
Belgian digital identity provider itsme argues that online age verification can — and should — be done without collecting full identity details. The comment comes as governments in Europe push for minimum age rules on social media, raising questions about how organisations will check users' ages while respecting privacy.
The problem with current age checks
Many online services today verify age by asking for extensive identity information — often a full ID or passport scan — when all that is actually needed is a yes/no answer to the question: "Is this person above the required age?" That approach creates unnecessary privacy risks and increases the potential damage from data breaches, because companies store sensitive personal data like birth dates, national ID numbers and names that are irrelevant to the age check itself.
Privacy-preserving verification: how it works
Modern digital identity techniques make a more targeted approach feasible. Instead of exchanging full identity records, a secure intermediary or app can confirm a single statement — for example, "age ≥ 18" — and send only a signed yes/no response to the requesting platform. The platform receives no birthdate, name or national ID number; it simply knows whether the age threshold has been met.
Practical examples and benefits
- Parcel pickup: a delivery worker can verify the recipient is over 18 to hand over alcohol, without seeing the person's date of birth or national ID number.
- Social platforms and online stores: providers can comply with a legal minimum age requirement while collecting minimal personal data.
- Reduced breach impact: holding less personal data lowers the consequences of unwanted exposure in the event of a leak.
What organisations should do next
itsme's statement calls for data minimisation to be front and centre when organisations redesign age checks in response to policy changes. Key recommended steps include:
- Start from the right question: ask whether someone meets the age requirement, not who they are.
- Use privacy-preserving identity methods that exchange only the necessary assertion (a signed yes/no).
- Integrate trusted intermediaries or identity wallets to keep sensitive personal data out of service provider systems.
- Communicate clearly with customers so they understand what is being shared and why, to build trust.
These approaches require a shift in how digital systems are built and in how intermediaries are used, but they can help reconcile stricter age rules with privacy and security goals.
Contact details in the original release point to itsme's communications team for further information.
Source: Original press release




