Current status: European Commission proposal — not adopted EU law

Age & access

Age assurance & age verification

The proposal uses different methods for different legal tasks. Strict EU age verification would apply to Article 6 account thresholds; other compliant age-assurance methods could support safety defaults and app-store access.

The proposal does not say that every person must use one EU app, show a platform an identity document or disclose their identity.

Four distinct concepts

Start with the legal purpose

The method depends on whether a provider needs to prove a specific threshold, apply child-safe defaults, restrict an app, or establish that an adult is responsible for a child.

Article 3(i)

Age assurance

The umbrella term for methods that determine, estimate or verify age. The proposal excludes a user’s simple self-declaration from this definition.

Article 3(h)

Age verification

A high-certainty process based on an identity document or another reliable, verified identification source. It establishes an age or threshold, not necessarily identity for the service.

Article 29(4)

Other methods

Alternative age-assurance solutions may be used for Article 8 adult-status decisions and Article 16 app-store controls if they meet Articles 27 and 28.

Article 26

Parental responsibility

A separate check: whether an adult is the child’s guardian. It can use official signals, existing service signals and, for now, a reasonably verified adult self-declaration.

When is EU age verification required?

Article 29(1) requires providers covered by the Article 6 account rules to verify whether a person has reached the relevant minimum age or whether a guardian-established limited account is needed.

For that task, Article 29(2) says the provider must rely exclusively on an EU age-verification solution using an EU proof-of-age attestation. The attestation must come from a third party; the solution and attestation provider must be certified under the EU Age Verification Scheme and appear in, or be verifiable against, the Commission’s EU lists.

What reaches the service?

A proof-of-age attestation is designed to authenticate that its holder meets an age, threshold or range. Article 28 says the age-assurance solution must not identify the recipient. The legal design is therefore a threshold claim—such as “15 or over”—rather than routine transfer of an identity document to the platform.

Where may other age-assurance methods be used?

Article 29(4) allows methods other than the certified EU verification route for two purposes:

  • establishing that a user is an adult before departing from Article 8’s child-safe design defaults; and
  • assessing age for the app-access and purchase restrictions in Article 16(2) and (3).

The provider must be able to demonstrate that the alternative method meets Article 27’s quality principles and Article 28’s privacy and data-protection rules. The Commission would specify detailed requirements by delegated act.

Self-declaration needs a precise explanation

A user’s simple age declaration is excluded from the proposal’s definition of age assurance. But Article 26 separately allows an adult’s self-declaration of parental responsibility at least until a delegated act is adopted, provided the provider makes reasonable efforts to verify that the adult exercises parental responsibility.

Privacy and data protection

Article 27 requires a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy, data protection and non-discrimination. Article 28 turns those principles into specific limits:

  • the solution must not identify, locate, track, target, advertise to or profile the recipient;
  • providers and age-assurance partners must not process more personal data than strictly necessary for the age threshold;
  • that information must not be further processed, shared or combined with other data, subject to the narrow age-signal rule;
  • age-assurance data must not be combined with data from the provider’s other services or third parties; and
  • measures must use state-of-the-art technology and, in the proposal’s wording, be “zero knowledge proof”.

For Article 8 and app-store age checks, a provider may store at account level only the minimum age signal showing that a threshold was met, solely to avoid repeated checks.

EU solutions, attestations and Commission lists

The proposal envisages an EU Age Verification Scheme built on the European Digital Identity framework. A public authority would certify conforming solutions and proof-of-age attestation providers. Certified European Digital Identity Wallets that meet the Scheme would be deemed certified, but the proposal does not make the wallet the only possible solution.

Under Article 30, the Commission would maintain public machine-readable lists of certified attestation providers and certified EU age-verification solutions. Implementing acts would set technical, organisational, privacy, security and interoperability specifications.

Incorrect result? A complaint route is required

Providers using the Article 6 verification route or a permitted Article 29(4) alternative must offer an effective internal complaint mechanism. A person must be able to challenge an incorrect outcome electronically and free of charge. Online platforms may use the DSA’s internal complaint-handling mechanism for this purpose.

Age signals and operating systems

An age signal is a token, attribute, credential or other information used to establish or demonstrate an age, threshold or range. If an operating-system provider has obtained a compliant age signal, Article 29(6) requires it—after the user’s consent—to enable sharing of that signal with an in-scope provider when needed for compliance. This is a specific role; operating systems are not subjected to every substantive duty in the proposal.

Existing accounts

For existing accounts on Article 6 services, Article 32 points to the EU verification framework. A provider need not verify if it can establish with a high degree of confidence that the user has reached 15. More broadly, an Article 8 provider or app store need not assess age where it can establish with high confidence that the person is not a minor.

Very large online platforms must submit a plan explaining how they will check existing accounts, apply the Article 8 default and use any high-confidence exception.

Member State responsibilities

Article 31 would require each Member State to:

  • provide at least one privacy-preserving electronic means of proving parental responsibility, free to the guardian and based on authentic national sources;
  • ensure accessibility, including for people with disabilities, limited digital access or skills, and vulnerable families;
  • offer alternatives where ordinary civil-status documents cannot prove responsibility;
  • ensure means to obtain a proof-of-age attestation; and
  • make at least one certified EU age-verification solution available free of charge to citizens and residents.

Age verification is not verification of parental responsibility

Age verification answers whether a person meets an age threshold. Article 26’s check answers whether a particular adult holds parental responsibility for a child—for example when establishing an Article 6 limited account, enabling Article 7 access or activating guardian tools.

Article 26 permits official national signals, relevant signals the service already holds from the adult’s and child’s past engagement, and temporarily a reasonably verified adult self-declaration. The check must be privacy-preserving and must not create extra processing that lets the provider locate, track, target or profile the adult or child.

See Parents & guardians for how that check connects to accounts and guardian tools.

Sources and legal references

Primary sources used

EU KIDS Act proposal, COM(2026) 681 final

Articles 3, 6, 8, 16 and 26–32.

Commission Recommendation (EU) 2026/1035

Existing policy framework for EU-wide, privacy-preserving age verification; it does not replace the proposal’s operative text.

eIDAS — consolidated text

The European Digital Identity framework used by the proposal for electronic attestations and wallets.

Implementing Regulation (EU) 2025/1569

The framework referenced in the proposal’s definition of the EU Age Verification Scheme.