
How does age verification work - and what does it keep?
- WeThePurple
- Proteggiti
- 5 min di lettura
Four methods, and they are not equivalent: ID upload, facial age estimation, third-party record checks, and identity wallets that prove 'over 18' without revealing a name. The question to ask an age gate is not how accurate it is, but what it stores.
Age checks used to be a checkbox saying you were over 18. That era is closing: the UK, several US states and Australia now require platforms to actually verify age for some content, and the platforms have had to pick a method. Which one they pick decides how much of your identity leaves your hands — and the methods differ far more than the outcome suggests.
There are four broad approaches, and they are not equivalent.
Uploading an ID document is the one people picture. You photograph a passport or driving licence and a provider reads it. It is the most accurate and the most exposing: a document number, a full name, a date of birth and an address all travel to prove a single yes-or-no fact. Ask what happens to the image afterwards — reputable providers delete it within minutes of extracting the age, and say so in writing.
Facial age estimation points your camera at your face and a model guesses your age bracket. No document leaves your device in the better implementations, and some run entirely on the device. The trade-off is accuracy at the boundary: estimating whether someone is 17 or 19 is exactly where these systems are least reliable, and error rates are not uniform across skin tones and ages — a documented weakness of face-analysis systems generally.
Third-party or credit checks confirm your age against records someone already holds: a mobile operator that knows your contract is adult, a bank, an electoral roll, a credit reference agency. Nothing new is created, but a new party learns you visited the site asking.
Digital identity wallets are the approach designed to fix the problem rather than manage it. A trusted issuer signs a credential that says only *this person is over 18*, and you present that assertion — not your birth date, not your name. The site learns one bit of information. This is the model behind the EU digital identity framework and several national schemes, and it is the only one where verifying does not mean disclosing.
The question worth asking of any age gate is not "is it accurate" but "what does it keep". A system that verifies you correctly and stores your passport scan for a year is worse for you than one that guesses your age bracket on your own phone and forgets it. Accuracy and exposure are separate axes, and the debate usually confuses them.
What to look for, practically. Does the site name its verification provider — a provider that can be looked up is a provider that can be held to something. Is there a stated retention period, in days rather than in vague terms. Is there an option that does not involve uploading a document. And does the check happen once per account or repeatedly, because each repetition is another copy of your identity in motion.
And the part rarely said out loud: an age gate is a data collection point sitting between an ordinary person and content they are legally entitled to see. It may be justified. It is still a new place where identity accumulates — and the sites least able to protect it are often the ones legally obliged to install it.


