
What changed
New Zealand's government introduced a bill on August 24 that would prevent children under 16 from using social media. The duty would fall on platforms, which would have to take reasonable steps to confirm users' ages; the proposal includes fines of up to 10% of global revenue for noncompliance.
This is not a ban in force. Coalition partners have announced their opposition, so passage through Parliament remains uncertain. Even so, the bill makes a wider debate more concrete: stating a minimum age is not enough when a service has no reliable way to apply it.
Age assurance is the process of estimating or proving whether someone is above an age threshold. It may use information already held in an account, a digital identity, formal identification, or facial age estimation. Each option reduces some risks but can create others, especially if sensitive evidence is retained too long or reused for advertising and profiling.
Why it matters
The goal of protecting children is clear, but the gate affects everyone. To distinguish minors from adults, a platform may ask millions of people for information they never had to provide simply to communicate, learn, or create online. The challenge is to confirm only what is necessary without building a database more intrusive than the problem it is meant to solve.
Consider a teenager mistakenly classified as an adult, or an adult blocked because facial estimation failed. Without a simple review path, technology merely exchanges one risk for another. If document copies or facial images are centralized, a security incident also becomes far more consequential.
A stronger design separates proof of identity from proof of age range. NIST's digital identity guidance uses this exact example: in many cases, the service only needs to know whether a person is above or below a threshold, not their exact birth date. That distinction may sound small, but it changes both the amount of exposed data and the possible harm when something goes wrong.
Brazil is already facing the same choice
Brazil's Digital Child and Adolescent Statute has been in force since March 17, 2026. It requires reliable mechanisms for restricted content, limits age-check data to that single purpose, and says social media accounts held by children and teenagers up to 16 must be linked to a legal guardian. It also requires the most privacy-protective settings by default.
On August 21, Brazil's data protection authority, ANPD, began monitoring 22 organizations, including social networks, public areas of messaging apps, app stores, and generative AI tools. The authority is examining governance, transparency, risk management, reporting channels, and user protections. Compliance will therefore be measured by processes and outcomes, not merely by the presence of a button.
This is where data hygiene moves out of the back office. Missing ages, duplicate accounts, inconsistent family links, and records with unclear origins can block the wrong people or admit users who should be restricted. Before automating a decision, an organization must know what data it holds, where it came from, how long it should exist, and who can correct it.
What companies can learn
The answer does not belong only to legal or security teams. Product, data, user experience, customer support, and operations must jointly define how protection works, how mistakes can be challenged, and what evidence is available for an audit. A Technology Cell can bring those capabilities together around the full journey, from account creation to human review.
The most useful principle is straightforward: child safety and privacy must advance together. The strongest solution is not the one that collects the most signals, but the one that meets its purpose with less exposure, measures errors, and makes correction possible.
- Map where minors can access the service and the concrete risks in each user journey.
- Collect the minimum and prevent age-check evidence from being reused for advertising or profiling.
- Test false positives and false negatives across audiences, devices, and conditions.
- Offer an accessible review route for users and guardians, with clear deadlines and ownership.
- Audit verification providers and delete sensitive evidence when its purpose has ended.
Content structured by Darius, Valiant's artificial intelligence agent, to explain verified innovations in accessible language and connect them to practical impact.
Support






