Online service providers face mounting pressure to keep children away from age-inappropriate content, yet the mechanisms used to verify or estimate age may themselves create significant privacy risks and erode online anonymity. In practice, this means that organizations should evaluate not only whether age assurance is effective, but also whether it is proportionate, privacy-conscious, and tailored to the risks the service creates.
Age Assurance Models
The guidance identifies three principal methods, each offering a different level of certainty about a user’s age:
- self-declaration, where the user states their age or date of birth without further proof.
- age estimation, which seeks to infer whether a user falls within a particular age band using methods such as biometric analysis, behavioral indicators, account data, or knowledge-based tests.
- age verification, which aims to provide a higher degree of certainty, for example, through official identity documents (“hard identifiers”), public databases, bank evidence, or trusted third-party services. It may also involve real-time comparison between the user’s face and the photograph appearing on the submitted document (photo-ID matching).
From a privacy perspective, the formal classification of a method matters less than how it is implemented in practice. An age estimation tool may seem less intrusive than document-based verification, yet if it relies on repeated or continuous monitoring, it may in fact be more invasive.
Privacy-Based Classification
The PPA classifies age assurance measures into three tiers according to the degree of privacy intrusion they entail.
This assessment depends on a range of factors, including the sensitivity and volume of the data processed; the purpose, whether age estimation or exact age verification; the type and number of data sources; whether processing is conducted in-house or outsourced; who can access the data; whether data is collected once or on an ongoing basis; how many methods are combined; the maturity of the technology; and whether there is a legal obligation. In general, the recommendation is that where lower-impact tools are sufficient, they should be preferred.
- Least intrusive measures use minimal, non-sensitive data provided directly by the user and not cross-checked, such as a self-declaration of age without supporting evidence.
- Moderate measures rely on limited, specific, and generally non-sensitive official sources, for example knowledge-based tests, bank evidence, public database checks, and trusted third-party services.
- Highly intrusive measures process sensitive information, biometrics, or data drawn from multiple variable sources or from continuous online monitoring, including hard identifiers. Such tools should be justified only in exceptional situations, such as where a specific legal or regulatory obligation mandates them, or where there is a concrete and substantial risk to minors that cannot be adequately addressed through less intrusive means. The PPA notes that, as of the publication date, it is not aware of any such Israeli legal obligation.
Proportionality
Under the principle of proportionality, public organizations should first examine the nature of the service, the risk it poses to minors, the likelihood of harm, and the sensitivity of the user environment. Only then should they determine whether age assurance is needed at all and, if so, what level of assurance is truly necessary. In relation to public organizations, the use of age verification with a high privacy impact, without sufficient justification and in circumstances where more moderate means may achieve the same purpose, may be considered disproportionate.
The PPA also notes that age assurance is not the only path to child protection. In some cases, the same objective can be achieved through product design choices or content-filtering tools, which do not rely on collecting and processing personal data.
Organizations should therefore assess the privacy and security implications of the chosen tool, including through privacy impact assessments, and trigger age checks only where risk arises, or at the point of access to specific content or functions, rather than across the service as a whole.
Purpose Limitation and Data Minimization
Purpose limitation: Personal data collected for age assurance purposes cannot be used for other purposes. For example, biometric data processed to estimate a user’s age cannot be reused for identification or facial matching without separate consent and a lawful basis.
Data minimization applies first at the collection stage: organizations should limit what is taken from official documents or other sources to what is strictly necessary for age assurance and select sources that generate the least excess data. The draft offers several rules of thumb:
- Usually, there is no need for a copy of an ID card or the user’s exact age. Instead, it is often enough to determine whether the user is above or below a relevant threshold or belongs to a defined age band. Therefore, a binary or categorical result may suffice.
- Organizations should carefully consider the risks associated with the use of biometric data, official documents or behavioral analysis for age assurance. As the PPA highlights, biometric data is inherently sensitive because of its identifying power and the consequences of misuse or leakage, while official documents frequently contain family details, nationality, and other hard identifiers. Age inferences drawn from online activity may reveal highly sensitive information, including political opinions, health conditions, or religious beliefs.
- Ongoing monitoring warrants the greatest caution. Continuous reassessment of age based on content consumption, speech patterns, or activity across the service is especially intrusive and will be difficult to justify where less intrusive safeguards exist.
Data minimization applies equally to retention. Once the age assurance process is complete, only the minimum information necessary for continued provision of service should be retained, and the remainder should be deleted, with periodic reviews for excess data. Where third-party providers are used, the data processing agreement should require the provider to delete the data used for age assessment once the result has been delivered.
Practical Takeaways
- Scope and Necessity: Assess whether age assurance is needed across the whole service or only at specific high-risk points, and whether product design or content filtering would achieve the same objective without processing personal data.
- Minimum Output: Solutions that provide only the minimum result needed for access control should be preferred, such as confirmation that a user is above a threshold age or belongs to a relevant category, rather than full identity information or the user’s exact age.
- Proportionality: Highly privacy-intrusive age assurance measures, such as biometrics, official identity documents, behavioral inference, continuous monitoring, and layered methods (combining multiple age assurance methods), should not be used by default and will generally be justified only in exceptional cases, such as where there is a significant risk to minors or a specific legal requirement.
- Notice and Consent: Age assurance can rely on legal obligation or consent. Consent should be informed, freely given, and preferably explicit (although, generally, implied consent is permitted under Israeli law). The notice should be presented in plain terms adapted for minors and should include, where relevant, disclosure of the sources from which personal data may be drawn for age assessment purposes.
- Retention: Organizations should retain only the minimum information necessary for age assurance, impose equivalent retention limitations on third-party providers, and avoid retaining exact age data or source documents where a binary result is sufficient.
Article provided by INPLP member: Dalit Ben-Israel (Naschitz Brandes Amir, Israel)
Discover more about the INPLP and the INPLP-Members
Dr. Tobias Höllwarth (Managing Director INPLP)
