Senton
News & Insights10 min read

EU Age Verification in 2026: Can You Prove Your Age Without Revealing Your Identity?

The EU is rolling out a privacy-preserving age verification system by the end of 2026. Here's what it means for your privacy, digital identity and the future of the internet.

A phone showing Age Verified 18+ on a shield, surrounded by cards reading no ID shared, no birth date, no details and your privacy protected

Age verification is becoming one of the biggest privacy questions on the internet. Governments want stronger protections to stop children reaching adult-only content, gambling services and other age-restricted platforms.

But asking millions of people to repeatedly upload passports, ID cards or selfies to websites could create an entirely new privacy problem. The European Union is now trying a different approach.

What you'll learn in this article

  1. What the EU announced
  2. How age verification will work
  3. What anonymous proof of age means
  4. Privacy risks & challenges
  5. What this means for the future

In April 2026 the European Commission urged EU Member States to roll out a privacy-preserving age-verification solution by the end of the year. The system is designed to let someone prove they are above a required age threshold without revealing their exact age, name or other unnecessary personal information to the website they are visiting.

That sounds simple. Technically, it represents a major shift in how online identity could work. Instead of asking who are you?, a website may only need the answer to are you over 18?

Someone at home confirming an age check on their phone while the website waits on the laptop beside them

That difference could become extremely important for the future of online privacy.

The short answer

The EU's proposed age-verification model is designed so that users can prove they meet an age requirement without giving the website their full identity.

The Commission's current blueprint allows an app to confirm something like age over 18: true without sending the person's name, date of birth or other identifying information to the website requesting verification.

The age-verification solution became technically ready in April 2026, and the Commission is encouraging Member States to make compatible solutions available by 31 December 2026.

The bigger question is whether this privacy-preserving approach will work as intended once millions of people, websites and national systems begin using it.

Why is the EU introducing age verification?

There is growing pressure across Europe to prevent minors from easily accessing content and services intended for adults. The EU's Digital Services Act requires online platforms to provide a high level of privacy, safety and security for minors, and age verification is being developed as one tool within that broader effort.

Initial use cases include proving that someone is over 18 before accessing services such as:

  • Adult content
  • Gambling
  • Alcohol-related services
  • Other legally age-restricted online environments

The same technical system could later support different age thresholds, such as proving someone is over 13 or eligible for an age-related service without revealing their exact date of birth.

The privacy challenge is obvious. Age-restricted websites may need to know whether you qualify to enter. They usually do not need to know:

  • Your full name
  • Your birthday
  • Your home address
  • Your passport number
  • Your nationality
  • Your complete identity

A privacy-friendly system should therefore reveal only the information necessary to answer the question.

How would the system work?

The European Commission has published an open technical blueprint that Member States and approved providers can adapt into national age-verification apps. The basic process works in two stages.

An ID card, passport, chip and bank card each crossed out on the way to a phone, which sends only an 18+ confirmation to a website
Everything on the left is used once to set the app up. Only the answer on the right reaches the website.

A two-step process, designed with privacy in mind.

  1. 1 Prove your age to the app Use a trusted source once: a biometric passport, a national eID, a banking app or an offline check.
  2. 2 Prove only the age threshold When a website asks, the app confirms the threshold without sending your name, birthday or the document behind it.

Step 1: Prove your age to the app

When setting up the age-verification app, the user first needs a trusted way to establish their age. According to the Commission, this could involve:

  • A biometric passport or ID card
  • A national electronic ID
  • A trusted third-party app such as a banking app
  • An offline verification process

Once the age has been established, the app is intended to retain only the necessary proof that the user meets the age threshold. The Commission says the app does not need to retain the person's name or birthday for future age checks.

Step 2: Prove only the age threshold

Later, suppose a website needs to confirm that you are at least 18. Instead of uploading your passport to that website, the app can provide a simple confirmation: over 18: yes.

The website gets the answer it needs without receiving your full identity. That is the core privacy idea behind the system.

What is anonymous proof of age?

Traditional online verification often works by sharing documents. A website might ask you to upload a passport, a driver's licence, a national ID or a selfie. That gives the verifier much more information than it needs.

If the only requirement is that you are over 18, handing over your complete passport is a bit like showing your entire bank statement just to prove you have twenty euros.

Privacy-preserving age verification attempts to minimise that disclosure. The Commission describes its approach as based on anonymous proof-of-age technologies, where the verifier receives confirmation of an age threshold rather than the user's complete identity. Its technical overview says the blueprint also incorporates zero-knowledge-proof technology.

What are zero-knowledge proofs?

The name sounds complicated, but the idea is straightforward. A zero-knowledge proof allows one party to demonstrate that something is true without revealing all of the underlying information used to prove it.

Imagine proving I am over 18 without saying my name is John Smith, I was born on 6 March 1992, here is my passport number and here is where I live. The verifier only gets the answer relevant to the transaction.

A phone holding name, date of birth, location and document details, with only an over-18 confirmation passing through to the website
Every attribute stays on the left. One fact crosses over.

That principle is sometimes called selective disclosure, and it could become important far beyond age verification. The same concept could eventually allow someone to prove that they:

  • Hold a valid driving licence
  • Live in an EU Member State
  • Have a particular professional qualification
  • Are entitled to a certain service

without automatically revealing every piece of information contained in the original credential.

How this connects to the EU Digital Identity Wallet

The age-verification system is not being developed in isolation. It uses technical specifications compatible with the upcoming European Digital Identity Wallet.

EU Member States are required to offer at least one European Digital Identity Wallet to residents by the end of 2026. Those wallets are intended to let people securely store and selectively share digital identity credentials and electronic attestations.

The age-verification tool can operate as a standalone app or eventually be integrated into these national wallets. The Commission describes the current implementation as a kind of smaller interim wallet that follows the same technical direction as the broader identity system.

That makes age verification one of the first real-world demonstrations of how privacy-preserving digital credentials might be used at scale.

Why not simply upload an ID?

Because identity documents contain far more information than most websites need. A passport or national ID can contain:

  • Full legal name
  • Photograph
  • Birth date
  • Document number
  • Nationality
  • Sex
  • Signature
  • Other identifying information

If thousands of websites start storing copies of those documents, the consequences of a breach become much more serious.

It also creates a tracking problem. If the same identity document or persistent identifier is repeatedly used across websites, those interactions could potentially become easier to correlate.

Someone holding a phone showing an 18+ confirmation while the laptop in front of them shows a green tick
The website gets a tick. It never sees the document that produced it.

A good privacy-preserving age-verification system should therefore follow one basic principle: reveal the minimum amount of information necessary for the transaction. For an adult-content website, the answer may genuinely need to be no more than 18+ = yes.

Could it still create privacy risks?

Yes. The design principles may be privacy-preserving, but implementation matters. There are several questions worth watching as the system rolls out.

Can websites link repeated age checks?

Even if a website never learns someone's legal identity, a poorly designed verification system could still allow repeated interactions to be linked together. The Commission says its approach includes measures designed to prevent tracking, but the effectiveness of those protections will ultimately depend on real implementations and scrutiny.

Who issues the age credential?

Users first need a trusted organisation to confirm their age, and that initial verification inevitably involves some form of identity or age evidence. The privacy goal is therefore not to eliminate verification entirely, but to prevent that full identity from being unnecessarily disclosed again every time the person visits an age-restricted website.

Will websites collect additional data anyway?

Age verification does not stop a website from using cookies, fingerprinting, analytics or other tracking technologies. Proving your age privately does not automatically make the rest of your browsing session private. These are different layers of privacy.

What happens if the system becomes mandatory everywhere?

There is also a broader policy question. A tool designed for genuinely age-restricted services could raise different concerns if websites begin demanding proof of age where it is not actually necessary. Privacy-preserving technology can reduce data exposure, but it cannot answer the policy question of when verification should be required in the first place.

Can a VPN bypass EU age verification?

The European Commission's own guidance acknowledges that age-verification systems may sometimes be technically circumvented, including through methods such as using a VPN. It argues that this does not eliminate the value of age controls as a barrier to minors reaching restricted services.

But this needs an important clarification. A VPN changes the network location or IP address seen by online services. It does not create a legitimate proof that someone is over 18.

If a service requires cryptographic age verification, a VPN and an age credential solve two completely different problems:

  • A VPN protects or changes the network layer.
  • Age verification proves eligibility based on age.

One should not be confused with the other.

Why this matters beyond adult websites

The most interesting part of the EU's initiative may not actually be age verification itself. It is the broader idea that digital identity could become attribute-based rather than identity-based.

Today, online services frequently ask for far more information than they need. In future, a privacy-preserving identity system could let users prove individual facts:

  • Over 18 instead of “here is my passport”
  • Licensed to drive instead of “here is every field on my driving licence”
  • Eligible for this service instead of “here is my entire identity profile”
A traveller in a station lounge checking a list of confirmed credentials on their phone, each one a single fact rather than a full identity
The same idea, applied more widely: a list of facts you can prove, one at a time.

That is a fundamentally different model for digital identity.

Senton's perspective

Senton is being built around a broader principle of data minimisation: digital services should only receive information that is genuinely necessary for the function being performed.

The EU's approach is interesting precisely because it follows a similar privacy principle. A website that needs to know whether someone is an adult does not necessarily need to know who that person is.

The strongest privacy systems do not merely promise that organisations will avoid using unnecessary information. They try to design the system so that unnecessary information is never disclosed in the first place. That is a much stronger foundation for digital privacy.

Final thoughts

The internet needs to solve two legitimate problems at the same time. Children should be better protected from services and content that are not appropriate for them. Adults should not have to surrender their full identity every time they access something age-restricted.

The European Union's 2026 age-verification initiative is one of the most ambitious attempts yet to reconcile those goals. Its central idea is promising: prove the fact that matters without revealing the identity behind it.

Whether the system ultimately delivers that level of privacy will depend on implementation, independent scrutiny and how broadly age verification is eventually required. But if it works, the bigger impact could extend far beyond proving age. It could demonstrate what digital identity looks like when services ask for less information rather than more.

What an ID upload reveals
  • Full legal name and photograph
  • Exact date of birth
  • Document number and nationality
  • Everything else on the page
What the site actually needs
  • Whether you meet the threshold
  • Nothing that identifies you
  • Nothing it has to store
  • Nothing it can correlate later

Frequently asked questions

The European Commission has created the technical framework and recommended that Member States make compatible solutions available by the end of 2026. How it is deployed may vary between Member States, from standalone apps to integration into national European Digital Identity Wallets.