In-article:

Age control on websites: the CNIL delivers its recommendations


Alexander Boero

July 27, 2022 at 11:50 a.m.

33

Pornhub © charnsitr / Shutterstock.com

© harnsitr / Shutterstock.com

Access to certain websites, pornographic not to mention them, is in theory reserved for adults. “In theory”, because checking the age on entry is not always easy.

Any website that reserves its access to adults and prohibits it in principle to minors must check the age of the Internet user. But this is not always easy, and reconciling youth protection, security and respect for privacy can be particularly complex. And generally, the devices put in place are not very effective and remain easily circumvented. The CNIL, which recalls that checking a visitor’s age is compatible with the GDPR insofar as the site offers sufficient guarantees to protect his privacy and his data, was keen to look into the subject and to make some recommendations.

Solutions exist, but few apply them and they are far from perfect

Solutions already exist to check that the Internet user respects the age limit set by a site. It is for example possible to use a bank card, in the case where the minor already has the latter, which is not necessarily a norm. The CNIL approves this technique, which “ is based on proven technology “. But it must be accompanied by an alternative.

Another existing solution: facial analysis of facial features, all thanks to the computer’s webcam and using an automatic system. But if this solution blocks access to the youngest and authorizes it to people who are clearly over 18, the risk of error for people who are a little over or a little under 18 is still too great.

These two solutions are operated by third parties who must offer a sufficient level of security and reliability. Because the risk of data theft is also significant. For the time being, the CNIL does not identify any more mature techniques at this stage. Pornographic sites that offer only a small warning or only require a click to enter are supposed to be illegal, but the publishers are often based abroad, it remains very difficult to move the lines and to block access to porn sites in France.

The recommendations of the CNIL, for a more “effective, reliable and respectful of privacy” verification

So, how to improve the effectiveness of age control while preserving the privacy of Internet users? First, the CNIL insists on the need for the solution put in place by such and such a pornographic site not to be operated by the site itself, but by a trusted third party. This would provide sufficient guarantees, insofar as it has a label or certification.

The Commission Nationale de l’Informatique et des Libertés then recommends that this trusted third party be able to receive reliable proof of age, not from the Internet user, but from an administration or a company which knows the latter and can certify his age. Then, the Internet user or the trusted third party would transmit this proof to the site to which access is requested.

For the CNIL, it is urgent to put in place a specific framework to deploy more efficient, reliable and privacy-respecting systems. With its various recommendations, the person issuing the proof of age knows the identity of the user well, but he does not know which site is consulted, or else he may know the site consulted but not the identity of the user. . Finally, the site that submits the user to verification obtains proof that the Internet user is of legal age, without knowing his real identity.



Source link -99