European Commission policy officer Johan Bodenkamp used his attendance at Nexus Luxembourg at Luxexpo The Box on 11 June to set out an age-verification blueprint designed to let online platforms check whether users are old enough for restricted services without seeing their identity, exact age or browsing behaviour.
“It is very important for online platforms to make sure that they can do that in a way that suits us, the Europeans, according to our European values,” Bodenkamp said.
Online services already have many ways to learn about their users. Bodenkamp’s pitch was that age checks should not add another one.
Bodenkamp is based in Luxembourg and works on safer internet policy in the European Commission’s DG CNECT department. He said the tool was intended to prove only whether a user was above a required threshold.
It is not a finished consumer app. Bodenkamp described it as a “blueprint”, or white-label application, that member states and companies can adapt before making it available.
Less data, not more
Bodenkamp said the application would allow users to prove they meet an age requirement “without revealing any kind of personal information, not even your exact age”.
A website would receive only a narrow confirmation that the user meets the relevant age condition.
Otherwise, an age check can become another data point. Platforms could try to infer age from a user’s behaviour, contacts or activity, but Bodenkamp said that was precisely the route the Commission wanted to avoid. “We would like to provide something that is in line with our European values,” Bodenkamp said. “We want to do it in a privacy-preserving way.”
A narrow proof
Under the version presented in Luxembourg, users would create a proof-of-age credential through a national electronic ID, a passport or identity card, a third-party application such as a banking or telecoms app, or an in-person check at a public or commercial counter.
If a passport or identity card is used, Bodenkamp said the data would remain on the user’s device while the credential is created and would then be deleted. “No data is leaving your device,” he said. “It only helps you to create this proof of age credential that only states you are above a certain age.”
The result would not be an identity document shared with websites. It would be an attestation that the user is above a given threshold. “The proof of age attestation only shows that you are above a certain threshold, an age threshold, nothing else,” Bodenkamp said.
The proof would also have to come from a trusted issuer. Bodenkamp said member states would publish lists of proof-of-age attestation providers, allowing platforms to check that the credential had been signed by a recognised source.
Open to scrutiny
The Commission has made the blueprint open source, so the code and technical specifications can be examined, tested and reused. “Anybody can have a look at the code, can have a look at the technical specifications, can come with input, and also help us to make it even better,” Bodenkamp said.
The tool is intended to work across the European Union using common standards, while still allowing national adaptation. Bodenkamp said the same blueprint could be adapted to different legal thresholds or deployment choices. “It is a harmonised solution across Europe,” he said. “It works EU-wide, because it is really working with the same specifications and standards.”
Not the whole internet
Bodenkamp used part of the presentation to address fears that age verification could become a general gateway to the internet. “Unfortunately we receive a lot of questions at the Commission about, oh my god, this is the end of the free internet,” he said. “This is obviously not our intention.”
He said the tool was not intended to prevent general online access, but to apply where age verification is required for a specific type of content or service.
The keynote included a video demonstration of a user creating a credential from a passport or identity card. The demo said document data and photos would not be stored in the app, and no personal data would leave the device. “No profiling, no tracking, no identity exposure,” the video said.
Below 18
The initial version presented by Bodenkamp focuses on the 18-plus use case, including access to age-restricted goods or services such as alcohol, gambling or adult content.
The harder cases start below 18. Bodenkamp said the blueprint could be adapted to other thresholds, including 16, 15 or 65-plus, depending on national law and use cases.
He also referred to the debate over whether young people should face a form of digital majority age for access to social media or similar services. The outcome remains open, but Bodenkamp said the technical model could be adapted if such thresholds are introduced.
Speaking to Paperjam after the session, Bodenkamp said the system should not be confused with platforms using behavioural data to infer how old someone is. “We don’t want big tech companies or small tech companies to have all sorts of data that they can use and reuse,” he said.
No silver bullet
Bodenkamp said the Commission’s blueprint should not be treated as a complete answer to online child protection. “What I’ve been presenting, as you can imagine, is not the silver bullet,” he said. “It’s not the magic solution to all our problems.”
The under-18 question is one reason. Bodenkamp pointed to Greece’s children’s wallet as an example of a country with a national registry that can support age checks for younger users, while saying other member states would need to see how the European debate develops.
He also drew a line between age estimation and age verification. Estimation may suit lower-risk cases, he said, but formal verification is expected for higher-risk services such as gambling, alcohol, tobacco, drugs or pornography, as well as where the law sets a specific age requirement.
Dating platforms describing themselves as 18-plus should also rely on verification rather than estimation, he said. The offer is proof of age, and little else.



