§6.1.4 Assessing the appropriateness and proportionality of any age assurance method
49. Before considering whether to put in place a specific age verification or estimation method supporting access restrictions, providers of online platforms accessible to minors should consider the following features of that method: (a) Accuracy. How accurately any given method determines the age of the user. The accuracy of an age verification or estimation method should be assessed against appropriate, clear, and publicly available metrics. These metrics are necessary to evaluate the extent to which the method can correctly determine whether a user is above or below a certain age, or a person's age range (50). Providers of online platforms should periodically review whether the technical accuracy of the method used still matches the state-of-the-art. (b) Reliability. How reliable a given method works in practice in real-world circumstances. For a method to be reliable, it should be available continuously at any time, and work in different real-world circumstances, beyond ideal lab conditions. Providers of online platforms accessible to minors should assess, before employing a specific age assurance solution, that any data relied upon as part of the age assurance process comes from a reliable source. For example, a self-signed proof of age would not be considered reliable. (c) Robustness. How easy it is to circumvent a given method. A method that is easy for minors to circumvent will not be considered robust enough and will therefore not be considered effective. Such level of ‘easiness’ shall be assessed by providers of online platforms accessible to minors on a case-by-case basis, considering the age of the minors to which the specific measures are addressed. Providers of online platforms accessible to minors should also assess whether the age assurance method provides safety and security, in line with the state-of-the-art, to ensure the integrity of the age data being processed. (d) Non-Intrusiveness. How intrusive is a given method on users’ rights. Providers of online platforms accessible to minors should periodically assess the impact the chosen method will have on recipients' rights and freedoms, including their right to privacy, data protection, and freedom of expression (51). According to the European Data Protection Board, and in line with Article 28(3) of Regulation (EU) 2022/2065 (52), a provider should only process the age-related attributes that are strictly necessary for the specific purpose and age assurance should not be used to provide additional means for providers to identify, locate, profile or track natural persons (53). If the method is more intrusive than another method that provides the same level of assurance and effectiveness, the less intrusive method should be chosen. This includes an assessment of whether the method provides full transparency about the process in line with Article 12 of Regulation (EU) 2016/679 and/or provides information about the user at risk. In no circumstances can the data processed for the purposes of ascertaining whether a user is above or below a certain age be stored or used for other purposes. (e) Non-discrimination. How a given method can discriminate against some users. Providers of online platform accessible to minors should make sure that the chosen method is appropriate and available for all minors, regardless of disability, language, ethnic, gender, religious and minority backgrounds. 50. Where age assurance measures do not achieve the criteria set out above, they cannot be deemed to be appropriate and proportionate. 51. Age assurance solutions which can be easily circumvented should not be considered as ensuring a high level of privacy, safety and security for minors. Such assessment should be conducted depending on the impact that the platform may have on the privacy, safety and security of minors. The storage of a proof of age should also depend on the risks associated with the relevant platforms. For example, adult-restricted online platforms should not allow sharing of user account credentials and thus conduct age assurance at each instance when their service is accessed. 52. The Commission considers that self-declaration (54) does not meet all the requirements above, in particular the requirement for robustness and accuracy. Therefore, it does not consider self-declaration to be an appropriate age assurance method to ensure a high level of privacy, safety, and security of minors in accordance with Article 28(1) of Regulation (EU) 2022/2065. 53. Furthermore, the Commission considers that the fact that a third party is used to carry out age assurance should be explained to minors – as in any case – in an accessible, visible way and in a child-friendly language (see Section 8.4 on Transparency). In addition, it remains the responsibility of the provider to ensure that the method used by the third party is effective, in line with the considerations set out above. This includes, for example, where the provider intends to rely on solutions provided by operating systems or device operators.
← 6.1.3.3 · All articles · 6.2 →
Source: EUR-Lex (Cellar) · retrieved 2026-09-07