Independent. MyID is not affiliated with the Department of Social Protection, MyGovID, or the Government of Ireland.

Privacy principles for age assurance

Published 2026-08-22Updated 2026-08-22By MyID Editorial

Age assurance should reveal no more than the service needs, be effective for its protective purpose, and avoid creating a reusable browsing-identity or marketing dataset from children's and adults' access decisions.

Ireland status · verified 22 August 2026

The EDPB's age-assurance statement applies GDPR principles including lawfulness, fairness, transparency, necessity, proportionality, minimisation, effectiveness and rights. Application still depends on the actual service and processing.

For: DPOs, trust-and-safety, product, legal and procurement teams. This is independent information, not legal, compliance or security advice.

Purpose before method

Record the protected risk, age threshold, decision and applicable rule. A method that does not effectively address that purpose cannot be justified simply because it is labelled privacy-preserving.

Minimise at every boundary

Prevent linkability

Examine identifiers, device signals, logs, credential values and network metadata across repeated sessions and different services. Anonymous-looking proof can still become trackable through surrounding implementation.

Rights and transparency

Evidence and limits

MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.

Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.

Next useful pages

Follow the Irish evidence

Get the business briefing when Irish wallet, verification and age-assurance evidence changes.

Join the business briefing