The Global Online Safety Regulators Network said (6-page / 272KB PDF) “a common, principles-based and privacy-preserving international approach to age assurance” would “facilitate better protections for children, consistent and effective compliance for services, and greater public trust”.
The network provides a forum for online safety regulators across the world to discuss their experiences and share their expertise. There are currently nine members of the network, comprising online safety regulators from the UK, Australia, Fiji, France, Ireland, South Korea, Slovakia, South Africa, Netherlands.
“Age assurance can be an important tool for online service providers in creating safer and age-appropriate experiences for all users,” the network said in its position paper. “For online service providers to be able to fulfill their role in this shared effort, they need to know whether and when their service is being used by a child or adult. This is why an increasing number of regulatory jurisdictions around the world have implemented or are in the process of implementing age assurance requirements for certain online service providers. When an online service provider knows that a user is a child, or under a certain age, services can comply with their obligations to protect those users.”
“In several jurisdictions where new or renewed age assurance requirements have come into force, there have been examples of both compliance and non-compliance by services, as well as attempts by users to circumvent age assurance systems and rules. To ensure children are protected, it is important for regulators to set out our common approach and commitment to age assurance and non-compliant companies are pursued with dissuasive sanctions,” it said.
The network has proposed that age assurance processes adhere to six core principles – that it be accurate, robust, reliable, proportionate, fair and inclusive, and non-intrusive. It added that processes should also be “implemented with attention to accessibility and interoperability” and said it is “non-negotiable” that they adhere to data protection law and uphold users’ right to privacy.
Publication of the network’s position paper comes after the Irish online media regulator, Coimisiún na Meán (the Media Commission), opened its first formal investigation under Ireland's Online Safety Code. The regulator is examining whether X has implemented effective age assurance measures and parental controls to prevent children from accessing pornography and other harmful video content.
The Online Safety Code in Ireland applies to video-sharing platform services (VSPS) designated by the Media Commission, including Facebook, Instagram, LinkedIn, Pinterest, TikTok, Tumblr, X and YouTube, and imposes additional obligations compared to the EU Digital Services Act, particularly around restricted content, age assurance and parental controls. For example, on age assurance, under the Online Safety Code, self-declaration of age by users is expressly deemed as an insufficient age assurance measure.
Breaches of the Online Safety Code can result in fines of up to 10% of annual turnover or €20 million, whichever is greater. Sarah Twohig of Pinsent Masons said online service providers in-scope of the code should proactively review their compliance programmes, particularly around child safety, age assurance and parental controls, and monitor the evolving regulatory landscape.
“This investigation marks the first enforcement action under Ireland's Online Safety Code, with the Media Commission’s enforcement activity in respect of online safety having been conducted under the EU Digital Services Act to-date,” Twohig said. “Providers of platforms designated as VSPS in Ireland should be mindful of the heightened regulatory requirements associated with the code.”