In our response, CIPL commends the OPC for its thoughtful, evidence-informed, and privacy-centered approach. To further strengthen the guidance, we encouraged the OPC to clarify that legal age restrictions should take into account children’s evolving capacities and should not automatically require the most robust forms of age assurance in the absence of a contextual risk assessment. Rather, age assurance should follow a proportionate, risk-based approach, with the level of assurance calibrated to the actual risk posed, the nature of the service, and the likelihood of children accessing it.
CIPL also called for a clearer risk taxonomy supported by practical examples, particularly for medium-risk scenarios. In addition, we emphasized that risk assessments should be continuous and holistic, balancing both the risks and benefits to children’s rights, with the best interests of the child serving as a guiding principle. Finally, CIPL encouraged the guidance to promote interoperable, technology-neutral, privacy-enhancing solutions, greater international convergence with recognized standards, and ongoing regulatory cooperation.