Technology

Why Age Verification Databases Pose Greater Risks Than Governments Realize

Age verification databases carry serious risks, from far-reaching state surveillance to the exposure of citizens’ personal data to hostile intelligence services. Such systems represent an incalculable security threat.

The transparent citizen – new verification rules risk exposing the individual. Photo: pixelfit/Getty Images/Gemini

The transparent citizen – new verification rules risk exposing the individual. Photo: pixelfit/Getty Images/Gemini

A case in Spain illustrates how far the debate over age verification on social media and other online platforms has drifted from reality. The Spanish Data Protection Agency (AEPD) recently fined the company Yoti €950,000 for setting up a biometric identity system that, according to the AEPD, breached the GDPR in three ways. Yoti's selfie function alone accounted for €500,000 of the penalty, as it enables the unique identification of an individual and therefore falls under the regulation's special category protections.

The AEPD imposed a further €250,000 fine for storing geolocation data for five years. A third penalty of €200,000 followed over data retention violations. Yoti had been keeping falsified identity data submitted during failed verification attempts beyond its original purpose and using it to train its algorithms. In effect, identity verification attempts that amounted to fraud were repurposed as training material, without the consent of the individuals involved.

Surface-level security

https://twitter.com/CovertRecon_17/status/2033942515141771717

Yoti is an app designed to allow users to verify their age without entering personal data. Founded in London in 2014 by Robin Tombs, the company specialises in artificial intelligence-driven age verification. Yoti's defining feature is that users are not required to provide their date of birth or upload official identification. Instead, the system relies on neural networks trained on millions of data points to estimate age from a single image. Therefore, in theory, a photo is enough to determine how old someone is.

In practice, this technology, once presented as highly secure, is proving inadequate when it comes to robust data protection. The Yoti case also exposes how poorly conceived many proposed age verification regulations are. Governments appear to be attempting to legislate their way out of a problem that may not have a workable solution. This is compounded by the complexity of data protection laws across the European Union, some of which were introduced by the same policymakers now advocating stricter controls.

Welcome to the comments section of the Štandard daily. Please take note of our guidelines, comments are moderated by us. You can contact the moderators at support@statement.com.

Participate in the discussion

Comments are available to subscribers only. If you'd like to join the discussion, choose a subscription starting at €6.72 per month.

All comments 0

    Register

    Comments are available to registered users only. If you'd like to join the discussion, register here.