By the VixQR team · published on · 2 min read
Age Verification by QR Code: How the European Approach Works
A site may need to know whether a visitor is over 18. The most intrusive method collects a complete identity document, revealing far more than necessary:…

A site may need to know whether a visitor is over 18. The most intrusive method collects a complete identity document, revealing far more than necessary: name, address, document number and exact birth date.
The European age-verification approach has a different goal: prove that a person is above a threshold without revealing their full identity. The European Commission stated that its solution became technically ready in April 2026 and could be customised by Member States and market participants.
Prove a threshold, not an identity
In a privacy-preserving model, the service receives a limited statement such as “the user is over 18.” It does not need the date of birth or a copy of the document used during enrolment.
Separating issuance from presentation is essential. An authority or provider verifies age initially. The app can later produce reusable proof without sending the underlying document to every website.
The QR code’s role
On a computer, the site can display a QR code. The user scans it with an age-verification app. The app receives the request, shows what will be shared and sends the proof after consent.
The code connects the browser session to the phone app. It should not publicly expose a birth date or identity-document number. Capturing it should not create a reusable, permanent proof.
Why the topic is accelerating in Europe
Protecting minors is a major element of Digital Services Act implementation. The Commission is working with Member States, platforms and users to test a coherent, privacy-preserving solution. Zero-knowledge proof technology has also been part of the announced direction.
The use case reaches beyond adult content. Age proof can apply to alcohol sales, venue entry, gaming and other restricted services. Every extension should remain proportionate and properly governed.
What sites should avoid
- requesting full identity when a threshold is enough;
- retaining document copies without necessity;
- placing age or birth date in plain text inside a QR code;
- using a static QR code as reusable proof;
- tracking the same person across services;
- presenting a homemade solution as officially compliant without assessment.
Can you use a QR code made with VixQR?
VixQR can create a link to information or the entry point of a service. It cannot turn a birth date into secure proof of age. Real verification requires an issuer, wallet or app, cryptographic signatures and a protocol that minimises disclosure.
Good innovation is not faster collection. It is asking for less information while obtaining stronger proof.