EDPB Principles for GDPR-Compliant Age Assurance

UK Version of GDPR

In February 2025, the EDPB published guidelines on age assurance and verification under the GDPR. These guidelines stress that businesses must choose proportional, risk-based methods that minimize data collection, avoid profiling, and reduce the risk of wrongful exclusion or discrimination. For online platforms offering age-restricted services—from social media to gaming—these principles clarify how to balance child protection with data minimization. Service providers will need to review their age verification processes, privacy policies, and consent collection workflows to ensure compliance with the new guidance.
🔗 Stephenson Harwood – Data Protection Update

Picture of Dposphere

Dposphere

Recent Post

The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving

The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate

The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the