

Stop Forcing Us to Hand Over Our IDs: Privacy Is a Right, Not the Price of Going Online
The Issue
You should never have to give up your identity for digital safety. The web should be a safe place where we don't have to relinquish our passports, driving licences or even biometrics to strangers. And that's where we're headed.
Today, people on the Web are being asked to submit government ID's or facial scans just to verify that they're of legal age for enjoying a perfectly legal service online.
This privacy annihilating manure has already become the common fallback, even though it imposes massive security liabilities on the innocent masses.
"Consider the straw man dichotomy between protecting online safety and preserving privacy. " Children deserve the protection. Adults deserve the privacy. We can and must have both.
Why this is significant you could also phrase it as: If you don't understand this, then how will you understand the rest? The obligate uploads of government issued identification result in an enormous concentration of highly sensitive information.
Some companies like Persona and Yoti would use identity documents and biometric data in providing an identity and age verification service.
Their privacy policy indicate they gather and process very sensitive data about a persons identity; they might hold the data for the period defined by law or contract, and they might share it with service providers customers regulators and others where required or authorised by law.
This shouldn't come as a surprise after history has already proved how dangerous this approach can be.
In 2025, a breach occurred involving a third-party provider which was used by Discord in their customer support and age verification process.
This breach compromised thousands of users' sensitive information, including images of approximately 70,000 government-issued ID images used for the process of age verification.
Just one more thing. THESE WERE REAL PEOPLE WITH REAL IDS.
Real passports. Valid driving licences. Authentic identities. When documents like these get out, there is no "resets" to undo the damage they cause.
People can endure years of attempts at consummate identity fraud impersonation financial crimes and the stressful knowledge that their most private personal information may never be safe again.
The Solution
If we're lucky, there's a much better way to do this.
Given the failures of the other approach, we call on the legislator and the technology companies to reinforce the privacy preserving approach exemplified by https://itsnot1984.uk/ rather than implementing mandatorily uploading of government IDs.
Conducting a one-off age check on a legitimate trusted website like GOV. UK. The development of a secure cryptographic token that is stored locally by the user (e. g. on their browser or in their password manager).
Allow websites to have a simple True/False check that the user falls in the required age range.
Making sure all websites and third party verification agency do not keep or receive passports, driving licences, or any other forms of ID when doing non-admin, non-merchant and aren't required to confirm the identity.
This method seeks to establish age while minimizing the amount of personal data disclosed to services and third parties, buying into the data minimisation principle rather than a mass collection of identities.
Modern cryptography is what we should have been using from the first namely, privacy-protection. Instead we were asking literally millions of people to upload their IDs wherever new services had age gates.
We call upon the UK Government, regulators, and major technology companies to:
End the routine requiring of mandatory third-party government ID uploads where privacy sensitive alternatives are feasible.
Seek to implement age verification systems which don't require the collection of personal data.
Support the implementation of cryptographically sound, tokenized proof-of-age schemes such as that advanced by https://itsnot1984.uk/ . Make certain that the future online security policies do not only look out for children, but also for the very basic of rights for every individual.
The https://itsnot1984.uk/ method works like this:
"1. BROWSER_AUTH
A secure age-verification control appears natively in the browser UI. Easy to use, no documents required.
Legislate all browsers available in the UK must provide a new simple token storage and OAuth feature.
2. GOV_VERIFIED
GOV.UK
Users verify once through trusted GOV.UK identity services. User is not tracked across sites.
Build a new GOV.UK service which can use existing government services or ID uploads for verification.
3. SECURE_TOKEN
A cryptographic token is stored in the browser, to be read by third party sites. No sensitive data is shared.
The token is returned to the browser in a hidden store and surfaced as a simple flag for websites to detect.
4. ONE-TIME_NO_RISK
This solution would enable safe browsing without risk to personal data or having your behaviour tracked.
Sensitive data is never uploaded to third parties or transferred to the browser, guaranteed verification."
All additional uploads are yet another gateway for the criminal, another database can be gained access to and another family potentially at risk.
It's essentially a "help yourself" buffet for cybercriminals.
No need to passively accept this privacy-destroying sludge as the host of our digital lives.
Demand for more. Request privacy by design.
So sign this petition today, and make sure you share it with whom people as more and more of us start to realize that digital security should never be at the expense of our basic right to privacy.
34
The Issue
You should never have to give up your identity for digital safety. The web should be a safe place where we don't have to relinquish our passports, driving licences or even biometrics to strangers. And that's where we're headed.
Today, people on the Web are being asked to submit government ID's or facial scans just to verify that they're of legal age for enjoying a perfectly legal service online.
This privacy annihilating manure has already become the common fallback, even though it imposes massive security liabilities on the innocent masses.
"Consider the straw man dichotomy between protecting online safety and preserving privacy. " Children deserve the protection. Adults deserve the privacy. We can and must have both.
Why this is significant you could also phrase it as: If you don't understand this, then how will you understand the rest? The obligate uploads of government issued identification result in an enormous concentration of highly sensitive information.
Some companies like Persona and Yoti would use identity documents and biometric data in providing an identity and age verification service.
Their privacy policy indicate they gather and process very sensitive data about a persons identity; they might hold the data for the period defined by law or contract, and they might share it with service providers customers regulators and others where required or authorised by law.
This shouldn't come as a surprise after history has already proved how dangerous this approach can be.
In 2025, a breach occurred involving a third-party provider which was used by Discord in their customer support and age verification process.
This breach compromised thousands of users' sensitive information, including images of approximately 70,000 government-issued ID images used for the process of age verification.
Just one more thing. THESE WERE REAL PEOPLE WITH REAL IDS.
Real passports. Valid driving licences. Authentic identities. When documents like these get out, there is no "resets" to undo the damage they cause.
People can endure years of attempts at consummate identity fraud impersonation financial crimes and the stressful knowledge that their most private personal information may never be safe again.
The Solution
If we're lucky, there's a much better way to do this.
Given the failures of the other approach, we call on the legislator and the technology companies to reinforce the privacy preserving approach exemplified by https://itsnot1984.uk/ rather than implementing mandatorily uploading of government IDs.
Conducting a one-off age check on a legitimate trusted website like GOV. UK. The development of a secure cryptographic token that is stored locally by the user (e. g. on their browser or in their password manager).
Allow websites to have a simple True/False check that the user falls in the required age range.
Making sure all websites and third party verification agency do not keep or receive passports, driving licences, or any other forms of ID when doing non-admin, non-merchant and aren't required to confirm the identity.
This method seeks to establish age while minimizing the amount of personal data disclosed to services and third parties, buying into the data minimisation principle rather than a mass collection of identities.
Modern cryptography is what we should have been using from the first namely, privacy-protection. Instead we were asking literally millions of people to upload their IDs wherever new services had age gates.
We call upon the UK Government, regulators, and major technology companies to:
End the routine requiring of mandatory third-party government ID uploads where privacy sensitive alternatives are feasible.
Seek to implement age verification systems which don't require the collection of personal data.
Support the implementation of cryptographically sound, tokenized proof-of-age schemes such as that advanced by https://itsnot1984.uk/ . Make certain that the future online security policies do not only look out for children, but also for the very basic of rights for every individual.
The https://itsnot1984.uk/ method works like this:
"1. BROWSER_AUTH
A secure age-verification control appears natively in the browser UI. Easy to use, no documents required.
Legislate all browsers available in the UK must provide a new simple token storage and OAuth feature.
2. GOV_VERIFIED
GOV.UK
Users verify once through trusted GOV.UK identity services. User is not tracked across sites.
Build a new GOV.UK service which can use existing government services or ID uploads for verification.
3. SECURE_TOKEN
A cryptographic token is stored in the browser, to be read by third party sites. No sensitive data is shared.
The token is returned to the browser in a hidden store and surfaced as a simple flag for websites to detect.
4. ONE-TIME_NO_RISK
This solution would enable safe browsing without risk to personal data or having your behaviour tracked.
Sensitive data is never uploaded to third parties or transferred to the browser, guaranteed verification."
All additional uploads are yet another gateway for the criminal, another database can be gained access to and another family potentially at risk.
It's essentially a "help yourself" buffet for cybercriminals.
No need to passively accept this privacy-destroying sludge as the host of our digital lives.
Demand for more. Request privacy by design.
So sign this petition today, and make sure you share it with whom people as more and more of us start to realize that digital security should never be at the expense of our basic right to privacy.
Petition Updates
Share this petition
Petition created on 7 August 2026