Prove Your Age, Not Your Identity: Europe’s Privacy Test for the New Internet
Europe is pushing for stronger age rules online, challenging social platforms to implement privacy-preserving age assurance without demanding excessive personal data.

Europe wants stronger age rules online. The difficult part is proving someone is old enough without forcing millions of people to hand social platforms passports, dates of birth or unnecessary personal data. The EU KIDS Act makes that privacy challenge impossible to ignore — and Ireland’s emerging digital-wallet approach offers a glimpse of what a better model could look like.
Key takeaways
- The European Commission proposed the EU KIDS Act on 17 September 2026; it is a proposal and is not yet final EU law.
- The proposal sets 15 as the EU-wide age for creating an autonomous social-media account and is built around safety by design, age assurance, parental responsibility and stronger enforcement.
- Privacy-preserving age assurance is different from full identity verification: a service may only need to know that a person is above a threshold, not who that person is.
- Ireland has been developing a digital identity wallet capable of proving an age condition without necessarily sharing a full date of birth with the online service.
- The central policy challenge is now clear: child protection must improve without normalising unnecessary identity collection or surveillance.
The internet is approaching an identity moment
For years, online age gates often amounted to little more than a box asking users to enter a date of birth. That model is increasingly difficult to defend when the service behind the box can expose children to adult content, addictive design, unwanted contact or other age-inappropriate experiences.
Europe’s response is moving quickly. On 17 September, the European Commission adopted its proposal for the EU KIDS Act. The proposal would create a common EU framework for children’s access to certain social networks and video-sharing services, place more responsibility on providers to demonstrate that services are age-appropriate and safe by design, and make age assurance a central part of the system.
But stronger age checks create their own risk if implemented badly. An internet in which every website or app asks for a passport, identity card or complete date of birth could solve one problem by creating another.
That is why the most important phrase in the current debate may be “privacy-preserving age assurance.”
Age assurance is not the same thing as identifying everybody
There is an important distinction between proving an attribute and proving an identity.
Imagine a service needs to know only whether a user is 18 or older. A privacy-preserving system can, in principle, return a simple answer — yes, the age threshold is met — without telling the service the person’s name, home address, exact birthday or government identifier.
That principle is already visible in Europe’s digital-identity architecture. The European Commission’s age-verification work is designed around proving an age threshold while minimising the information disclosed to the online service. Ireland has also been developing a digital wallet aligned with European standards. The Irish Government told RTÉ earlier this year that such a wallet could confirm only what is needed for a particular transaction — for example, proving age without sharing a date of birth — and said wallet or credential use would not be tracked.
That is a materially different proposition from uploading an identity document directly to every social platform a person wants to use.
Why this matters for adults too
Child online safety is the reason age assurance is receiving political urgency, but the privacy architecture will affect adults as well.
If platforms need reliable evidence that a user is above a threshold, every adult may eventually encounter some form of age check. The design question therefore cannot be reduced to “how do we identify children?” It is also “how do we allow adults to prove eligibility without unnecessarily identifying themselves?”
Data minimisation matters because identity data is valuable and sensitive. The more services that collect it, the more places exist where it can be misused, breached, correlated or retained beyond its original purpose.
A strong age-assurance system should therefore answer the narrowest possible question with the least possible information.
Ireland is already testing the boundaries of the debate
Ireland is particularly important because it sits at the intersection of European technology regulation, platform enforcement and digital-identity development.
Coimisiún na Meán opened its first formal investigation under Ireland’s Online Safety Code on 8 September 2026, examining concerns about X’s implementation of age-assurance mechanisms and parental controls. The opening of an investigation does not establish that a breach occurred, but it demonstrates that age assurance is no longer merely a theoretical policy discussion in Ireland.
Under the Online Safety Code, age assurance is required in relevant circumstances to help prevent children from encountering categories of harmful video content including pornography and extreme or gratuitous violence.
At the same time, Ireland’s digital-wallet debate has attracted legitimate civil-liberties concerns. Earlier proposals around broader use of the Public Services Card prompted criticism from privacy groups. That debate is useful rather than inconvenient: public trust in age assurance will depend on strict limits around purpose, data sharing, retention and tracking.
The KIDS Act changes who has to prove what
One of the most consequential ideas in the Commission’s KIDS Act proposal is a reversal of responsibility. The Commission says providers would have to show that services are age-appropriate and safe by design.
That matters because children and parents have historically carried a large share of the burden: find the right setting, recognise the dangerous interaction, understand the algorithm, report the content, or discover that a child has bypassed an age gate.
A safety-by-design model asks a different question: what did the service do before the harm occurred?
Age assurance is one part of that answer, but it cannot be the entire answer. A platform that verifies age perfectly but still uses risky defaults, weak contact controls or inappropriate recommendations has not solved the wider safety problem.
What good age assurance should look like
A credible system should follow several principles.
First, proportionality. A low-risk service should not automatically demand the same evidence as a high-risk adult environment.
Second, data minimisation. If the platform only needs an age threshold, it should not receive a complete identity profile.
Third, separation of functions. Where possible, the party establishing an age attribute should not give the destination service more personal information than it needs.
Fourth, security and deletion. Any sensitive data used during an assurance process should have clear security, retention and deletion rules.
Fifth, accessibility. Age assurance must work for people who do not have the newest phone, a particular document or an easy digital-identity path.
Finally, accountability. Users should know what was checked, what information was shared, and how to challenge mistakes.
Where Safegram fits — live, developing and planned
Safegram’s direction is relevant to this debate because the platform is being built around verified participation, privacy and safer communities rather than anonymous reach at any cost.
Live Safegram functionality includes end-to-end encrypted chat, verification layers for users and businesses, Safegram Exchange functionality and creator/business tools. Safegram’s product architecture also includes safety-oriented account controls.
Safegram’s teen and family safety model is designed around stronger separation between teens and adults in discovery and messaging, age-aware access and family safety notifications without giving family members access to private message content. Some individual elements of that architecture may remain under implementation or evolve as testing and European requirements develop, and should not be represented as universally live unless confirmed in the production build.
Privacy-preserving age assurance should be treated the same way: it is an important direction for safer platforms, but Safegram should not claim a particular government-wallet or EU age-verification integration is live unless that integration has actually been implemented and verified.
The opportunity is to build the principle into the product: verify what is necessary, expose as little personal information as possible, and make safety controls understandable to the people using them.
The next internet should know less, not more
There is a false choice at the centre of much of the age-verification debate: either leave children exposed or identify everybody online.
Europe now has an opportunity to demonstrate a third model.
A teenager can receive stronger protection. A platform can know that a user belongs in an age-appropriate experience. A parent can have meaningful tools. And an adult can prove an age threshold without broadcasting an identity across the internet.
If policymakers and technology companies get that architecture right, age assurance could become something unusual in technology policy: a safety mechanism that actually reduces the amount of personal information companies need to know.
Frequently asked questions
Is the EU KIDS Act already law?
No. The European Commission adopted the proposal on 17 September 2026. It must proceed through the EU legislative process, and the final text may change.
What age does the proposed KIDS Act set for social media?
The Commission says the proposal would prevent children under 13 from holding social-media accounts and establish 15 as the EU-wide age for opening an autonomous account, with a gradual approach and parental responsibility between those points.
What is age assurance?
Age assurance is the broader process of establishing or estimating whether a person meets an age requirement. It can include several technical approaches and does not necessarily require revealing a full identity.
Is age assurance the same as uploading a passport?
No. Privacy-preserving systems can be designed to prove only an age threshold. The exact method depends on the service and legal framework.
Will Ireland’s digital wallet be mandatory?
Ireland is required under EU rules to make a European Digital Identity Wallet available, but government statements reported by RTÉ have said use of the wallet will not be mandatory. Specific deployment of age-verification functions can still evolve.
Can age checks alone make social media safe for children?
No. Age assurance can help create age-appropriate access, but safety also depends on product design, contact controls, recommendation systems, reporting, moderation, privacy and enforcement.
Does Safegram currently use Ireland’s government digital wallet for age verification?
Safegram should not be described as having a live government-wallet integration unless that integration is confirmed in production. Safegram’s current direction is privacy-first verification and age-aware safety, with further technical integrations subject to implementation and regulatory requirements.
Source references
-
European Commission, “EU KIDS Act to restrict social media platforms’ access to children in the EU”, 17 September 2026; updated 22 September 2026.
-
European Commission, “Proposal for EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy”, 17 September 2026.
-
European Commission, KIDS Act policy overview, updated 18 September 2026.
-
RTÉ News, “One week off social media: Would an Australia-style ban work?”, 5 March 2026 — Irish digital-wallet and privacy-preserving age-verification details.
-
RTÉ News, “Media watchdog to investigate X over age verification, parental control concerns”, 8 September 2026.
-
Coimisiún na Meán, Online Safety Framework and guidance on illegal/harmful content.
-
RTÉ News, “Concerns over use of Public Services Card as age ID”, 15 April 2026 — civil-liberties concerns and Irish identity-policy context.
More from Safegram
Try Safegram
Privacy-first social and a verified marketplace, built in Dublin.