惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Engineering at Meta
Engineering at Meta
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence
IT之家
IT之家
博客园 - 【当耐特】
U
Unit 42
云风的 BLOG
云风的 BLOG
L
LangChain Blog
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
B
Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
宝玉的分享
宝玉的分享
N
Netflix TechBlog - Medium

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
CNIL- Privacy Friendly Age Verification System | iubenda
2022-09-29 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

CNIL Privacy friendly Age Verification System 

It goes without saying that online age verification is a complicated issue with serious privacy and security risks. That’s why the French DPA (CNIL) released an analysis to help clarify its position on online age verification and outline how publications can meet their legal obligations.

Age Verification System
(Photo credit: Demonstration of a privacy-preserving age verification process)

What is an age verification system?

In short, an age verification system is a method used to verify a person’s age before granting them access to certain content or services. Age verification systems can use various methods such as asking for the user’s date of birth, verifying a user’s government-issued identification, or using third-party verification services. The purpose of these systems is to prevent children or minors from accessing content or services that are not appropriate for their age, and to help companies comply with laws related to privacy and data protection.

The CNIL examined the various forms of age verification systems, notably on pornographic websites where such verification is required. CNIL considers it easy to bypass the current systems and advocates for developing more privacy-friendly alternatives.

Knowing an individual’s identity can help with age verification; however, it can connect the individual to their online activities, which contain highly private and sensitive information.

Therefore the necessity to identify internet users’ ages raises privacy and personal data protection concerns.

Users are required to identify themselves in order to access certain websites or participate in certain online activities (e.g., to buy goods on an e-commerce site).

Age verification is likely to change how well users’ privacy is protected. While access to sites or online services does not necessarily require identification, if the users do not give the publisher information on their identity, they will be blocked from visiting the site.

Given the growing significance of digital technologies in people’s lives, the CNIL emphasizes the significance of educating and creating awareness among minors, parents, legal guardians, and employees in the educational community about safe online practices.

In this regard, as part of its work on minors’ digital rights, the CNIL published general recommendations in August 2021 to comply with the obligations of the GDPR and the Act on minors’ access to social networks. The recommendations reinforce the standards set to,

“verify the age of the child and parental consent while respecting the child’s privacy.”

Age verification systems should be built on six pillarsminimization, proportionality, robustness, simplicity, standardization, and third-party intervention.

💡 The CNIL tends to favor user-controlled systems over centralized or imposed ones. From this perspective, parental control seems to be the most considerate of people’s rights because it encourages households to limit access to sensitive information.

The purchase of alcohol, online gaming and betting, some financial services, and other products are all subject to age restrictions under French legislation and various European rules. Therefore, such sites are required to confirm the customer’s age. Additionally, certain services have contractually mandated age restrictions (e.g., access to application settings for children).

The legal framework already requires a fairly strong confirmation of identity, and website publishers have consequently incorporated age verification systems.

💡 CNIL predicts an increase in age verification requirements for some services in order to protect children better online. That being said, CNIL also urges caution not to unreasonably raise the standards for online age verification, which would result in a decrease in the number of sites that can be freely accessed.

Recommendations and cautions from CNIL regarding online age verification

Age verification methods must be managed in the short term by a reliable third party.

When using a trusted third party, as the CNIL advised in its decision dated 3 June 2021, the age verification is divided into two distinct operations:

  1. One is the issuance of proof of age, which entails the implementation of a system to verify the accuracy of the user’s age. 

This verification may be provided by a variety of organizations that are familiar with the user, including digital identity service providers and organizations with which the user is acquainted (a merchant, a bank, an administration, etc.)

2. Second, the website visited must receive this verified evidence of age before deciding whether to grant access to the requested content.

However, these two factors raise significant data protection and privacy concerns, especially in light of the desire to maintain the option of using the internet anonymously or without disclosing personally-identifying information. 

So, how do we protect our users’ data while verifying their age? 

🚀 To effectively protect people’s data while verifying their age, CNIL advises using an unbiased third party.

The CNIL advises sites subject to age verification requirements not to conduct age verification operations themselves but rather to rely on third-party solutions whose validity has been independently verified in order to maintain a high level of data protection.

How to transmit a valid proof of age to a site

🚀 To effectively transmit a valid proof of age to a site,* CNIL advises using an independent third-party verifier* whose use is under the user’s discretion for the purpose of transmitting a verified proof of age to a website.

A third party would be responsible for choosing one or more methods that would enable the issuance of legitimate proof of age by using cryptographic signatures that enable the information’s source and authenticity to be confirmed.

The safeguards used in this proof of concept: 

  • prevent the third party from knowing the website visited; and
  • prevent the website visited knowing the third party who provided the age verification.

This trusted third party could take the form of an “attribute management” service, which would give each user the option to select from a well-known data provider to disclose their data (such as an electricity company to certify an address or an identity service to certify an age). 

The CNIL has examined various solutions that are now available for online age verification to see if they meet the criteria for sufficiently reliable age verification. You can read this analysis here

CNIL Privacy-friendly Age Verification System 

CNIL is developing an age verification system with a focus on privacy. In order to achieve this, the CNIL’s Digital Innovation Laboratory (LINC) has shown that a system based on a secure protocol employing “zero-knowledge proofs” is feasible. 

This technique is based on a method used in cryptology that enables users to provide proof of age without disclosing any additional information.

This demonstration explains how the security of a user’s identity and the principle of data minimization can be guaranteed through a third-party system while still retaining a high level of confidence in the correctness of the data supplied. 

👋 See here for the Demonstration of a privacy-preserving age verification process. 

Whatever method is used to determine a users age, it must be reliable, the data must be kept private, and the amount of data transferred must be kept to a minimum.

Ready to implement CNIL’s Privacy Friendly Age Verification System on your website?

Sign up for iubenda today to simplify your compliance with privacy laws and protect your users’ data.

Click here to get started

See Also, 

  1. Legal Requirements for Websites and Apps Used by Children
  2. App Privacy Requirements for Kids