For compliance, legal and DPOs

Age verification your DPO will actually like

Tessio proves a user is over 18 from their EU Digital Identity Wallet and stores no personal data. No document images, no dates of birth, nothing to breach. Here is the compliance posture in plain terms.

Most age checks add data risk. A document scan or a database match means you now hold identity data you have to secure, minimise and justify. Tessio flips that. The user proves one claim, that they are over 18, and you get a signed yes or no. There is no date of birth, no document image and no selfie, on your systems or ours.

That posture lines up with the rules. GDPR asks you to minimise personal data, and the DSA is explicit that protecting minors should not push you to collect more personal data to check age. A single over-18 boolean is about as data-minimal as an age check gets.

You store no personal data

The result is an over-18 yes or no, not a date of birth or a document. You cannot leak what you do not hold, so your breach exposure drops to almost nothing.

Data minimisation by design

One question, one answer. That fits the GDPR principle of data minimisation and the DSA caution against collecting extra personal data just to check age.

Auditable results

Each result is signed, so you keep verifiable evidence that you ran a real check for your regulator, without keeping any identity data behind it.

Self-host for data residency

When identity data cannot go to a hosted service, run the open source .NET verifier inside your own environment with managed trust updates. EU based, with EU data residency.

The compliance posture

  • No personal data stored: no date of birth, no document image, no selfie.
  • An over-18 result only, so your GDPR footprint and breach exposure stay low.
  • A signed, auditable result you can keep as evidence of a real check.
  • Aligned with the DSA principle that you should not collect extra data to check age.
  • Built on the EU Digital Identity Wallet standards for the eIDAS mandate.
  • The verification core is open source under Apache-2.0, so teams that cannot send identity data to a third party cloud can run it themselves.

Frequently asked

Do you store any personal data?

No. A check returns an over-18 yes or no. There is no date of birth, no document image and no selfie kept, on your systems or ours. That is the whole point of the design.

Is it GDPR compliant?

We check one claim and store no personal data, which is the data-minimisation posture GDPR and the EU Digital Identity framework are built for. You stay in control of your own processing, and if you need the check inside your own boundary you can self host the open source core.

Where is verification processed?

Tessio is EU based with EU data residency. If your obligations mean identity data cannot leave your environment at all, you can self host the .NET verifier and keep processing in your own boundary.

Keep exploring

For compliance, legal and DPOs

Talk through your posture

Tell us your sector and the duties you're meeting, and we'll walk through how a wallet based over-18 check with no stored data fits. Access is invite only while we onboard design partners.