France's Court Ruling Shows Why Age Checks Risk Everyone's Privacy
France's Constitutional Council struck down a social media ban for under-15s, ruling that age verification forces every adult online to prove their identity too.
On 14 August 2026, France's Constitutional Council struck down legislation that would have banned children under 15 from accessing social media platforms including TikTok, Instagram, and Facebook. The ruling was not primarily about children's rights or parental consent—it was about what age verification does to everyone else. The Council found that banning minors from these services inherently forces every adult user to prove their identity before accessing lawful content, and that the law provided no adequate legal framework to protect the data involved in doing so.
That finding matters well beyond France. The UK's Online Safety Act already pushes platforms towards age assurance, and EU member states are watching the French ruling carefully to assess whether similar domestic legislation could face constitutional challenges. This article looks at what the Constitutional Council actually decided, why the privacy implications of age verification are structural rather than incidental, and what the ruling signals for the direction of online identity policy in Europe.
What the French Law Said—and What the Council Found
French lawmakers approved the bill in July 2026, making France the first EU country to attempt legislation modelled on Australia's under-16 social media ban, which came into force in December 2025. The French version set the threshold at 15 and would have required platforms to enforce it at the point of access.
The Constitutional Council's reasoning was direct. The provisions, it found, "disproportionately infringe upon freedom of expression and communication" and fail to provide adequate privacy safeguards. The central problem was structural: you cannot identify who is a minor without first identifying everyone. Any mechanism that sorts users by age requires all users—including adults with every legal right to access the service—to submit proof of identity to a platform or a third-party verification system before proceeding.
The Council ruled that the law offered no sufficient protections for this mass collection of identity data. There was no binding standard for how that data would be stored, for how long, by whom, or under what conditions it could be shared or compelled by law enforcement. The disproportionality finding was not that protecting children online is an illegitimate goal—it clearly is not—but that this particular mechanism sacrifices adult privacy wholesale to achieve it, without a legal architecture capable of limiting the damage.
Why Age Verification Is a Privacy Problem by Design
It is worth being precise about why age verification creates privacy risk as a matter of logic, not merely implementation. The issue is not that a given vendor might handle data carelessly, though that risk is real. The issue is that proving age requires disclosing identity, and disclosing identity to access a service creates a record that did not previously exist.
Consider what a workable age check actually requires in practice:
- A document or credential that establishes date of birth—typically a passport, driving licence, or government-issued ID
- A system capable of reading and verifying that document—either the platform itself or a third-party intermediary
- A link, however transient, between the verified identity and the service being accessed
That third point is the crux. Even where a verification provider claims to return only a yes/no age signal to the platform, a record exists somewhere that a specific individual's credentials were used to verify access to a specific service at a specific time. That record is a data asset. It can be subpoenaed, breached, sold, or retained beyond any stated policy. The privacy harm is not hypothetical—it is built into the transaction.
Proponents of age verification often argue that privacy-preserving techniques, such as zero-knowledge proofs or device-level attestation, can solve this. These approaches are technically interesting, but they remain largely undeployed at scale, and none of the legislation moving through UK or EU processes mandates them specifically. In the absence of that technical precision in law, platforms default to the simplest compliant method available—which is typically document upload or credit-card triangulation, both of which are significantly more invasive.
The UK Context: Age Assurance Under the Online Safety Act
The French ruling arrives at an uncomfortable moment for UK regulators. The Online Safety Act places age assurance obligations on platforms likely to be accessed by children, and Ofcom has been developing codes of practice that will give those obligations practical shape. The Act does not specify a single verification method, which in principle leaves room for privacy-preserving approaches—but it also leaves room for platforms to choose the cheapest compliant option.
What the Constitutional Council's reasoning adds to this debate is a clear articulation of the problem that UK law has not yet squarely addressed: the absence of adequate legal protections for the identity data generated by age checks. A UK platform complying with an Ofcom age assurance code might satisfy the letter of the Online Safety Act while still collecting, storing, and potentially mishandling identity data for which there is no specific statutory protection beyond the general provisions of UK GDPR.
That gap is not theoretical. If a third-party age verification provider suffers a data breach, the individuals affected lose not just a password—they lose the confidentiality of which platforms they used, and potentially documents that are difficult or impossible to replace.
What Other EU Member States Are Taking From the Ruling
France is not alone in pursuing age-based access restrictions. Germany, Belgium, and Ireland have all had active legislative or regulatory discussions about similar measures, and the European Commission's Digital Services Act creates a broader framework within which age verification sits as a compliance mechanism for very large online platforms.
The French ruling is already being studied in those jurisdictions. Constitutional courts in EU member states operate independently, but they share common reference points—the EU Charter of Fundamental Rights, the European Convention on Human Rights, and GDPR—and a ruling from France's highest constitutional authority that finds age verification disproportionate and insufficiently protective of privacy provides a credible template for challenges elsewhere.
The practical consequence is likely to be a period of legislative reconsideration across multiple jurisdictions simultaneously. President Macron has tasked the Prime Minister with rewriting the French legislation, with a revised version targeted before spring 2027. Whatever framework emerges from that process will be watched closely, because it will either resolve the constitutional objections or demonstrate that they are irresolvable within the current technical and legal landscape.
What a Privacy-Respecting Age Check Would Need to Look Like
The Constitutional Council did not say that protecting children online is impossible or that age verification can never be constitutionally compliant. It said that this law, as written, did not provide adequate safeguards. That distinction matters, because it implies that a revised version—one with those safeguards—could pass constitutional scrutiny.
What would those safeguards need to include? Based on the Council's reasoning, at minimum:
- A binding technical standard specifying that only an age signal—not identity data—may pass between a verification system and a platform
- Strict data minimisation requirements with defined retention limits and a prohibition on using verification data for any secondary purpose
- Independent audit rights for the body responsible for verifying compliance, with meaningful penalties for breach
- A legal route for individuals to establish what data was collected about them and to have it deleted
None of this is technically impossible. Zero-knowledge proofs and selective disclosure credentials can, in principle, confirm that a user is over a threshold age without revealing their identity, their date of birth, or any other personal detail. The challenge is deploying these systems at the scale of major social media platforms, mandating them specifically in law rather than allowing platforms to substitute cheaper alternatives, and ensuring the underlying credential infrastructure is itself trustworthy.
Why This Affects Everyone Who Uses the Internet
Age verification is often framed as a child protection measure, which makes it politically difficult to oppose. But as the Constitutional Council made clear, the mechanism does not act only on children—it acts on every person who attempts to access a service. Adults who have never given a platform their real identity are, under any workable age verification regime, required to do so. The scale of that change is significant.
For context: the services named in the French legislation—TikTok, Instagram, Facebook—collectively have hundreds of millions of adult users in Europe. Age verification would require all of them to authenticate their real identity to access services they currently use pseudonymously or anonymously. The normalisation of identity checks at the point of service access is a structural shift in how the internet operates, not a narrow technical adjustment.
This matters for anyone who has thought carefully about their online privacy, who uses tools like a VPN to reduce their data footprint, or who simply values the ability to access lawful content without their identity being logged. If you want to understand the broader picture of what your digital activity reveals and how to limit it, our introduction to VPNs and our free IP leak test are good starting points. And if you are concerned about network-level surveillance in restrictive environments, PremierVPN Protect offers basic browser-level protection at no cost.
What Comes Next
The immediate picture is legislative revision in France, legal scrutiny in other EU member states, and continued regulatory pressure in the UK. The French government has until spring 2027 to produce a revised bill that addresses the Constitutional Council's objections. That bill will need to satisfy both the child protection objective that motivated the original legislation and the privacy requirements that caused it to fail.
The broader question—whether any age verification regime can meet that dual standard at the scale of modern social media—remains genuinely open. The French ruling has made it harder to dismiss privacy objections as secondary concerns. It has established, at constitutional level, that the privacy of adults is not an acceptable casualty of age-gating, and that legislation which treats it as such will not survive scrutiny.
That is a meaningful constraint on how Europe—and by extension, the UK, which will be watching the same debates—can legally pursue child safety online. The debate is not over. But it is now being held on more honest terms.
Share this article
Protect your privacy with PremierVPN
Fast, secure, and truly private VPN service with servers in 12+ countries.
Get Started