惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
P
Privacy International News Feed
Vercel News
Vercel News
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园 - 叶小钗
F
Fortinet All Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 最新话题
AWS News Blog
AWS News Blog
Engineering at Meta
Engineering at Meta
Attack and Defense Labs
Attack and Defense Labs
Recent Announcements
Recent Announcements
Recent Commits to openclaw:main
Recent Commits to openclaw:main
PCI Perspectives
PCI Perspectives
Cloudbric
Cloudbric
AI
AI
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
IT之家
IT之家
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
J
Java Code Geeks
M
MIT News - Artificial intelligence
Cisco Talos Blog
Cisco Talos Blog
V2EX - 技术
V2EX - 技术
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
Cyberwarzone
Cyberwarzone
博客园 - 聂微东
G
Google Developers Blog
W
WeLiveSecurity
罗磊的独立博客
P
Privacy & Cybersecurity Law Blog
阮一峰的网络日志
阮一峰的网络日志
A
About on SuperTechFans
WordPress大学
WordPress大学
The GitHub Blog
The GitHub Blog
T
Tailwind CSS Blog
V
Visual Studio Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
Secure Thoughts
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
F
Full Disclosure
Blog — PlanetScale
Blog — PlanetScale
The Last Watchdog
The Last Watchdog
P
Proofpoint News Feed

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
CNIL- Privacy Friendly Age Verification System | iubenda
2022-09-29 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

CNIL Privacy friendly Age Verification System 

It goes without saying that online age verification is a complicated issue with serious privacy and security risks. That’s why the French DPA (CNIL) released an analysis to help clarify its position on online age verification and outline how publications can meet their legal obligations.

Age Verification System
(Photo credit: Demonstration of a privacy-preserving age verification process)

What is an age verification system?

In short, an age verification system is a method used to verify a person’s age before granting them access to certain content or services. Age verification systems can use various methods such as asking for the user’s date of birth, verifying a user’s government-issued identification, or using third-party verification services. The purpose of these systems is to prevent children or minors from accessing content or services that are not appropriate for their age, and to help companies comply with laws related to privacy and data protection.

The CNIL examined the various forms of age verification systems, notably on pornographic websites where such verification is required. CNIL considers it easy to bypass the current systems and advocates for developing more privacy-friendly alternatives.

Knowing an individual’s identity can help with age verification; however, it can connect the individual to their online activities, which contain highly private and sensitive information.

Therefore the necessity to identify internet users’ ages raises privacy and personal data protection concerns.

Users are required to identify themselves in order to access certain websites or participate in certain online activities (e.g., to buy goods on an e-commerce site).

Age verification is likely to change how well users’ privacy is protected. While access to sites or online services does not necessarily require identification, if the users do not give the publisher information on their identity, they will be blocked from visiting the site.

Given the growing significance of digital technologies in people’s lives, the CNIL emphasizes the significance of educating and creating awareness among minors, parents, legal guardians, and employees in the educational community about safe online practices.

In this regard, as part of its work on minors’ digital rights, the CNIL published general recommendations in August 2021 to comply with the obligations of the GDPR and the Act on minors’ access to social networks. The recommendations reinforce the standards set to,

“verify the age of the child and parental consent while respecting the child’s privacy.”

Age verification systems should be built on six pillarsminimization, proportionality, robustness, simplicity, standardization, and third-party intervention.

💡 The CNIL tends to favor user-controlled systems over centralized or imposed ones. From this perspective, parental control seems to be the most considerate of people’s rights because it encourages households to limit access to sensitive information.

The purchase of alcohol, online gaming and betting, some financial services, and other products are all subject to age restrictions under French legislation and various European rules. Therefore, such sites are required to confirm the customer’s age. Additionally, certain services have contractually mandated age restrictions (e.g., access to application settings for children).

The legal framework already requires a fairly strong confirmation of identity, and website publishers have consequently incorporated age verification systems.

💡 CNIL predicts an increase in age verification requirements for some services in order to protect children better online. That being said, CNIL also urges caution not to unreasonably raise the standards for online age verification, which would result in a decrease in the number of sites that can be freely accessed.

Recommendations and cautions from CNIL regarding online age verification

Age verification methods must be managed in the short term by a reliable third party.

When using a trusted third party, as the CNIL advised in its decision dated 3 June 2021, the age verification is divided into two distinct operations:

  1. One is the issuance of proof of age, which entails the implementation of a system to verify the accuracy of the user’s age. 

This verification may be provided by a variety of organizations that are familiar with the user, including digital identity service providers and organizations with which the user is acquainted (a merchant, a bank, an administration, etc.)

2. Second, the website visited must receive this verified evidence of age before deciding whether to grant access to the requested content.

However, these two factors raise significant data protection and privacy concerns, especially in light of the desire to maintain the option of using the internet anonymously or without disclosing personally-identifying information. 

So, how do we protect our users’ data while verifying their age? 

🚀 To effectively protect people’s data while verifying their age, CNIL advises using an unbiased third party.

The CNIL advises sites subject to age verification requirements not to conduct age verification operations themselves but rather to rely on third-party solutions whose validity has been independently verified in order to maintain a high level of data protection.

How to transmit a valid proof of age to a site

🚀 To effectively transmit a valid proof of age to a site,* CNIL advises using an independent third-party verifier* whose use is under the user’s discretion for the purpose of transmitting a verified proof of age to a website.

A third party would be responsible for choosing one or more methods that would enable the issuance of legitimate proof of age by using cryptographic signatures that enable the information’s source and authenticity to be confirmed.

The safeguards used in this proof of concept: 

  • prevent the third party from knowing the website visited; and
  • prevent the website visited knowing the third party who provided the age verification.

This trusted third party could take the form of an “attribute management” service, which would give each user the option to select from a well-known data provider to disclose their data (such as an electricity company to certify an address or an identity service to certify an age). 

The CNIL has examined various solutions that are now available for online age verification to see if they meet the criteria for sufficiently reliable age verification. You can read this analysis here

CNIL Privacy-friendly Age Verification System 

CNIL is developing an age verification system with a focus on privacy. In order to achieve this, the CNIL’s Digital Innovation Laboratory (LINC) has shown that a system based on a secure protocol employing “zero-knowledge proofs” is feasible. 

This technique is based on a method used in cryptology that enables users to provide proof of age without disclosing any additional information.

This demonstration explains how the security of a user’s identity and the principle of data minimization can be guaranteed through a third-party system while still retaining a high level of confidence in the correctness of the data supplied. 

👋 See here for the Demonstration of a privacy-preserving age verification process. 

Whatever method is used to determine a users age, it must be reliable, the data must be kept private, and the amount of data transferred must be kept to a minimum.

Ready to implement CNIL’s Privacy Friendly Age Verification System on your website?

Sign up for iubenda today to simplify your compliance with privacy laws and protect your users’ data.

Click here to get started

See Also, 

  1. Legal Requirements for Websites and Apps Used by Children
  2. App Privacy Requirements for Kids