Selective Disclosure: Proving You Are Over 18 Without Handing Over Your ID
Selective disclosure can let someone prove they are old enough for an online service without sending a copy of a passport or driver’s licence. It offers a possible middle ground as age-assurance rules collide with concerns about routine identity collection.

An online service that needs to know whether a customer is over 18 does not necessarily need that person’s name, home address, document number or date of birth. Yet many age-checking systems still ask users to upload a government ID or submit to a face scan, creating databases of sensitive information that can be misused, breached or repurposed.
Selective disclosure is a technical approach designed to narrow that exchange. Instead of presenting an entire identity document, a person can present a cryptographic proof of one fact: that they are over a specified age, for example, or that they live in a particular country. The service receives the answer it needs, while the underlying document and unrelated personal details stay with the holder.
A privacy answer to the age-assurance debate
Age assurance, the process of estimating or verifying whether a user meets an age threshold, has become a central policy issue in the United States and Europe. Lawmakers and regulators are pressing platforms to protect children from age-restricted content, products and services. The resulting rules and proposals vary widely, but many create pressure for stronger checks than a self-declared birthday.
Privacy and digital-rights advocates warn that poorly designed age checks can turn everyday web access into an ID checkpoint. A requirement to collect identity documents for adult content, social media or retail purchases could expose users to tracking and create attractive targets for criminals. It can also exclude people without conventional documents or reliable access to a smartphone.
Selective disclosure does not resolve every legal or practical question in age assurance. It does, however, separate a service’s legitimate need to know an age-related result from its ability to collect a full identity. That distinction is why the technology is increasingly discussed as a bridge between child-safety goals and data-minimisation principles, including those reflected in European privacy law.
How a proof can reveal less
The basic model has three parties: an issuer, a holder and a verifier. A government agency, bank, university or other trusted organization acts as the issuer. It checks a person’s identity or eligibility and creates a digitally signed credential containing relevant attributes, such as date of birth or country of residence. The holder keeps that credential, commonly in a digital wallet on a phone.
When a website or shop asks whether the holder is over 18, the wallet can generate a response limited to that request. In some designs, it discloses an age-over-18 attribute. In others, it produces a zero-knowledge proof, a cryptographic proof that demonstrates a statement is true without revealing the information used to establish it. The verifier checks the issuer’s digital signature and the proof, rather than inspecting the original document.
- A liquor-delivery service could receive confirmation that a customer is over its required age, not a birth date or address.
- A service restricted to a jurisdiction could receive proof that a user is a resident of a country or state, without receiving a full credential.
- A well-designed exchange can also use a one-time or audience-specific proof, reducing the chance that separate services can link a person’s activity through a persistent identifier.
The privacy gain is not automatic. A credential can still be presented in a way that exposes a stable identifier, collects transaction records or reveals more fields than necessary. The design of the wallet, credential and verifier request matters as much as the headline claim of “selective disclosure.”
Standards are moving toward narrower presentations
The standards landscape is evolving, but the direction is clear. Mobile driver’s licence specifications, including ISO 18013-5, define ways for a holder to present selected data from a driving credential to a relying party, with mechanisms intended to support privacy-preserving presentation. The exact privacy properties depend on the implementation and on what a verifier requests.
Verifiable credentials, a broad family of digitally signed credentials used across public and private identity systems, can also support selective disclosure. Different credential formats and cryptographic schemes offer different capabilities. Some are built around revealing chosen fields, while others can support stronger proof-based claims such as an age threshold. Interoperability work remains important because a credential useful in one wallet or jurisdiction is not automatically accepted everywhere else.
Trust still has to be earned
A cryptographic proof is only as reliable as the process behind it. The verifier must trust the issuer to have checked age or residence accurately, and must be able to determine whether the credential is current and has not been revoked. Governments will also have to decide which issuers qualify for regulated age-assurance uses and what oversight, redress and audit rules apply.
Security creates another limit. If a phone is stolen, compromised or shared, a wallet-based credential may be misused unless it is protected by device security and an appropriate user check. Conversely, systems that demand intrusive biometrics at every presentation can undermine the privacy benefit they were meant to provide.
Finally, adoption is decisive. Issuers need to create usable credentials, people need accessible ways to hold them, and websites, retailers and platforms need reasons and technical capacity to accept them. Selective disclosure can reduce unnecessary ID sharing, but it cannot by itself guarantee anonymous access or solve the policy choices embedded in age-assurance law. Its value lies in giving those choices a more proportionate technical option.


