This statement outlines key principles for designing GDPR-compliant age assurance systems. It emphasizes the need for proportionality, data protection by design, and risk-based assessments to ensure the least intrusive methods are used while balancing safety and privacy. The document highlights the application of Articles 5, 25, and 32 of the GDPR in online services requiring age assurance, such as minimum age checks for legal acts, services, and goods that may pose risks to children. DPIAs are recommended for high-risk processing activities.
Author: European Data Protection Board (EDPB)
Status: Adopted / Published
Adoption date: 2025-02-11
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Other official document