Prove Your Age Without Being Tracked

Two ways to check an age online: take the face, or leave a receipt. Why age assurance must be notice-first, built on Digital Public Transparency Infrastructure.

Share

Prove Your Age Without Being Tracked

There are two ways to check someone's age online: take their face, or leave them a receipt. Age assurance is being built face-first. A set of expert comments to the ISO editors recommends the fix: notice before identification, and a disclosure you can actually audit.

In January 2026, age-verified Roblox accounts went up for sale on eBay, from about four dollars to over a hundred. That is what face-first age checks actually produce: a resale market for verified identities, built on the surveillance rail the checks were meant to protect children from.

Governments around the world are now mandating age checks across large parts of the internet. The intention is child safety. The mechanism, as currently drafted in international standards, quietly asks something else of everyone: present your face, your ID, or a credential first, and find out later, if ever, who collected it, why, and under what authority. That is the face. There is another way: the receipt. Whenever something identifies you, by your face or by a digital identifier, you should walk away with a digital receipt of it. That receipt is what lets people track the services checking them, independently, instead of trusting the operator's own record.

That is backwards. This month we submitted expert comments to the ISO editors to turn it the right way round.

What was filed

A coordinated set of expert comments has been submitted for WD 27566-2, the working draft of ISO/IEC 27566-2, "Age Assurance Systems, Part 2: Benchmarking." Part 2 is the standard that will define how age assurance systems are measured and compared. What it benchmarks becomes what the market builds.

The comments make one argument, expressed across eight linked clauses: an age assurance system can satisfy the draft in full and still leave no inspectable record of what was disclosed, when, by whom, under what lawful basis, and with what cross-border scope. The current draft still treats notice as narrative text (for analogue privacy risk) inside a practice statement. Privacy law does not. It requires the controller, the purposes of processing, the rights of the individual, and contact information to be provided at or before collection (GDPR Articles 12 to 14, Convention 108+ Article 8, PIPEDA 4.3 and 4.8), and it requires the controller to demonstrate afterward that this actually happened (GDPR Articles 5(2) and 7(1)). Narrative text cannot demonstrate anything after the event. It is not operative notice or transparency.

These are expert comments to the editors, not a demand on ISO. They recommend one thing: embed co-regulated, identity-management transparency into the benchmark. The reason is blunt. As drafted, the standard is not privacy compliant, and it is not even consent capable. It offers no structure to record consent, so where a method relies on consent, that consent cannot be demonstrated at all.

The modern fix: online notice first, and as a record

The recommendation is concrete, not rhetorical. Where an age assurance system processes personal data, the benchmark should require four things:

  • Controller identity, authority, purposes, rights, and contact provided before identification, biometric capture, inference, or credential presentation, aligned to ISO/IEC 29184 for content and timing.
  • That notice bound to durable evidence of disclosure using the record structure of ISO/IEC TS 27560:2023, so audits and complaints do not depend on the operator's own internal logs.
  • A version-bound notice with defined material-change triggers, each change written to an append-only notice event log with a timestamp and a link to the prior version, so the transparency position at any past moment can be recovered.
  • Where age estimation or inference runs on consent, a consented notice receipt (a two-factor notice, 2fN, to anchor the TS 27560) binding that consent to the exact notice version, the method used, and the retention period.

There is a key milestone made with these comments worth pausing on, because it dissolves the objection age+id verification vendors always raise. You do not need to identify a person to prove you disclosed to them. Canadian expert comment on Clause 6.4.3 makes evidence of disclosure work without an account or a personal identifier, using the ANCR TS 27560 Notice Record Extension. Minimisation and accountability stop being a trade-off. With operational transparency, an individual can see whether age assurance is being used anonymously and whether identification inferences (the metadata) are localised, so the system can hold no more data than necessary and still hold evidential proof.

None of this needs new machinery or a licence. ISO/IEC 27566-1, the age assurance framework, has recently been made free and open access, and it pairs with ISO/IEC 29100, the free and open privacy framework, and with the ANCR TS 27560 Notice Record Extension, the consent record information structure built on the Kantara Consent Receipt. The base of the transparency and consent layer is standardised in ISO/IEC TS 27560:2023; the notice-record extension is being progressed through ISO PWI 26689, backed by a gap analysis of the notice and consent standards. The building blocks are freely available to integrate and adopt now.

Why this matters beyond age

Age assurance is the sharpest test of privacy by default we have. It is the frontline, because it is being deployed under a safety mandate that should hold the standard to a very high bar, not become an excuse that makes "identify everyone" feel responsible. Identify-first, notice-second is not safe, and it carries high privacy risk. If the standard is written identification-first, age checks become a surveillance on-ramp for the whole internet, justified by protecting children while, in effect, dis-intermediating human authority and harming them. If it is written notice-first, the same child-safety goal is met by a system that shows its authority before it asks for anything, and leaves a record anyone can inspect.

This is what an Internet Transparency Code of Practice is for. Age assurance is digital public infrastructure: deployed at internet scale to gate access, it becomes a shared identification layer the whole population passes through. Public infrastructure that enables co-regulated digital identification management needs a matching layer of Digital Public Transparency Infrastructure (DPTI): an open-standards stack that makes the system inspectable, notice-first, and evidence-based, instead of a private practice statement no one can audit. The Internet Transparency Code of Practice is how that transparency infrastructure is co-regulated, so digital identification management stays accountable to the public rather than becoming privatised surveillance.

This is the purpose of Global Privacy Rights: operational transparency mitigates the risk of age assurance technology through digital privacy rights controls. Dynamically transparent authority, and notice of surveillance conditions that is externally inspectable without being identified, is what keeps people safe and secure before age assurance and other identifier-inference technologies are used and a digital ID is demanded.

The regulators want it. The scientists are warning about it.

Two public signals bracket exactly the gap Canada's comments close.

In September 2024, six privacy regulators including Canada's Privacy Commissioner issued a joint statement on age assurance. They require that personal information be "limited to what is necessary for the purpose of age assurance," that the process be "lawful, fair, transparent, and non-discriminatory," and that providers be able to demonstrate their approach is "privacy preserving, effective, and proportionate." A practice statement written as narrative text cannot demonstrate anything after the fact. Meeting the regulators' own bar requires a record of the notice provided, in effect a transparency accord.

In February 2026, a group of cryptographers and security researchers went further, warning that age verification as it is being deployed, privatised and not transparent, creates greater privacy and security risks that outweigh the claimed benefits, and that rather than protecting minors, these systems enable surveillance and support technical exclusion without rights. Their warning is not hypothetical: a month earlier, the age-verified Roblox accounts described at the top of this piece were already for sale on eBay. Identification-first age checks build upon the exact surveillance infrastructure they are meant to protect children from.

Put the two together. Regulators demand demonstrable accountability and data minimisation. Scientists warn that identity-first collection is itself the harm. Notice-first age assurance provides evidence of disclosure that does not require a personal identifier, and it is inclusive. It is the one design that satisfies the first without committing the second. That is what these comments recommend the editors embed.

This is not theoretical

Don't take my word for it, we run it. At globalprivacyrights.org the Controller Identification Record, the versioned notice, and the Notice Event Log are live, publicly resolvable, and machine-readable, with no login and no identification required. You can read who controls the data and what they do with it, watch a disclosure event append itself to the log in real time, and verify the hash that ties the notice to the controller record. First-factor notice, anonymous and auditable, is already serving from a URL.

We have set out what this means for regulators, and how operational transparency gives them inspectable, bilateral oversight, in our statement on operational transparency assurance. And transparency and consent performance can now be scored with the ANCR Transparency Performance Indicators (TPI-R), for physical and digital age assurance alike.

Law and regulators are clear: if an individual does not need to be identified, they should not be. The notice-first record and receipt recommended here is not an invention. It is the oldest human trust technology we have. It already runs in production, on established standards, so embedding it in the benchmark adds little cost. Not a new burden. A known pattern.

Sources and further reading

  • Global Privacy Rights, Operational Transparency Assurance: A Statement for Regulators. globalprivacyrights.org/statement
  • ANCR Transparency Performance Indicators Recommendation ("PII Controller Identification for Valid Consent"), Kantara Initiative ANCR WG, August 2025. kantarainitiative.org
  • ANCR Notice Receipt Extension to ISO/IEC TS 27560:2023, Kantara ANCR WG. kantarainitiative.github.io/ancr-wg
  • Joint statement on a common international approach to age assurance, six data protection and privacy authorities including the Office of the Privacy Commissioner of Canada, September 2024. priv.gc.ca
  • Open letter on age verification, cryptography and security researchers, February 2026. csa-scientist-open-letter.org
  • Age-verified Roblox accounts are already being sold on eBay, Jessica Filby, Dexerto, January 2026. dexerto.com

These expert comments were submitted to the ISO editors. Interested parties can request the working draft through their national body.

The standard is being written now. What it requires, the market builds. Demand the receipt, not the face. This is the moment to require that people can prove their age without being tracked.

Mark Lizar, Global Privacy Rights / 0PN Transparency Lab / Interoperability Expert Group, Co-Founder and Advisor