We are increasingly asked how the myriad EU and UK legislation requiring age restrictions online all fit together. This article seeks to explain this. We do so by primarily considering the UK which is leading the way in the SafetyTech sector and its associated legislation and regulation, but it is already apparent that the EU is mirroring many, if not all, of these measures to some degree.
So, first of all, which are the applicable laws when considering online age restrictions?
Contract Law
Various legacy legislation on the sale of age-restricted goods applying online
Various legacy legislation on access to age-restricted online services.
Advertising restrictions
General Data Protection Regulations
There is also a very specific requirement for parental consent before younger children can give permission (under Article 8) for the processing of their data. This ‘digital age of consent’ varies between Member States of the EU. In the UK it is 13, for example. (Note that consent is only one of a number of legal bases to process personal data, so it is not a general prohibition on processing the data of younger children with their parents’ approval - organisations can also rely on performance of a contract, a legitimate interest, a vital interest, a legal requirement, and a public interest.)
The Audio-Visual Media Services Directive
VSPs must establish and operate systems for obtaining assurance as to the age of potential viewers. VSP providers must ensure that restricted material that has the most potential to harm the physical, mental or moral development of children must be subject to the strictest access control measures.
This began life in 1989 as the “Television without Frontiers” directive, and was renamed in 2008, applying a requirement for age verification to linear television channels with adult content. In 2018 it was extended to cover online VSPs such as Youtube. EU laws have to be transposed into the domestic law of Member states before they are effective; only 4 states did so by the deadline of 19 Sept 2020, but others are progressively catching up under pressure from the European Commission. The UK has put the directive into law, but its regulator, Ofcom, is still consulting on how it will enforce it.
Age-Appropriate Design Code (also known as the Children’s Code)
Online Safety Bill (UK, not yet law)
Strict or basic age verification.
There are different levels of reliability and accuracy required by the various legislation – referred to as “levels of assurance.”
Broadly these fall into two categories:
- Strict verification is where an actual date of birth is required to be legally compliant. This is either because the law specifies an exact age, or the level of risk of harm to a child is high enough to warrant the strongest forms of due diligence about their age. An example of a specific age is the Digital Age of Consent” where if you are 12 years and 11 months old in the UK, it will not be legal for a website to process your data on the basis of consent without your parents’ approval. Likewise, to sign a contract that can be enforced, you must be at least 18 years-old. A day short, and the other party will fail in court so the contract is worthless.
- Basic age verification allows for an estimate of a user’s age to be sufficient to keep regulators happy. The Age-Appropriate Design Code is the best example. The ICO goes as far as setting out five age-bands as guidance, but services can choose their own age bands, and indeed, they may specify overlapping bands.
Other examples could be the processing of children’s data based on legitimate interest where the nature of the processing is not a significant risk to a child of 8½ but would normally be more reasonably considered acceptable once they reach 10.
The UK Online Safety Bill is also a proportionate requirement, with risk assessments guided by the regulator through published risk profiles for different types of service, and codes of conduct for each new duty. But there is a wide degree of discretion for the services to determine what level of protection, if any, is required for children of different ages. This introduces, again for lower levels of potential harm, the opportunity to use softer estimation techniques.
The AVPA is leading the design of a pan-European infrastructure for parental consent and age verification, as a pilot project funded by the European Commission at the request of the European Parliament. This interoperable network of providers, www.euCONSENT.eu, will allow such checks to be made with little or no impact on the user experience.