The European Commission has adopted a recommendation urging all EU member states to accelerate deployment of a bloc-wide age verification app, with a target of making it available to citizens by the end of 2026. Unlike the UK’s approach, which asks users to upload identity documents and has driven a measurable spike in VPN usage as people look for workarounds, the EU’s design deliberately avoids collecting or transmitting the underlying personal data at all.
Proving an age without revealing an identity
The app is built around zero-knowledge proofs: a user can demonstrate they meet an age threshold, for example being over 18, without sharing their date of birth, name or any other identifying detail with the platform requesting the check. Member states can deploy it as a standalone application or fold it into the broader European Digital Identity Wallet, the EU’s push toward a single digital identity credential usable across public and private services. Seven member states, Denmark, France, Greece, Italy, Spain, Cyprus and Ireland, are already integrating the app into their national digital wallet rollouts, with Denmark, France, Greece, Italy and Spain acting as first-wave pilots.
The regulatory hook is already in force
This is not a voluntary nice-to-have sitting alongside existing obligations. The Digital Services Act already requires platforms to take “appropriate and proportionate measures” to protect minors, and age assurance is one of the concrete steps regulators point to when assessing whether a platform has met that bar. As the EU age verification infrastructure becomes available nationally, the practical expectation on any platform with age-restricted content, adult products, gambling or similarly regulated services, will shift from “have some form of age check” to “integrate with the standard the EU has built for exactly this.”
What to check now, not in December
For any organisation serving EU users, the sensible move is to start mapping this against your own compliance obligations well before member states finish their rollouts. That means identifying whether your platform falls under DSA age-assurance expectations, understanding how EUDIW-based verification would slot into your existing signup or checkout flow, and making sure whatever age-gating you run today does not quietly become the weakest link in an otherwise GDPR-compliant setup. Bolting on identity verification at the last minute tends to produce exactly the kind of rushed data handling that data protection authorities have been fining companies over all year.
If you need help assessing what EU age verification and DSA obligations mean for your specific platform, or want a privacy-by-design integration plan rather than a last-minute scramble, contact Excello Digital. We help European businesses turn incoming compliance deadlines into implementation plans with enough lead time to get them right.
