Site icon Truth on the Market

Proof of Age, Leap of Faith: The EU KIDS Act’s Security Gamble

The European Commission’s proposed EU KIDS Act would bar children under 15 from creating or using accounts on certain social-networking and video-sharing services, with a guardian-controlled option for 13- and 14-year-olds. It would also require providers to build broader safety protections into their services. Both sets of obligations would rely on age assurance—methods for verifying or estimating users’ ages.

Critics have raised concerns about freedom of expression and privacy, and whether the restrictions are proportionate. Michael Veale argues that the drafting is so flawed that the Commission should withdraw the proposal. Researchers also question the maturity of the age-assurance technology it relies on. The underlying justification faces scrutiny, too. Our International Center for Law & Economics (ICLE) colleagues Julian Morris and Ben Sperry, writing with Lura Forcum, argue that the “evidence does not establish that social media broadly causes adolescent mental-health problems.”

We’ll focus on a narrower question. Would KIDS significantly and disproportionately increase the exposure of identity data for children and adults across Europe? Even supporters of age restrictions should want a convincing answer.

The proposal includes privacy and security safeguards. Writing them into law, however, does not demonstrate that providers will reliably implement them—or that the remaining risks will be acceptable. A law intended to protect children should not create a population-scale security problem and leave the existing data-protection rules to clean up the mess.

A Children’s Law With an Adult-Sized Reach

Article 6 of the proposal would bar children under 15 from creating or using accounts on social-networking and video-sharing services that pose specified risks. Article 8 goes further, requiring social networks, video-sharing platforms, online games, artificial intelligence (AI) companions, general conversational chatbots, and app stores to apply protections for minors by default. Providers could relax those protections only after establishing, through age assurance, that a user is an adult.

The Commission’s accompanying analysis acknowledges that age-assurance measures “would be potentially affecting all users.” The French Constitutional Council made the same point when it struck down France’s under-15 ban. As Sperry notes, the council observed that such a prohibition implies “that any person, even an adult, must prove their age.”

That marks a change in direction for European Union (EU) law. Article 28(3) of the Digital Services Act (DSA) states that its duties to protect minors “shall not oblige providers of online platforms to process additional personal data in order to assess whether the recipient of the service is a minor.” KIDS would require that additional processing without amending the DSA provision—a tension Veale rightly highlights. If lawmakers intend to abandon that principle, they should say so explicitly and demonstrate that the added exposure is justified.

Several of the proposal’s provisions would reduce how often users must prove their age, but the initial check would still require processing personal data. Under Article 8, a service could avoid distinguishing adults from children by keeping the protective defaults for everyone. That raises separate concerns about freedom of expression and access to information. It also seems an unlikely choice for most providers. Turning a service into a “universal kids’ playground” would diminish its usefulness for adults. In practice, most services would therefore need to check adult users’ ages, too.

The GDPR Is a Rulebook, Not a Force Field

The Commission’s analysis criticizes services that “force users to upload their identity documents directly to the service” and identifies privacy risks in how providers deploy and operate age assurance. It then cites an external study’s finding that “these risks can be largely mitigated through adherence to the General Data Protection Regulation” (GDPR) and declares: “The proposed Regulation ensures this.”

Alas, the GDPR cannot bear that weight. Its security standard depends on the risks involved. As France’s data-protection authority, the Commission nationale de l’informatique et des libertés (CNIL), puts it, security is “an obligation of means”—a duty to take appropriate precautions. In Natsionalna agentsia za prihodite (C-340/21), the Court of Justice of the European Union held that a breach alone does not establish that a data controller—the organization responsible for processing personal data—used inadequate safeguards.

That reasoning cuts both ways. A breach does not prove GDPR noncompliance, and compliance does not make breaches impossible. Lawmakers who compel population-scale processing must account for imperfect compliance across many organizations and the risks that remain even when everyone follows the rules.

The France Travail case illustrates the compliance problem. Attackers used hijacked partner accounts to access data on everyone who had registered with the French employment service over 20 years. The CNIL fined the agency €5 million in January 2026, noting that “most of the appropriate security measures had been identified by FRANCE TRAVAIL, prior to the implementation of the processing, in the impact assessments, but had not actually been implemented.” Identifying safeguards on paper does little good if an organization never puts them into practice.

The Honeypot Moves Upstream, and Takes Your ID With It

KIDS does include security safeguards that go beyond the GDPR, but they address a different risk from the one that matters most.

A familiar objection to age verification is that it creates “honeypots”—collections of users’ passport copies and other identity documents that make attractive targets for attackers. KIDS would bar age-assurance systems from enabling identification or tracking and require zero-knowledge proofs. These let a website confirm that someone meets an age threshold without learning who they are.

But someone still has to check the identity evidence. The honeypot simply moves upstream, to the systems that enroll users and issue proof of age. A website may learn almost nothing about you while the age-verification process still puts extensive personal data at risk.

The Commission’s own threat model for its age-verification blueprint acknowledges this. It states that “[t]he issuer knows who the user is (it verified their age)” and identifies exposure during enrollment as a separate threat, T-16.

That upstream honeypot can extend well beyond a single database. Identity evidence can accumulate in document images, photographs, biometric templates (digital representations of physical traits), issuance records, fraud-investigation files, logs, backups, customer-support tools, and subcontractors’ systems.

The 2025 Discord incident shows how much those peripheral systems matter. Discord reported that an attacker compromised 5CA, its third-party customer-service provider, potentially exposing government-ID photos of about 70,000 users. The vendor had used those photos “to review age-related appeals.” The attacker reached customer-support records without having to defeat cryptography.

KIDS would require an appeals process, too. Article 29(5) obliges providers to offer a free electronic complaint mechanism for users who believe an age-assurance result is wrong. But it leaves unanswered how providers should resolve those complaints without collecting fresh identity evidence.

Guardian verification opens another channel. For 13- and 14-year-olds using the guardian-controlled option, providers must make “reasonable efforts to verify” that the adult has parental responsibility. As Veale observes, many member states lack digital guardianship records. Verification will therefore often require documents that reveal extensive information about the child.

These systems pose two distinct risks. Accumulated-data risk comes from information they retain. Live-processing risk comes from information passing through them. Each applicant’s data may remain exposed only briefly, while the service processes a steady stream of applicants. A compromised enrollment service could intercept each person’s information before deletion. While retention limits reduce how much data sits in storage, they do not secure the flow of incoming data.

‘Low Risk,’ Provided Everything Goes Right

T-16 provides the most detailed public assessment of enrollment risk. It identifies “retention beyond need, breach of issuer systems, or capture artefacts (images in caches, logs, crash reports) on the device.” It requires implementers to limit issuer retention (“for example, discard document images immediately after the attestation is issued”), remove capture remnants from users’ devices, and conduct and publish a data-protection impact assessment before launch. It rates the remaining risk “Low.”

That rating comes with a substantial qualification. It assumes “that all applicable required actions have been completed correctly by the implementer.” The reference implementation—the sample software others can build on—is itself “not a production-ready service.” The assessment justifies accepting the risk partly because “[a] breach window exists only around the enrolment moment and only at parties that already lawfully process identity data.” It also points to issuers’ existing GDPR obligations.

Each reassurance warrants scrutiny. France Travail shows that lawful processing offers no guarantee of operational security. A brief exposure window for each enrollment can still expose everyone who enrolls during a compromise, and the window opens again with every new applicant. GDPR compliance, meanwhile, does not establish that the remaining breach risk is acceptable.

The reference app’s history illustrates the gap between design and deployment. When the Commission presented it in April 2026, Commission President Ursula von der Leyen called it “technically ready.” Within hours, researchers reported flaws in the published code. The Commission replied that they had tested a “demo version.” “Ready,” apparently, came with qualifications of its own.

Prove the System Works Before Making Everyone Use It

A convincing security case would start by comparing what KIDS would require with current practices—including the document uploads the Commission rightly criticizes—and less intrusive ways to achieve the same objective. How many people would need to enroll for the first time? What additional information would providers collect or transfer, and who would receive it?

The assessment should cover the whole service, from enrollment and issuance through account recovery, fraud checks, complaints, guardian verification, backups, and closure. Article 5 of the proposal already requires independently audited compliance plans for social-networking and video-sharing services designated as very large online platforms. The proposal also requires certification of age-verification solutions. Those mechanisms should include independent testing of complete services—covering deletion, staff and administrator access, compromised suppliers, and interception of incoming data.

That assessment should lead to concrete choices. Where a public authority already holds reliable age information, it should issue a credential that reveals only the age information needed when doing so demonstrably avoids further collection or transfer of identity evidence. The Electronic Identification, Authentication, and Trust Services (eIDAS) Regulation already provides for attestations from public bodies responsible for authoritative records.

Public issuers still need scrutiny. In 2021, an attacker downloaded 286,438 document photos from Estonia’s identity-documents database through a flawed photo-transfer service. Private issuers should likewise face independent evaluation of the entire service, renewed scrutiny after material changes, enforceable retention and subcontracting limits, and plans for handling incidents and closing down safely.

Compulsory use should depend on demonstrated readiness. As drafted, KIDS requires providers to establish existing account holders’ ages within six months after the regulation begins to apply, regardless of whether certified solutions, supervision, and recovery arrangements are ready. Providers should first have working alternatives and accessible recovery processes that do not routinely send users back for another round of document uploads.

Lawmakers also need to resolve how KIDS fits with the GDPR. Giving providers a legal basis to process data does not establish that compelling the processing is proportionate. GDPR Article 6(3) requires the law itself to be “proportionate to the legitimate aim pursued.” Data minimization—collecting and using only what is necessary—should shape the system’s architecture from the outset. That includes asking whether identity evidence needs to leave an authoritative source or the user’s device at all.

The law should also draw a clearer line between permissible age verification and prohibited identification and tracking. A recital asking providers to “limit the creation, by minors, of secondary accounts” already blurs that line. Checking someone’s age and recognizing them when they return are different tasks.

Protecting Children Includes Protecting Their Data

KIDS pursues a legitimate goal—protecting children online. Its privacy safeguards, however, leave significant security risks unresolved. Issuers and subcontractors may still process identity information during enrollment, issuance, appeals, and guardian verification. Short, strictly enforced retention limits may reduce stored-data risks but they still leave incoming data vulnerable. And GDPR compliance alone cannot establish that the system is acceptably secure in practice.

Children and families bear those risks, too. Any assessment of a child-protection law must count the harm it could cause by exposing children’s identity data. Lawmakers need to demonstrate that the added exposure is necessary, minimized, and proportionate, and that enrollment, issuance, complaints, and recovery systems work before making their use compulsory.

A law that asks everyone to prove their age should first prove its own security case.

Exit mobile version