

Make Companies Offer Safe Alternatives to ID and Face Scan Age Verification
The issue
Governments and companies are increasingly introducing online age verification systems. Protecting children online is important, but forcing users to upload government ID, face scans, selfies, or biometric data creates serious privacy and security risks.
This is not a hypothetical concern. Discord confirmed that around 70,000 users globally may have had government-ID photos exposed in a third-party breach involving age-related appeals. Once ID documents or face scans are collected, they become high-value targets for hackers, extortion groups, data brokers, and misuse.
A password can be changed after a breach. A face, date of birth, passport, licence, or government-ID image cannot be easily changed. Age checks should verify whether someone meets an age requirement. They should not become a mass identity collection system.
We are calling for governments, regulators, and online platforms to require privacy-preserving age verification alternatives, including:
- anonymous age tokens that only confirm whether a user is over the required age
- zero-knowledge proof systems
- on-device ID checks where documents are not uploaded or stored
- age confirmation through trusted providers such as banks, telcos, schools, or digital identity services
- parental or guardian approval where appropriate
- strict bans on unnecessary storage, resale, or sharing of age verification data
Companies should only collect the minimum information required. Users should not be forced to hand over sensitive identity or biometric data just to access lawful online content or services.
Child safety and privacy should not be treated as opposites. We can protect young people online without creating a permanent identity surveillance system for everyone.
The standard should be simple: Verify age, not identity.

1
The issue
Governments and companies are increasingly introducing online age verification systems. Protecting children online is important, but forcing users to upload government ID, face scans, selfies, or biometric data creates serious privacy and security risks.
This is not a hypothetical concern. Discord confirmed that around 70,000 users globally may have had government-ID photos exposed in a third-party breach involving age-related appeals. Once ID documents or face scans are collected, they become high-value targets for hackers, extortion groups, data brokers, and misuse.
A password can be changed after a breach. A face, date of birth, passport, licence, or government-ID image cannot be easily changed. Age checks should verify whether someone meets an age requirement. They should not become a mass identity collection system.
We are calling for governments, regulators, and online platforms to require privacy-preserving age verification alternatives, including:
- anonymous age tokens that only confirm whether a user is over the required age
- zero-knowledge proof systems
- on-device ID checks where documents are not uploaded or stored
- age confirmation through trusted providers such as banks, telcos, schools, or digital identity services
- parental or guardian approval where appropriate
- strict bans on unnecessary storage, resale, or sharing of age verification data
Companies should only collect the minimum information required. Users should not be forced to hand over sensitive identity or biometric data just to access lawful online content or services.
Child safety and privacy should not be treated as opposites. We can protect young people online without creating a permanent identity surveillance system for everyone.
The standard should be simple: Verify age, not identity.

The Decision Makers


Petition Updates
Share this petition
Petition created on 29 April 2026