A website asks if you’re over 18. You click yes.
That proves very little, so the next screen asks for a passport or identity card. Suddenly, a platform that only needed one fact may receive your full name, photo, date of birth, document number and nationality. That’s a lot of personal data for a yes-or-no question.
The EU is working on a privacy-first age-verification tool. It’s designed to confirm that you meet an age limit without showing the platform who you are. Sounds science-fiction, but it’s reality – it became feature-ready in April, and it’s now in the national pilot work phase.
The website may only need one answer
Age verification and identity verification often get pushed into the same process. They’re not the same thing.
A video platform may need to know that a viewer is over 18. An online shop selling alcohol may need the same confirmation. Neither automatically needs the person’s exact birthday.
The EU approach uses a digital credential that reveals one required attribute – that this person is over 18.
The platform doesn’t receive the date of birth behind that answer. It doesn’t receive a passport scan either. This is known as selective disclosure. The credential may contain more information, but the user shares only the part the service needs.
Someone still has to verify the age
The proof doesn’t appear from nowhere.
A user first receives the credential through a trusted source. That may involve a national electronic identity system, passport, identity card, banking app or an in-person check through an approved provider.
Once issued, the credential can be used later without sending the original document to every website.
That changes the risk quite a bit. Uploading an ID takes a few seconds. Most people have no idea how long the copy stays in a database, who can access it or what happens if the platform gets breached three years later.
With a digital credential, the full identity check happens once. Later services receive only the proof they actually asked for.
Zero-knowledge proofs handle the clever part
The technical blueprint uses zero-knowledge proof cryptography.
The name sounds more dramatic than the result. One system proves that a statement is true without revealing the information used to prove it.
For age verification, the statement could be “this user is over 18.” The platform receives a valid confirmation but doesn’t see the user’s name, birth date or identity document.
The design also aims to stop separate websites from matching the same user through a shared identifier. A gambling site, social network and alcohol retailer shouldn’t be able to compare tokens and work out that the same person visited all three.
That’s the useful part. The proof confirms eligibility without quietly becoming another tracking tool.
Age-restricted platforms still need more than one check
A trusted gaming platforms like Bet Jordan needs reliable proof that its users meets the age requirements. Asking for too little creates an obvious problem. Asking for every available identity detail creates another one.
An anonymous over-18 credential could answer the age question early in the process without requiring a passport image.
It wouldn’t remove every identity check from online gambling.
Licensed gambling operators still need to identify customers. There are anti-money-laundering (AML) requirements, payment controls and fraud checks that rely on a player’s real identity.
So the distinction matters. Privacy-preserving verification can confirm age without revealing identity, while the operator may still need identity information later for other legal reasons.
The system reduces unnecessary disclosure. It doesn’t make those other duties disappear.
One credential could replace repeated uploads
The European Commission describes the current system as a mini wallet. It uses the same technical base as the forthcoming European Digital Identity Wallets, which EU Member States are expected to provide.
The age function can work as a separate app first and later become part of the wider wallet system.
In practice, someone could verify their age once through a trusted issuer, then present proof to several services. No repeated passport photos. No trying to remove glare from the document number while balancing the card on a kitchen table.
The same system could – and will probably have to support different thresholds, depending on the service and local rules. Especially with so many European countries considering restricting children’s access to social networks.
The design still has weak points
Privacy-preserving doesn’t mean foolproof.
A minor could use an adult’s phone. A compromised device might present someone else’s credential. Platforms still need to recognise trusted issuers and reject copied, expired or manipulated proofs.
The blueprint deals with some of this through signed credentials, trusted lists and app-based checks. The broader result will still depend on how Member States and private companies implement it.
France, Denmark, and Greece are some of the countries involved in pilot work during 2026.
Access may also be uneven at first. The blueprint currently supports Android and iOS, while other platforms remain under consideration. People without a compatible device will need another route.
And old habits may survive. A site could request an anonymous age proof, then ask for a full birth date on the next screen because some forgotten database field still demands it.
The question may finally match the answer
The EU blueprint is technically ready, but it isn’t yet available to everyone across Europe. Member States and private providers still have to deploy and connect their systems, with broader availability recommended by the end of 2026.
The core idea is simple enough.
The platform asks whether you’re old enough. Your device proves that you are. The platform gets that answer, rather than a passport photo it never really needed.



