@kuriharan: Learn out. EU Citizens Demand Brussels Make Its Privacy-First Age Verification App Legally Binding https://techtimes.co…

X AI KOLs Timeline News

Summary

EU citizens, backed by the Pirate Party, have launched a formal initiative demanding that the European Commission legally mandate its own privacy-first age verification app, highlighting a gap between existing technology and policy adoption.

Learn out. EU Citizens Demand Brussels Make Its Privacy-First Age Verification App Legally Binding https://techtimes.com/articles/321469/20260724/eu-citizens-demand-brussels-make-its-privacy-first-age-verification-app-legally-binding.htm… #tech #digital #privacy #crypto #ai
Original Article
View Cached Full Text

Cached at: 07/25/26, 04:08 PM

Learn out. EU Citizens Demand Brussels Make Its Privacy-First Age Verification App Legally Binding https://techtimes.com/articles/321469/20260724/eu-citizens-demand-brussels-make-its-privacy-first-age-verification-app-legally-binding.htm… #tech #digital #privacy #crypto #ai


EU Citizens Demand Brussels Make Its Privacy-First Age Verification App Legally Binding

Source: https://www.techtimes.com/articles/321469/20260724/eu-citizens-demand-brussels-make-its-privacy-first-age-verification-app-legally-binding.htm On July 22, Brussels registered a formal citizens’ initiative that puts the European Commission in an unusually awkward position: the Pirate Party-backed petition is demanding the EU make legally mandatory a privacy-preserving age-verification technology the Commission already built, already pilots with seven member states, and already describes as meeting “the highest privacy standards in the world.” The question raised by “Stop Killing The Internet: No Digital ID & No Age Verification” is not whether the technology exists. It is whether the Commission will ever choose to mandate it — or whether, absent a legal requirement, platforms will default to government-ID-based verification that has already triggered multiple data breaches and a €950,000 (approximately $1.1 million USD, exchange rate as of July 24, 2026; conversions are approximate) regulatory fine against one of the industry’s most widely-used providers. The Commission’s registration of the initiative was confirmed by itsofficial press release IP/26/1658.

A Citizens’ Initiative Targets the Gap Between Commission Design and Commission Policy

The European Citizens’ Initiative mechanism — a formal democratic tool created by the Treaty of Lisbon that allows EU citizens to invite the Commission to propose legislation —officially registered “Stop Killing The Internet” on July 22, 2026, following an eligibility review that found the proposal legally admissible, within the scope of EU competence, and not contrary to EU fundamental values. Organizers now have up to six months to open a 12-month signature-collection window, during which they must gather at least one million valid signatures from citizens in at least seven EU member states before the Commission is required to formally examine the proposal and issue an official response. Registration is not an endorsement — the Commission made that explicit — but it is a finding of seriousness that distinguishes this petition from those Brussels turns away.

The initiative was registered by Paul Diegel, a senior policy advisor to Czech Pirate Party MEP Markéta Gregorová on cybersecurity legislation, with Daniel Mönch, Federal Political Director of Germany’s Pirate Party, serving as substitute representative, as reported byBiometric Update’s coverage of the ECI registration. The specific demands go well beyond the initiative’s headline name. Organizers are asking the Commission to enshrine in law: mandatory privacy-preserving cryptography for anonymous or pseudonymous age assurance; data minimization and selective disclosure by default; open standards with publicly auditable cryptographic protocols; independent security and fundamental-rights audits; a prohibition on cross-service tracking by service providers; and — most contentiously — guaranteed equivalent non-digital alternatives for all affected services.

The last demand is where the initiative most clearly departs from what EU regulators and industry practitioners consider achievable in the near term. Spain’s own data protection regulator, the AEPD, has called for non-biometric authentication alternatives to the EU Digital Identity (EUDI) Wallet, but acknowledged that achieving the same assurance level as digital verification without introducing significant friction remains an unsolved problem,according to Biometric Update’s reporting.

How the EU’s Own Tech Works — and Why It Matters

The Commission’s Age Verification Blueprint, published in July 2025 and now being piloted in seven front-runner member states — Denmark, France, Greece, Italy, Spain, Cyprus, and Ireland — is built on zero-knowledge proof (ZKP) cryptography, specifically the Ligero protocol with ECDSA-based anonymous credentials, as described in theEU age verification Blueprint. A ZKP allows a user’s device to prove a single binary fact — “this user is over 18” — to a platform without disclosing the user’s name, date of birth, nationality, or any other identifying attribute. The platform learns only pass or fail. The user’s responses to different platforms cannot be linked to one another, so the verification provider cannot build a profile of which sites the user visits, as explained in theEU Commission’s age verification FAQ.

This is architecturally different from what most commercially deployed age-verification systems do today. Government-ID-based systems — the kind used by companies like AU10TIX, which processes identity verification for TikTok, Uber, and X — require users to upload passport or driver’s license images to third-party processors. Those processors then hold high-value collections of biometric data, government ID images, and personal identifiers. AU10TIX left its administrative credentials exposed for at least 18 months, from December 2022 through June 2024, during which time a logging platform containing users’ names, birth dates, nationalities, and identity document images was accessible via a link posted to Telegram from March 2023 onward. The Electronic Frontier Foundation described such systems as “surveillance systems” in which data breaches are “not a hypothetical concern,” inits report on the age verification privacy danger.

In March 2026, Yoti — a British age-verification provider whose clients include Meta, Sony, TikTok, and Spotify — was fined €950,000 (approximately $1.1 million USD) by Spain’s AEPD for three violations of the EU’s General Data Protection Regulation: €500,000 (approximately $570,000 USD) for unlawful processing of biometric data, €200,000 (approximately $228,000 USD) for processing user data without valid consent, and €250,000 (approximately $285,000 USD) for retaining user data longer than permitted, as detailed inBiometric Update’s report on the Yoti GDPR fine. Yoti had been ISO 27001 certified at the time. A separate breach at Discord’s own age-verification deployment exposed approximately 70,000 users’ government IDs in October 2025, as reported byTechCrunch.

The Commission’s ZKP-based Blueprint avoids all of these failure modes by design. Once a user’s age has been attested through the EUDI Wallet or a certified third-party app, the app issues an anonymous digital credential. The communication between the attestation provider and the verification app stops at that point. No name, no birthday, no address is saved; no record of which sites the user visited is retained, according to theEU Commission’s age verification FAQ.

The ECI is not asking the Commission to develop this technology. It is asking the Commission to make it mandatory — to close the gap between what Brussels designed and what the law actually requires platforms to use.

What “Voluntary” Means When There’s No Alternative

The Commission describes the EUDI Wallet — which all 27 member states are required to make available to citizens by the end of 2026 — as voluntary for individuals, as outlined in theEU Digital Identity Wallet deployment timeline. By late 2027, large online platforms and organizations in regulated sectors including banking, healthcare, and telecoms will be required to accept the wallet as a primary authentication method. The Commission also describes its age-verification app — built on the same EUDI Wallet framework and now being piloted — as voluntary.

Critics, including the Electronic Frontier Foundation, argue that “voluntary” in this context is a category error, asthe EFF’s analysis of EU digital identity and age verificationexplains. Digital Services Act Article 28 requires online platforms to ensure a high level of privacy, safety, and security for minors — a standard the Commission has already enforced against pornographic platforms. The DSA does not name age verification as the mandated mechanism. But when the Commission enforces Article 28 and the only high-assurance technology scalable to platform level is age verification, platforms implement it regardless of whether the law explicitly requires it. Tech Policy Press described this dynamic directly: the eIDAS regulation “lacks an obligation for zero-knowledge proofs,” meaning platforms could comply with DSA Article 28 using government-ID-based systems rather than the Commission’s ZKP-based Blueprint, even as the Blueprint’s privacy guarantees are technically superior, as analyzed inTech Policy Press’s examination of EU age verification privacy.

The practical result is what advocates call a “de facto mandate”: legislation that does not require age verification but that, under Commission enforcement, functions as if it does — while leaving the choice of verification mechanism (privacy-preserving ZKP or government-ID-based) entirely to platforms. The ECI’s demand for “mandatory privacy-preserving cryptography” and “publicly auditable cryptographic protocols” is, in this light, a demand to convert the Commission’s own technical recommendation into a binding legal requirement.

Gregorová’s Broader Battle for Digital Rights

Markéta Gregorová, the Czech Pirate Party MEP whose office is home to the ECI’s lead organizer, has become one of the EU Parliament’s most visible voices on digital rights issues precisely because she frames them as inseparable from questions of democracy and procedural legitimacy.

Her most recent parliamentary intervention came in early July, when she described the European People’s Party’s procedural maneuver to re-introduce Chat Control 1.0 — a framework allowing voluntary scanning of private communications for child sexual abuse material — as “unprecedented” and as something that “questions the essence of democracy,” as quoted inGregorová’s statement on the Chat Control vote. The extension passed July 9, 2026, through a second-reading route that required only a plurality to pass rather than the absolute majority of 361 votes needed to block it; 314 MEPs voted against, 276 in favor, but opponents fell 47 votes short of the blocking threshold, as covered inTechTimes’ own report on the Chat Control vote. The episode is relevant context for the ECI: both Chat Control 1.0 and the digital-ID/age-verification agenda share the same structural tension — child-safety and fraud-prevention objectives pursued through mechanisms that privacy advocates argue create infrastructure for disproportionate surveillance.

Gregorová’s office has previously demonstrated an ability to mobilize ECI support at scale. The “Stop Destroying Videogames” initiative, backed by the Pirate Party in the European Parliament and “Stop Killing Global,” submitted 1,294,188 verified statements of support to the Commission on January 26, 2026 — easily clearing the one-million-signature threshold and meeting national minimums in 24 member states, as documented bythe European Pirates’ report on the Stop Destroying Videogames initiative. The Commission replied on June 16, 2026, declining to propose legislation but committing to a voluntary industry code of conduct by end-2026. The precedent is instructive: a successful ECI forces a formal response and a public Parliament hearing, but does not obligate the Commission to legislate. The Pirate Party’s track record shows it can reach the threshold; what happens after depends on political will in Brussels.

What the Commission Is Already Planning — and Why That Matters for the ECI’s Timing

The ECI’s registration on July 22 arrives at a moment of significant policy momentum in the precise direction the petition contests. On July 13, 2026, the Commission’s special expert panel on child safety online — convened following EU Commission President Ursula von der Leyen’s announcement in her 2025 State of the Union address — delivered its final report recommending a harmonized EU-wide minimum age of 13 for social media access with parental supervision requirements, and specifically endorsing zero-knowledge proofs over biometric age checks as the preferred verification mechanism, as reported byBiometric Update’s coverage of the Commission child safety panel report. The Commission has indicated it will present a binding legislative proposal on social media minimum age restrictions after the 2026 summer recess.

That proposal, when it arrives, will be the Commission’s next opportunity to either mandate ZKP-based verification — as both the ECI and its own expert panel now recommend — or leave the mechanism choice to platforms. The ECI’s 12-month signature window, once opened, will run in parallel with that legislative process, giving organizers a concrete policy backdrop against which to build their case.

The April 2026 Recommendation on age verification — non-binding, as all Commission Recommendations are — calls on member states to deploy the ZKP-based Blueprint by the end of 2026, as set out inthe Commission’s April 2026 Recommendation on age verification technologies. The ECI is asking for something the Recommendation explicitly declines to deliver: a binding legal obligation to use privacy-preserving cryptography rather than government-ID-based alternatives.

Can It Actually Reach a Million Signatures?

The ECI mechanism, governed by Regulation 2019/788, has been registered 135 times since its launch; only a handful of initiatives have ever crossed the one-million-signature threshold, as documented byEuropean Sting’s report on ECI registration history. The Stop Destroying Videogames campaign is the 14th to do so, a success built partly on viral gaming community support. The digital-rights constituency for the Stop Killing The Internet ECI is broader and more diffuse — potentially encompassing anyone with a privacy concern about mandatory digital identification — but that breadth can cut both ways: the framing of the initiative may struggle to generate the visceral engagement that gaming preservation did.

The Pirate Party’s campaigning infrastructure, however, has demonstrated that it can convert abstract digital-rights concerns into concrete signatures at speed. And the timing works in the campaign’s favor: the EUDI Wallet is scheduled to launch across all 27 member states by the end of 2026, the Commission is preparing a binding social media age-restriction proposal, and Chat Control 1.0 has just been extended in a procedurally contested vote that generated significant public anger. The ECI’s window for signature collection — once opened — will run directly through the period in which these policies land.

The Commission is also in a position it rarely occupies: the technical solution the ECI demands is one the Commission designed, funds, and currently promotes. That alignment does not guarantee legislative action, as the Stop Destroying Videogames precedent demonstrates. But it does mean the Commission cannot credibly argue the demand is impractical.


Frequently Asked Questions

What exactly is zero-knowledge proof age verification, and why does it matter for everyday internet users?

A zero-knowledge proof (ZKP) is a cryptographic method that allows a user’s device to prove a single fact — such as “I am over 18” — to a website or app without revealing any other information: no name, no birth date, no nationality, no document images. The platform receives only a pass/fail answer. This is architecturally different from standard government-ID-based age verification, where users upload passport or driver’s license images to third-party processors who then hold sensitive personal data. Those processors are high-value breach targets: AU10TIX exposed 18+ months of identity records via a Telegram link, and Yoti was fined €950,000 (approximately $1.1 million USD) by Spanish regulators for GDPR violations. The EU Commission’s own age-verification Blueprint already uses ZKPs. The ECI is demanding the Commission make this technology legally required rather than a voluntary recommendation that platforms can ignore in favor of cheaper, less privacy-safe alternatives.

Is the EU Digital Identity Wallet actually mandatory for citizens?

No — citizens are not required to have or use a EUDI Wallet. But all 27 EU member states are required to make at least one certified EUDI Wallet available to their citizens by the end of 2026. By late 2027, large online platforms and organizations in banking, healthcare, and telecoms must accept the Wallet as a primary authentication method. The Pirate Party’s argument — and a core concern behind the ECI — is that once major platforms are required to accept the Wallet and may prefer it for identity and age verification, the practical voluntariness of the system erodes, even without a legal mandate for individual citizens. A user who cannot access a service without using Wallet-based verification is not meaningfully exercising a voluntary choice.

What happens if the “Stop Killing The Internet” petition reaches one million signatures?

If the ECI crosses the one-million threshold and meets national minimums in at least seven EU member states, the European Commission is required to formally examine the proposal and issue an official response within six months. Organizers are also invited to present the initiative at a public hearing in the European Parliament. Critically, a successful ECI does not obligate the Commission to propose legislation — the Commission can decline with a written explanation. The Stop Destroying Videogames ECI, which collected 1,294,188 verified signatures, reached this stage in early 2026 and received a Commission reply in June 2026 that declined to legislate. Reaching the threshold forces a response; whether that response is meaningful depends on political will and the broader policy moment.

What can EU internet users do right now if they have privacy concerns about age verification?

First, check whether age-verification requests you encounter are using the Commission’s ZKP-based age-verification app — which discloses no identity data — or commercial government-ID-based systems, which require uploading personal documents to third-party processors. The EU age-verification Blueprint (ageverification.dev) is open source and should be distinguishable from commercial alternatives. Second, if you wish to support the ECI, you can sign the petition once organizers open the formal collection window — they have up to six months from the July 22 registration to do so. Third, contact your national Digital Services Coordinator if you believe a platform’s age-verification demand is disproportionate or non-compliant with DSA data minimization requirements. Finally, consider that no mitigation fully addresses the structural risk of government-ID-based systems: if a platform’s chosen verification provider is breached, the data is gone regardless of your individual privacy settings.

Similar Articles

What's wrong with EU age verification? (Nothing)

Lobsters Hottest

A blog post argues that criticisms of the EU's online age verification approach are often uninformed, explaining why age restrictions are necessary for children and proposing a privacy-preserving method using signed attestations rather than full identity disclosure.