










The OpenID Foundation is publishing a series of papers to contribute to the global conversation about child safety online. This first paper is a piece of research, conducted by Dr. Rachel O’Connell and Aebha Curtis, and commissioned by the OpenID Foundation Board. It explores the experiences of guardians – in particular those responsible for children in alternative care – as they attempt to keep children safe in digital environments. The research is available here.
Future papers (currently in development) will leverage this research and explore the harms we are solving for, the technologies and privacy implications of age-gating, technologies and policy needs for privacy-preserving verifiable guardianship, and a framework for carving a path forward.
Subsequent papers will utilize the research, published as final today, and will include a public review period during which we invite comments from the community. Please join the OpenID Foundation as a member or follow us on LinkedIn to receive updates as the series of papers come out.
When a parent enrolls a child in a banking app, signs them up for a family safety tool, or opens a gaming account, they typically check a box confirming legal guardianship. Most platforms accept this self-declaration without question. No legal authority is ever verified.
Offline, this gap would be unthinkable. Schools, healthcare providers, and local authorities routinely verify parental responsibility through care orders, birth certificates, or formal delegations before an adult acts on a child's behalf. Online, however, these verification mechanisms remain virtually non-existent.
This research explores how this gap affects guardians, particularly those in alternative care scenarios. Despite the paper’s focus on some of the most challenging scenarios, its findings extend to a broad array of family structures in which parenting and child-care is distributed among multiple parties. Indeed, many findings are applicable to any family.
The paper highlights that this procedural gap widens significantly for children in alternative care, including foster, kinship, or residential care, where legal responsibility is intentionally distributed among multiple parties.
In these settings, a local authority may hold legal guardianship while delegating day-to-day oversight to a primary carer. Meanwhile, birth parents may retain specific rights while others transfer to the state. Offline, these arrangements are meticulously documented in auditable care plans designed for legal clarity and accountability.
Yet in the digital domain, there is no standardized mechanism to assert or verify these structured legal relationships. Carers with full legal responsibility for a child’s well being possess no recognized digital status, even as modern legal frameworks increasingly extend parental responsibility into digital environments. Consequently, the burden falls on carers to act as ‘human firewalls,’ performing ongoing, invisible labor without recognized authority.
The paper examines how verification could work in practice, seeking to inform the eKYC & IDA WG's Delegated Authority (currently a WG draft) as it progresses. This standard could enable digital platforms to verify parental and guardianship authority without exposing sensitive, unnecessary personal data. The closely associated topic of age assurance is also expected to arrive in the Digital Credentials Protocols WG, which is the home of the OpenID for Verifiable Presentations specification that will play an important role in privacy-preserving age assertions in future. Parties wishing to get involved should participate in the respective Working Group.
Solving this guardianship and age assurance problems could benefit all digital ecosystems, if it is done with these core principles in mind and without imposing new invasive checks affecting all users. It would allow platforms to verify authority with the same rigor as offline institutions, providing clear, auditable recognition of legal responsibility. For children in alternative care, it could turn digital safeguarding from a reactive, unacknowledged burden into a proactive, legally recognized component of care.
This series on protecting children online was approved by the OpenID Foundation to better understand the emerging policies, technical requirements and standards, and the nature of the current public and private discourse.
The domain is informed by requirements emerging from civil society and government policies, not just in one country but in many countries simultaneously. Solutions and the patterns emerging around the world reflect the ongoing dialogue between policy makers and technologists.
As a technical standards body, OIDF is often a core part of this dialogue, particularly in addressing how standards can support policy and offering insights into the technical gaps that exist. OIDF additionally seeks to support governments with their due diligence on specifications when we can, help the community identify patterns that benefit from standardization, and offer feedback in the form of thought leadership like this paper series.
We also seek to bring insights to the community on a timely basis. For example, some themes from this research were shared at the Global Digital Collaboration September 1-3, 2026 in Geneva. The age assurance materials presented and thematic learnings from the event will be published in a blog post shortly.
The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation's OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile - built on OAuth 2.0 - has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation's standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling "networks of networks" to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。