Table of Contents
- Executive Summary
- Introduction
- Age Assurance and Age Verification
- Pursuing Kids Safety through Online Age Verification Legislation
- Challenges with Age Verification
- Social Media Platforms and Age-Appropriate Practices
- The Path Forward: Minimizing Potential Ramifications of Online Age Verification
- Appendix
Age Assurance and Age Verification
While there are 鈥渘o universally recognized legal definitions鈥 for these terms, age assurance is generally used as an umbrella term to describe online operators鈥 methods to vet the ages of users and implement age restriction laws online.1 Any鈥攐r a combination of the following鈥攁ge assurance techniques can be used to determine a user鈥檚 age range or a binary statement about their age (such as this person is or is not 21+ years old):
- Age-gating/age-screening, or asking a user to self attest their age through checking a box or inputting a date of birth to confirm they are or older than the necessary age to access content;
- Age estimation, or estimating a user鈥檚 age by analyzing their online profile, activity, history, or facial data;
- Third-party verification, or trusting a third-party to verify a user鈥檚 age, using methods such as referencing linked accounts, vouching of age from parents or other users, or inspecting hard identifiers such as government-issued identification; and
- Age verification, or directly inspecting identifiers such as government-issued identification or biometric data to confirm a user鈥檚 age.
The terms age assurance and age verification are often used interchangeably鈥攖hough this can cause confusion, particularly when implementing legal mandates. Age assurance includes a variety of methods to 鈥渆stablish, determine, or confirm a user鈥檚 age with some level of confidence,鈥 according to the Digital Trust & Safety Partnership.2 These methods offer varying degrees of accuracy, authenticity, reliability, and verifiability. Age verification is a subset of age assurance, which implies authenticating and confirming a user鈥檚 age with a higher level of certainty, often through the use of government-issued identification. As such, age verification in practice often means identity verification, requiring a user to disclose their identity beyond their age.
It is important to note that identity verification has implications for user privacy that differ from the implications of age verification. Identity verification requires a user to provide personally identifiable information about themselves to establish and verify their identity. Or as the National Institute for Standards and Technology (NIST) defines it, 鈥渢he process of confirming or denying that a claimed identity is correct by comparing the credentials…of a person requesting access with those credentials previously proven…and associated with the identity being claimed.鈥3
On the other hand, age verification can simply mean establishing or verifying a person鈥檚 age. The Age Verification Providers Association (AVPA) defines age verification as 鈥渢he process of checking the age of an internet user, without necessarily needing to know their identity.鈥4 This distinction around identity is critical. Requiring a user to disclose their identity is in itself a privacy intrusion, and online handling and processing of data can put personal information at risk. Additionally, forced identity disclosure can create a chilling effect on speech and exclude people who lack appropriate identification from online spaces and services.5 Online operators implementing age restrictions currently must rely on either age assurance techniques or age verification through the use of a government-issued ID鈥攚hich in practice poses the same challenges and risks as identity verification. To help maintain these distinctions, this report will use strict age verification to refer to age verification methods that do not require verifying a person鈥檚 identity. However, the reality is that limitations in today鈥檚 technology do not enable this type of strict age verification.
Age Verification Methods
Young online users are subject to the Children鈥檚 Online Privacy and Protection Act (COPPA), which requires online operators to obtain parental consent for their collection, use, or disclosure of personal data for children under 13 years old.6 To, presumably, avoid being subjected to COPPA requirements, social media platforms鈥攁s well as many other websites鈥攐ften require account holders to be older than 13 years of age.
As such, current age assurance practices mimic the approved methods of parental consent outlined by the Federal Trade Commission鈥檚 COPPA standard for acceptable methods of obtaining parental consent.7 These methods include signing and submitting a consent form; using a credit card, debit card, or online payment system; calling a toll free number; connecting via video conference; providing a copy of government-issued ID that can be checked against a database; answering multiple knowledge-based questions; and verifying a photo ID with a real-time photo using facial recognition technology.
Each age assurance method and implementation strategy comes with its own trade-offs for user rights, data privacy, and security. Below is a non-exhaustive survey of age assurance methods, categorized by the underlying age assurance techniques outlined above. These methods are listed generally in order of lowest to highest level of assurance, broadly reflecting AVPA鈥檚 levels of age assurance and levels of assurance outlined in NIST鈥檚 Digital Identity Guidelines.8 However, levels of assurance will vary based on accompanying implementation practices.
Citations
- Eric N. Holmes, Online Age Verification (Part I): Current Context (Washington, DC: Congressional Research Service, 2023), .
- Age Assurance: Guiding Principles and Best Practices (Washington, DC: Digital Trust & Safety Partnership, 2023), .
- 鈥淚dentity Verification,鈥 in Computer Security Resource Center Glossary, National Institute of Standards and Technology, .
- 鈥淲hat is age verification?鈥 Age Verification Providers Association, 2024, .
- David L. Hudson, Jr., 鈥淐hilling Effect Overview,鈥 Foundation for Individual Rights and Expression, .
- Child Online Protection Act of 1998, Pub. L. NO.105-277, 112 Stat.2631-736 (1998), codified at 47 U.S.C.搂 231, .
- 鈥淐hildren鈥檚 Online Privacy Protection Rule: A Six-Step Compliance Plan for Your Business,鈥 Federal Trade Commission, .
- 鈥淚nternational Standards for Age Verification,鈥 Age Verification Providers Association, ; Paul A. Grassi, Michael E. Garcia, and James L. Fenton, NIST Special Publication 800-63-3 Digital Identity Guidelines (Gaithersburg, MD: National Institute of Standards and Technology, June 2017), .