For compliance, legal and DPOs
Age verification your DPO will actually like
Tessio proves a user is over 18 from their EU Digital Identity Wallet and stores no personal data. No document images, no dates of birth, nothing to breach. Here is the compliance posture in plain terms.
Most age checks add data risk. A document scan or a database match means you now hold identity data you have to secure, minimise and justify. Tessio flips that. The user proves one claim, that they are over 18, and you get a signed yes or no. There is no date of birth, no document image and no selfie, on your systems or ours.
That posture lines up with the rules. GDPR asks you to minimise personal data, and the DSA is explicit that protecting minors should not push you to collect more personal data to check age. A single over-18 boolean is about as data-minimal as an age check gets.
You store no personal data
The result is an over-18 yes or no, not a date of birth or a document. You cannot leak what you do not hold, so your breach exposure drops to almost nothing.
Data minimisation by design
One question, one answer. That fits the GDPR principle of data minimisation and the DSA caution against collecting extra personal data just to check age.
Auditable results
Each result is signed, so you keep verifiable evidence that you ran a real check for your regulator, without keeping any identity data behind it.
Self-host for data residency
When identity data cannot go to a hosted service, run the open source .NET verifier inside your own environment with managed trust updates. EU based, with EU data residency.
The compliance posture
- No personal data stored: no date of birth, no document image, no selfie.
- An over-18 result only, so your GDPR footprint and breach exposure stay low.
- A signed, auditable result you can keep as evidence of a real check.
- Aligned with the DSA principle that you should not collect extra data to check age.
- Built on the EU Digital Identity Wallet standards for the eIDAS mandate.
- The verification core is open source under Apache-2.0, so teams that cannot send identity data to a third party cloud can run it themselves.
Frequently asked
Do you store any personal data?
No. A check returns an over-18 yes or no. There is no date of birth, no document image and no selfie kept, on your systems or ours. That is the whole point of the design.
Is it GDPR compliant?
We check one claim and store no personal data, which is the data-minimisation posture GDPR and the EU Digital Identity framework are built for. You stay in control of your own processing, and if you need the check inside your own boundary you can self host the open source core.
Where is verification processed?
Tessio is EU based with EU data residency. If your obligations mean identity data cannot leave your environment at all, you can self host the .NET verifier and keep processing in your own boundary.
Keep exploring
Age verification for dating apps
Dating and matchmaking
Age verification for adult platforms
Adult content
Age verification for social and UGC platforms
Social and user content
EU Digital Services Act and age assurance
EU regulation
UK Online Safety Act age assurance
UK regulation
The EU Digital Identity Wallet, for relying parties
EU Digital Identity
Tessio for developers
For developers
Developer docs
The age verification API
For compliance, legal and DPOs
Talk through your posture
Tell us your sector and the duties you're meeting, and we'll walk through how a wallet based over-18 check with no stored data fits. Access is invite only while we onboard design partners.