Why the EU age-verification tool does not solve privacy concerns
An EU legislative proposal for a social media ban will be presented at the State of the European Union (SOTEU) annual address, but the tools which are pitched as “ready” and “privacy-preserving” fail on both counts. Here is a technical account of the shortcomings.
The EU is preparing a proposal for social media bans
The EU Commission will present an EU legislative proposal for a social media ban at the State of the European Union (SOTEU) annual address, Ursula von der Leyen declared in July 2026. She added that the proposal would rely on the same EU age-verification app which she had proudly announced months before as “technically ready and soon available for citizens to use,” but which was quickly ridiculed on both counts.
Confusingly, instead of an app, the Commission had back then published a mere ‘blueprint’, meaning a sample design based on which Member States were themselves invited to build their own app, together with a demo app showing what the end result might look like. The Commission nicknamed this the ‘mini-wallet’, as it recommends basing its technical specifications on those of the eID Wallet, which each government must provide to its residents by the end of 2026.
At EDRi, we argue that there are ways to ensure online safety without resorting to widespread, mandatory age verification. If lawmakers still insist on using age-gates, however, then it’s essential that this be done via tools which respect the highest standards of privacy, cybersecurity and data protection, and which are available to all without discrimination. The Commission promises a tool which supposedly respects these ‘highest standards’, but hasn’t delivered yet. Let’s look at this infrastructure of control whose deployment is unfolding so quickly.
Unlinkability is optional: the shortcomings of batch issuance
The problem starts at the foundation: the mini-wallet relies on the eID Wallet, which already has serious privacy weaknesses. As we explained elsewhere, the European Commission appears to be weakening the privacy protection required by law for the Wallet. The law says the system should “ensure” unlinkability where relevant. In simple terms, this means that the Wallet should not allow anyone to connect your age-gated online activities to your real identity. However, the Commission is changing this requirement to merely “hindering” linkability, meaning this should be difficult, but not necessarily impossible. That’s not a very reassuring starting point for the new age verification measure.
The technical requirements of the age-verification mini-wallet itself do not ensure unlinkability. To provide reliable age verification, a ‘trust anchor’ (a reliable source) is used – here, your state-provided ID, coupled to the mini-wallet via biometric verification. This is not a great start toward anonymous age verification: it will lead to your exclusion if you don’t have ID documents, an adequate smartphone, or do not wish to undergo facial recognition. Yet, it is actually possible to prove to an age-gated service that you are over 18 without revealing your identity or any other data borne on your ID. This can notably be done through a cryptographic mechanism using Zero Knowledge Proofs (ZKPs).
While the technical specifications published by the Commission do suggest using ZKPs, they do not, however, make it mandatory. Indeed, the blueprint uses the optional “SHOULD” every time it refers to Zero-Knowledge Proofs (ZKPs), instead of the mandatory “SHALL”:
• The age-verification apps “SHOULD implement the Zero-Knowledge Proof mechanism specified”.
• The relying parties (the service providers to which we present our age credentials in order to gain access) “SHOULD implement the Zero-Knowledge Proof verification mechanism.”
• In contrast, the attestation providers (which issue the age credential to the wallet) merely “SHALL support batch issuance of Proof of Age attestations,” and “SHALL set the timestamp […] with a precision that limits the linkability information” (emphasis added on ‘limits’).
In other words, the system does not require the parties involved to use the strongest privacy-preserving technologies available.
Instead, the blueprint requires the use of the ‘batch issuance’ technique, which does not protect privacy adequately. Under this scheme, the provider gives you a ‘batch’ of different, single-use credentials; as you provide a different one to each age-gated services you access, these services cannot collaborate and identify which of their users they have in common. Nonetheless, these credentials still contain several pieces of information which are unique to you or your credential and which the provider can link back to you, such as salts, hashes, public keys, signatures and timestamps. If there is cooperation — on a voluntary or mandatory basis — between the provider of the age credentials and the websites on which these are used, these pieces of information would identify you across the different services you use.
This is why, while batch issuance can make tracking people more difficult, it does not make tracking impossible and should not, by itself, be described as a privacy-preserving solution.
Unlinkability can hardly be guaranteed: the shortcomings of Zero-Knowledge Proofs
As noted above, it is problematic that the mini-wallet proposes ZKPs mechanisms without requiring their use: mandating them would have been a good first step. Yet, mandatory ZKPs would not guarantee a privacy-preserving system either.
Consider how the blueprint recommends that “an Attestation Provider also acts as the provider of an Age Verification App to which it issues attestations.” This centralises control over both the issuing and the presentation of age attestations in the same hands, which in turn makes it more less difficult for the issuer (say, the State) to take a peek whenever we present our age credentials to an age-gated service.
Further, the blueprint merely does “not require the Attestation Provider to store any permanent information related to a Proof of Age Attestation.” This is a missed opportunity in terms of data minimisation, because to forestall surveillance, the wording should be: “the Attestation Provider SHALL NOT store any permanent information related to a Proof of Age Attestation.”
Finally, it is also clear that, depending on the system’s actual architecture, linkability could still be achieved based on the app’s back-end transaction handling, the network-level interactions, or on the correlation of the issuance/presentation flow. As underlined by 438 security and privacy scientists and researchers, if the central authority in charge of the system is technically able to connect data points, privacy disasters will quietly unfold every time it will be breached, subpoenaed, or if it ever acts maliciously.
For these reasons, merely mandating ZKPs would not be enough to achieve strict unlinkability. Especially for centralised age-verification systems, the whole system needs to be independently checked to make sure that it minimises data collection, keeps different actors and roles properly separated, limits logging and data retention, and uses privacy-protecting network technologies where necessary.
The problem, therefore, goes far beyond the embarrassing security flaws found in the Commission’s demo of its app, when an independent security review showed that the just-unveiled app had serious, yet basic, security problems.
Twenty-seven shades of repurposable age-verification apps – and counting
As noted above, the whole system needs to be independently checked, if we are to trust the promises of ‘privacy-preserving’ tech. Fortunately, the eIDAS Regulation stipulates that governments must make their eID Wallet apps open source. This means that, in principle, the public should be able to inspect the code and see how the app works. Yet, both client-side and server-side open code matter for public scrutiny, and the Regulation unfortunately adds that where justified, governments may refuse this level of transparency to the “source code for the libraries used, communication channel or other elements that are not hosted on the user device.” Further, this requirement only applies to the national eID Wallet, not to the national age verification apps (which may or may not be based on, or integrated into the eID Wallet).
We’re already seeing governments deploy age-verification systems which contain proprietary code. The Danish app even has proprietary code on the client-side, which makes any meaningful independent public scrutiny of the app impossible. Given the risk that age-verification apps and wallets could be used for the surveillance of people’s online activities, any obstacle to the auditability and scrutability of these systems will impede users’ trust.
On top of that, several governments do not intend to follow the Commission’s proposed technical specifications. This means that we could get 27 shades of age-verification apps, one for each Member State, with different designs, technologies and privacy protections. Each of these systems would need to be independently audited to the extent possible, at its launch but also throughout its lifecycle. This is a lot of work, and if any issue is identified, we will have no leverage — except public shaming — on government(s) to secure better code.
Besides, once the infrastructure exists, the promise of “privacy-preserving age verification” can be revoked or made meaningless overnight. Some EU Member States are already considering systems that would require people to provide their legal identity, not just their age, before they can access social media (Belgium) or video-sharing platforms (Austria).
Age verification marks the end of free access to the internet. We should refuse to build it — whether at EU or national level — while refusing is still an option. Online safety is reachable via other routes.
• Electronic Frontier Foundatio (EFF), Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
• EDRi, The eID Wallet still doesn’t deserve your full trust
• EDRi, Why age verification misses the mark and puts everyone at risk
• EDRi, Age verification gains traction: the EU risks failing to address the root causes of online harm
• Joint statement of 438 security and privacy scientists and researchers on Age Assurance
