Overview
ISO/IEC 27566-1:2025 provides a framework for age assurance systems used to support age‑related eligibility decisions. The standard defines core characteristics of age assurance, covering privacy, information security and cybersecurity requirements, methods for assessing age (verification, estimation, inference), stakeholder roles, and practical guidance on deployment and testing. It is intended to help organizations design, evaluate and operate systems that reliably determine or infer a user’s age while protecting personal data and resisting attacks.
Key technical topics and requirements
- Terms and definitions: Common vocabulary for age assurance, actors, data elements and processes to ensure consistent implementation.
- Age assurance methods: Distinguishes age verification (credential-based), age estimation (modelling/biometrics), and age inference (behavioural or contextual signals), including successive validation approaches.
- Functional characteristics: Requirements for data acquisition, binding results to the correct individual, primary/secondary credentials, configuration management, and delivery of age results.
- Performance characteristics: Guidance on assessing effectiveness and efficiency using metrics such as classification accuracy, primary metrics, outcome error parity, resource utilization and testability.
- Privacy characteristics: Emphasis on privacy by design and default, data minimization, purpose limitation, non‑disclosure of age‑related data, access control, data disposal, avoidance of enlarging digital footprints, user awareness and audit logging.
- Security characteristics: Security by design, protections against replay/forwarding/reuse of results, resistance to attack vectors (including biometric presentation attacks, spoofing, counterfeiting), contra indicators and fail‑safe behaviours.
- Acceptability and inclusivity: Requirements for user engagement, assistance, inclusivity, complaint handling and other user‑facing considerations.
- Practice statements: Recommended practices for age assurance providers, relying parties and intermediaries.
Practical applications and who uses this standard
- Organizations implementing age verification on online platforms (e‑commerce, gaming, streaming, social media).
- Identity providers, age assurance providers and intermediaries designing credentialing workflows.
- Platform operators and relying parties that must make age‑related eligibility decisions while complying with privacy and security obligations.
- Regulators, policymakers and consumer protection agencies evaluating technical measures and harmonizing policy.
- Security and privacy auditors testing performance, robustness and compliance of age assurance systems.
Related standards
ISO/IEC 27566-1:2025 complements other ISO/IEC standards in information security, identity management and privacy by providing age‑specific framework guidance. Organizations should align implementations with applicable national and sectoral regulations and relevant ISO/IEC privacy and cybersecurity standards for a holistic approach.