Recommendation ITU-T X.1901 (04/2026) Age assurance systems – Framework
Summary
History
Keywords
FOREWORD
Table of Contents
1 Scope
2 References
3 Definitions
     3.1 Terms relating to age assurance
     3.2 Terms relating to actors and parties
     3.3 Terms relating to data and processes
4 Abbreviations and acronyms
5 Conventions
6 Overview of age assurance
     6.1 Age
     6.2 Characteristics of age assurance systems
     6.3 Age assurance methods
          6.3.1 Overview of age assurance methods
          6.3.2 Age verification methods
          6.3.3 Age estimation methods
          6.3.4 Age inference methods
          6.3.5 Successive validation
     6.4 Stakeholders
          6.4.1 General
          6.4.2 Policy makers
          6.4.3 Consumer protection agencies
          6.4.4 Sector associations
7 Functional characteristics
     7.1 Age assurance systems
          7.1.1 General
          7.1.2 Age assurance providers
          7.1.3 Intermediaries
     7.2 Data acquisition for age assurance components
          7.2.1 Sources of data
          7.2.2 Primary and secondary credentials
          7.2.3 Date transposition errors
     7.3 Binding of age assurance result to the correct individual
          7.3.1 Binding characteristics
          7.3.2 Approaches to binding
     7.4 Age assurance data processing
     7.5 Configuration management
     7.6 Context in use
     7.7 Delivery of age assurance result
8 Performance characteristics
     8.1 Performance effectiveness
          8.1.1 General
          8.1.2 Effective age assurance systems
          8.1.3 Ineffective age assurance systems
          8.1.4 Use of self-asserted age
          8.1.5 Other factors affecting effectiveness
     8.2 Indicators of effectiveness
     8.3 Performance metrics
          8.3.1 Classification accuracy
          8.3.2 Primary metrics
          8.3.3 Outcome error parity
          8.3.4 Performance efficiency
     8.4 Resource utilization
     8.5 Testability
9 Privacy characteristics
     9.1 General
     9.2 Privacy by design and default
     9.3 Data minimization
          9.3.1 Collection limitation
          9.3.2 Non-disclosure of age-related data
          9.3.3 Compliance with legal obligations
          9.3.4 Purpose limitation
          9.3.5 Access control
          9.3.6 Data disposal
     9.4 Avoidance of adding to digital footprint
     9.5 User awareness
     9.6 Audit logs
10 Security characteristics
     10.1 Security by design and default
     10.2 Replay, forwarding or reuse of age assurance result
          10.2.1 Replay of an age assurance result
          10.2.2 Forwarding of an age assurance result
          10.2.3 Planned memorization or reuse of an age assurance result
     10.3 Resistance to attack
          10.3.1 Preparation for attack
          10.3.2 Attack vectors
          10.3.3 Biometric presentation attacks
          10.3.4 Spoofing attack
          10.3.5 Counterfeiting attack
     10.4 Contra indicators
     10.5 Fail safe
11 Acceptability characteristics
     11.1 General
     11.2 Inclusivity
     11.3 User engagement and assistance
     11.4 Complaint handling
12 Practice statements
     12.1 General
     12.2 Practice statements by age assurance providers
     12.3 Practice statements by relying parties
     12.4 Practice statements by intermediaries
Bibliography