Spain advances privacy-preserving solution for age verification
The Spanish Ministry of Digital Transformation on 1 July launched “technical specifications for age verification”, with an app allowing users to obtain tokens proving they are over 18 that can be used to access pornography sites.
“We welcome the commitment of the Spanish regulator to address this issue which is a critical component to ensure age-appropriate experiences for children online,” said 5Rights Executive Director Leanda Barrington-Leach. “It is positive that more stakeholders are working on practical solutions that are effective and rights-respecting. We hope this will contribute to the development of a robust regulatory framework for age assurance systems based on best practice as set out in the industry standard IEEE 2089-1.”
When age-assurance systems are in place, they should meet the following minimum standards:
- Adhere to data minimisation in order to be privacy-preserving, only collecting data that is necessary to identify the age, and age only, of a user
- Protect the privacy of users in line with GDPR and other data protection rules and obligations
- Be proportionate to the risk of harm arising from the service, or a feature of the service, and the purpose of the age assurance solution used
- Be easy for children to understand and consider their evolving capacities
- Be secure and prevent unauthorised disclosure or safety breaches
- Provide routes to challenge and redress if the age of a user is wrongly identified
- Be accessible and inclusive to all users, particularly those with protected characteristics
- Do not restrict children from services or information that they have a right to access
- Provide sufficient and meaningful information for a user to understand how the age assurance system works, in a format and language they can easily understand – including children
- Be effective in assuring the actual age, or age range, of a user
- Anticipate that users may not tell the truth, and do not rely solely on this information.
Effective age verification is a necessity for access to products and services that are legally restricted by age, such as pornography or gambling. Age assurance more broadly, including age estimation techniques, is an important starting point to provide age-appropriate experiences; it should not be used to shut children out, or instead of age-appropriate design of service. In many cases, making services safe for the youngest users is a preferable option that precludes the need for knowing age.
Recommended Reads
ICO research illustrates risk to children’s data
The Information Commissioner’s Office (ICO) published new research detailing the misuse of children’s data and announced notices to three companies suspected to have failed to comply with the Age Appropriate Design Code.
UK Government must uphold children’s privacy in new data law
5Rights welcomes the draft proposals of the UK Data Bill that strengthen the accountability of tech firms on children’s safety but warns that many of the most problematic aspects to water down data protection remain.
Online Safety Act one year on: Ofcom must fix holes in regulation
Today marks one year since the Online Safety Act was passed into UK law. We recognise the scale of Ofcom’s task but do not believe the current proposals create the online world envisioned by the legislation.
5Rights calls for robust enforcement to protect children’s data
Three years into the Age Appropriate Design Code’s enforcement, the Information Commissioner’s Office has failed to meet the Code’s foundational aims. At 5Rights, we’ve raised what must change to stop the continual misuse of children’s data.