On International Privacy Day, the FTC Should Confront the Privacy Risks of Age Verification
Wednesday is International Privacy Day, and ironically, it’s also the day the U.S. Federal Trade Commission (FTC) is holding a workshop to explore “how to deploy age verification more widely.” According to the agenda, the FTC workshop will focus on understanding why age verification matters, how these tools work, and how to deploy these tools at scale. Yet, far from protecting anyone’s privacy, age verification tools put users’s most personal information at risk. We hope that panelists will raise and grapple with critical questions about how age verification technologies impact users and their ability to access online services freely and privately. The FTC should conduct an honest and balanced assessment, rather than putting a thumb on the scale in favor of the age verification industry
To verify or estimate who is a child, these technologies collect a great deal of data on all users, ultimately undermining users’ ability to access the web privately and freely. Many age verification tools collect government identification such as driver’s licenses or birth certificates to verify a user’s age with a high degree of certainty. Other types of age assurance tools rely on predictive models to estimate users’ ages by collecting and analyzing biometric data such as facial scans or user activity data such as keyword searches and social networks and other such imperfect proxies for age.
The harms posed by widespread use of these technologies are multifold. Requiring users to provide sensitive personally-identifying information to access online services undermines their ability to speak and access information anonymously. Users are likely to forgo participation in online spaces should they have to provide identifying information to access them. This can have chilling effects for many users, especially when they use online services to access sensitive information related to subjects such as their health, sexual preferences, experiences with intimate or domestic violence, or political views. Further, users in some jurisdictions may not want to identify themselves before they can search for abortion-related information in their region.
Further, even if they might be willing to provide identification, many people, most relevantly children, lack appropriate ID to grant themselves access to online services. Many adults too lack access to ID, including millions of people with disabilities who may face additional barriers to access driver’s licenses, people who are facing homelessness and do not have a permanent address, and others. Many users then face an impossible choice: forgo access to certain online spaces or subject themselves to more invasive data collection, often of even more sensitive information such as facial scans.
Laws that mandate the use of age verification tools often amplify the risks of these tools. Many of the state bills and laws requiring the use of age verification cover all sorts of mixed-audience services ranging from Google search to Coursera to the New York Times, meaning that a substantial portion of the internet will collect users’ ages, fundamentally changing the way everyone (not just children) accesses the internet. Increasingly, as age verification laws pop up across the nation and around the world, online services and the third party vendors they use to determine users’ ages may also be strongly incentivized to retain age-related data and the underlying proof of age indefinitely out of fear of liability. Meanwhile, data brokers will celebrate — once it’s normalized that users have to provide detailed identifying information to access any website, they’ll be happy to buy and sell info on users’ internet habits tied to their verified driver’s license and passport.
The collection of this data can make age verification intermediaries enticing targets for data breaches and malicious hacks. Age-related and biometric data is both sensitive and lucrative, making services that collect and store it attractive to malicious hackers. Requiring the widespread collection of this data is a gift to organized crime which will use this data for blackmail and extortion, as well as large scale identity theft and financial fraud. Children in particular are prime targets of this type of data theft often because they have clean records and because parents are likely to pay a premium on their behalf if faced with extortion.
Just last year, government-issued IDs of over 70,000 Discord users were leaked and inappropriately accessed when a third-party service Discord contracted with to process age estimation-related appeals faced a data breach. One age verification vendor, AU10TIX exposed the driver’s licenses, date of birth, and nationality, and other sensitive information of users across TikTok, X, and Uber due to lax security practices in 2024. And more recently, PornHub confirmed that more than 200 million records were exposed including users’ email addresses and keyword searches by a malicious data breach. Thankfully, government IDs were not part of that breach given PornHub has not historically collected them, though age verification laws in Montana and North Carolina will require it to. Few providers offering these technologies make clear whether and how this data is secured and protected from bad actors.
Chair Ferguson recognized the risks posed by third-party services to user privacy, including children’s privacy, writing in a concurring statement related to COPPA rule amendments one year ago that sending “children’s data to third-party vendors with poor security records, or sending those data to many third-party vendors, increases the risk of accidental disclosure or data breach.” Yet, without explanation, later in the same statement he writes that COPPA’s limits on data collection and retention should not be extended to age verification, despite this process too often being conducted by third-party vendors with poor security records.
limiting the collection, sharing, and retention of age-related data for anything other than verifying age;
preventing any further use of data collected for mandatory age verification;
minimizing or entirely preventing linkability between where users provided age-related data and the issuer of that data (e.g., ensuring that the the entity verifying age should not disclose to the issuer of the ID (for example: a state DMV) which sites the user is accessing);
declining to collect or store any information not needed to to determine the user’s age or age range (e.g., if a user provides an ID, the verifier should not collect non-age-related data on that ID, nor information such as a social security number or driver’s license number);
limiting retention and deleting data promptly once no longer needed for age verifying purposes; and
implementing cybersecurity measures (e.g., encrypting data in transit and storage) to prevent malicious access to or uses of age-related data.
Additionally, the FTC ought to consider alternatives to age verification tools, particularly when the intended purpose of their use is to protect children’s privacy. Alternative architectural designs that leverage labeling and signalling standards allow parents who wish to prevent their children from accessing adult websites (or any user who wishes to limit access to certain types of content) to use existing technical methods to do so.
International Privacy Day is meant to recognize the global importance of privacy and the commitment of companies and governments to protecting this human right. Children’s safety online is a key area where researchers, industry, and policymakers could collaborate to better protect children’s privacy and improve privacy for everyone. We hope that in this and future workshops and investigations, the FTC focuses on and addresses privacy specifically, rather than sweeping it under the rug.
Not All Guardrails Are Created Equal: Comparing Content Safety and Copyright Filtering
As courts and policymakers work through questions about chatbot liability, they should be wary of analogies that flatten meaningful technical differences. Copyright filtering and safety intervention share real challenges around ambiguity and evasion, but they diverge in what each control must assess, how each manifests over the course of a conversation, and how much can be verified from the outside.
Op-Ed: France’s Constitutional Council Ruling Tests the Limits of Social Media Bans
Read our analysis the legal and policy significance of the Constitutional Council’s decision on ongoing social media age restriction and age assurance debates ahead of the most-anticipated EU-wide approach on child online safety due by December 2026.
The brief explains that Section 230’s liability protections are essential to enable free expression online and they extend to the use of automated systems to engage to rank and order content as part of traditional publishing activities.