Comments to Office of the Privacy Commissioner of Canada Regarding Online Age Assurance
Introduction and Summary
The Information Technology and Innovation Foundation (ITIF) and its Centre for Canadian Innovation and Competitiveness (CCIC) are pleased to submit these comments in response to the Office of the Privacy Commissioner (OPC) of Canada’s request for public comment concerning its guidance for websites and online services on assessing whether and how to use age assurance.[1] ITIF is a nonprofit, non-partisan public policy think tank committed to articulating and advancing pro-productivity, pro-innovation, and pro-technology public policy agendas around the world that spur growth, prosperity, and progress.
Ensuring the online safety of children is extremely important, and age assurance is one—though not the only—tool in policymakers’, parents’, and platforms’ toolkit. As OPC correctly notes, age assurance can have negative impacts on privacy, and these privacy concerns, particularly any loss of anonymity, can disincentivize even users above a certain age from using certain online services or accessing certain content, raising free speech concerns. When used in ways that minimize these risks and account for technology constraints, age assurance can limit children’s exposure to harmful or inappropriate material and contribute toward a safer online environment for children.
In its comments to OPC regarding age assurance and privacy in 2024, ITIF highlighted a few key points to inform policymakers when creating policies mandating age assurance systems.[2] These points can also inform regulators when carrying out age assurance mandates.
Age Assurance Should Be Limited to High-Risk Circumstances
In most cases, regulation should not require online services to treat their users as children unless proven otherwise. Likening the Internet to a shopping mall that contains a bar, it would be disproportionate to check every person’s ID upon entering the mall, not to mention inconvenient for patrons and difficult for the owners of the mall to implement. Instead, patrons would only need to show ID in order to enter the bar, while people of all ages could freely navigate the rest of the mall. In the same sense, regulators and online services should be cautious to require users to verify their ages in order to access large swaths of the Internet.
Creating age assurance systems where the onus is on the user to prove they are an adult when trying to access websites that pose a relatively low risk to children would, like requiring every mall visitor to show ID upon entry, be overly burdensome and impractical for both users and businesses. Age assurance requirements should target use cases where there is a significant risk of harm to children. In gauging the level of risk, regulators should take care to consider edge cases—online services designed for a general audience that may contain small amounts of age-inappropriate content, such as online encyclopedias, legal databases, and news websites.
OPC’s guidance aligns with this principle, establishing a risk-based threshold for age assurance. However, OPC should strengthen its guidance in line with this principle by recommending that, when possible, online services mitigate the risk of harm to children through less invasive, non-age-based means. In rare cases when age assurance is the only feasible method of mitigating serious risk, online services should apply age assurance to the specific content, feature, or activity that creates the risk, rather than imposing it as a condition of general access to the service.
The Level and Means of Age Assurance Should Match the Level of Risk
The level and means of age assurance should be proportionate to the risk of the use case at hand. There are multiple ways online services can verify users’ ages, and each of these methods comes with different strengths and weaknesses. Some are more accurate but more invasive, whereas others are less invasive but also less accurate. The method of age assurance should be the minimum required in a particular use case relative to the risk to children’s online safety. This will minimize friction in user experience and avoid imposing unreasonable demands on online services that do not pose a significant risk to children.
OPC’s guidance aligns with this principle, explicitly using risk to determine the strength of assurance, matching age assurance accuracy to the level of risk, and matching the method of age assurance to its goal. However, OPC should strengthen its guidance by clarifying that, where age assurance is justified, online services should use the least intrusive method reasonably capable of mitigating the identified risk.
Age Assurance Systems Should Be Technologically and Commercially Agnostic
Technological development in the field of artificial intelligence (AI) age estimation is progressing rapidly, and there are many competing models. Regulators should not mandate that age assurance systems use specific technologies or technology providers in the long-term.
The U.S. National Institute of Standards and Technology’s face analysis technology evaluation report from 2024 notes that AI age estimation accuracy has improved significantly since 2014 and that some proprietary facial analysis algorithms performed better than others with various demographic groups.[3] Combined with privacy protections requiring online services to delete users’ images after the age estimation process is complete, this would minimize the amount of personal information users have to give up in order to verify their age.
Digital forms of government-issued identification could likewise solve some of the privacy concerns associated with age assurance, as well as make the process more efficient. Currently, online ID checks typically require users to upload a photo of their physical ID as well as sometimes additional steps to prove the ID belongs to them, such as uploading a current image of their face to compare to the photograph on the ID. If designed right, digital IDs would streamline this process and allow users to only share necessary information. For example, individuals trying to access an age-restricted online service could verify that they are over a certain age without providing their exact date of birth, let alone all the other information a physical ID would reveal. Such systems should be designed so that the credential issuer does not learn which services a user accesses.
OPC’s guidance aligns with this principle. It avoids prescribing any particular technology and instead focuses on outcomes, risk, proportionality, privacy, and effectiveness.
Regulators Should Avoid Inflexible Requirements
Regulation should allow online services to implement solutions that work for their particular use cases rather than prescribing specific systems across the board. Online services will be best-suited to determine which method of age assurance—or alternatives to age assurance—will minimize privacy risks and the risk of harm to children, work within their business model, and cause users the least inconvenience. Flexibility also leaves room for innovation, such as continued developments in AI age estimation and digital IDs.
OPC’s guidance aligns with this principle. Its risk-based approach naturally discourages inflexible rules by recognizing that different circumstances require different approaches. It avoids prescribing a single technical standard and relies instead on concepts such as “reasonable,” “appropriate,” and “proportionate.”
Conclusion
Age assurance should not become a default prerequisite for accessing the Internet, but it can still hold a place in a comprehensive approach to children’s online safety. Minimizing the potential negative impacts of age assurance requires reserving age assurance for high-risk circumstances, matching the level and means of age assurance to the level of risk to children, and maintaining a flexible, technologically and commercially neutral regulatory approach. OPC’s guidance largely aligns with these principles.
Thank you for your consideration.
Endnotes
[1]. Office of the Privacy Commissioner of Canada, “Assessing whether and how to use age assurance – Guidance for websites and online services,” updated May 4, 2026, https://www.priv.gc.ca/en/privacy-topics/age-assurance/aa-gd-web/.
[2]. Lawrence Zhang, “Comments to Canada’s Office of the Privacy Commissioner Regarding Age Assurance and Privacy,” September 13, 2024, https://itif.org/publications/2024/09/13/comments-to-office-of-privacy-commissioner-regarding-age-assurance-and-privacy/.
[3]. Kayee Hanaoka et al., “Face Analysis Technology Evaluation: Age Estimation and Verification,” NIST Internal Report, NIST IR 8525, https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8525.pdf.
