GDPR Information Security Personal data Privacy

EU Age Verification under scrutiny as transparency questions remain

The European Commission’s DG CONNECT disclosed nine documents in response to an access-to-documents request, but all were already publicly available resources. No Data Protection Impact Assessment (DPIA), internal privacy-by-design documentation, threat models, or controller-role assessments were released.

DG CONNECT stated it does not hold a DPIA, arguing that responsibility lies with the future publisher of the age verification application. The applicant argues this does not prove that no DPIA or related assessments exist elsewhere within the Commission, contractors, or pilot projects.

Questions remain about the evidence supporting the Commission’s public claims that the app is “technically ready,” anonymous, unlinkable, and impossible to track. Public documentation indicates the solution is a reference implementation that still requires additional integration before production deployment.

The architecture includes passport verification, facial comparison, and liveness detection, although some components are left to implementers rather than being included in the reference solution. The documents also appear inconsistent on the maturity of zero-knowledge proofs, describing them as implemented in some places but experimental or future functionality in others.

A new confirmatory application has been filed, requesting a broader search for DPIAs, security assessments, dataflows, and technical documentation across Commission services and contractors. While the procedural complaint over delayed disclosure has been closed, the substantive review of the Commission’s transparency and privacy documentation remains ongoing.