulatory pressure is driving this shift, and better fraud outcomes are giving teams another reason to make the change. Fewer false positives, meaning fewer legitimate users wrongly blocked, more accurate detection against account takeover and mule account handovers, and a signal that gets stronger as behavioral history accumulates. For teams still running identity-centric models in Europe, the compliance pressure is real. As fraud evolves, those models were already losing to the fraud types they were designed to stop. Better fraud prevention is not about having more data. It is about having the right signals to make the right decision.

Join our LinkedIn group Information Security Community!

No posts to display