Mitigating risk to rights with age verification: Privacy-preserving guardrails that should accompany deployments of age verification approaches
Around the world, age verification tools are popping up more and more frequently. In the UK, in the aftermath of the enactment of the Online Safety Act, users have been required to to submit identity documents or have their faces scanned to access not just adult-content providers and even certain other online content on services ranging from Spotify to Discord. In the U.S. age verification requirements are spreading rapidly, with states passing laws like Mississippi’s Walker Montgomery Protecting Children Online Act, Louisiana’s Act 440, and Montana’s Senate Bill 544, all mandating age verification of all users in order to restrict minors from accessing anything from adult content to social media services in their entirety. After the Supreme Court’s worrying ruling inFree Speech Coalition v. Paxton (FSC v. Paxton), a case examining whether Texas could require age verification to access content “obscene as to minors”, age verification may become a more permanent fixture in our everyday lives.
Age verification raises significant concerns for users’ privacy and free expression rights. First, requiring users to prove their age to access content or services leads to more data collection and retention by already data-rich services. Just as importantly, users forced to hand over identity information lose the ability to access the web anonymously when they have to provide proof of age documents or other identity-revealing information beforehand. People go online to access — and speak about— all sorts of sensitive topics such as their health status, sexuality, religious or political views, whistleblowing, and experiences with domestic violence. Users often want to access and share this information privately. Because removing minors’ ability to communicate or access content that may be deemed age-inappropriate requires sorting minors from adults, all users’ ability to surf the web privately and speak freely goes away. This is likely to create chilling effects for many users who are reluctant to seek out sensitive and important information to which they don’t want to be publicly linked.
Given these and other foreseeable harmful consequences, some services may decide to avoid providing service in jurisdictions with particularly invasive age verification mandates. Indeed, Bluesky no longer offers service in Mississippi for this reason — a “significant blow” for Mississippians. Other services, too, have stopped offering service to Mississippi residents, ranging from PornHub, an adult-content website, to Dreamwidth, an open source online journal and blogging community. These jurisdiction-by-jurisdiction decisions lead to increased fragmentation of the web, harming users who can no longer access the information or other capabilities the service offers.
The way all users access the web and online services is changing fundamentally. This blog post walks through alternative approaches online services can employ to protect minors online, as well as to mitigate risks to users’ rights when faced with mandates to deploy age assurance mechanisms.
Companies’ first choice should be easy-to-use and privacy-preserving approaches to protecting children, avoiding service-side data collection.
Age verification schemes often rest on the premise that there is consensus on the nature of content or services that young users must be restricted from accessing. But this consensus doesn’t exist. Moreover, there is no one-size fits all system for protecting children in online spaces. Parents themselves believe that young people of the same age can differ significantly in their levels of maturity, experience, and other characteristics. Content or a service may be appropriate for one child and harmful to another of the same age. Thus, even correctly identifying a user’s age range does not ensure a provider can determine the suitable content or experience for them.
All users — particularly young people and their parents — should have tools and safety-by-design features that they can use to proactively select the kinds of content they want, fitting the needs of users of all ages without harming their rights.
For example, client and device-side tools can take advantage of existing labeling and signalling standards. These tools allow parents who wish to prevent their children from accessing adult websites (or any user who wishes to limit access to certain types of content) can use existing technical methods to do so. Labeling is a method which adult content sites already employ — and are incentivized to employ — where they label themselves as “adults-only” via metadata. This lets users filter out those sites proactively using their browser or a third-party tool. (Parental controls can and do also use other sources of metadata, including AI-based heuristics, to categorize and filter content.) Signaling approaches let parents and other users configure their devices or software to indicate a preference for age-appropriate content, just as some services offer users a “safe mode” version today. Apple’s Declared Age Range API and California’s Digital Age Assurance Act (AB 1043) both envision such an approach, where devices are configured to voluntarily provide age range signals set by users or their parents to installed applications, which can customize content and features to be age-appropriate.
Labeling and signaling interventions enable user control with fewer privacy and security risks. These approaches minimize service-side data collection and also provide dynamic, nuanced control for parents and families. Policymakers should incentivize the use of these rights-respecting and more cost-effective approaches, including by investing in research and development in standards-setting arenas.
If companies are forced to use invasive methods to verify age, they should implement strong guardrails to mitigate risks to user rights.
Online safety proposals often require or incentivize the use of invasive age verification mechanisms without sufficient safeguards to govern the secondary use, retention, and third-party sharing of this data. Age verification approaches often require platforms to collect hard identifiers of age (such as government ID) or biometric data from all users as a prerequisite to access the service. This opens the door for vast data collection and retention from users and risks linking users’ identity to their online activity, which itself can be incredibly sensitive. Platforms should resist using these methods to the extent possible, but at times, they are left with impossible tradeoffs: comply with laws and undermine users’ rights; leave the jurisdiction and abandon users there; or evade compliance and face punitive and even existential penalties (an understandably unlikely choice).
If companies are to comply with these requirements that put users’ rights and safety at risk, they should do so with the highest level of guardrails in place to mitigate risks where possible. They should employ rights-protective criteria by ensuring that deployments of age verification are:
proportional and narrowly tailored;
reliant on high quality sources of data to ensure context-dependent accurate verification;
nondiscriminatory and uniformly accessible to all;
private and secure, meaning
unlinkable
data-minimized
limited-retention
purpose-restricted
securely implemented and
not shared or distributed;
transparent; and
accountable and remediable.
Age verification approaches should be proportional and narrowly tailored to the harm they seek to minimize. This means mixed-audience services should evaluate the burden to all users, including adults, and implement age verification measures as narrowly as possible. For example, if an age verification mandate applies to adult content and only some content on a site falls in that category, the site should apply age gates only to access the adult content rather than the entire site.
Companies should rely on high quality sources of data to verify age and ensure accurate verification. The data collected by age assurance providers should vary by context. For example, some providers may already have relevant data about users and need to collect little additional information to verify age; others will have no information. The appropriate degree of accuracy may also vary by the particular risks that verification is intended to protect against. For example, a dating site through which users routinely arrange meet ups in the real world may require greater accuracy than a site in which a small portion of the content includes nudity.
Additionally, these approaches should be nondiscriminatory and uniformly accessible as demonstrated by periodic audits and pre- and post-deployment testing. User control tools and age verification approaches should be uniformly and consistently available and compatible with different devices and operating systems. This includes ensuring that mechanisms work with parity for all users regardless of their language, age, race, gender, or nationality. Furthermore, it is particularly important that age verification mechanisms are accessible to people with disabilities, including people who are blind or low-vision, and comply with accessibility standards enshrined within relevant disability rights statutes, including, but not limited to, the Americans with Disabilities Act and the EU Accessibility Act.
Companies should adhere to clear privacy and security limits to restrict the use, sharing, and retention of the data collected. Age-related data is not only sensitive but also lucrative, making services that collect and store it attractive to malicious hackers. Information pertaining to a person’s age, date of birth, home address and birthplace, as well as biometric data, is either immutable or difficult to change and therefore particularly sensitive. In the event of identity theft or improper access, the consequences can be devastating and difficult to address.
Specific data protections should include:
limiting the collection, sharing, and retention of age-related data for anything other than verifying age;
preventing any further use of data collected for mandatory age verification;
minimizing or entirely preventing linkability between where users provided age-related data and the issuer of that data — e.g., ensuring that the the entity verifying age should not disclose to the issuer of the ID (for example: a state DMV) which sites the user is accessing;
declining to collect or store any information not needed to to determine the user’s age or age range (e.g., if a user provides an id, the verifier should not collect information such as a social security number or driver’s license number);
limiting retention and deleting data promptly; and
implementing cybersecurity measures (e.g., encrypting data in transit and storage) to prevent malicious access to or uses of age-related data.
Linking IDs (and all of the information on them) to users’ online behavior creates a massive cyber-security and privacy risk. Moreover, the mere spectre of linkability and greater data collection will chill users’ inclination to access constitutionally-protected speech, a phenomenon demonstrated in the states where age verification laws are already in place.
Entities engaged in age verification should delete underlying proof of age data, such as scans or images of government ID, after the verifier determines the user’s age or age range. Data that is present on proof of age documents, such as place of birth, date of birth, and more, are sensitive and difficult to change; prolonged retention of age-related data or ID-data makes users vulnerable to identity theft and misuse of their personal data. There is no reason for age verification providers to retain this data given its sensitivity. It also opens up companies as targets of malicious attacks by actors seeking to access sensitive data for profit or abuse. Just this week, Discord disclosed that it was subject to a data breach, in which part of the data that was inappropriately accessed by an unauthorized third party was users’ IDs provided to Discord as part of the company’s process to appeal incorrect age estimations made by the platform’s age assurance process. And last year, a leading age verification provider was hacked, allowing users’ names, drivers’ licenses and nationality to be made available to others on the internet.
The impact of data breaches can be profound, forcing victims to shut down or secure bank accounts or acquire new IDs to thwart or rectify identity theft. Deleting underlying age proof data immediately after verifying age can help verifiers minimize data breaches and inappropriate access to data and protect users. Some age verification providers have promised to delete underlying proof of age data (such as a face scan) 7 days after collecting it to comply with some laws. Verifiers should also prefer tokenized age proof systems when available, so that they never receive the underlying documentation, just an attested proof of age.
Any age verification approach should offer users clear transparency and disclosure on the method used, what data is collected and stored, and with whom data is shared. Furthermore, users should know who is operating the age verification system and how to meaningfully request deletion of data and remedy inaccurate age classification if and when it occurs. This includes instances where users have already opted into age verification but change their mind at a later point and seek to delete their account and the data that was used to verify or assign them an age.
These criteria match or overlap to some degree with principles set by international regulators in Europe and beyond. Already, some investigations are revealing popular age verification providers who are not meeting commitments to privacy set by regulators. For example, an evaluation by AI Forensics of France’s AgeGO, an age verification provider gating youth access to adult content, found that the provider did not adequately mitigate risks to user privacy or meet accuracy, transparency, and other set criteria by ARCOM, France’s independent administrative agency.
Platforms and governments can do more to enshrine these protections in law and company policy. By holding age verification providers to these more rights-respecting criteria, we can minimize the degree to which deployments of age verification undermine user rights.
Not All Guardrails Are Created Equal: Comparing Content Safety and Copyright Filtering
As courts and policymakers work through questions about chatbot liability, they should be wary of analogies that flatten meaningful technical differences. Copyright filtering and safety intervention share real challenges around ambiguity and evasion, but they diverge in what each control must assess, how each manifests over the course of a conversation, and how much can be verified from the outside.
Op-Ed: France’s Constitutional Council Ruling Tests the Limits of Social Media Bans
Read our analysis the legal and policy significance of the Constitutional Council’s decision on ongoing social media age restriction and age assurance debates ahead of the most-anticipated EU-wide approach on child online safety due by December 2026.
The brief explains that Section 230’s liability protections are essential to enable free expression online and they extend to the use of automated systems to engage to rank and order content as part of traditional publishing activities.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.