Jumio Competitors: BEST 8 Jumio Alternatives

EU Age Verification in 2026: The DSA Mini-Wallet Blueprint and What It Means for Online Platforms

Table of Contents

Key Takeaways

  • The EU’s age verification blueprint became technically ready on 15 April 2026, with pilots underway in Denmark, France, Greece, Italy, and Spain.
  • It’s called the mini-wallet because it’s built on the same technical specifications as the forthcoming European Digital Identity Wallet, ensuring long-term compatibility.
  • It proves a single fact, that a user is over a given age threshold, without revealing name, date of birth, or any other personal information.
  • The solution supports compliance with Article 28 of the Digital Services Act, which requires platforms to protect minors online.
  • Identity verification providers can adopt the open-source blueprint and build compliant age verification into their own offerings.

“Age is just a number” seems to resonate quite literally when gaining access to online platforms. Ever consider how simple it is to bypass age verification? If a 14-year-old wants to access an adult content site or a violent online game, the age gate is just a button: “I am over 18. Click to enter.” They click and they’re in. That’s the entire check. The alternative some sites use, require users to upload a passport or driver’s license, which actually verifies age but also forces adults to hand over their full name, date of birth, address, and photo to companies they have no reason to trust.  

Platforms are stuck between two bad options: a privacy-friendly check that stops no one, or real verification that makes users dangerously over-share. The European Commission sought a real solution to this problem. In April 2026, this solution became technically ready, giving member states and online platforms a standard, privacy-preserving way to confirm a user’s age without collecting unnecessary personal data. Any platform serving European users should strive to understand this solution, nicknamed ‘mini-wallet’. 

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

Let’s shed some light into what it is, why it was created, how it works, and what it means to platforms and identity verification providers.

What Is the EU Age Verification Mini-Wallet?

The mini-wallet is a standardized, privacy-preserving app that lets a person prove they meet an age requirement, initially being over 18, without disclosing anything else. When a user visits an age-restricted service, the app confirms only that the person clears the threshold. Not the exact age, not the name, not the date of birth.

The nickname comes from its architecture. It is built on the same technical specifications as the future European Digital Identity Wallet, scheduled to roll out across all Member States by the end of 2026. That shared foundation makes it a stepping stone toward the wider wallet ecosystem, and it will integrate directly into national wallets as those become available.

The solution is open source and free to use. The Commission published the first blueprint on 14 July 2025, followed by an enhanced second version in October 2025 that added passport-based onboarding. It became feature-ready on 15 April 2026. Member States can either integrate the functionality into their national digital wallets or publish a customized standalone app. Italy has integrated it into the IT Wallet, France is using France Identite, and Denmark is using MitID.

A key detail underpins the privacy promise: the solution relies on zero-knowledge proof cryptography, which confirms a fact about a person without exposing the underlying data. If you are new to the topic, our explainer on what age verification is provides useful grounding.

The DSA Article 28 Context: Why the EU Needed a Standard Solution

The mini-wallet is a direct response to obligations under the Digital Services Act, the EU’s framework for regulating online platforms.

Article 28 requires platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security for children. The problem was that the DSA set the obligation without prescribing a method. Platforms were left to interpret what counted as a robust age check, and the result was inconsistency: self-declaration checkboxes, document uploads, facial age estimation, all with wildly varying privacy implications.

On 14 July 2025, the Commission published guidelines on Article 28 alongside the first blueprint, effectively naming the mini-wallet as the reference standard for a device-based method of age verification. The guidelines are not legally binding in themselves, but they serve as the evaluation standard supervisors will use to assess whether a platform meets its Article 28 obligations. Platforms should not mistake non-binding for unimportant.

The stakes are considerable. Violations of the DSA can result in fines of up to 6% of global annual turnover. Importantly, the Article 28 guidelines address all platforms that allow access to minors, not only the Very Large Online Platforms with more than 45 million EU users.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

How the Mini-Wallet Works in Practice

The flow is designed to be simple for the user and to reveal as little as possible to the platform:

  • The user obtains an age attestation. Through the app or their national wallet, the user proves their age once using a trusted source such as a national eID, an ID card with an eID function, or a passport.
  • The app issues a proof-of-age attestation. This is an electronic attestation of attributes confirming the user is above a given threshold, and nothing more.
  • The platform requests confirmation. On the web this uses the Digital Credentials API through deep links or QR codes; native apps use OpenID for Verifiable Presentations.
  • The platform receives only a yes or no. The server verifies the attestation signature against the public keys of the national issuing authority, confirming the user clears the threshold without ever seeing the date of birth.

Because the attestations are single-use and non-reusable, a platform cannot store and replay them, limiting tracking. The credential is protected by the same security as the national wallet, meaning PIN, biometrics, and secure hardware, so a lost phone does not expose it.

Who Must Implement DSA-Compliant Age Verification?

A common misconception is that dsa age verification obligations apply only to the largest platforms. That is not the case. The Article 28 guidelines apply to any online platform accessible to minors that offers age-restricted content or services. The platforms most likely to need robust age verification include:

  • Adult content providers, where confirming users are over 18 is the clearest use case.
  • Social media platforms, particularly as Member States push for minimum-age requirements.
  • Online gaming and gambling services, which carry their own age-restriction obligations.
  • Alcohol, tobacco, and other age-restricted e-commerce, where the solution can be extended to relevant thresholds.
  • Very Large Online Platforms, which face the most direct scrutiny but are far from the only entities in scope.

The solution is also flexible on thresholds. While the initial focus is proving a user is over 18, the blueprint can be configured for other ages, such as 13+ for certain social media or 16+ for particular services. For platforms weighing how age verification fits alongside broader compliance duties, our overview of KYC regulations explains the wider verification context.

What the Mini-Wallet Means for Identity Verification Providers

For identity verification providers, the EU framework is both a challenge and an opportunity, setting a new baseline for what privacy-preserving age verification looks like.

The opportunity is clear. The blueprint is open source and free, so providers can build on it, delivering age verification demonstrably in line with the Article 28 guidelines. Providers that support the European standard as an additional verification method give their platform clients a direct path to DSA compliance.

There are challenges too. The bar for privacy is now high, anchored in data minimization and zero-knowledge cryptography, and providers relying on older approaches such as document upload or standalone facial age estimation may find those methods judged against a more demanding reference standard. The market is also moving toward interoperability, with an EU-wide coordination mechanism supporting cross-border acceptance of proof-of-age attestations. Providers that build for that interoperable future will have the advantage.

Crucially, the mini-wallet is a bridge to the eu digital identity wallet, due to roll out across all Member States by the end of 2026. Our deep dive on eIDAS 2.0 and the EU Digital Identity Wallet is a useful companion for anyone planning ahead.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

FAQ

What is the difference between DSA Article 28 and the Online Safety Act in the UK?

Both aim to protect minors online but differ in approach. The EU's Article 28 favors a privacy-preserving, device-based model built around the mini-wallet. The UK's Online Safety Act takes a faster, more identity-linked route. Both carry heavy penalties, though the UK allows fines up to 10% of turnover versus the EU's 6%.

Do platforms need to verify age for all users or only in specific situations?

Age verification applies where a platform offers age-restricted content or services accessible to minors. It is not a blanket requirement for every user of every site. The obligation is proportionate, meaning it should match the risk the content poses to minors, with adult content representing the clearest case.

What is a qualified attestation of attributes under eIDAS 2.0?

It is an electronic attestation confirming a specific attribute about a person, such as being over a certain age, issued under the eIDAS framework. The mini-wallet's proof-of-age tokens are electronic attestations of attributes, confirming the holder clears an age threshold without disclosing their date of birth or other personal data.

Can the EU mini-wallet be used for gambling compliance?

The blueprint supports configurable age thresholds, so it can technically confirm a user meets the minimum age for gambling. Whether it satisfies a specific national gambling regulator's full requirements depends on that jurisdiction's rules, but as an age-proofing layer, the solution is well suited to the use case.

How does the mini-wallet protect user privacy?

It uses zero-knowledge proof cryptography to confirm a single fact, that the user meets an age threshold, without revealing name, date of birth, or other data. Attestations are single-use and non-reusable, limiting tracking, and the credential is secured on the user's device with PIN, biometrics, and secure hardware.