Google Play KYC verification is the identity check Google runs on the person or company behind a developer account, and in 2026 it sits at the front of onboarding in every region. This checklist walks through Play Console identity verification end to end: what developer identity verification 2026 requires for personal and organization accounts, the Google Play developer verification documents that survive review, the photo and file specifications, the submission path and realistic timelines, and the fixes for the five most common rejections.
1. What KYC verification is, and why Google tightened it in 2026
KYC stands for “know your customer”. Google’s version of it on Play is a check on the legal name, the address, and — for companies — the legal existence of the entity that publishes apps. Google’s stated reason is in its own wording: verification exists so that Google can “better understand developers and help prevent bad actors from distributing malware.” The practical consequence is that the verified identity is also the identity shown to users on your Google Play developer page, so the data you submit is not merely internal paperwork.
The 2026 rules split into two tracks, and choosing the wrong one is the most expensive mistake at registration:
- Personal account — you verify an official government identity document, and the payments profile linked to the account must be verified as well. The verification is on a natural person.
- Organization account — you additionally need a D-U-N-S number (a business identity record held by Dun & Bradstreet) plus an official organization document, typically a business registration certificate or a VAT registration certificate for the country you register in.
- Known government organizations or agencies — exempt from the D-U-N-S requirement. If you are one and Console still asks for a D-U-N-S number, the documented path is to contact Google support through the Help section in Play Console rather than inventing a company record.
The tightening is visible in the surrounding checks too: a developer email address that must be confirmed with a 6-digit code, a developer phone number that cannot be verified until the other verifications are complete, and a website verification step for organizations. Each one is a separate task in Console with its own status.
2. When verification is triggered
It is not a one-time gate on signup. In practice a Play developer account passes through identity verification in at least four situations:
- New account creation. Verification is part of account setup, and Google lets you complete it up to 60 days before your individual deadline, which is why a fresh account can look usable for weeks and then stop being able to publish anything.
- Accounts created before September 2023. Older accounts are being brought through the same identity and organization verification with valid ID and official documentation. Being a long-standing account is not an exemption.
- When account information changes. If you change your legal name, address, or organization details, Play Console flags the account for re-verification and notifies all team members; for organization accounts the flow asks for new documents validating the identity details stored with Dun & Bradstreet. Moving offices or renaming a company is therefore a compliance event, not a settings edit.
- After an account recovery or reinstatement. Access restored through an appeal typically lands you back in the verification queue, because the identity behind the account has to be reconfirmed.
One dependency worth planning around: developer phone verification cannot proceed until identity verification (plus website verification for organizations, device verification for individuals) is done. If you are handing an account to a teammate, the sequence matters.
3. What to prepare
Build the document set before you open the Console task, because the forms are single-session and a half-prepared upload is where most people lose days.
- Government identity document — passport, national ID card, or driver’s licence, depending on nationality and the document types Google accepts for your country or region. The exact acceptable list is published per country, so check the country/region document page before you photograph anything.
- Official organization document — business registration certificate, certificate of incorporation, or a VAT registration certificate that shows the legal entity name and registration number. An invoice, a letterhead, or a screenshot of a company website is not an organization document.
- D-U-N-S number — for organization accounts (with the government-agency exemption above). If your company already has a D-U-N-S record, make sure the legal name and address on it match what you are about to type into Console; mismatches are a standard rejection.
- Proof of address — requested for some countries and account types; the accepted document is specified on the same country list. Bank statement or utility bill in the account holder’s name is the usual shape.
- A payments profile — you either link an existing Google Payments profile or create a new one during registration. Personal and organization profiles have different verification requirements, and the legal name on the profile is what reviewers compare your documents against.
- Contact channels you control — a developer email that can receive the 6-digit verification code, and a developer phone number in international format. Organizations must display and verify a phone number; Korean personal accounts must provide one as well.
Prepare the identity, not the paperwork. Every one of these documents has to belong to the developer account holder. Submitting someone else’s ID or a borrowed company document is treated as identity fraud and is the fastest route to a permanent ban — there is no legitimate version of that shortcut, and no service can responsibly offer one.
4. Photo and file specs that pass review
Most first-round rejections are photographic, not substantive. The reviewer has to be able to read the document and see that it is genuine and unedited.
- All four corners in frame. A cropped document reads as a partial document. Photograph or scan the full page, including the machine-readable zone on a passport and the registry stamp on a company certificate.
- Flat, lit, unstyled. Lay it on a dark, plain surface and use daylight. Flash glare, a finger over a corner, a shadow across the name field, or a photo taken at an angle all get bounced.
- Colour, not greyscale. Colour scans and colour photos are what the flow expects; black-and-white copies hide the security features reviewers look for.
- Valid at submission. An expired passport or ID is a rejected document even if it proves who you are.
- Name consistency. The legal name you type into Play Console and the payments profile must match the document exactly — including middle names, suffixes, and the order of characters for non-Latin scripts. Where a transliteration is required, use the version printed on the document itself.
- One file per requirement. Do not reuse the same upload to satisfy two different fields, and never submit an edited or digitally retouched file. File format and size limits are shown in the upload prompt; JPEG, PNG, and PDF are the usual accepted shapes.
5. Submission path and timeline
- Sign in to Play Console and open the verification tasks on the home page. They stay visible with a status per task, so you always know which one is blocking you.
- Confirm the account type and the legal name and address that will be shown on Google Play.
- Link or create the payments profile, then upload the identity document (and for organizations, the organization document and the D-U-N-S number).
- Verify the developer email address with the 6-digit code.
- Complete the remaining checks in order: website verification for organizations, device verification for individuals, then the developer phone number.
- Submit and wait for the result, which is delivered by email and reflected in the Console task list.
On timing: Google does not publish a fixed service level for document review. In practice, straightforward personal-account uploads often come back within a few business days, while organization checks that have to be reconciled against business registers and D-U-N-S records can take noticeably longer. If you are close to a deadline, Google’s documented option is a 90-day extension request on your verification deadline — asking for it is ordinary, not an admission of a problem. Until verification clears, keep expecting publishing and payout surfaces to stay gated, and do not build a launch date on top of an unverified account.
6. The five most common rejection reasons, and the fix for each
- Photo quality. Glare, a cropped corner, or a visible screen reflection. Fix: rescan flat, in daylight, no flash, full page.
- Name mismatch. The ID says one thing, the payments profile or the account details say another (added middle name, translated first name, or a company suffix dropped). Fix: align the account and profile fields to the source document — the document is the reference, not your preferred spelling.
- Wrong document type for the country. The ID you use daily may not be on the accepted list for your registration country. Fix: work from the per-country document list before re-uploading.
- Organization document that does not prove a legal entity. Invoices, purchase orders, or a website home page cannot substitute for a registration or VAT certificate with a registry number. Fix: upload the certificate that names the legal entity and its registration number, and make sure the D-U-N-S record matches it.
- Address that cannot be validated. A PO box, a co-working address that does not accept mail, or a bank statement in a different name. Fix: use the address that appears on official records and supply the proof your country list asks for.
Two patterns sit behind a large share of these: uploading a screenshot or a PDF someone edited “to make it clearer”, and uploading documents for a person who is not the account holder. Both are detectable, and both escalate the case from a fixable document problem into an integrity problem.
7. KYC, PIN, and tax info are three different checks
They fail in different places, they are fixed in different screens, and confusing them wastes weeks.
- KYC — identity verification. Proves who the developer is. Handled in Play Console with a government identity document and, for organizations, an organization document and D-U-N-S number. Reviewed by Google Play.
- PIN — address verification. Belongs to the monetization side. Google mails a unique 6-digit PIN to your payments address; you enter it under Payments → Verification check. Until the PIN is entered, the payments surface can be held back — but re-entering a PIN never resolves an identity mismatch.
- Tax info — W-8BEN / W-9. Proves tax residency and provides the TIN. Non-US merchants submit the Certificate of Foreign Status (W-8BEN, or W-8BEN-E for entities); US-based merchants submit a W-9. It is entered in the payments profile (Play Console → Settings → Payments Settings → your country’s tax info), not in the verification task list. US reporting thresholds for a 1099-K ($20,000 gross and 200 transactions) live here too, and an incorrect TIN has a limited number of correction attempts.
The useful mental model: KYC answers “who are you”, PIN answers “does mail reach you”, tax info answers “who reports the income”. A rejection notice in one queue is not cured by editing the other two.
8. What KappS does — and what we do not promise
Our role in verification work is preparation and clean submission, not outcomes. Concretely, that means: pre-checking your document set against the country-specific accepted list before you upload, aligning the legal name and address across the identity document, the payments profile, and the account details so reviewers see one consistent entity, advising on organization documents and D-U-N-S mismatches, drafting the factual explanation when Google asks a follow-up question, and reviewing a rejection to identify which requirement actually failed before re-submitting in the correct channel.
What we will not do, and cannot do: we do not submit documents that do not belong to the account holder, we do not treat a rejection as something to talk around, and we do not promise a pass. Verification is built so that only the real identity clears it, and anyone promising otherwise is promising a ban. Where an account is genuinely short of a document, we say so up front and tell you which official route — a new registration certificate, a corrected D-U-N-S record, a fresh proof of address — actually unblocks the case.
The one-line version: KYC is a document-matching exercise — one identity, perfectly consistent across the ID, the payments profile, and the account record, submitted as clean colour images through the official Play Console flow.
Quick checklist before you upload
- Account type decided (personal vs organization) and matching the payments profile.
- Legal name, address, and entity name typed identically in every surface.
- Government ID valid, colour, all four corners, no glare.
- Organization document with a registry or VAT number uploaded.
- D-U-N-S record matching the legal name for organization accounts.
- Country-specific document list checked for accepted types.
- Developer email and phone reachable; verification order respected.
- Result timeline accepted, extension requested if the deadline is tight.
Sources
- Play Console Help — Verify your developer identity information
- Play Console Help — Required information to create a Play Console developer account
- Play Console Help — Developer verification: required documents by country and region
- Play Console Help — Keeping your developer account information up to date
- Play Console Help — Enter merchant tax information (W-9 / W-8BEN)
- AdSense Help — Address verification (PIN) overview