ETSI TR 104 077-2 V1.1.1 (2024-12)
Human Factors (HF); Age Verification Pre-Standardization Study Part 2: Solutions and Standards Landscape
Human Factors (HF); Age Verification Pre-Standardization Study Part 2: Solutions and Standards Landscape
DTR/HF-00301568
General Information
Standards Content (Sample)
TECHNICAL REPORT
Human Factors (HF);
Age Verification Pre-Standardization Study
Part 2: Solutions and Standards Landscape
2 ETSI TR 104 077-2 V1.1.1 (2024-12)
Reference
DTR/HF-00301568
Keywords
age verification, privacy, security, user
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and
microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2024.
All rights reserved.
ETSI
3 ETSI TR 104 077-2 V1.1.1 (2024-12)
Contents
Intellectual Property Rights . 5
Foreword . 5
Modal verbs terminology . 5
Executive summary . 5
Introduction . 6
1 Scope . 7
2 References . 7
2.1 Normative references . 7
2.2 Informative references . 7
3 Definition of terms, symbols and abbreviations . 10
3.1 Terms . 10
3.2 Symbols . 11
3.3 Abbreviations . 11
4 Overview and Diagram of Age Assurance Systems . 12
4.1 Overview . 12
4.2 Diagrams . 12
5 Overview of European and International solutions and standards for Age Verification . 14
5.1 Introduction . 14
5.2 Standards Development Organizations . 14
5.2.1 ETSI . 14
5.2.1.1 TC Cyber . 14
5.2.1.2 TC Human Factors (HF) . 17
5.2.1.3 TC Electronic Signatures and Trust Infrastructures (ESI) . 18
5.2.2 CEN/CENELEC . 19
5.2.3 ISO/IEC . 20
5.2.3.1 ISO/IEC General Information . 20
5.2.3.2 ISO/IEC JTC 1/SC 27 & SC37 . 21
5.2.3.3 ISO/IEC JTC 1/SC 37 . 22
5.2.4 ITU. 24
5.2.5 IEEE . 24
5.3 Age Verification Framework / Architecture . 25
5.3.1 euCONSENT ASBL . 25
6 Overview of National solutions and standards for Age Verification . 26
6.1 Introduction . 26
6.2 National . 26
6.2.1 France . 26
6.2.1.1 Association Française de Normalisation (AFNOR, English: French Standardization Association) . 26
6.2.1.2 CNIL . 27
6.2.2 Italy . 27
6.2.2.1 Comitato Elettrotecnico Italiano (CEI, English: Italian Electrotechnical Committee) . 27
6.2.2.2 Ente Nazionale Italiano di Unificazione (UNI, English: Italian National Unification) . 27
6.2.2.3 Agcom . 28
6.2.3 Ireland . 28
6.2.3.1 National Standards Authority of Ireland (NSAI) . 28
6.2.3.2 Coimisiún na Meán . 28
6.2.4 Spain . 29
6.2.4.1 Asociación Española de Normalización y Certificación (AENOR, English: Spanish Association
for Standardization and Certification) . 29
6.2.4.2 AEPD . 29
6.2.5 Germany . 30
ETSI
4 ETSI TR 104 077-2 V1.1.1 (2024-12)
6.2.5.1 Deutsche Kommission Elektrotechnik Elektronik Informationstechnik im DIN und VDE (DKE,
English: German Commission for Electrotechnical, Electronic & Information Technologies of
DIN and VDE) . 30
6.2.5.2 KJM. 30
6.2.6 UK . 31
6.2.6.1 British Standards Institution (BSI) . 31
6.2.6.2 Childnet . 31
6.2.6.3 Information Commissioner's Office (ICO). 32
6.2.6.4 Ofcom . 32
6.2.6.5 National Cyber Security Centre (NCSC) . 33
7 Conclusions . 33
Annex A: Overview of Stakeholder Requirements from ETSI TR 104 077-1 . 35
Annex B: The evolution of age verification and estimation with the adoption of AI techniques . 40
History . 41
ETSI
5 ETSI TR 104 077-2 V1.1.1 (2024-12)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations
pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be
found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to
ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Human Factors (HF).
The present document is part 2 of a multi-part deliverable covering Age Verification Pre-Standardization Study, as
identified below:
Part 1: "Stakeholder Requirements";
Part 2: "Solutions and Standards Landscape";
Part 3: "Proposed Standardization Roadmap".
Modal verbs terminology
In the present document "should", "should not", "may", "need not", "will", "will not", "can" and "cannot" are to be
interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
Executive summary
The present document reviews and analyses existing solutions and standards for age verification in Europe:
technological solutions; national/regional implementations and regulations, and existing standardization (IEC, others,
etc.). The range of technical solutions and existing implementations (national and regional) is reviewed from the
perspective of the stakeholders' requirements identified in ETSI TR 104 077-1 [i.7].
ETSI
6 ETSI TR 104 077-2 V1.1.1 (2024-12)
Introduction
The present document aims to identify the existing solutions and standards landscape for age verification, laying the
groundwork for future European standards in this field as requested in the Digital Services Act. A heterogeneous
landscape of age-verification solutions exists from "Click here to confirm that you are 18 years old or older" to
sophisticated technical solutions involving the verification of official documents (machine-readable ID cards).
Regulation (EU) 2022/2065 [i.51] mandates the development of standards for targeted measures to protect minors
online (Article 44 (j)), including age verification systems and parental control tools (Article 35 (j)).
However, achieving a unified European solution for age verification might be challenging due to disparate national
systems. Thus, establishing a comprehensive understanding of the landscape for age verification and parental controls,
as well as standardized interfaces for service providers to access verified age data, is crucial for protecting minors
online. International organizations like ITU/IEC/ISO/IEEE, national standards bodies, and the euConsent NGO have
explored age verification and protection of minors. Their research provides a basis for assessing current solutions and
identifying gaps.
While the euConsent project explored age verification in-depth, its solutions primarily focus on agency-supported
verification, with follow-on projects for age verification exploring unanswered questions. For example, the direct
sharing of verified age data between parents, minors, and digital service providers without the need for third-party age
assurance providers is an area that requires further study.
The present document will focus on identifying and understanding the existing and proposed solutions plus the
standards landscape in age verification. The present document aims to understand how the existing solutions and
standards can be used to meet the stakeholder requirements for age verification as identified in ETSI
TR 104 077-1 [i.7], this includes standards and solutions that are not specifically aimed at age verification as many of
the stakeholder requirements are the same as other cybersecurity, privacy and data protection requirements found
throughout many different industries and services.
ETSI
7 ETSI TR 104 077-2 V1.1.1 (2024-12)
1 Scope
The present document reviewed from a perspective of the stakeholder requirements identified in ETSI
TR 104 077-1 [i.7] is a study of the landscape of international, regional and national existing solutions (identified in
ETSI TR 104 077-1 [i.7]), approaches (frameworks/architecture) and standards for age verification in Europe.
2 References
2.1 Normative references
Normative references are not applicable in the present document.
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee
their long term validity.
The following referenced documents are not necessary for the application of the present document but they assist the
user with regard to a particular subject area.
[i.1] ETSI TR 103 305-1 (V4.1.2) (2022-04): "Cyber Security (CYBER); Critical Security Controls for
Effective Cyber Defence; Part 1: The Critical Security Controls".
[i.2] ETSI TR 103 305-2 (V2.1.1) (2018-09): "CYBER; Critical Security Controls for Effective Cyber
Defence; Part 2: Measurement and auditing".
[i.3] ETSI TR 103 305-4 (V3.1.1) (2022-11): "Cyber Security (CYBER); Critical Security Controls for
Effective Cyber Defence; Part 4: Facilitation Mechanisms".
[i.4] ETSI TR 103 305-5 (V2.1.1) (2023-02): "Cyber Security (CYBER); Critical Security Controls for
Effective Cyber Defence; Part 5: Privacy and personal data protection enhancement".
[i.5] ETSI TR 103 935 (V1.1.1) (2023-12): "Cyber Security (CYBER); Assessment of cyber risk based
on products' properties to support market placement".
[i.6] ETSI TS 103 457 (V1.2.1) (2023-03): "CYBER; Trusted Cross-Domain Interface: Interface to
offload sensitive functions to a trusted domain".
[i.7] ETSI TR 104 077-1: "Human Factors (HF); Age Verification Pre-Standardization Study; Part 1:
Stakeholder Requirements".
[i.8] ETSI TR 103 370 (V1.1.1) (2019-01): "Practical introductory guide to Technical Standards for
Privacy".
[i.9] ETSI TS 103 485 (V1.1.1) (2020-08): "CYBER; Mechanisms for privacy assurance and
verification".
[i.10] ETSI TR 103 642 (V1.1.1) (2018-10): "CYBER; Security techniques for protecting software in a
white box model".
[i.11] ETSI TR 103 309 (V1.1.1) (2015-08): "CYBER; Secure by Default - platform security
technology".
[i.12] ETSI TS 102 165-1 (V5.2.5) (2022-01): "CYBER; Methods and protocols; Part 1: Method and pro
forma for Threat, Vulnerability, Risk Analysis (TVRA)".
ETSI
8 ETSI TR 104 077-2 V1.1.1 (2024-12)
[i.13] ETSI TS 103 992 (V1.1.1) (2024-05): "Cyber Security (CYBER); Implementation of the Revised
Network and Information Security (NIS2) Directive applying Critical Security Controls".
[i.14] ETSI TR 103 838 (V1.1.1) (2022-01): "Cyber Security; Guide to Coordinated Vulnerability
Disclosure".
[i.15] ETSI EG 203 499 (V3.1.1) (2024-07): "Human Factors (HF); User-centred terminology for
existing and upcoming ICT devices, services and applications".
[i.16] ETSI EN 301 549 (V3.2.1) (2021-03): "Accessibility requirements for ICT products and services".
[i.17] ETSI TR 103 349 (V1.1.1) (2016-12): "Human Factors (HF); Functional needs of people with
cognitive disabilities when using mobile ICT devices for an improved user experience in mobile
ICT devices".
[i.18] ETSI EG 203 350 (V1.1.1) (2016-11): "Human Factors (HF); Guidelines for the design of mobile
ICT devices and their related applications for people with cognitive disabilities".
[i.19] IEEE 2089™-2021: "IEEE Standard for an Age-Appropriate Digital Services Framework Based
on the 5Rights Principles for Children".
[i.20] IEEE P2089.2™: "IEEE Standard for Terms and Conditions for Children's Online Engagement".
[i.21] IEEE 2089.1™-2024: "IEEE Standard for Online Age Verification".
[i.22] CNIL (2022): "Demonstration of a privacy-preserving age verification process".
[i.23] Agcom (2024): "Linee guida parental control (Delibera n. 9/23/CONS)".
[i.24] Coimisiún na Meán (2024): "Online Safety Code".
[i.25] AEDPD (2023): "Decalogue of principles - Age verification and protection of minors from
inappropriate content".
[i.26] KJM (2022): "Criteria for evaluating concepts for age verification systems as elements for
ensuring closed user groups in telemedia in accordance with § 4 para. 2 sentence 2 Interstate
Treaty on the Protection of Human Dignity and Minors in Broadcasting and Telemedia (JMStV)
("AVS-MATRIX")".
[i.27] ICO: "Age appropriate design: a code of practice for online services".
[i.28] ICO: "Age assurance for the Children's code".
[i.29] Ofcom (2023): "Guidance on age assurance and other Part 5 duties for service providers
publishing pornographic content on online services".
[i.30] Ofcom (2024): "Quick guide to children's access assessments".
[i.31] Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012
on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and
Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC,
2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing
Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of
the Council (Text with EEA relevance).
[i.32] CEN and CENELEC Workshop Agreement (2023) CWA 18016: "Age appropriate digital services
framework".
[i.33] ISO/IEC DIS 27566-1: "Information security, cybersecurity and privacy protection — Age
assurance systems — Part 1: Framework".
[i.34] ISO/IEC PWI 27566-2 (Ed 2): "Age assurance systems — Part 2: Technical approaches and
guidance for implementation".
[i.35] ISO/IEC AWI 27566-3 (Ed 3): "Age assurance systems — Part 3: Benchmarks for benchmarking
analysis".
ETSI
9 ETSI TR 104 077-2 V1.1.1 (2024-12)
[i.36] ITU (2020): "Digiworld An example of how the ITU Guidelines on Child Online Protection can be
delivered in practice".
[i.37] Ministry for the Digital Transformation and Civil Service (2024): "Digital Wallet; Specification
for the use of the "Age of majority" credential Age verification system for access to online
content".
[i.38] Ministry for the Digital Transformation and Civil Service (2024): "Digital Wallet; Age verification
protocol Age verification system for access to online content".
[i.39] ISO/IEC JTC 1/SC 27 TR 15443-1:2012: "Information technology — Security
techniques — Security assurance framework Part 1: Introduction and concepts".
[i.40] ISO/IEC JTC 1/SC 27 TR 15443-2:2012: "Information technology — Security
techniques — Security assurance framework Part 2: Analysis".
[i.41] ISO/IEC JTC 1/SC 27 29115:2013: "Information technology — Security techniques — Entity
authentication assurance framework".
[i.42] ISO/IEC JTC 1/SC 27 29128-1:2023: "Information security, cybersecurity and privacy protection
— Verification of cryptographic protocols — Part 1: Framework".
[i.43] ISO/IEC JTC 1/SC 27 27551:2021: "Information security, cybersecurity and privacy
protection — Requirements for attribute-based unlinkable entity authentication".
[i.44] ISO/IEC JTC 1/SC 37; 30136:2018: "Information technology — Performance testing of biometric
template protection schemes".
[i.45] ISO/IEC JTC 1/SC 37; 24714:2023: "Biometrics — Cross-jurisdictional and societal aspects of
biometrics — General guidance".
[i.46] ISO/IEC JTC 1/SC 37; TR 30110:2015: "Information technology — Cross jurisdictional and
societal aspects of implementation of biometric technologies — Biometrics and children".
[i.47] AgeAware; euConsent (2024), AgeAware® Specification, Consultation Document: "WP1:
Business Requirements".
[i.48] Produced by Childnet International for The National Lottery Heritage Fund, Digital Skills for
Heritage: "Working with Children and Young People Online".
[i.49] NCSC: "Cyber Essentials".
[i.50] BSI PAS 1296:2018: "Online age checking. Provision and use of online age check services. Code
of Practice".
[i.51] Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on
a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act).
[i.52] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
protection of natural persons with regard to the processing of personal data and on the free
movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
[i.53] ETSI TS 119 461 (V1.1.1) (2021-07): "Electronic Signatures and Infrastructures (ESI); Policy and
security requirements for trust service components providing identity proofing of trust service
subjects".
[i.54] ETSI TS 119 462: "Electronic Signatures and Trust Infrastructures (ESI); Wallet interfaces for
trust services and signing".
[i.55] ETSI TS 119 471: "Electronic Signatures and Trust Infrastructures (ESI); Policy and Security
requirements for Providers of Electronic Attestation of Attribute Services".
[i.56] ETSI TS 119 475: "Electronic Signatures and Trust Infrastructures (ESI); Relying party
authorizations for access to EUDI Wallet".
ETSI
10 ETSI TR 104 077-2 V1.1.1 (2024-12)
[i.57] ETSI EN 319 411-2 (V2.5.1) (2023-10): "Electronic Signatures and Infrastructures (ESI); Policy
and security requirements for Trust Service Providers issuing certificates; Part 2: Requirements for
trust service providers issuing EU qualified certificates".
[i.58] IEEE 2089.3™: "Online Parental Consent".
[i.59] ETSI TR 104 077-3: "Human Factors (HF); Age Verification Pre-Standardization Study; Part 3:
Proposed Standardization Roadmap".
[i.60] ETSI TR 104 031 (V1.1.1) (2024-01): "Securing Artificial Intelligence (SAI); Collaborative
Artificial Intelligence".
[i.61] ETSI TR 104 032 (V1.1.1) (2024-02): "Securing Artificial Intelligence (SAI); Traceability of AI
Models".
[i.62] ETSI TR 104 225 (V1.1.1) (2024-04): "Securing Artificial Intelligence TC (SAI); Privacy aspects
of AI/ML systems".
[i.63] ETSI TR 104 048: "Securing Artificial Intelligence; Data Supply Chain Security".
[i.64] ETSI TR 104 221: "Securing Artificial Intelligence; Problem statement".
[i.65] ETSI TR 104 062 (V1.2.1) (2024-07): "Securing Artificial Intelligence; Automated Manipulation
of Multimedia Identity Representations".
[i.66] ETSI TS 104 223: "Securing Artificial Intelligence TC (SAI); Baseline Cyber Security
Requirements for AI Models and Systems".
[i.67] ETSI TS 104 224: "Securing Artificial Intelligence TC (SAI); Explicability and transparency of AI
processing".
[i.68] Regulation (EU) 2022/2480 of the European Parliament and of the Council of 14 December 2022
amending Regulation (EU) No 1025/2012 as regards decisions of European standardisation
organisations concerning European standards and European standardisation deliverables.
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the following terms apply:
age assurance: methods used to determine the age or age range of an individual, including age verification, estimation,
and self-declaration
NOTE: From ISO 27566-1 [i.33]: "set of processes and methods used to verify, estimate or infer the age or age
range of an individual, enabling organizations to make age-related eligibility decisions with varying
degrees of certainty".
age estimation: age assurance method-based analysis of biological or behavioural features of humans that vary with
age
age inference: age assurance method based on verified information which indirectly implies that an individual is over
or under a certain age or within an age range
Age Verification (AV): process to determine an individual's age or age range
NOTE: From ISO 27566-1 [i.33]: "age assurance method based on calculating the difference between a verified
year or date of birth of an individual and a subsequent date". Also, in some cultures, an alternate
calculation (such as use of birth year rather than birth date) may be applicable.
inclusivity: capability of a product to be utilized by people of various backgrounds include (and are not limited to)
people of various ages, abilities, cultures, ethnicities, languages, genders, economic situations, education, geographical
locations and life situations
ETSI
11 ETSI TR 104 077-2 V1.1.1 (2024-12)
practice statement: documentation of the practices, procedures and controls employed by an organization to fulfil a
service
relying party: entity that relies on an age assurance result to make an age-related eligibility decision
3.2 Symbols
Void.
3.3 Abbreviations
For the purposes of the present document, the following abbreviations apply:
ABUEA Attribute-Based Unlinkable Entity Authentication
AENOR Asociación Española de Normalización y Certificación
AEPD Agencia Española de Protección de Datos
AFNOR Association Française de Normalisation
Agcom Communications Regulatory Authority
AI Artificial Intelligence
AIA AI Agents
AV Age Verification
BSI British Standards Institution
CCPN Standardization Coordination and Steering Committee
CEI Comitato Elettrotecnico Italiano
CEN European Committee for Standardization
CENELEC European Committee for Electrotechnical Standardization
CIA Confidentiality, Integrity, Availability
CNIL Commission nationale de l'informatique et des libertés
COP Child Online Protection
COS Strategic Committees
CSC Critical Security Control
DID Decentralized Identifier
DKE Deutsche Kommission Elektrotechnik Elektronik Informationstechnik im DIN und VDE
DNE Digital Networked Economy
EG ETSI Guide
EN European Standard
ESI Electronic Signatures and Trust Infrastructures
ESO European Standard Organisation
ETSI European Telecommunications Standards Institute
EUDI European Digital Identity
GDPR General Data Protection Regulation
HF Human Factors
ICO Information Commissioner's Office
ICT Information and Communications Technology
IEC International Electrotechnical Commission
IEEE Institute of Electrical and Electronics Engineers
ISO International Organization for Standardization
ISS Internet Society Services
ITU International Telecommunication Union
JMStV Interstate Treaty on the Protection of Minors in the Media
KJM Kommission für Jugendmedienschutz
LoA Levels of Entity Authentication
NCSC National Cyber Security Centre
NIS2 Revised Network and Information Security Directive
NSAI National Standards Authority of Ireland
NSB National Standards Bodies
PAS Publicly Available Specification
SAI Securing Artificial Intelligence
SDO Standards Development Organization
TC Technical Committee
ETSI
12 ETSI TR 104 077-2 V1.1.1 (2024-12)
TR Technical Report
TS Technical Specification
UNI Ente Nazionale Italiano di Unificazione
WBC White Box Cryptography
4 Overview and Diagram of Age Assurance Systems
4.1 Overview
Age-related eligibility decisions are required when a person should either be a certain age, older or younger than a given
age or be within an age range, where ages are counted in years and where these criteria are dependent upon the type of
goods, content, services, venues or spaces to be provided. Although an individual's age is an attribute of their identity, it
is not necessarily the case that establishing the full identity of an individual in a global context is needed to gain age
assurance. As such, the process of age assurance may in some instances be connected to identity verification but can
also be performed in ways other than via identity verification.
An age assurance system should be capable of meeting the stated and implied needs of relying parties when it is used
under specified conditions. A functionally complete age assurance system comprises of one or more age assurance
methods selected or designed to provide the relying party with the necessary information to make an age-related
eligibility decision. The functional characteristics (performance, privacy, security and acceptability) describe what a
relying party, intermediary or age assurance provider is supposed to accomplish as set out in their practice statement.
4.2 Diagrams
Both figures 1 and 2 are from ISO/IEC DIS 27566-1:2025 [i.33].
Age assurance methods
Age verification methods Age estimation methods Age inference methods
Calculating the difference between a Analysis of biological or behavioural Verified information which indirectly
verified year or date of birth of an features of humans that vary with age implies that an individual is over or
individual and a subsequent date under a certain age or within an age
range
Figure 1: Illustration of the three age assurance methods
Figure 1 describes the three different age assurance methods, which when taken together with the binding of evidence to
the individual can be used to generate an age assurance result leading to an age-related eligibility decision.
Figure 2 shows the different characteristics of an age assurance system with examples of standards, solutions and
frameworks from clauses 5 and 6 that align with the different characteristics.
ETSI
13 ETSI TR 104 077-2 V1.1.1 (2024-12)
Age assurance systems
Performance characteristics
Effective age assurance e.g.
CNIL Demonstration of a
privacy-preserving age
verification process
Indicators of confidence
Performance metrics
Resource utilisation
Age assurance
systems e.g.
Privacy characteristics
Standard for
Age Assurance
Privacy by design and default e.g.
Systems
ETSI TS 103 485 - Mechanisms for
ISO/IEC 27566
Functional
Acceptability
privacy assurance and verification
Series
characteristics
Data minimisation characteristics
Age assurance
Digital footprint
components
User awareness
Inclusivity e.g.
Data
ETSI N 301 549
acquisition
- Accessibility
Security characteristics
Binding of age
requirements
assurance
for ICT products
Data Security by design and default e.g.
and services
processing ETSI TR 103 309 - Secure by Default
User
Practice - platform security technology
engagement
statements Resistance to presentation attack
Redress
Utilisation
Contraindicators
Freshness of derived credentials
Reliability and recoverability
Fail safe
Practice Statements
Figure 2: Illustration of the structure of the framework with example standards & solutions
ETSI
14 ETSI TR 104 077-2 V1.1.1 (2024-12)
5 Overview of European and International solutions
and standards for Age Verification
5.1 Introduction
In this clause solutions and standards from regional and international standards development organizations will be
identified and mapped to the relevant stakeholders' requirements from clause 7 of ETSI TR 104 077 [i.7] and copied to
annex A.
Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European
standardization [i.31] lays down a procedure for the provision of information in the field of technical standards and
regulations and identifies the three European Standardization bodies responsible for drafting harmonised standards are
European Committee for Standardization (CEN), European Committee for Electrotechnical Standardization
(CENELEC) and European Telecommunications Standards Institute (ETSI). Recently, Regulation (EU)
No 2022/2480 [i.68] - adopted by the co-legislators on 14 December 2022 - introducing amendments to
Regulation (EU) No 1025/2012 [i.31] to grant the decision-making on European Standards and European
standardization deliverables to the National Standards Bodies (NSB).
5.2 Standards Development Organizations
5.2.1 ETSI
5.2.1.1 TC Cyber
The main responsibilities of ETSI TC CYBER are:
• To act as the ETSI centre of expertise in the area of Cyber Security.
• To advise and assist all ETSI Groups with the development of Cyber Security requirements.
• To develop and maintain the Standards, Specifications and other deliverables to support the development and
implementation of Cyber Security standardization within ETSI.
• To collect and specify Cyber Security requirements from relevant stakeholders.
• To identify gaps where existing standards do not fulfil the requirements and provide specifications and
standards to fill these gaps, without duplication of work in other ETSI committees and partnership projects.
• To ensure that appropriate Standards are developed within ETSI in order to meet these requirements.
• To perform identified work as sub-contracted from ETSI Projects and ETSI Partnership Projects.
• To coordinate work in ETSI with external groups such as ENISA.
• To answer policy requests related to Cyber Security, and security in broad sense in the ICT sector.
The activities of TC CYBER are performed in close co-operation with relevant standards activities within and outside
ETSI. They include the following broad areas:
• Cyber Security.
• Security of infrastructures, devices, services and protocols.
• Security advice, guidance and operational security requirements to users, manufacturers and network and
infrastructure operators.
• Security tools and techniques.
ETSI
15 ETSI TR 104 077-2 V1.1.1 (2024-12)
• Provision of security mechanisms to protect privacy.
• Creation of security specifications and alignment with work done in other TCs.
Table 1: Mapping of ETSI TC CYBER output to stakeholder requirements
Title of the Standard Description Stakeholder Requirement
See Annex A
ETSI TS 103 992 - Implementation of It describes an ensemble of Privacy and Data protection
the Revised Network and Information cybersecurity specifications and other Compliance and governance
Security (NIS2) Directive applying materials, especially the ETSI Critical Implementation and governance
Critical Security Controls [i.13] Security Controls in ETSI
TR 103 305-1 [i.1] that can be applied to
support NIS2 Directive requirements by
EU Member States and affected
essential and important entities.
The present document also considers,
and refers to, the work being done by
ETSI ESI on Trust Services.
ETSI TR 103 305-1 - Critical Security It describes a specific set of technical Privacy and Data protection
Controls for Effective Cyber Defence; measures available to detect, prevent, Compliance and governance
Part 1: The Critical Security Controls respond, and mitigate damage from the Implementation and governance
[i.1] most common to the most advanced of
cyber-attacks. The measures reflect the
combined knowledge of actual attacks
and effective defences.
ETSI TR 103 305-2 - Critical Security This is a repository for measurement Privacy and Data protection
Controls for Effective Cyber Defence; and effectiveness tests of Critical Compliance and governance
Part 2: Measurement and auditing [i.2] Security Control (CSC) Implementation and governance
implementations. The CSC are a
specific set of technical measures
available to detect, prevent, respond,
and mitigate damage from the most
common to the most advanced of
cyber-attacks.
ETSI TR 103 305-4 - Critical Security This is a repository for diverse Privacy and Data protection
Controls for Effective Cyber Defence; facilitation mechanism guidelines for Compliance and governance
Part 4: Facilitation Mechanisms [i.3] Critical Security Control Implementation and governance
implementations.
ETSI TR 103 305-5 - Critical Security This is a repository for data protection Privacy and Data protection
Controls for Effective Cyber Defence; and privacy enhancing implementations Compliance and governance
Part 5: Privacy and personal data using the Critical Security Controls, Implementation and governance
protection enhancement [i.4] ETSI TR 103 305-1 [i.1]. These
presently include a comprehensive,
consistent approach for analysing the
latest version of the Controls aiming to
meet requirements that include the EU
General Data Protection Regulation
(GDPR) and the U.S. DHS Fair
Information Practice Principles.
ETSI TR 103 935 - Assessment of The TR examines the background to the Implementation and Compliance
cyber risk based on products' assessment of cybersecurity risks and Implementation and best practices
properties to support market placement identifies issues that may arise in the
[i.5] context of placing ICT products and
services in the EU Single Market under
the applicable legal requirements.
ETSI TS 103 457 - Trusted The TS specifies a high-level Privacy and Data Protection
Cross-Domain Interface: Interface to service-oriented interface, as an Implementation and best practices
offload sensitive functions to a trusted application layer with a set of mandatory
domain [i.6] functions, to access secured services
provided by, and executed in a More
Trusted Domain. The transport layer is
out of scope and left to the architecture
implementation.
ETSI
16 ETSI TR 104 077-2 V1.1.1 (2024-12)
Title of the Standard Description Stakeholder Requirement
See Annex A
ETSI TR 103 838 - Guide to The TR is for companies and Privacy and data protection - data
Coordi
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...