Privacy principles for age assurance
Age assurance should reveal no more than the service needs, be effective for its protective purpose, and avoid creating a reusable browsing-identity or marketing dataset from children's and adults' access decisions.
The EDPB's age-assurance statement applies GDPR principles including lawfulness, fairness, transparency, necessity, proportionality, minimisation, effectiveness and rights. Application still depends on the actual service and processing.
For: DPOs, trust-and-safety, product, legal and procurement teams. This is independent information, not legal, compliance or security advice.
Purpose before method
Record the protected risk, age threshold, decision and applicable rule. A method that does not effectively address that purpose cannot be justified simply because it is labelled privacy-preserving.
Minimise at every boundary
- Collect an age band or threshold result instead of exact date where sufficient.
- Keep identity evidence away from the relying service where possible.
- Separate age assurance from advertising, profiling and unrelated analytics.
- Limit issuer knowledge of later presentations.
- Delete raw images, documents and templates when no longer justified.
Prevent linkability
Examine identifiers, device signals, logs, credential values and network metadata across repeated sessions and different services. Anonymous-looking proof can still become trackable through surrounding implementation.
Rights and transparency
- Use child-appropriate and adult-readable explanations.
- Identify each responsible organisation.
- Explain method, outcome and alternatives without exposing attack detail.
- Support access, correction, deletion where applicable and complaint.
- Provide human review or another route after an adverse error.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- EDPB Statement 1/2025 on Age Assurance
- General Data Protection Regulation
- European Commission approach to age verification
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing