When an age check becomes biometrics: the line the AEPD drew

September 30, 2026

When an age check becomes biometrics: the line the AEPD drew

Facial age estimation that never establishes identity produces no biometric data under the GDPR. The Article 4(14) definition requires processing that allows or confirms the unique identification of a person. Recital 51 is plain: photographs meet that definition "only when processed through a specific technical means allowing the unique identification or authentication". An age check becomes biometrics — and a matter for Article 9 — at the point where identification appears: Spain's AEPD fined the vendor Yoti not for estimating age but for a facial template that lived as long as the account and was matched again on PIN change and account recovery. That line is what this article maps.

Any age check, meanwhile, creates personal data processing: a lawful basis, minimisation, retention, a risk assessment, a processor agreement. Closing an obligation towards minors opens a privacy obligation towards users.

The working question: what you collect, where it is computed, how long it lives, who sees it. Three parties answered over six months, two in one September week.

Three answers: Discord, Apple, a Brazilian court

Discord: age without a camera

Discord began the global rollout of its age check on 23 September 2026, over about a week; co-founder Stanislav Vishnevskiy set out the mechanics a day earlier in a company post.

Automatic estimation runs with no camera: for more than 90% of users age comes from account signals — account age, communities and games, activity. The company is literal about content: the model "does not look at your messages, calls, or other content". Users land in three groups: Adult 18+, Teen 13-17, Unconfirmed. In the UK and Australia it is not available yet, with no reason given.

Everyone else gets seven manual routes, all described: a credit card whose details "k-ID routes… to Stripe"; an age range from the App Store; the same from Google Play; Google Wallet against a passport pass; a video selfie that "stays on your device"; an ID scan with a selfie, of which "Both are deleted right after"; the reusable AgeKey. k-ID handles manual reviews generally, and any partner offering facial age estimation "must run it entirely on your device".

The breach at support contractor 5CA, disclosed in October 2025, reached identity documents: roughly 70,000 users "may have had government-ID photos exposed, which our vendor used to review age-related appeals". That is a subset of those affected: the incident as a whole was wider. Elsewhere the same press release sizes the leak in a way that does not compare: the unauthorised party "also gained access to a small number of government-ID images". One figure counts users whose documents may have been exposed, the other counts images to which access was in fact gained; the primary source gives no way to reduce them to a single number. The IDs sat there because of age appeals, and the September post closes that loop: the old manual process is "fully retired" and reviews moved to k-ID.

February set out a different design, and it was not the thing delayed. The press release of 9 February 2026 promised teen defaults to everyone: "all new and existing users worldwide will have a teen-appropriate experience". The delay came two weeks later, as an update to that same release, and it covered the rollout of the check itself: "we've made the decision to delay the global rollout of age assurance until the second half of 2026 to expand verification options". Automatic estimation was in the design even then — the same update reads "Over 90% of users will continue using Discord exactly as they do today". What went wrong the company set out in a separate post: "We're delaying our global rollout to the second half of 2026". September lands that delayed age assurance rollout. The "teen until proven otherwise" regime never came with it.

Apple: a range instead of a birth date

Apple calls the approach Age Assurance and gives developers the Declared Age Range API: an app receives an age range, the exact date of birth stays with Apple. The documentation adds a caveat easy to miss: the range is "based on information declared by an end user, or their parent or guardian", only "may be confirmed" by a payment method or an ID, and "you are solely responsible for ensuring compliance".

In the UK the check moved to device level with iOS and iPadOS 26.4. Apple dates the build itself: its security releases page reads "iOS 26.4 and iPadOS 26.4 … 24 Mar 2026", and macOS Tahoe 26.4, tvOS 26.4 and watchOS 26.4 carry the same date, so it is a coordinated branch date. What in that build turned the UK check on, Apple does not say: that link comes from trade coverage — a 9to5Mac piece of 25 March 2026. The regulator gave its comment on the launch to Engadget, and 9to5Mac reprints it in the same piece: "Apple's decision that the UK will be one of the first countries in the world to receive new child safety protections on devices is a real win for children and families". On its UK page the company cites "regional age assurance laws" and never names the Online Safety Act.

Brazil: a court, an app store and a casino game

The Câmara Especial of the São Paulo state court partly granted emergency protection in proceeding 2225166-11.2026.8.26.0000, rapporteur Egberto de Almeida Penido. The report carries no date of the ruling; the report itself ran on 21 September 2026. Apple has five days to stop downloads of "Casino Roulette: Roulettist" by users registered as minors and chip purchases without an age check, and to admit no new apps with equivalent casino mechanics absent age control, at 100,000 reais a day.

The measure is provisional: the court declined to pull casino apps altogether, settled no civil liability, and named one addressee, Apple as App Store operator.

What the rule actually says about Article 9

The unique-identification condition sits inside the definition of biometric data. A system answering "18+ or not" neither allows nor confirms identification, so it produces no biometric data. Article 9 adds a purpose filter: the prohibition covers "biometric data for the purpose of uniquely identifying a natural person".

That reading comes from the text of the rule. Regulators answer the neighbouring question: theirs is about Article 9, and the Article 4(14) definition stays out of it. They also put it more cautiously. In Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement (Version 2.0, adopted on 26 April 2023) the EDPB writes that detection of behaviour, emotions or silhouettes "may not be considered as biometric systems processing special categories of personal data", with the modal left standing, on two conditions held together: no aim of uniquely identifying a person, and no other special categories involved. The document is written under Directive (EU) 2016/680 on law enforcement processing, with the GDPR in a bracketed footnote; the rule carries over to commercial age checks, but a reader should see where it comes from. A footnote marks the far edge: Article 9 applies where biometrics sort people into clusters by ethnicity or another special category. Age is not on the GDPR list. CNIL drew that line straight to this case back in a publication of 22 September 2022: "Some age estimate procedures are based on facial analysis, but are not intended to identify the individual". The same page advises that a local estimate "should be preferred in order to minimise the risk of data leakage".

A regulator has drawn the boundary. In case EXP202317887 Spain's AEPD fined age and identity verification vendor YOTI LTD 950,000 euros, 500,000 of it under Article 9. Yoti defended itself with this article's own argument: the processing "no tiene el propósito de identificar o autenticar a un individuo". The principle was not rejected; the product failed on its own facts. Its facial template lives as long as the account and is matched on PIN change and account recovery. That is identification, and Article 9 engaged on purpose.

While a system returns an age group and stores nothing, Article 9 stays out. A stored facial template and a repeat match pull the processing under Article 9. No CJEU ruling settles this boundary; a reasoned regulator decision already does.

The DSA pushes the same way: compliance with Article 28 "shall not oblige providers of online platforms to process additional personal data in order to assess whether the recipient of the service is a minor".

Six methods and what each leaves on your side

Comparison table

What regulators recommend

The EDPB in Statement 1/2025 on Age Assurance and CNIL reduce the advice to four things:

The EU mini-app carries that logic all the way: it discloses to a site "only whether the user meets the requested age threshold". Recommendation (EU) 2026/1035 asks Member States to make the solution available by 31 December 2026.

The EU and the UK: two regimes that should not be mixed

EU GDPR. Article 5 requires minimisation and storage limitation; Article 35 an impact assessment where risk is high. Article 35(3)(a) states the case in full: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the person or similarly significantly affect them. No EU-wide list of DPIA triggers exists by the rule's own design: Article 35(4) assigns those lists to the supervisory authority.

United Kingdom. UK GDPR and the Online Safety Act apply, the children's duties are already in force, and the standard is "highly effective age assurance". In its joint statement with the ICO, Ofcom lists the methods that fail the standard: self-declaration used in isolation, payment methods that do not require the user to be 18 or over (its example is debit cards), and general contractual restrictions on age. The other half of the list sits in the same statement as an image (Figure 2) and does come out of the PDF: the methods Ofcom counts as capable of being highly effective "include, but are not limited to" credit card checks, open banking, photo-ID matching, facial age estimation, mobile-network operator (MNO) age checks, digital identity services and email-based age estimation. Credit cards and facial age estimation stand in that column, on the regulator's own list. For services with a 13 bar the ICO gives its own examples: "For services enforcing a 13 minimum age, current examples include, but are not limited to, facial age estimation, digital ID, or one-time photo matching". Profiling the ICO considers "not currently an effective method for preventing underage users". The penalty ceiling is the greater of £18 million and 10% of qualifying worldwide revenue. A DPIA sits in the same statement as expected conduct: the service "conducts a DPIA to evaluate the risks associated with its data processing activities".

How to choose a method: five steps

STEP 1 — Write out thresholds and jurisdictions

In a table: which threshold, under which law, which country. Article 8 GDPR is easy to stretch beyond the rule: it works where the lawful basis is consent under Article 6(1)(a) and the service is offered directly to a child. There the bar stands at 16, and a Member State may lower it to no less than 13. The map is easier to build with a licensing and compliance team, since age verification rarely arrives alone.

STEP 2 — Choose by what stays on your side tomorrow

Put the table's two columns side by side: what is collected, where it is processed. A method leaving nothing behind beats a more precise one.

STEP 3 — Fix the fate of the data in the vendor contract

Three points: what the vendor receives, what it retains and how long, what returns. Discord's vendor requirement works as model wording: keep what is submitted "for as long as it takes to confirm your age, and to permanently delete it immediately after", then pass the platform "a signal containing your age group". Checking that clause against the perimeter is part of a regulatory compliance audit.

STEP 4 — Run the DPIA before launch

Behavioural estimation falls under 35(3)(a) once both limbs of the rule meet: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, and decisions based on it that produce legal effects or similarly significantly affect the person. Wrongly locking an adult out is, in our assessment, such a decision. That is where GDPR, CCPA and COPPA support starts.

STEP 5 — Describe the mechanics in product documents

The privacy policy names the method, the categories collected, the retention and the vendor. Updating that set is part of the product document package: privacy policy, EULA, terms and conditions.

Verification methods split on one criterion: what sits on your disk tomorrow morning. A passport scan creates risk out of all proportion to telling a fifteen-year-old from an eighteen-year-old; a boolean closes the same task with almost no new obligations. The AEPD case draws the boundary inside one technology: a one-off verdict does not engage Article 9, a stored facial template does.
— Futura Digital's assessment

What has actually been penalised

The nearest big case is retold wrong. TikTok's €345 million fine of September 2023 covered public-by-default profiles of child users — the regulator's own term — and transparency failures. Its age verification was found compliant with Article 25, and Article 35 appears nowhere among the infringements.

Ofcom has been fining failures of that same highly effective age assurance standard since November 2025: from £50,000 (Itai Tech Ltd, which ran the nudification site Undress.cc, 20 November 2025) up to a record £1.35 million (8579 LLC, 23 February 2026). Two weeks after the Itai Tech decision, on 4 December 2025, the million went to AVS Group Ltd: "we do not consider it to be highly effective, and have fined the company £1,000,000". The headline figures repay unpacking: Youngtek Solutions' £600,000 is £500,000 for the missing age check plus £100,000 for not answering the regulator's information request, and separate non-response penalties went to Itai Tech (£5,000) and to AVS and 8579 LLC (£50,000 each). The targets so far have been services carrying pornographic content.

Need help choosing a method and the documents behind it — write to us. We work through your product mechanics and assemble a set that survives regulator and store review.