TL;DR: Discord’s teen-by-default rollout and the backlash to its age-assurance choices show that face scans, government-ID uploads and behavioural inference can satisfy policy pressure while deepening privacy, bias and breach concerns, according to Trusona. The governance question is no longer whether platforms need age checks, but how to avoid turning verification into a data-harvesting layer that undermines trust.
NHIMG editorial — based on content published by Trusona: I Don't Want to Scan My Face to Send Memes to My Friends
By the numbers:
- A 2025 survey by Common Sense Media found that 64% of adults support age verification for social media platforms.
- Nearly 86% of adults fear companies will sell or share children’s age data without consent.
- 80% of adults worry about permanent storage of, children’s information.
Questions worth separating out
Q: How should platforms verify age without collecting more identity data than necessary?
A: Platforms should use the smallest proof that satisfies the policy.
Q: Why do biometric age checks create governance concerns for identity teams?
A: Biometric age checks create governance concerns because they involve sensitive personal data, consent expectations, retention decisions, and user trust all at once.
Q: What breaks when age verification is outsourced to a third party?
A: Outsourcing does not remove accountability.
Practitioner guidance
- Minimise identity data in age checks Use the least-disclosing method that still meets the policy requirement.
- Map the verification data flow end to end Document where ID images, facial data, inferred attributes and decision logs are created, stored, processed and deleted.
- Apply privacy and security review before rollout Require a formal assessment for bias, retention, deletion, access control and breach impact before enabling any age-verification workflow.
What's in the full article
Trusona's full article covers the implementation detail this post intentionally leaves for the source:
- How ATO Protect verifies age through encrypted data sources and secure attestations without face scans or ID uploads
- The product's handling of anonymous credentials and yes/no age signals for platform integration
- Implementation notes on preserving user privacy while meeting age-assurance requirements
- The vendor's explanation of how its approach differs from facial age estimation and liveness checks
👉 Read Trusona’s analysis of privacy-first age verification and Discord backlash →
Age verification without biometrics: are platforms getting the balance right?
Explore further
Age verification is becoming an identity governance problem, not just a safety control. Platforms are being asked to prove age while collecting as little identity data as possible, which creates a new verification design standard. If the access decision requires a biometric, a government ID or persistent behavioural profile, the platform has already crossed into heavier identity governance than the policy may justify. Practitioners should treat age assurance as a data minimisation and entitlement problem, not only a compliance task.
A question worth separating out:
Q: Should organisations prioritise privacy-preserving verification over biometric proofing?
A: Yes, when the business requirement can be met without biometric capture. Privacy-preserving verification reduces the amount of sensitive data in scope, lowers the impact of breaches and helps preserve trust in communities that rely on anonymity or pseudonymity.
👉 Read our full editorial: Age assurance without face scans: privacy, trust and platform risk