Spain’s AEPD Age Verification System Explained

Spain's data protection agency is finalizing an age verification system using a digital ID app and blocklists for non-compliant websites.

English · Original discussion in Spanish · Published

Spain’s AEPD Age Verification System Explained
AEPD to Mandate Age Verification via Digital ID App

Protecting minors' privacy will force adults to identify themselves before accessing much of the internet. The paradox is summed up in one blunt phrase: "To supposedly protect my data (AEPD), I have to give my data." The Spanish Data Protection Agency (AEPD) has been designing, alongside other bodies, the system Spain will use to verify citizens' age while browsing, using apps, or playing games. On paper, this model prevents visited sites from knowing who you are, though some warn it doesn't prevent records showing you were there.

How the AEPD's Age Verification Will Work

The central piece is a free mobile app developed by the Royal Mint (FNMT). The application accesses an official document—the DNI, passport, digital certificate, or European eIDAS digital identity—thus verifying the user's age without exposing their other data. Meanwhile, the browser checks if a site is suitable for minors by reading an age.xml file at the domain root. If age verification is required, it invokes the FNMT app, which returns a positive response only if the citizen meets the requirements, revealing nothing else. For desktop or consoles, the phone generates a QR code scanned by camera or typed manually.

The design isn't new. The General Audiovisual Communication Law has required video platforms since mid-2022 to implement age verification systems to prevent minors from accessing harmful audiovisual content. The CNMC, responsible for ensuring the system's adequacy, already warned that merely declaring adulthood without subsequent verification does not provide sufficient security. The obligation extends beyond video to advertising promoting behavior harmful to minors.

Which Websites Will Be Blocked If They Don't Comply?

The AEPD, CNMC, FNMT, Ministry of Interior, and Ministry of Digital Transformation have been working together since March in the Age Verification Working Group. The first intended use is video platforms; subsequently, several participants assume it will extend to age-rated games or online casinos. Responsibility will fall on services, which must properly label their content, and the Agency suggests maintaining blocklists for non-compliant sites. This raises doubts among those trinc the proposal: if the system is limited to Spain, which international website will bother implementing it? The most repeated forecast among participants is that most will ignore it and end up blocked.

The Trace Left by Each Verification

The official argument is that neither the browser nor the service obtains any user data. The doubt concerns the intermediary. "Linking the Hash of that token with a real ID, even without access to the token creator, is extremely simple," argue those monitoring the proposal, warning that such a design would concentrate enormous power: blocking specific users on certain sites, at certain times, or during certain actions. And that, likely, the token would be shared and everyone's digital consumption sold. To supposedly protect privacy, they claim, a centralized digital identity emerges.

Can a VPN Bypass Age Verification?

For knowledgeable users, yes. The most common answer is hiring a VPN service, which encrypts traffic and changes DNS, so the operator doesn't see where you connect. The objection is scale. "They aren't targeting the 3% capable of doing that, but the 97% who won't," summarizes a comment: the goal isn't the expert, but the average citizen who won't set up a tunnel to view a page. Some see this situation as a push toward paying for anonymity services, now computed as another connection fee.

Minors Already Know How to Evade It

The uncomfortable data for any verification system comes from outside. According to an analysis released recently, 75% of sanctioned teenagers describe bypassing restrictions as easy or very easy. Common methods: lying about age in verification requests (57%), entering false birth dates during registration (44%), using a parent's or older sibling's account (42%), and connecting via VPN (30%). 64% of surveyed 14- and 15-year-olds didn't even suffer account deletion.



The system is in the design phase with no confirmed implementation date. Some see a necessary tool; others, the door to mandatory digital identification. With verification in the browser, the app on the phone, and blocklists in reserve, how long until the "internet ID card" stops being a hypothesis?

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (175 replies).

More summaries

All summaries in English →

Back