In today’s digital age, ensuring the safety of children online has become an increasingly complex issue that demands our attention. A survey conducted by Common Sense Media in 2020 revealed that children in the United States, ranging from infancy to eight years old, typically spend an average of two-and-a-half hours per day engaging with various forms of “screen media.” The widespread use of personal devices by children to access the internet has further amplified the need for safeguarding measures like age verification. The COVID-19 pandemic has only accentuated this trend, as children rely on digital connectivity to communicate with their families, teachers, and friends. Many children now have their own social media accounts on platforms like Snapchat or TikTok, and some even have their own email addresses.
The dynamic and constantly evolving world of social media presents a diverse range of platforms that offer a wealth of information and countless opportunities for engagement. However, it also exposes young and vulnerable individuals to inherent risks. Inappropriate or harmful content, such as self-harm promotion, adult content, race or religion-based abuse, and cyberbullying, pose serious threats to children’s well-being.
Compounding these risks is the fact that many individuals, including children, participate in the digital sphere without proper identification, making identity and age verification a significant challenge across the industry. Considering that a government-issued ID is primarily necessary for activities like driving and age-restricted purchases, the need for children to obtain such an ID is significantly diminished. Conversely, the unlawful collection of personal data from minors raises concerns about the potential misuse of information for targeted and malicious advertising.
The discussion surrounding robust, privacy-preserving age verification for social media and similar platforms holds significance not only for the industry but also for upholding parental rights and creating a safer online environment. When implemented alongside a resilient legal framework and well-crafted regulations, age verification solutions present a practical approach to fostering a secure digital ecosystem.
In this blog post, we will take a comprehensive look at age verification and its pivotal role in championing child safety online. Our focus will be on exploring the legal landscape pertaining to children’s data privacy, with a specific emphasis on the United States’ Children’s Online Privacy and Protection Act (COPPA) and the UK’s Online Safety Bill. By gaining a thorough understanding of the existing regulatory frameworks, readers will acquire valuable insights into how age verification technologies can contribute to creating a secure digital environment for children.
Age Verification and Regulatory Framework
While a reliable age verification technology solution is undeniably crucial, it alone cannot fully address the intricate challenges of safeguarding children in online spaces. To effectively address these issues, it is imperative to combine technological advancements with carefully crafted legislation. This harmonious integration ensures widespread compliance and facilitates the successful implementation of age verification and content filtering practices. Regulations such as the Children’s Online Privacy and Protection Act, more commonly known as COPPA, not only impose legal obligations but also establish a solid structure that fosters responsible behavior and holds all relevant stakeholders accountable for shielding children from potential online risks.
What is COPPA?
The Children’s Online Privacy and Protection Act (COPPA) is a United States federal legislation that imposes certain requirements on digital services to protect the privacy of children under the age of 13. This law applies to all websites, including social media platforms, that collect data from children under the established age threshold. While COPPA does not regulate online content specifically, it mitigates risks to children by putting parents in control of how their children engage with the internet and requires that operators subject to the law obtain Verifiable Parental Consent (VPC) before collecting a child’s Personally Identifiable Information (PII) online.
Enacted by the U.S. Congress in 1998, COPPA officially took effect in April 2000. It was developed as a response to growing concerns about the risks posed to children’s safety and well-being in the digital landscape. These concerns encompassed issues such as the commercialization of children’s data, child predation, and exposure to age-inappropriate content.
As legislation often lacks specific implementation details, it is up to the respective government agency to determine the necessary steps. In the case of COPPA, the Federal Trade Commission (FTC) has taken on the responsibility of defining and clarifying these requirements. To support website operators in meeting their obligations under the legislation, the FTC has developed comprehensive guidelines. These guidelines serve as invaluable resources for promoting compliance and safeguarding children’s privacy. The following are key recommendations outlined by the FTC for website operators:
- Create clear and transparent privacy policies.
- Obtain verifiable parental consent before collecting personal information.
- Implement data security measures to protect children’s information.
- Provide ongoing parental control options for managing and modifying data.
The FTC explicitly states that parents have the right to request the deletion of their child’s personal information but do not possess the authority to make any other modifications to the information.
COPPA establishes a foundational level of protection by empowering parents to tailor online experiences according to their children’s specific needs. Simultaneously, it mandates online service providers to establish explicit guidelines for services targeted at children, ensuring a safer and more secure online environment.
However, the legislation has faced criticism from various sectors including industry, academia, and civil liberties organizations. One major concern mentioned is COPPA’s reliance on Verifiable Parental Consent (“VPC”), as these organizations claim VPC can struggle to distinguish between children and adults in the online realm.
The facts in age verification show the opposite, however. Verification of adults is effective whether through the utilization of electronic data or the use of electronic document verification. It is used in banks, alcohol retailers, tobacco marketers, and online sportsbooks and iGaming.
Every day, online verification of adults occurs in the online gambling industry under the review and scrutiny of US state governments. These KYC and age verification services offered by Aristotle Integrity actively keep underage users off these sites. For COPPA, Integrity provides VPC to actively validate parents (18+) and promote the rights of the parents over their child’s PII, granting the parent the ability to determine if these websites get access to that PII.
Critics also claim that these mechanisms for obtaining parental consent often result in certain families being excluded from accessing online services. With the myriad of options available from data, to document, to video, there is no reason why a site could not reasonably offer a solution to their parents to become verified. While children under 13 can legally provide personal information with parental permission, numerous websites, including social media platforms and others that collect substantial personal data, choose to offer access to children under 13 without parental approval by accepting the youths’ self-assertion of 13 years of age. Instead of addressing underage users claiming older ages, they refuse to address the misstatement of this fact: users under 13 years of age are a substantial piece of their audience.
The final claim that VPC does not work is primarily due to the “significant costs and efforts” required to comply with the law. That too is a falsehood. Age verification in the US is typically less than $0.30 and even lower in high volumes. Online sportsbooks find these prices reasonable and actually reduce fraudulent accounts.
UK’s Online Safety Bill
The Online Safety Bill was introduced in the House of Commons on 17 March 2022. The Bill represents a fresh set of laws in the United Kingdom aimed at safeguarding both children and adults online. Its purpose is to hold social media companies accountable for ensuring the safety of their users on their respective platforms. By introducing this legislation, a greater level of responsibility is placed on these companies to actively prioritize user safety and address potential risks and harms that may arise from online interactions.
Following recent updates to the Online Safety Bill aimed at bolstering child protection measures, the UK is set to impose stringent requirements on services that publish or allow pornography on their platforms. Social media platforms and other digital services will be explicitly required to use age verification or age estimation tools to prevent children from accessing pornography. The goal is to ensure that these tools are highly effective in accurately determining whether a user is a child or an adult. By implementing these heightened age assurance measures, the UK aims to create a robust safeguarding system that prevents children from accessing harmful content.
The legislation will hold top tech executives personally accountable for the safety and well-being of users, particularly the youngest and most vulnerable among them. This increased level of responsibility highlights the importance of prioritizing child protection and underscores the need for proactive measures to mitigate risks and ensure user safety.
Understanding Age Verification, Age Assurance, and Age Estimation
In discussions surrounding age-related processes, it is crucial to grasp the distinction between Age Verification, Age Assurance, and Age Estimation.
- Age Verification specifically refers to the process of determining an individual’s age by examining identity attributes associated with them. This method has been the focal point of many discussions, particularly regarding online platforms and services. This category encompasses the use of data, and/or document services, typically electronic means of assessment, including NFC chip-based and video verification to establish a none or compliant verification.
- Age Assurance is a broader concept. It involves the comprehensive process of establishing and communicating an individual’s age, as defined by the International Standards Organization. Age assurance recognizes that age determination goes beyond a singular method and necessitates considering additional approaches.
- One such approach is Age Estimation, which involves assessing an individual’s likely age category based on various factors such as assurance components, inherent features, and observable behaviors. Age estimation serves as a complementary process within the realm of age assurance that may use facial biometrics and machine learning to assess a potential range of age.
Age Assurance Methods: Classification
Age Assurance methods can be classified into four distinct categories. Let’s delve into each of them:
Self-declaration involves individuals voluntarily providing their age or birthdate during the registration or account creation process, or before they can access material. Users are typically asked to input their age or select their date of birth from predefined options. For instance, it is common to provide your date of birth as a prerequisite for accessing an alcohol website. While this method relies on user honesty, it is straightforward to implement and commonly used in popular social media platforms like Facebook, Reddit, Spotify, Instagram, TikTok, and Snapchat.
Instagram is introducing a new approach to age verification called social vouching. Under this system, if a minor claims to be over 18 years old, they have the option to request verification from three of their “mutual followers” who are confirmed to be at least 18 years old.
Given the evolving legislative and regulatory landscape, it is unlikely that self-attestation mechanisms alone would suffice as acceptable means for determining a user’s age. The latest changes in regulations emphasize the need for more robust and reliable age verification methods.
- User-Submitted Hard Identifiers:
This requires users to submit hard identifiers, such as images of government-issued identification documents, or commercially-used or government-provided personal identity databases to verify their identity and age. By providing official documents, or PII which may include government identity numbers or date of birth, users offer tangible proof of their age, enhancing the accuracy and reliability of the verification process.
While this approach may present greater difficulty for minors to circumvent, it is essential to recognize that its implementation necessitates platforms to manage the collection, storage, and processing of potentially sensitive personal data. This can raise valid concerns regarding privacy and data protection.
- Third-Party Institutional Attestation:
This method involves relying on trusted organizations or institutions to verify an individual’s age. These organizations may possess authoritative data or databases that can be used to confirm age information. Examples of such organizations/institutions can include:
- Educational Institutions that can verify a person’s age by confirming enrollment or graduation dates,
- Certain government agencies, such as the Department of Motor Vehicles (DMV), that can provide age verification based on driver’s licenses or ID cards,
- Financial Institutions, including banks, that may use customer records or account information to verify the age of individuals.
By leveraging the expertise and credibility of these institutions, age verification becomes more robust and reliable. Additionally, certain platforms may require users to provide their credit card information to verify their age. Some parents, however, may hesitate to provide the financial or identification information required for verification.
- Inferential Age Assurance:
This strategy utilizes advanced technologies, such as artificial intelligence (AI), to estimate an individual’s age based on various data points. These data points may include facial features, biometric measurements, or behavioral patterns. Inferential methods analyze these data to make an educated estimation of a person’s age, offering a more automated and efficient approach to age assurance.
Certain platforms, such as TikTok, YouTube, and Facebook have implemented AI-based age inference systems. These systems analyze user behavior and content to identify individuals who are likely to be minors. When the system detects a potential user under the age of 18 or 13, many platforms require additional forms of age verification, for instance, by uploading either an ID or a video selfie.
One issue with inferred age is that it is hardly foolproof or entirely reliable.
Age Verification vs. Age Assurance in Protecting Children Online
Social media platforms and digital service providers employ a diverse range of age assurance methods to enhance safety measures for younger users when accessing services. They must guarantee that no child is inadvertently exposed to content that could pose a risk to their well-being or is unsuitable for their age.
The task of estimating or verifying a user’s age is a complex undertaking that prompts questions about the feasibility of different approaches, privacy implications, equitable access, and the need to adhere to legal requirements. Therefore, careful consideration must be given when choosing the technology provider to ensure effective age assurance while upholding privacy and legal compliance.
While Age Estimation is claimed to be less intrusive, more frictionless, and versatile, Age Verification solutions offer several advantages over Age Estimation solutions. Firstly, Age Verification offers a higher level of accuracy by relying on verifiable data such as government-issued identification documents or databases. This accuracy is particularly important in industries with strict age restrictions, ensuring regulatory compliance and legal protection. By implementing Age Verification, companies can demonstrate that they have taken reasonable measures to prevent minors from accessing age-restricted products or services.
There are also certain flaws in Age Estimation that might prove problematic in maintaining proper age restrictions enabling underage accounts to masquerade as legitimate parents. For instance, a child could very easily use the facial image of a person on their bus, or waiting in line as their parental age estimation. There is no real limitation as to whose face is estimated. Secondly, the age ranges of Age Estimation are not as exact as one would hope, leaving accuracy as a problematic element in contrast with Age Verification.
Secondly, age verification solutions address privacy concerns more effectively. While Age Estimation often relies on facial recognition and Machine Learning algorithms, Age Verification typically requires the collection of PII. Although privacy is still a consideration, companies can handle and protect this data responsibly to maintain user trust. Moreover, Age Verification reduces the likelihood of false negatives, ensuring that individuals of legal age are not mistakenly denied access to age-restricted products or services.
In summary, Age Verification solutions provide higher accuracy, regulatory compliance, and legal protection, and they address privacy concerns more effectively compared to Age Estimation solutions. They offer a reliable and robust method for confirming a person’s age, making them a preferable choice for companies operating in industries with rigorous age restrictions.
An effective identity and age verification solution empowers online service providers to offer individuals the opportunity to explore the vast online world with an additional layer of child protection, ensuring the convenience of instant verification.
Integrity: Your Trusted Leader in Identity and Age Verification Solutions
A division of Aristotle, Integrity is committed to creating a safer online environment for users of all ages. Integrity offers a wide array of trusted, widely-accepted Identity and Age Verification solutions and services. As a global leader in technology for campaigns and organizations, we are at the forefront of preventing underage access to electronic services. Our team understands the importance of balancing the need for fast and robust identity and age verification systems with considerations of privacy, data security, and equitable access to services.
Integrity provides customized solutions for both commercial and government sectors, offering the most versatile, comprehensive, and cost-effective approach to age and identity verification across multiple platforms.
Our Age Verification solutions harness the power of best-in-class tools to ensure reliable data and instant confirmations. With seamless, accurate, and real-time age verification, Integrity ensures strict compliance with internationally recognized age verification laws and stringent regulations such as Children’s Online Privacy and Protection Act or Online Safety Bill. Our expertise lies in guiding organizations through the complex regulatory landscape, ensuring adherence to the necessary requirements.
Social media platforms can establish appropriate age restrictions and create experiences that are suitable for the intended age group by utilizing Integrity’s flagship product, Integrity ID-Direct for Age Verify. This web-based solution allows users to authenticate and verify their age promptly and securely, ensuring compliance with regulations. ID-Direct seamlessly verifies the age and identity of website visitors against a comprehensive database of government-issued ID’s for citizens of 135 countries around the globe. With access to a database that encompasses over 10 billion citizen records globally, your organization can have full confidence in utilizing our trusted age verification system.
Adding age and identity verification to your website has never been easier. ID-Direct simplifies the process and automates online verification, ensuring a frictionless experience for both you and your users. With convenient API and URL interfaces, installation is straightforward and hassle-free.