The proposed Regulation should not prejudice the high standard of personal data protection and protection of privacy of communications and private life set in EU legislation. Furthermore, measures aimed at ensuring children’ online safety can be expected to enhance their privacy. Several safety by design measures aim at ensuring that their information remains private or only shared with a limited circle if the minor so decides.
The obligation to establish age assurance systems to support the implementation of the access delay and the safety by design measures imply the processing of personal data. Considering the need for a consistent approach and the existing obligations in terms of age assurance present in EU and national legislation ( ), the European Data Protection Board (EDPB) provided specific guidance and high-level principles outlining key considerations for age assurance systems to be in line with data protection requirements ( ).
The proposed Regulation establishes clear requirements for the deployment and use of age assurance systems in line with the principles outlined by the EDPB ensuring a high standard of data protection. These criteria include a high level of accuracy, reliability, robustness, security, non-discrimination and non-intrusiveness. Following a risk-based approach and ensuring proportionality, age verification is only mandated for the implementation of the access delay.
As noted in the external study, age verification – whether through the EU Age Verification Solution or through comparative solutions – can be implemented in ways that are privacy-preserving by design. In that context, the external study recommended that to mitigate rights interferences, the legislative instrument should require services to use age verification methods that utilise double-blind architecture, and which incorporate technological innovations like zero-knowledge proof cryptography. The proposed Regulation requires, where age verification is required, to rely on the EU Age Verification solutions, which will have to meet the highest standards in terms of privacy and data protection, using zero-knowledge proof cryptography.
Moreover, as noted in the external study, many privacy and data protection risks that arise in the context of age assurance relate to how age assurance is deployed by service providers and how age assurance systems are operated. This includes questions of what personal data is collected, how it is processed, which entities it is shared with, and how it is stored. The study further noted that these risks can be largely mitigated through adherence to the General Data Protection Regulation, and through clear application to age assurance providers of the GDPR’s provisions on data minimisation, purpose limitation, transparency, and data protection by design and default. The proposed Regulation ensures this, by laying down additional safeguards for age assurance providers and the providers of services relying on age assurance solutions, such as further specifying the application of principles of purpose limitation, data minimisation, and data protection by design and by default. Furthermore, it should also be underscored that service providers’ implementation of the proposed Regulation’s age assurance requirements are subject to the horizontal rules of the GDPR, and they must be undertaken in strict accordance with GDPR’s principles on data processing.
Separately, the external study characterised the age assurance market as a vibrant and mature one, where age assurance providers are increasing competing and innovating on privacy and accessibility grounds. The study recommended that any future legislative proposal capitalise on this reality, by allowing service providers in scope of an age assurance requirement to utilise third-party age assurance solutions that meet high standards of privacy and security. By enabling third-party age verification solutions to adopt the EU Age Verification blueprint and by allowing service providers to adopt a range of age assurance methods for the purposes of safety by design, the proposed Regulation leverages the competitive forces of the market in favour of privacy-preserving approaches.
Accounts created by parents for their children also further requires verifying that the adult is the guardian of the minor concerned. The proposed Regulation establishes that such verification must be done in a privacy-preserving manner, through the use of ‘zero knowledge proof’, and not lead to the additional processing of data that could enable the identification or tracking of the adult or minor concerned.
Ultimately, by enshrining safeguards in law, affirming the applicability of the GDPR, and setting a baseline standard for how third-party age assurance solutions should operate, the proposed Regulation provides for the effective use and deployment of age assurance systems while ensuring a high standard of data protection for their use. The proposed Regulation provides for clear legal standards, which will promote the deployment of an innovative market of age assurance solutions respectful of fundamental rights.
As for AI companions and general conversational chatbots, the requirement for providers to avoid features posing risk of emotional dependencies protects minors’ private life because systems that simulate human emotions or relationships can encourage children to disclose intimate thoughts, feelings, routines, fears, or family matters as if they were speaking to a trusted person or friend. Limiting such design features therefore helps safeguard minors against both undue emotional influence and against the extraction or exposure of intimate aspects of their private life.