India IT rules India

India's DPDP Age-Check Rules Avoid Persona's Biometric Trap — By Routing the Same Risk Through Aadhaar Instead

Germany certified a US facial-scan vendor on trust; India's DPDP Rules skip the vendor but centralize age checks through state ID infrastructure instead.

Two Countries, Two Age-Check Architectures People of Internet Research · India ~75M Roblox players biometric-scanned Mostly minors, verified via Person… 1B+ Persona verifications globally Across more than 4,000 client comp… 18 months DPDP Rules compliance window Children's verifiable-consent obli… peopleofinternet.com
Two Countries, Two Age-Check Architect… People of Internet Research · India ~75M Roblox players biometric-scanned 1B+ Persona verifications gl… 18 months DPDP Rules compliance window peopleofinternet.com

Key Takeaways

What Netzpolitik found

A Netzpolitik investigation published this week traced how LinkedIn, Etsy, and Roblox verify user age and identity: not in-house, but through Persona, a San Francisco identity-verification vendor that has run more than 1 billion checks across 4,000-plus client companies. At Roblox alone, roughly 75 million players — mostly minors — have handed Persona a selfie or ID photo to estimate their age. Germany's youth-protection regulator, the Kommission für Jugendmedienschutz (KJM), certified Persona's age-estimation model in 2024 as adequate to keep minors off adult content. The certification rested partly on Persona's own representations that it would not retain data or match faces against other databases — claims Netzpolitik's reporting and Persona's own privacy policy now appear to contradict. Privacy lawyers cited in the piece argue the resulting data collection "can hardly ever be proportionate" for a task as narrow as confirming someone is over 18, and flag exposure under the US CLOUD Act once biometric data sits with an American vendor.

The lesson isn't that age verification is illegitimate — child-safety regulators have a real, defensible interest in keeping minors off adult platforms, and self-declared birthdates are trivially false. The lesson is narrower and sharper: a regulator certified a vendor's black box largely on the vendor's word, and the gap between promise and practice took two years to surface.

India chose a different design, and it matters

India is mid-rollout on its own version of this problem. The Digital Personal Data Protection Rules, 2025, notified by MeitY on 13 November 2025 under Gazette notification G.S.R. 846(E), operationalize Section 9 of the Digital Personal Data Protection Act, 2023, which requires "verifiable consent" of a parent or guardian before any platform processes a child's personal data. Rule 10 specifies how that verification happens — and it does not ask platforms to collect a selfie. A Data Fiduciary may rely on identity and age details it already holds, or on details supplied through "a virtual token mapped to such details, which is issued by an authorised entity" — in practice, expected to run through DigiLocker, India's government-backed digital document wallet.

That is a genuinely different architecture from Persona's. Instead of a platform shipping raw biometric data to a private US vendor that then runs its own opaque retention and matching pipeline, the Indian model interposes a state-issued token that answers a yes/no age query without handing the platform (or a vendor) the underlying ID. Give India's regulators credit here: this sidesteps precisely the failure mode Netzpolitik exposed — a foreign commercial intermediary holding facial biometrics of Indian minors with no independent audit of what it actually does with them.

But the token model imports a different version of the same risk

The substitution isn't free. As Biometric Update's reporting on India's DigiLocker-based approach notes, the design still means "a parent's Aadhaar credentials are associated with their child's account so that platforms can send a yes-or-no age query" — which, even without storing raw Aadhaar numbers, creates a queryable record of which children are on which platforms, at population scale, sitting inside state infrastructure. Where Persona concentrated risk in a private vendor's servers, DigiLocker-based verification concentrates it in a government identity chokepoint that every social platform, gaming app, and edtech service will eventually query. That is not a hypothetical trade-off — it is the trade-off, and MeitY has not yet published the audit or oversight framework that would tell users what happens to those query logs.

The draft rules were criticized as vague on exactly this point when first floated in January 2025, and much of the operational detail — including the Fourth Schedule that will define reliable age-verification sources in full — remains unfinished. Children's consent obligations don't become enforceable until the back end of the DPDP Rules' 18-month phased rollout, putting the real deadline around May 2027. That gap is a genuine opportunity, not just a delay.

The proportionate fix is auditability, not vendor choice

The policy takeaway from Netzpolitik's investigation isn't "biometric vendors bad, government IDs good." It's that self-certification failed: KJM approved Persona's tool in 2024 based on representations nobody independently verified until journalists did the work two years later. India has, so far, avoided routing minors' faces through an unaudited private vendor. It should not now recreate the identical failure by routing the same population through an unaudited state token system on the same trust-the-issuer basis. Before Rule 10 obligations bite in 2027, MeitY should use the Fourth Schedule to mandate independent, published audits of any DigiLocker-adjacent verification flow — retention limits, query-log minimization, and a right for parents to see what a "virtual token" check actually transmitted. A verification system that nobody can audit is a verification system nobody should trust, whether the entity running it is a Delaware-incorporated startup or a ministry in New Delhi.

Sources & Citations

  1. Netzpolitik: Who scans your face when you verify online
  2. PIB: Government notifies DPDP Rules, 2025
  3. Section 9, Digital Personal Data Protection Act 2023
  4. Biometric Update: Meta's WhatsApp age-check trial vs India's digital ID plans
  5. Bar and Bench: MeitY notifies final DPDP Rules 2025