This is ridiculous and clearly shows both nefarious intent and complete disregard for the GDPR and it's core principle of data minimisation. There must be a simpler solution to this - maybe through attestation from a trusted third party who has already (legitimately) verified the user's identity - like a bank. Imagine a user creating and providing a token that allows a one-time request through the open banking standards to receive an attestation on whether or not the user is over 18 - without disclosing the users actual dob or any other personal information except who and how the attestation was made. Not sure if it would even be necessary for companies to store precisely when the attestation was made if the banks themselves record the event.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: