Mmcp.market

age-verification-methods skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Evaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.

A100/100content scan

Is the age-verification-methods skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the age-verification-methods skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/age-verification-methods ~/.claude/skills/age-verification-methods
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Age Verification and Estimation Methods

Overview

Age verification and age estimation are distinct but complementary approaches to determining whether a user is a child for the purpose of applying appropriate data protection safeguards. Age verification provides a definitive confirmation of age through documentary or transactional evidence. Age estimation provides a probabilistic assessment of age using technological methods such as facial analysis, behavioural analysis, or device signals. The selection of an appropriate method requires balancing accuracy, privacy impact, accessibility, and proportionality. This skill covers the full spectrum of available methods, their regulatory context under the GDPR, UK AADC, COPPA, and emerging legislation such as the EU Digital Services Act (DSA) and the UK Online Safety Act 2023, and provides implementation guidance based on ICO and CNIL recommendations.

Regulatory Context

GDPR Article 8(2)

"The controller shall make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the child, taking into consideration available technology."

The "reasonable efforts" standard is context-dependent. The EDPB has not prescribed specific technologies but expects controllers to adopt verification proportionate to the risk of the processing.

UK AADC Standard 3 — Age-Appropriate Application

"Take a risk-based approach to recognising the age of individual users and ensure you effectively apply the standards in this code to child users." The ICO guidance states that the level of certainty required depends on the risks to children from the processing. Higher risks demand more robust age assurance methods.

UK Online Safety Act 2023

Section 11(3) requires providers of regulated user-to-user services and search services to use "proportionate systems or processes" designed to prevent children from encountering primary priority content that is harmful to children. Ofcom's codes of practice specify age verification as a recommended measure for pornographic content and age estimation for broader content categories.

EU Digital Services Act — Article 28

Providers of online platforms accessible to minors must put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors on their service. This includes age verification for services with content restrictions.

France — Loi SREN (2024)

France's law to regulate and secure the digital space requires age verification for access to pornographic websites, mandating technical solutions certified by CNIL that verify age without identifying the user. The CNIL-approved reference system requires a "double-blind" architecture where the identity verification provider and the content provider cannot link the user's identity to the content access.

Age Verification Methods

Method 1: Document-Based Verification

Description: User uploads or presents a government-issued identity document (passport, national ID card, driver's licence) which is verified against document security features and optionally against government databases.

Technical Implementation:

  • Optical Character Recognition (OCR) extracts date of birth and document details
  • Machine Readable Zone (MRZ) validation for passports and ID cards conforming to ICAO Doc 9303
  • Document authenticity checks: hologram detection, microprint analysis, UV feature verification (for physical presentation)
  • Optional: NFC chip reading for ePassports conforming to ICAO 9303 Part 10
  • Optional: Liveness check to confirm the person presenting the document matches the photo

Accuracy: Very high (99%+ when combined with liveness detection)

Privacy Considerations:

  • Collects highly sensitive identity data (ID number, full name, address, photo)
  • Data minimisation: extract only date of birth, discard full document image immediately after verification
  • Storage: do not retain the document image or full identity data; retain only a binary age-confirmed flag and a verification token
  • DPIA required under Art. 35 due to large-scale processing of identity documents

Accessibility: Excludes individuals without government-issued ID (estimated 1.5 million UK adults lack photo ID per Electoral Commission 2021 data). Not appropriate as the sole method.

Use Cases: Age-restricted content (gambling, alcohol, adult content), high-risk services

Method 2: Facial Age Estimation (AI-Based)

Description: Machine learning models estimate a user's age from a facial image captured by the device camera. The estimation provides an age range (e.g., "over 18" or "13-17") rather than a precise age.

Technical Implementation:

  • Convolutional Neural Network (CNN) trained on large-scale age-labelled facial datasets
  • Real-time processing on-device (edge computing) to avoid transmitting facial images to servers
  • Liveness detection to prevent spoofing via photographs or video replay
  • Age estimation outputs a confidence interval (e.g., estimated age 14 +/- 2 years with 95% confidence)
  • The facial image is processed in volatile memory and not stored

Accuracy: Mean Absolute Error (MAE) of 1.5-3 years depending on the model and demographic. Accuracy varies by: age group (lower accuracy for children under 8 and adults over 65), ethnicity (documented bias in some commercial systems), lighting and image quality.

Privacy Considerations:

  • Facial images constitute biometric data under GDPR Art. 4(14) and Art. 9(1) if used for unique identification
  • When used solely for age estimation (not identification), the processing may not constitute "biometric data for the purpose of uniquely identifying" under Art. 9 — the ICO has confirmed this interpretation in its Children's Code guidance
  • On-device processing with no server transmission significantly reduces privacy risk
  • DPIA is recommended even when processing is on-device due to sensitivity of facial data

Key Providers: Yoti (Age Estimation), VerifyMyAge (EstimateMyAge), Privately SA

ICO Position: The ICO has stated that facial age estimation technology that processes images locally, does not store images, and does not identify the individual can be a proportionate method for age assurance. The ICO conducted a joint audit with the Australian Information Commissioner (OAIC) of Yoti's age estimation technology in 2022 and concluded it met data protection requirements when implemented with appropriate safeguards.

Method 3: Digital Identity Verification

Description: User authenticates through a trusted digital identity provider (eID, digital wallet, Open Banking) that confirms age without disclosing full identity to the relying party (service provider).

Technical Implementation:

  • OpenID Connect for Identity Assurance (OIDC4IDA) protocol for attribute-based verification
  • The identity provider confirms a specific attribute (e.g., "isover18": true) via a signed assertion
  • The relying party receives only the age attribute, not the user's name, address, or other identity data
  • EU Digital Identity Wallet (eIDAS 2.0 Regulation, expected 2026 rollout) will enable selective attribute disclosure
  • UK Digital Identity and Attributes Trust Framework (DIATF) provides a certification scheme for identity providers

Accuracy: Very high (dependent on the identity provider's verification of the underlying identity)

Privacy Considerations:

  • Minimal data disclosure: only the specific age attribute is shared
  • The identity provider knows the user's identity but not which service they are accessing (if double-blind architecture is used)
  • The service provider knows the user is accessing their service but not their full identity
  • Aligns with CNIL's recommended "double-blind" approach for age verification

Use Cases: EU/EEA services preparing for eIDAS 2.0 Digital Identity Wallet; UK services using DIATF-certified providers

Method 4: Self-Declaration with Risk Mitigation

Description: User declares their age through a date-of-birth field or age-range selector. The declaration is treated as the baseline, supplemented by risk-based measures to detect false declarations.

Technical Implementation:

  • Neutral age prompt: "What is your date of birth?" with a scrollable date picker (no calendar default to current date)
  • No indication of the "correct" answer or the age threshold being applied
  • Behavioural signals that may indicate false declaration: immediate re-entry with a different date, cookie evidence of prior declaration, typing speed patterns inconsistent with the declared age
  • If false declaration is suspected, escalate to a higher-assurance verification method

Accuracy: Low as a standalone method. Children commonly misrepresent their age online. Ofcom's 2023 research found that 33% of UK 8-17 year olds have a social media profile despite being below the platform's minimum age.

Privacy Considerations: Minimal data collection (only declared date of birth). No biometric processing. No identity document collection.

Use Cases: Low-risk services as a first-line screening measure, always combined with additional safeguards for medium and high-risk services

Method 5: Credit Card or Payment Verification

Description: User's age is inferred from possession of a credit card (typically issued only to adults 18+) through a monetary transaction.

Technical Implementation:

  • Micro-transaction (USD/EUR/GBP 0.50) charged and refunded within 48 hours
  • The card must be a credit card (not a debit card or prepaid card, which may be issued to minors)
  • Transaction notification sent to the cardholder provides an audit trail
  • Some implementations use 3D Secure (3DS2) authentication for additional identity assurance

Accuracy: Moderate. Establishes that the person has access to a credit card, which correlates with being over 18. Does not verify the specific age of the cardholder. Children may use a parent's card.

Privacy Considerations: Payment card data is subject to PCI DSS requirements. The service should not store full card details. Only the transaction confirmation and a binary "has credit card" flag should be retained.

Method 6: Mobile Network Operator (MNO) Verification

Description: The mobile network operator confirms the user's age bracket based on the subscriber information associated with the SIM/eSIM, without disclosing the user's identity to the requesting service.

Technical Implementation:

  • API call to MNO (via aggregator such as GBG, boku, or Sinch) with the user's mobile number
  • MNO returns a binary response (e.g., "isover18": true/false) without disclosing identity
  • Relies on the age data the MNO collected during subscriber registration (ID check at point of sale)

Accuracy: High for determining over/under 18, since MNO registration typically involves ID verification. Lower certainty for granular age (e.g., distinguishing 13 from 15) as MNOs may not record precise birth dates.

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway
  • Aarckit-at-dsgvo[COMMUNITY] Assess Austrian DSG / DSGVO obligations — Datenschutzbehörde patterns, §§12–13 DSG special provisions, image processing (§12 DSG), and Austrian enforcement practice

All agent skills → · MCP servers