
Insights · Data protection
Digital age verification
- Published
- 26 January 2026
- Author
- Jochen Harttung, LL.M. (Toronto)
- Reading time
- 7 min read
Digital age verification is in the process of moving from a “nice to have” to a genuine compliance topic. The reason: the EU is increasing the pressure to protect minors more effectively online while at the same time safeguarding privacy. Companies that operate digital offerings feel this at several points. In audits, in internal risk analyses and in enquiries from data protection and IT security.
The challenge is rarely the question of whether one has to do something. Rather: what is appropriate, what is practicable, and how can it be implemented so that one’s own compliance is secured without alienating users or collecting unnecessary data.
What digital age verification is actually meant to achieve
At its core it is about a simple statement: is someone old enough for a particular item of content or a particular function. Many solutions of the past processed far more data for this than necessary. Upload a copy of an ID document, store the full date of birth, check the real name – and at the end there is still uncertainty as to whether all of this is really necessary and proportionate.
Modern approaches go in a different direction. They aim to confirm only the age attribute. So, for example, “over 18” rather than identity. That is not only more privacy-friendly, but often also more technically stable, because fewer data flows, less storage and a smaller attack surface arise.
Why the topic is gaining importance right now
Age verification becomes relevant wherever minors can encounter content or interactions that are not intended for them. That concerns not only obvious areas such as gambling or erotic content, but also platforms with user-generated content, chats, direct messages, live functions or content that can be harmful in certain contexts. The discussion about age restrictions for social networks is currently on everyone’s lips.
At the same time, the expectation is growing that protective measures are not purely symbolic. A checkbox or a pop-up notice is increasingly rarely regarded as a sufficient measure if the service can realistically be used by minors and risks are identifiable.
In Germany, the state media authorities have for some time been in dispute with platforms for pornographic content, which has already produced a series of (in part contradictory) court decisions. In May 2025 the European Commission opened official proceedings against four large providers of pornographic content on the internet.
Legally, regulation in the European context is complex. How assertively the authorities proceed is often also a political question. The courts have to bring national and European rules into line.
A further major question will be what role telecoms companies play in this constellation. They are not obliged to carry out a proactive check. There is, however, reason to fear that regulators will increasingly approach them if they cannot get hold of those who are actually responsible.
How privacy-friendly age verification works in practice
A good model separates the roles cleanly. The body that establishes age is not the same as the one that provides the service. And in the end the service receives no more than the information it really needs. Ideally it receives only confirmation that the relevant age threshold has been reached.
The direct requirements of the European legislator in Art. 28 of the Digital Services Act (DSA) are extremely thin and indeterminate. The central point of reference is therefore the guidelines on the protection of minors published by the EU Commission in July 2025. Instruments for age verification are accordingly to be accurate, reliable, robust, non-intrusive and non-discriminatory. In parallel, the Commission is working on the so-called “Blaupause zur Altersüberprüfung”, a technical solution that is intended to meet the requirements named.
What companies often underestimate
From a compliance perspective, the topic of youth protection and thus also of age verification will foreseeably and increasingly come to the fore. The basis here must be a solid examination of one’s own duties: what legal “role” does one’s own company have in the statutory system, and what duties follow from this in the respective countries in which one is active.
Added to this is the operational component: in projects one repeatedly sees the same stumbling blocks. The problem is rarely a lack of will, but rather the sequence. Age verification is often treated as a purely technical feature that is “quickly added” at the end. In practice, however, considerably more hangs on it: product logic, user guidance, data protection, security, demonstrability and not least the question of how well the whole thing can be operated in day-to-day use.
Frequently, requirements are only clarified after implementation has begun. It then becomes apparent that solutions work technically, but process unnecessary data or can barely be justified. Providers or procedures are also sometimes chosen without clarifying early on which evidence and documentation will later be needed for internal or external reviews. Data protection and IT security are also often involved only late – with the result that subsequent adjustments become time-consuming and expensive.
What helps is an early, structured check that brings technology and law together and derives clear guardrails from that. It has proved particularly worthwhile to go through these points systematically right at the start:
- Which specific content or functions are to be protected, and why
- Which age threshold is really required and how finely it must be drawn
- How high the risk is in the specific service, for example through UGC, chats, direct messages or interaction functions
- Which user groups are realistically affected and what the typical usage context looks like
- What kind of evidence is sufficient, that is, an age attribute rather than identity, or in exceptional cases more after all
- What data arise in the process, who receives them, how long they are stored and how tracking can be prevented
- What operations look like, including support, failed attempts, fallbacks and abuse scenarios
- What documentation is needed in order later to demonstrate that the solution is suitable and proportionate
From these points it usually quickly becomes clear in which direction one should go. Frequently the data-minimising variant is not only more elegant legally, but also better on the product side, because it generates less friction and fewer follow-on questions in operations. What matters is that these guardrails are set early and then implemented consistently. That avoids expensive detours and in the end leads to a solution that holds both in the user experience and in the legal argument.
Blocking orders as an additional pressure factor
A further point that is becoming increasingly important in practice is blocking orders. If authorities or supervisors see protection deficits, that can end not only in recommendations or review reports, but also in concrete orders. That can mean that certain content, functions or entire areas of an offering have to be blocked or made accessible only on a restricted basis without effective age verification.
For companies this is sensitive because such measures often take effect at short notice and intervene directly in operations, revenue or user guidance. Those who take care of a viable concept at an early stage not only reduce the risk of an unpleasant surprise, but also create the technical and organisational basis for being able to react quickly and cleanly.
What makes sense now, without rebuilding everything at once
In practice, a pragmatic approach helps. First it should be clear where age verification is really needed. Then one should decide whether a mere age confirmation is wanted or whether, exceptionally, a genuine identity link is needed. In most cases the age attribute is sufficient and easier to justify.
A review of the implementation options is then worthwhile: existing providers, integration into identity or wallet approaches, or own components. What matters here is not only the technology, but also governance. Who establishes what. Who stores what. For how long. And how the whole thing is documented so that one can later explain why the solution is appropriate.
What it comes down to in the end
Digital age verification is not a hype topic that one should sit out. It is becoming a component of compliance, data protection and product responsibility. Those who proceed in a structured way now reduce later friction, avoid hurried retrofitting and create a solution that works in day-to-day use and can be explained legally.
With our support you ensure that the right guardrails are set and typical pitfalls are avoided early.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


