A New Global Yardstick for Age Verification

The organizations behind international technology standards have released a public draft of ISO/IEC 27566-3, the third part of a framework designed to help evaluate how well age assurance systems actually work. According to Biometric Update, this section focuses on analysis, offering guidance for comparing age verification, age estimation, and age inference methods against one another.

If you've noticed more websites, apps, and platforms asking you to prove your age before letting you in, you're not imagining it. Age verification requirements have expanded rapidly across social media, adult content sites, and even general online services in response to child safety laws. ISO/IEC 27566-3 is an attempt to bring some order to that landscape by giving companies, regulators, and auditors a shared way to measure whether these systems are accurate, fair, and effective.

Verification, Estimation, and Inference: Three Different Privacy Trade-offs

The draft standard covers three distinct approaches to figuring out how old someone is, and each comes with different implications for your personal data.

Age verification typically means confirming your exact age using an official document, like a government-issued ID or a credit card. This is the most precise method, but it also requires handing over sensitive identity documents to a third party, sometimes a company you've never heard of that specializes in identity checks.

Age estimation relies on analyzing biometric signals, most commonly a photo of your face, to guess your age range without requiring a formal ID. This avoids some of the document-sharing concerns, but it means a company is processing a facial image and running it through an algorithm, raising its own set of biometric privacy questions.

Age inference uses indirect signals, such as account activity, purchase history, or behavioral patterns, to estimate whether someone is likely to be a minor or an adult without directly asking for proof at all.

The fact that ISO is now building formal guidance for comparing these methods signals something important: regulators and industry groups are recognizing that not all age checks are created equal, and the method a platform chooses has real consequences for how much of your data gets collected, stored, and potentially exposed.

Why This Matters Beyond the Technical Standard

Standards documents rarely make headlines, but this one lands at a moment when age verification is becoming a flashpoint for privacy advocates. Lawmakers in the United States have been pushing bills like the Kids Online Safety Act, whose duty-of-care provisions recently cleared a Senate committee, partly on the strength of age-appropriate design requirements. Meanwhile, in the UK, public unease about identity systems is already visible: a recent survey found that many Britons fear being tracked under a proposed national digital ID scheme, a concern that overlaps directly with worries about age verification databases.

The underlying tension is the same in both cases. Verifying age often requires collecting sensitive information, whether that's a scanned ID, a facial image, or behavioral data, and that information has to go somewhere. If it's stored insecurely or shared beyond its original purpose, it becomes a target. Cases involving the misuse of personal images and data, like the sentencing of a member of an online extortion network in a recent sextortion case, are a stark reminder of what can go wrong when sensitive personal content ends up in the wrong hands.

A well-designed comparison standard like ISO/IEC 27566-3 won't eliminate these risks, but it could help push the industry toward methods that collect less data or handle it more responsibly, since companies and auditors will have a common benchmark to measure privacy-invasiveness alongside accuracy.

What This Means For You

As age verification becomes more common online, you're likely to encounter more requests to prove your age through ID uploads, selfie-based checks, or less visible behavioral analysis. Standards like this one are meant to improve the quality and consistency of those systems, but they don't replace your own due diligence.

Before submitting an ID or a facial scan to any age check, look for information about who is processing the request. Many platforms outsource age verification to third-party vendors, and that vendor's data retention and security practices matter just as much as the platform's own policies. Estimation methods that use a live photo may feel less invasive than uploading a passport, but they still involve biometric processing, so check whether the image is deleted after the check or retained.

Key Takeaways

  • ISO/IEC 27566-3 is a draft standard for comparing age verification, estimation, and inference methods, not a law or mandate.
  • Each age-check method carries different privacy trade-offs, from document sharing to biometric scanning to behavioral tracking.
  • Ask platforms who handles your age verification data and how long it's retained before submitting sensitive information.
  • Stay informed about age verification laws in your region, since requirements and consumer protections vary widely and continue to evolve.