Article 28 Data protection in age assurance
Age assurance solutions shall not enable the identification of the recipient nor locate, track, target, advertise to or profile recipients for any purpose.
Providers of services and of systems falling within the scope of this Regulation, and any entity acting on behalf or together with such providers in age assurance, shall not maintain, acquire or process more personal data than strictly necessary to assess if the recipient of the service or the user of the system has met the age thresholds laid down in this Regulation, and shall not further process, share or combine this information with any additional data, without prejudice to Article 29(6), and they shall not combine personal data stored or relating to the use of the system with personal data from any other services offered by the provider or from third-party services.
Providers of services and of systems falling within the scope of this Regulation, and any entity acting on behalf or together with such providers in age assurance, shall ensure that the measures used are based on state-of-the-art technology.Any age assurance measure shall be zero knowledge proof.
By way of derogation from paragraph2, providers referred to in Article 16(4) and Article 8(1) may store, at account level, the age signal that a user has successfully met a specific age threshold under this Regulation, for the sole purpose of avoiding repeated age assurance. Such age signal shall be limited to the minimum information necessary for that purpose.
Providers of services and of systems falling within the scope of this Regulation shall take the necessary relevant technical and organisational measures to comply with paragraphs 1, 2, 3 and 4.