The statute’s awkward, necessary bargain
Among the most discussed pieces of Bill C-34 is the under-16 social media account restriction for services designated by regulation. Treat C-34 as proposed legislation and track it on parl.ca. Operators would need adequate age-verification or age-estimation measures designed to prevent people under 16 from registering.
“Adequate,” in the summaries and bill structure circulating among counsel, is not a vibes test. The Commission would need to be satisfied that measures are effective; that personal information is collected or used only for age-verification or age-estimation; that information is protected until it is destroyed; that it is destroyed once verification or estimation is complete; and that other regulatory requirements are met. Exemptions may exist where operators prove strong child-safety safeguards.
That package is honest about the trade-off. Child protection needs friction at the account gate. Privacy needs the gate not to become a permanent identity registry.
Why this is a paradox in practice
I have reviewed enough age-gating proposals to know the failure patterns:
- Self-declaration is cheap and useless against motivated minors.
- Credit card checks exclude people without cards and still leak financial metadata.
- Government ID upload is effective-ish and creates catastrophic breach value if stored.
- Facial age estimation can reduce document collection but introduces biometric sensitivity, bias risk, and model error at the edges of 15 vs 16.
- Parent consent flows can reintroduce household surveillance dynamics and messy identity linkage.
Bill C-34’s destroy-immediately logic pushes operators away from “collect everything and keep it for appeals.” That is good. It also creates operational stress: what do you produce if a regulator asks you to prove the system works? Aggregate metrics and third-party certifications will matter more than retaining raw scans.
Age checks are still personal-information processing under PIPEDA and stricter provincial regimes such as Quebec Law 25. A federal safety bill does not create a free pass to build an ID warehouse.
PETs and zero-knowledge are not optional polish
Privacy-enhancing technologies are how you thread the needle:
- Age tokens / attributes. A trusted issuer confirms “over 16” without handing the platform a birthdate, address, or document image.
- Zero-knowledge proofs. A user proves a statement (age ≥ 16) without revealing the underlying credential.
- On-device estimation with limited telemetry. Estimation happens locally; the service receives a result and integrity signal, not a face template archive.
- Data-minimized vendor separation. If a specialized age-assurance provider is used, contractual and technical barriers should prevent the social platform from receiving reusable identity payloads.
None of these eliminate error. They reduce the blast radius when error or breach happens. That is the governance win.
Design rules I would impose before legal forces them
- Purpose lock. Age data cannot feed ads, ranking, fraud beyond the gate, or “just in case” analytics.
- TTL measured in minutes, not months. If destruction is the standard, retention defaults should be embarrassingly short.
- No central photo lake. If images are needed transiently, process and discard; do not build a searchable gallery.
- Bias testing at the decision boundary. Misclassifying 16-year-olds is a rights issue and a product issue.
- Fallback without humiliation. Manual review paths should not force people to email passports to a shared inbox.
- Commission-ready evidence. Effectiveness metrics, false accept/reject rates, and destruction logs that do not themselves re-identify users.
- Cross-border honesty. If a vendor processes verification outside Canada, document transfer safeguards and Canadian rights paths.
The exemption trap
C-34 contemplates possible exemptions where services show adequate child safeguards. I am wary of two outcomes: platforms racing to weak “safe enough for kids” claims to avoid age gates, or age gates so invasive that adults migrate to darker, less moderated spaces. Privacy professionals should push for high-assurance, low-retention methods so the protective goal does not depend on mass identity collection.
There is also a procurement angle. Many organizations will buy age-assurance as a vendor feature. That does not outsource accountability. You still need to know what the vendor retains, where it processes, how quickly it destroys, and whether its model bias profile is acceptable for a hard age-16 line. Put those questions in the RFP. Require deletion attestations you can audit. Align contract language with OPC expectations on accountability and service providers.
Testing what “destroy immediately” really means
I ask vendors for a live demo of the destruction path, not a slide. Where does the image go in memory? How long do error logs keep face crops? Who can restore a failed verification attempt? If engineering cannot answer, assume retention is longer than marketing claims. Then write your internal standard to the stricter of the vendor reality and the bill’s purpose limit.
Actionable takeaway
The age-verification privacy paradox is not a reason to abandon child protection. It is a specification: effective assurance, narrow purpose, hard destruction. If your answer to under-16 restrictions is “upload your driver’s licence and we’ll keep a copy,” you have solved the wrong problem. Build for proofs and tokens, not vaults. Confirm C-34 remains a proposal on parl.ca, design against the adequacy test in the bill materials, and keep PIPEDA and CAI / Law 25 constraints on any biometric or ID flow. Effectiveness without an identity warehouse is the only design I will defend to a board — or to a teenager’s parent.