Prove Your Age Without Being Tracked Across the Internet
Age assurance is being standardised reidentification-first and its not safe. Expert comments to the ISO editors in charge of Age Assurance recommend the fix: ensure a notice before identification, and a disclosure you can actually audit.
Age assurance is being standardised identification-first (up until now). Expert comments to the ISO editors recommend the fix: notice before identification, and a disclosure you can actually audit.
Governments around the world are now mandating age checks across large parts of the internet. The intention is child safety. The mechanism, as currently drafted in international standards, quietly asks something else of everyone: present your face, your ID, or a credential first, and find out later, if ever, who collected it, why, under what authority, and where.
That is backwards. This month as an expert, through the the Canadian national body we filed a set of comments in ISO to turn it the right way round.
What was filed
The Canadian expert comments to ISO/IEC SC 27 WG 5 on Privacy and Digital Identity Management, focused on transparency in the working draft of ISO/IEC 27566-2, "Age Assurance Systems, Part 2: Benchmarking." Part 2 is the standard that will define how age assurance systems are measured and compared. What it benchmarks becomes what the market builds.
The comments illustrate a gap, expressed across eight linked clauses: an age assurance system can satisfy the Age Assurance Benchmark's in full and still leave no inspectable record of what was disclosed, when, by whom, under what lawful basis, and with what cross-border scope. Providing individuals with no way to see if they can trust age assurance technologies.
The current Age Assurance standard 27566-1, upon which -2 is focused, still treats notice as narrative text (for analogue privacy risk) inside a practice statement. Typical of analogue (or face to face) data protection rules for notice and consent
Privacy law does not. It requires (digital equivalent) of assurance controller ID, the purposes of processing, the rights of the individual, and contact information to be provided at or before inference, collection (GDPR Articles 12 to 14, Convention 108+ Article 8, PIPEDA 4.3 and 4.8), and it requires the controller to demonstrate afterward that this actually happened (GDPR Articles 5(2) and 7(1)). Narrative text cannot demonstrate anything after the event. It is not operative notice or transparency.
These expert comments to the editors, respectfully,. They recommend one thing: embed co-regulated, Controller identity-management transparency (instead of user-id-transparency) into the benchmark. The reason is blunt. As drafted, the Age Assurance standard is not privacy compliant, and it is not even consent capable. It offers no structure to record consent, so where a method relies on consent, that consent cannot be demonstrated at all.
The modern fix: online notice first, and as a record
The recommendation is concrete, not rhetorical. Where an age assurance system processes personal data, the benchmark should require four things:
- Controller identity, authority, purposes, rights, and contact provided before identification, biometric capture, inference, or credential presentation, aligned to ISO/IEC 29184 for content and timing.
- That notice bound to durable evidence of disclosure using the record structure of ISO/IEC TS 27560:2023, so audits and complaints do not depend on the operator's own internal logs.
- A version-bound notice with defined material-change triggers, each change written to an append-only notice event log with a timestamp and a link to the prior version, so the transparency position at any past moment can be recovered.
- Where age estimation or inference runs on consent, a consented notice receipt (a two-factor notice, 2fN, to anchor the TS 27560) binding that consent to the exact notice version, the method used, and the retention period.
There is a key milestone made with these comments worth pausing on, because it dissolves the objection age+id verification vendors always raise. You do not need to identify a person to prove you disclosed to them. Canadian expert comment on Clause 6.4.3 makes evidence of disclosure work without an account or a personal identifier, using the ANCR extension to TS 27560. Minimisation and accountability stop being a trade-off. With operational transparency, an individual can see whether age assurance is being used anonymously and whether identification inferences (the metadata) are localised, so the system can hold no more data than necessary and still hold evidential proof.
None of this needs new machinery or a licence. ISO/IEC 27566-2 is free and open access. It pairs with ISO/IEC 29100, the free and open privacy framework, and with the ANCR extension to ISO/IEC TS 27560:2023, the consent record information structure built on the Kantara Consent Receipt. The transparency and consent layer is already standardised and now freely available to integrate and adopt.
Why this matters beyond age
Age assurance is the sharpest test of privacy by default we have. It is the frontline, because it is being deployed under a safety mandate that should hold the standard to a very high bar, not become an excuse that makes "identify everyone" feel responsible. Identify-first, notice-second is not safe, and it carries high privacy risk. If the standard is written identification-first, age checks become a surveillance on-ramp for the whole internet, justified by protecting children while, in effect, dis-intermediating human authority and harming them. If it is written notice-first, the same child-safety goal is met by a system that shows its authority before it asks for anything, and leaves a record anyone can inspect.
This is the purpose of Global Privacy Rights: operational transparency mitigates the risk of age assurance technology through digital privacy rights controls. Dynamically transparent authority, and notice of surveillance conditions that is externally inspectable without being identified, is what keeps people safe and secure before age assurance and other identifier-inference technologies are used and a digital ID is demanded.
The regulators want it. The scientists are warning about it.
Two public signals bracket exactly the gap Canada's comments close.
In September 2024, six privacy regulators including Canada's Privacy Commissioner issued a joint statement on age assurance. They require that personal information be "limited to what is necessary for the purpose of age assurance," that the process be "lawful, fair, transparent, and non-discriminatory," and that providers be able to demonstrate their approach is "privacy preserving, effective, and proportionate." A practice statement written as narrative text cannot demonstrate anything after the fact. Meeting the regulators' own bar requires a record of the notice provided, in effect a transparency accord.
In February 2026, a group of cryptographers and security researchers went further, warning that age verification as it is being deployed, privatised and not transparent, creates greater privacy and security risks that outweigh the claimed benefits, and that rather than protecting minors, these systems enable surveillance and support technical exclusion without rights. Their evidence is not hypothetical: age-verified Roblox accounts are already being sold on eBay. Identification-first age checks build upon the exact surveillance infrastructure they are meant to protect children from.
Put the two together. Regulators demand demonstrable accountability and data minimisation. Scientists warn that identity-first collection is itself the harm. Notice-first age assurance provides evidence of disclosure that does not require a personal identifier, and it is inclusive. It is the one design that satisfies the first without committing the second. That is what these comments recommend the editors embed.
This is not theoretical
We run it. At globalprivacyrights.org the Controller Identification Record, the versioned notice, and the Notice Event Log are live, publicly resolvable, and machine-readable, with no login and no identification required. You can read who controls the data and what they do with it, watch a disclosure event append itself to the log in real time, and verify the hash chain that ties the notice to the controller record. First-factor notice, anonymous and auditable, is already serving from a URL.
We have set out what this means for regulators, and how operational transparency gives them inspectable, bilateral oversight, in our statement on operational transparency assurance. And transparency and consent performance can now be scored with the ANCR Transparency Performance Indicators (TPI-R), for physical and digital age assurance alike.
Law and regulators are clear: if an individual does not need to be identified, they should not be. The notice-first record and receipt recommended here is not an invention. It is the oldest human trust technology we have. It already runs in production, on established standards, so embedding it in the benchmark adds little cost. Not a new burden. A known pattern.
Sources and further reading
- Global Privacy Rights, Operational Transparency Assurance: A Statement for Regulators. globalprivacyrights.org/statement
- ANCR Transparency Performance Indicators Recommendation ("PII Controller Identification for Valid Consent"), Kantara Initiative ANCR WG, August 2025. kantarainitiative.org
- ANCR Notice Receipt Extension to ISO/IEC TS 27560:2023, Kantara ANCR WG. kantarainitiative.github.io/ancr-wg
- Joint statement on a common international approach to age assurance, six data protection and privacy authorities including the Office of the Privacy Commissioner of Canada, September 2024. priv.gc.ca
- Open letter on age verification, cryptography and security researchers, February 2026. csa-scientist-open-letter.org
Canada's national body comments were filed through the ISO process. Interested parties can request the working draft through their national body.
The standard is being written now. What it requires, the market will build. This is the moment to require that people can prove their age without being tracked.
Mark Lizar, Global Privacy Rights / 0PN Transparency Lab / Interoperability Expert Group, Co-Founder and Advisor