§6.1.3.2 Age verification technologies
39. Age verification should be treated as a separate, distinct process that is not connected with other data collection activities exercised by online platforms. Age verification should not entitle providers of online platforms to store personal data beyond information about the user’s age group. 40. As further elaborated under Section 6.1.4, any age assurance method should be robust, thus not easily circumventable, to be considered appropriate and proportionate. A method that is easy for minors to circumvent will not be considered an effective age assurance measure. 41. Methods that rely on verified and trusted government-issued IDs, without providing the platform with additional personal data, may constitute an effective age verification method, in so far as they are based on anonymised age tokens (40). Such tokens should be issued after reliable verification of the person’s age, and they should be issued by an independent third-party rather than the provider of the online platform, especially when it offers access to adult content. The Commission considers that cryptographic protocols such as key rotation or zero-knowledge proofs (41) constitute a suitable basis for providing age assurance without transmitting personal data. 42. Member States are currently in the process of providing each of their citizens, residents and businesses an EU Digital Identity Wallet (42). The upcoming EU Digital Identity Wallets provide safe, reliable, and private means of electronic identification within the Union. Once they are deployed, they may be used to share only specific information with a service, such as that a person is over a specified age. The EU Digital Identity Wallet Once implemented, the EU Digital Identity Wallets will provide safe, reliable, and private means of electronic identification for everyone in the Union. Every Member State is required to provide at least one wallet to all its citizens, residents, and businesses, which should allow them to prove who they are, and to safely store, share and sign important digital documents by the end of 2026. All EU Digital Identity Wallets embed the opportunity to receive a token of age, and Member States can implement services to issue such tokens. 43. To facilitate age verification before the EU Digital Identity Wallets become available, the Commission is currently testing an EU age verification solution as a standalone age verification measure that respects the criteria of effectiveness of age assurance solutions outlined in Section 6.1.4. Once finalised, the EU age verification solution will provide a compliance example and a reference standard for a device-based method of age verification. Providers of online platforms that are expected to use age verification solutions for their services, are therefore encouraged to participate in available testing of early versions of the EU age verification solution, which may inform those providers as to the best means of ensuring compliance with Article 28 of Regulation (EU) 2022/2065. 44. Implementation of the reference standard (43) set by the EU age verification solution can be offered through apps published by public or private entities or integrated in the upcoming EU Digital Identity Wallets. Implementation of this standard will constitute an age verification technology that is privacy-preserving, data-minimising, non-traceable and interoperable, in compliance with the criteria of effectiveness of age assurance solutions outlined in Section 6.1.4. EU age verification solution The EU age verification solution, including an app, will be an easy-to-use age verification method that can be used to prove that a user is 18 or older (18+). The solution will bridge the gap until the EU Digital Identity Wallet is available. This solid, privacy-preserving and data minimising solution will aim to set a standard in terms of privacy and user friendliness. The EU age verification solution provides a compliance benchmark for the accuracy of an age assurance solution while minimising the impact on the rights and freedoms of the recipients. Users will be able to easily activate the app and receive the proof in several different ways. The proof only confirms if the user is 18 years or older. It does not give the precise age, nor does it include any other information about the user. The user can present the 18+ proof to the online platform in a privacy-preserving way without data flows to the proof provider. In addition, mechanisms will be put in place to prevent tracking across online platforms. The use of the app is simple. When requesting access to adult online content, the user presents the 18+ proof via the app to the online platform. Following verification of its validity, the online platform grants the user access. The user’s identity and actions are shielded from disclosure throughout the whole process. The trusted proof provider is not informed about which online services the user seeks to access with the 18+ proof. Likewise, 18+ online service providers do not receive the identity of the user requesting access, only a proof that the user is 18 or older. The EU age verification solution will also be technically capable of providing other attributes, such as liveness tests. In countries where valid methods for attestations of ages below 18 years are supported, the EU age verification solution can also provide for age verification below the age of 18. 45. Providers of online platforms accessible to minors may use other age verification methods to ensure a high level of privacy, safety, and security of minors, provided that they are compatible with the EU reference standard (as described in paragraphs 43 and 44 above) and meet the criteria outlined in Section 6.1.4. The EU age verification solution is an example of a method meeting those criteria. 46. To ensure compliance with the principles of data minimisation, purpose limitation, and user trust, providers of online platforms are encouraged to adopt double-blind age verification methods. A double-blind method ensures that (i) the online platform does not receive additional means to identify the user and, instead only receives information allowing it to confirm whether they meet the required age threshold and that (ii) the age verification provider does not obtain knowledge of the services for which the proof of age is used. Such methods may rely on local device processing, anonymised cryptographic tokens, or zero-knowledge proofs (44).
← 6.1.3.1 · All articles · 6.1.3.3 →
Source: EUR-Lex (Cellar) · retrieved 2026-09-07