Verify age without building identity trails

Kenya should not confuse knowing someone's age with knowing someone's identity. The best age-assurance system is the one that establishes the required fact with the least additional surveillance.

Photo credit: Shutterstock

Kenya is right to demand strong protection for children online. But there is a dangerous way to achieve it: make every user reveal who they are to prove how old they are.

That would turn child protection into identity infrastructure. Age assurance is becoming one of the hardest problems in digital governance. Platforms need reliable ways to distinguish adults from children when access to pornography, gambling or other age-restricted services is at stake.

Obvious solutions like uploading a national ID, submitting a selfie, scanning a passport or consulting identity databases can create new stores of sensitive information and targets for attackers.

The policy question should, therefore, change. How little identity must a platform learn to make the age decision safely?
Kenya has the legal foundation for that approach.

The Data Protection Act requires personal data to be adequate, relevant and limited to what is necessary.

The Office of the Data Protection Commissioner (ODPC) says age-verification methods involving children must be proportionate, privacy-preserving, compliant with data minimisation and grounded in risk. It also requires data protection by design and impact assessment for such mechanisms.

The Communications Authority's child-online-protection guidelines reinforce this.

Kenya should turn those principles into a Minimum Identity Principle. An online service should learn no more about a person than is necessary to establish the age-related fact required for access.

A service may need to know that a user is over 18. It does not automatically need the user's full name, address, national identity number and date of birth. A platform applying protections for younger users may need an age band, not a permanent identity dossier.

The distinction is achievable. The European Commission's age-verification architecture allows users to prove they are over 18 without revealing their age, identity or other personal information. Its 2026 approach calls for anonymous proof-of-age technology, cybersecurity scrutiny and trusted verification providers.

W3C standards provide another building block. Verifiable credentials can carry cryptographically protected claims, while privacy-preserving designs can support selective or predicate disclosure.

W3C's 2026 credential threat model gives the age example directly. Instead of revealing an entire document, a person could prove only the required age fact. It warns that poor designs can make credentials linkable across services.

This is no longer an unstandardised niche. ISO/IEC 27566-1:2025 establishes a global framework for age-assurance systems in which privacy and security are core characteristics. Kenya's eventual architecture should pass five tests.

Necessity: Is an age check genuinely required for the risk being controlled? Unicef warns that age restrictions alone cannot create safe digital environments.

Proportionality: The strength of verification should match the risk. The ODPC takes this position: higher-risk processing should demand greater certainty rather than imposing the strongest possible identity check everywhere.

Minimum disclosure: Where feasible, the system should reveal the age fact required. “Over 18” can be enough without surrendering a reusable copy of a passport.

Unlinkability: Proving age on one service should not create a mechanism through which platforms, verification providers or other actors can map the person's activity across the internet.

Lifecycle security: What happens to ID scans, facial images, biometric templates, tokens and verification logs after the decision? This matters because facial age estimation is probabilistic rather than infallible.

NIST testing demonstrates measurable estimation error and notes that different applications require different accuracy thresholds.

The Communications Authority and the ODPC should develop a national age-assurance framework aligned with Kenya's data-protection regime and ISO/IEC 27566-1.

Kenya should not confuse knowing someone's age with knowing someone's identity. The best age-assurance system is the one that establishes the required fact with the least additional surveillance.

Kenya can protect children without constructing identity trails for everyone.

The internet sometimes needs to know whether a user is old enough. It should not automatically need to know who that user is.

George Kariuki is an ICT and Cybersecurity Professional

PAYE Tax Calculator

Note: The results are not exact but very close to the actual.