Your ID Shouldn't Be the Price of Proving You're 18
Here's something that should bother you more than it probably does. When a website asks you to "verify your age," it often doesn't just learn your age. It learns your full name, your date of birth, your address, sometimes your ID number — and occasionally, a scan of your face. All of that, just to confirm one yes-or-no fact: are you old enough?
A well-designed age check should answer exactly one question — "yes, old enough" or "no, not yet" — without collecting your name, birth date, address, or ID number. Western Australia is testing a system that actually does this, and understanding how it works will change how you judge every identity check from now on.
Western Australia has quietly launched an optional pilot program to test exactly this idea. The goal: prove someone meets an age threshold without forcing them to hand over their whole identity. It sounds obvious when you say it out loud. But the way most age-verification systems are actually built, it's genuinely radical.
Why "Verify Your Age" Usually Means So Much More
Think about what happens when a streaming service, a gaming platform, or an alcohol retailer asks you to confirm you're over 18. In most cases, they send you to a third-party verification service. You upload a photo of your driver's license or passport. The service reads your name, your date of birth, your ID number, and sometimes your address. It may scan your face to confirm you're the person in the document. Then it tells the platform: "Yes, this person is old enough."
The platform got the one answer it needed. But the verification service? It just collected a small filing cabinet's worth of personal data about you — to answer a question that only had two possible answers.
That data has to live somewhere. It gets stored, processed, sometimes shared with other companies. And wherever data lives, it can leak. A 2023 breach at a major identity verification provider exposed the records of millions of users who had uploaded their government IDs — people who just wanted to watch a movie or buy a bottle of wine.
Here's the uncomfortable part: none of that extra data was necessary. The platform only needed to know one bit of information. One binary answer. Yes or no. Old enough or not. This article is part of a series — start with Philippines Biometric Ai Privacy Review What It Means For Yo.
The Concept That Changes Everything: "Prove Eligibility, Not Identity"
Privacy experts have a phrase for the smarter approach: data minimization — which just means collecting the smallest amount of personal information needed to do a specific job. Nothing more. For age checks, that principle leads to a genuinely elegant question: what if the system never learned who you were at all?
This is what Western Australia's pilot is exploring. Instead of a verification service reading your full ID and storing your details, the system is designed to return a single answer. Not your name. Not your birthdate. Just: this person meets the age requirement.
The technical mechanism that makes this possible is called a zero-knowledge proof — and stay with me here, because the idea is genuinely cool once you see it. A zero-knowledge proof is a way of mathematically proving that something is true without revealing the underlying information. You prove the fact without showing the evidence.
Think of it like this. Imagine you want to prove you know the password to a vault, but you don't want to say the password out loud. A zero-knowledge proof lets you demonstrate — mathematically, provably — that you know it, without the other person ever hearing the actual password. Applied to age verification: the system can confirm that your birthdate makes you over 18 without ever transmitting or storing your actual birthdate.
Your government-issued ID gets checked once, locally, on your device or through a trusted government app. The system generates a small cryptographic token (think of it as a sealed, tamper-proof note) that says only: "age requirement met." That token is what gets sent to the website. Your name, your ID number, your exact birthdate — none of it ever leaves the process.
The Misconception That Makes This Hard to See
Most people assume that to verify something, the verifier needs to see the raw evidence. If I want to know you're over 18, I need to see your ID. If I want to know you live in this country, I need to see your address. That assumption feels so natural that almost nobody questions it. Previously in this series: That Weird Fingers Deepfake Trick Its Why Youll Get Scammed .
It's also completely wrong — or at least, it's wrong for a world with modern cryptography in it.
And look, it's not a dumb assumption. For most of human history, it was correct. A bouncer at a bar needs to physically see your driver's license because there's no other mechanism available. But software doesn't have to work that way. A digital system can be built so that verification happens in one protected step, and only the conclusion — not the evidence — travels any further.
The reason most companies don't build it this way isn't technical. It's economic. Collecting your full identity data is valuable. It can be used for marketing, sold to data brokers, or folded into advertising profiles. "We need your ID to verify your age" is technically true. "And then we're going to use everything on that ID for purposes you didn't sign up for" is the part nobody mentions in the terms of service.
"Age assurance should use the minimum personal information necessary to determine whether a user meets the applicable age requirement." — Australian Government, Online Safety (Minimum Age for Social Media) Act 2024 regulatory guidance
Australia's federal government put this principle into law in 2024 when it passed rules requiring social media platforms to keep children under 16 off their services. The law explicitly says age assurance — the broader term for any system that estimates or confirms someone's age — must use the minimum personal information necessary. Western Australia's pilot is essentially a test of what that looks like in practice.
What "Optional" Actually Means Here — and Why It Matters
One detail worth sitting with: the WA pilot is optional. Users can choose whether to participate. That isn't a weakness in the design — it's actually a feature of privacy-respecting systems. Consent matters. A system that forces you to verify your age through one specific mechanism, using one specific technology, concentrates a huge amount of data collection into a single chokepoint. Optional participation, with alternative pathways, spreads that risk and keeps people in control of their own information.
This connects to something we think about a lot at CaraComp when working with facial recognition and identity systems: the best identity check is the one that asks the smallest question it can get away with. Facial recognition is a powerful tool — and like any powerful tool, it should only be deployed when the job genuinely requires it. Confirming someone is over 18? That job probably doesn't require their face, their name, or their address. It just requires one answer. Up next: Your Face Isnt A Password One Country Just Made That The Law.
What You Just Learned
- 🧠 Most age checks collect way more than they need — your name, ID number, and address aren't required to answer "old enough?"
- 🔬 Zero-knowledge proofs make "prove eligibility, not identity" technically real — a system can verify a fact without ever seeing or storing the underlying evidence
- 💡 The reason companies collect extra data usually isn't technical — it's because your identity information has commercial value beyond the one question they asked
- 🔒 Data minimization is the safety rule that protects you — the less personal information a system collects, the less there is to breach, sell, or misuse
The Rule You Can Apply Starting Tonight
Here's the practical takeaway — the thing you can actually use the next time an app or website asks for identity proof.
Ask yourself: what is the one question this service actually needs answered? Is it "are you over 18?" Is it "do you live in this country?" Is it "are you the account holder?" Each of those is a single yes-or-no question. If the service is collecting your full name, your home address, a scan of your government ID, and a selfie — when all it needed was a yes-or-no — that's a red flag. Not necessarily a scam. But a sign that someone is collecting more than the job requires.
A well-designed identity check collects the minimum information needed to answer one specific question. When a service asks for more than that, it's worth asking why — because the technology to do it properly already exists. The gap between "what they need" and "what they collect" is almost never a technical limitation.
Good privacy protection doesn't require you to understand cryptography. It just requires noticing the mismatch. A nightclub bouncer needs to see your face to check your ID is yours. A website asking whether you're over 18 doesn't need your face, your name, or your address — and if it takes all three anyway, that tells you something about what it's really after.
Western Australia's pilot didn't invent this idea. But it's making it real in a place where most people will actually interact with it. And once you've seen what a minimum-data age check looks like, you can't unsee it. Every over-engineered identity form starts to look like what it is: not a security requirement. A data grab wearing a security badge.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
That "Weird Fingers" Deepfake Trick? It's Why You'll Get Scammed Tonight
Most people think deepfakes get caught by visual glitches. The real catch? A three-layer evidence trail that starts long before you look at the pixels. Learn the method that actually works.
digital-forensicsStop Watching the Face: 3 Places Deepfakes Quietly Fall Apart
The face in a deepfake can look completely real. The tell is somewhere else entirely. Learn the three places fake videos quietly fall apart — and why your instincts are aimed at the wrong target.
digital-forensicsThat Tattoo in the Photo? It's Now Searchable — But It Can't Prove It's You
Everyone assumes biometrics means faces. But NIST is benchmarking tattoo recognition too — and understanding how it actually works (hint: it's not a fingerprint) makes you a smarter reader of any case photo. Learn what a tattoo match can and can't tell investigators.
