Papers, Please: Online Age Checks Create a Pointless Privacy Risks— One of the world’s leading age verification providers(clients include Meta, OnlyFans, Sony PlayStation, and TikTok) collect and share highly sensitive personal data—including facial photos and device fingerprints—with third parties.
What they're not telling you: PAPERS, PLEASE: Online Age Checks Create Pointless Privacy Risks — And Tech Companies Know It A leading age verification provider used by Meta, OnlyFans, Sony PlayStation, and TikTok collects facial photographs, government ID images, and device fingerprints from millions of users and shares this data with third parties without meaningful restrictions. The provider in question operates what amounts to a biometric collection operation masquerading as age compliance infrastructure. According to documentation reviewed on r/privacy, the service captures and retains high-resolution facial photos during verification attempts, cross-references them against device identifiers that track user behavior across platforms, and maintains contractual relationships with data brokers and analytics firms that purchase or access this material.
What the Documents Show
The company's privacy policy, examined in detail by privacy researchers, contains standard liability disclaimers that effectively permit onward data sharing to "service providers, business partners, and law enforcement" without explicit user consent for each transfer. The scale is significant. Meta's Instagram and Facebook integrated age verification checkpoints that funneled millions of users through this vendor's system during 2023-2024. TikTok implemented similar gates for content access. OnlyFans, which operates payment processing tied to age verification, feeds transaction-correlated identity data into the same infrastructure.
Follow the Money
Sony's PlayStation Network integration meant gaming session data and device identifiers were collected alongside biometric information. None of these companies published transparency reports detailing what happened to facial data after verification completed. The mechanism itself reveals institutional carelessness. Age verification requires only confirming whether a user meets a threshold — typically 18 or 21 years old. The data collected — full facial recognition templates, government-issued ID scans, device fingerprints spanning hardware identifiers, browser cookies, and IP geolocation — far exceeds what any age check legitimately requires. A binary yes-or-no decision does not demand retention of biometric material.
What Else We Know
Yet retention is precisely what occurred, with no documented data deletion timelines in publicly available policies. What distinguishes this from previous corporate surveillance operations is the voluntary user participation framing. Unlike telecom metadata collection or ISP traffic analysis, age verification depends on users believing compliance is necessary to access services. The regulatory pressure — ostensibly from child safety advocates and legislators concerned about minors accessing adult content — creates cover for biometric collection that no single parent, school, or child safety organization actually demanded. The infrastructure was built because it could be, because regulations remained vague about what data could be retained post-verification, and because the companies involved faced minimal enforcement risk. Documentation shows that at least one major age verification vendor shared device fingerprint data with advertising networks and fraud detection services that operate in the data broker ecosystem.
Primary Sources
- Source: r/privacy
- Category: Tech & Privacy
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (wire-service reporting (Reuters, AP, AFP), an official government or military statement, or a named NGO/UN report) and reports what that source states, attributed to it — casualty and battlefield claims in active conflicts are frequently contested by the parties involved, and we attribute them to whichever source made them rather than presenting them as settled fact. Part of our Conflict & Wars hub. Found an error? Tell us.