Article 30 Empowerment to the Commission
The Commission shall maintain:
an EU list of providers of EU proof of age attestations certified in accordance with Article 29(3) and notified by any Member States;
an EU list of EU age verification solutions certified in accordance with Article 30(2) and notified by any Member States.
The Commission shall publish the EU list and keep it up to date in a secure and machine-readable form.
The Commission shall adopt implementing acts laying down the specifications as a basis of the functioning of the EU Age Verification Scheme, including the requirements applicable to EU age verification solutions and to the issuance, presentation and verification of EU proof of age attestations. Such implementing acts shall be limited to what is necessary to ensure the effective, secure, privacy-preserving, interoperable and uniform implementation of Article 29(2) and (3) and shall be based on the principle of data minimisation, purpose limitation, security, technological neutrality and proportionality, and shall ensure interoperability with the European Digital Identity Wallets provided pursuant to Article 5a of Regulation (EU) No 910/2014. Those implementing acts shall specify the detailed technical, organisational, privacy and security requirements applicable to EU proof of age attestations and their providers and for EU age verification solutions and their providers, the evidence and procedures for demonstrating and assessing public authorities, and the specifications of the EU lists referred to in paragraph 1. The implementing acts may also include requirements for a trust mark for age verification solutions. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 40(2).
The Commission shall adopt delegated acts, in accordance with Article 39, in order to supplement this regulation by specifying:
the requirements applicable to alternative age assurance solutions as referred to in Article 29(4), including the requirements necessary to demonstrate compliance with Article 27 and Article 28. Those delegated acts shall specify the detailed technical, organisational, privacy and security requirements applicable;
the obligations applicable to operating systems as referred to in Article 29(6), including the requirements necessary to ensure the secure, privacy-preserving and interoperable sharing of age signals.