Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Age verification privacy claims: what evidence should teams trust?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Researchers and university articles falsely claimed an age verification platform shares facial images with third parties, while the company says images are processed inside its own systems and deleted immediately after age estimation, according to Yoti. The dispute shows why identity verification governance depends on auditability, data-flow proof, and careful handling of privacy claims, not vendor assertions alone.

NHIMG editorial — based on content published by Yoti: its public response to allegations about age verification privacy practices

By the numbers:

Questions worth separating out

Q: How should security teams evaluate privacy claims in age verification systems?

A: They should ask for evidence of how biometric data is captured, processed, stored, deleted, and audited.

Q: Why does age verification become an identity governance issue?

A: Age verification becomes an identity governance issue when the organisation must prove policy compliance, retain evidence, and defend decisions after the user has been admitted.

Q: What do organisations get wrong about inclusive biometrics?

A: They often assume that a vendor’s accuracy claim is enough.

Practitioner guidance

  • Map the biometric data flow end to end Document where facial images enter, where they are processed, where they are stored temporarily, and where they are deleted.
  • Require independent evidence for privacy claims Ask for audit reports, test attestations, and deletion-verification evidence that confirm facial images do not leave the provider’s environment.
  • Review third-party and subprocessor boundaries Validate whether any external services touch device fingerprints, metadata, or decision outputs, and confirm the contractual scope for each processor.

What's in the full analysis

Yoti's full post covers the factual dispute and the technical assertions this analysis intentionally leaves at source:

  • The exact language Yoti uses to dispute the university claims about facial image sharing and deletion.
  • The broader correspondence context, including requests for correction, apology, and retraction.
  • Yoti's description of its certifications, audit approach, and bug bounty context.
  • The full wording of the allegations and the response letter sent to the institutions.

👉 Read Yoti’s response to the age verification privacy allegations →

Age verification privacy claims: what evidence should teams trust?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Biometric privacy claims now require proof, not positioning. Age verification sits at the intersection of identity verification, privacy law, and trust engineering, so claims about image handling must be testable. When a provider says facial images are deleted immediately and never shared, the burden is on evidence that a practitioner can review, not on corporate confidence alone. The practitioner conclusion is simple: treat biometric handling as a control assertion that must be independently validated.

A question worth separating out:

Q: Who is accountable when disputed identity verification claims damage trust?

A: Accountability sits with the provider for control evidence, with the publisher for factual accuracy, and with the buyer for verifying claims before deployment. In regulated environments, teams should treat documentation, auditability, and contract terms as part of the accountability chain.

👉 Read our full editorial: Yoti dispute shows age verification privacy claims need stronger evidence



   
ReplyQuote
Share: