It is reported that 60 per cent of the age-certification process “Yoti”, used by websites and platforms requiring age certification, including PlayStation, Meta and TikTok, allegedly “collects a large amount of private information beyond what is strictly necessary for the age of certification” and even shares it with “the Quadripartite Quartet, where several users are less visible”.

According to Futurity, this report, entitled “Certificate: A first look at the age of the Internet”, was published at the IEEE (Institute of Electrical and Electronic Engineers) safety and privacy seminar on 18 May. The report states that Yoti’s data collection methodology “draws a worrying picture of age-validation privacy and effectiveness”.

The report states that Yoti’s age-validation software “collects a large amount of high-resolution data on user equipment” and that such information “is necessary for non-age-validation”. Includes information collected from equipment during the age verification process, such as ” operating system version string, available memory, connection type and CPU architecture ” . The report also indicates that these “solely identifiable” information may be used for “unauthorized tracking of user equipment”.

Most worrying is “Yoti shares sensitive user information with a Quadripartite, which is not easy to detect by multiple users”, including payment processor Stripe. The report states that Stripe “collects a large amount of telemetry data, which may be used as a unique identifier”, including information captured from the first-party website used to validate the age of users through Yoti software: “We find that the service collects a large amount of private information beyond what is necessary for age verification, including high entropy data and metadata on equipment and other surprise telemetry data”.

However, since the report was first released, researchers behind it have indicated that “Yoti has indicated that they have repaired Stripe’s website, but the researchers have also indicated that they are unable to verify the validity of this claim.

This in itself raises the question of complete independence. Yoti referred to the above-mentioned issue as “a loophole”, which left open the question of whether the data provided to him by users were being processed in a safe and sound manner, and which did not explain whether the data provided to Stripe were still being retained.