Last updated: August 2026 • Not legal advice
Two taps. A bright green check. “You are 18.” It looks easy. But behind that small screen live laws, proofs, and risk. The right wallet can share only what you need. The wrong one can leak your life. Let’s make sense of the tools, the rules, and what really works.
“Digital identity wallet” is a safe store on your phone. It can hold items like an ID card, a driver license, or a proof that you are over a set age. You can show a “yes/no” signal, not your full birth date. This is called selective disclosure.
There are a few models. Some are state-run (national eID, EUDI Wallet). Some tie to a driver’s license (mDL). Some are bank-led (BankID). Some are telco-led (SIM-based ID). Some are “self-sovereign” and use W3C Verifiable Credentials model (DID/VC). Big apps can also hold your KYC data in a “custodial” way and give a claim when you need it.
Assurance levels still matter. A selfie match alone is weak. A live chip read, a signed claim from a strong issuer, or device-bound keys give more trust. For risk and fraud, teams still lean on the NIST Digital Identity Guidelines to judge strength.
Global reach is not even. Rules, trust lists, and tech stacks vary by market. The landscape is wide; for a big picture view, the World Bank ID4D work shows how digital ID grows across regions.
Not all wallets do age checks the same way. Some share a date of birth. Some share “over 18” only. Some let you prove a range (over 18, under 21) with math proofs. Device-bound IDs cut copy risk. To compare, we point to core standards like the ISO standard for mDL (ISO/IEC 18013-5), W3C VC, and OpenID flows. The table below maps signals, privacy, trust, fit with law, and fit for gambling use.
| Govt eID / EUDI Wallet | W3C VC + OIDC/OID4VC | Over-X attribute; DOB on request | Strong; selective disclosure | Yes; issuer can revoke/update | Govt issuer; EU trust lists | High in EU; growing cross-border | Med; needs trust framework | Low once set up | Low per check; set-up costs | Strong in EU markets | Policy shifts; rollout pace |
| ISO mDL (phone license) | ISO/IEC 18013-5/-7 + reader app | Over-X or DOB; on-device | Strong; device-bound | Yes; license lifecycle | State DMV or authority | US states; AU; some EU pilots | Med; reader SDKs needed | Low with NFC/QR | Medium; cert + SDK | Strong where mDL wide | Reader support uneven |
| Self-sovereign (DID/VC) | W3C VC + OID4VC | Over-X; ZK range proof | Very strong; minimal data | Yes; status lists | Issuer-signed; verifier checks | Varies by market | Med; standards-based | Low with deep-link | Low per check | Strong if issuers trusted | Issuer quality varies |
| Bank-led (BankID) | OIDC / signed claims | Over-X; DOB on request | Good; bank KYC base | Yes; bank updates | Banks as trusted issuers | High where BankID used | Low; mature SDKs | Low; users know flow | Per check fees | Strong in local markets | Cross-border limits |
| Telco-led ID | SIM auth + OIDC | Over-X (derived) | OK; depends on telco | Yes | Telco as issuer | Varies; strong in some EU | Low–Med | Low | Per check fees | Medium | Port-out, SIM-swap risk |
| Custodial KYC (platform) | Proprietary + OIDC | DOB or over-X claim | Weaker; more PII stored | Yes; platform rules | Platform is issuer | Depends on audits | Low; quick to ship | Low–Med | Per check + storage | Medium; fast start | PII breach surface |
| Biometric-only estimate | Model + liveness | Age estimate (prob.) | Can be private if on-device | N/A; model updates | Verifier trusts vendor | Mixed; some bans | Low; SDK drop-in | Low | Per check fees | Low alone; add doc check | Bias; legal pushback |
Key takeaways: (1) Over-X claims with selective disclosure cut data risk. (2) Device-bound IDs raise trust. (3) Local trust frameworks decide what is “good enough.” (4) For gambling, speed and legal fit matter as much as tech strength.
Some say “you must share more to be safe.” That is not true. You can prove age with less data. A wallet can share “over 18” only, signed by a trusted issuer. The site gets a yes/no and a time stamp. No name. No address. No photo.
Open standards help. With OpenID for Verifiable Credential Issuance, a verifier can ask for a narrow claim. The wallet can show what is asked and nothing more. Zero-knowledge range proofs can show “over 18” without the date itself. This cuts breach impact and lowers legal risk. It also builds user trust, which lifts pass rates.
Case 1: A 17-year-old opens a site. The site asks for “over 18.” The phone shows a wallet prompt. The teen tries an mDL. The mDL says “under 18,” and the flow stops. No upload. No extra data left behind.
Case 2: An 18-year-old does the same. The wallet sends “over 18.” The site checks the signature. It binds the session to the device key. The pass shows in under three seconds. No need to type name or address. If the user’s wallet is a bank-led one, the bank app gives a quick confirm, then returns to the site. With a VC wallet, a deep link opens, shows what will be shared, and returns a signed claim.
Edge case: The user has no wallet. The site offers a one-time doc scan with live check. The flow is longer. The pass is fine, but more data is held. If the user comes back later with a wallet, the site can switch to over-X claims and then purge extra data.
EU: The EU EUDI Wallet aims for trusted, cross-border claims. It backs selective disclosure and signed attributes. Age checks can be only what is needed. Local trust lists and conformity checks apply.
UK: The ICO Children’s Code pushes services to choose age assurance that fits risk and to use data minimization. The Online Safety framework adds duties for adult content. Logs and vendor due care matter.
US states: Laws now ask sites to check age for porn, some social media, and some 18+ content. They vary by state. The NCSL overview tracks the patchwork. Biometric-only checks can face bans or strict limits in some places. Vendor contracts must note data use and deletes.
France: The CNIL wants age checks that do not expose full identity. It favors trusted third parties and over-X proofs, with clear limits on logs and a right to erase.
Germany: The KJM sets strict youth protection rules. Remote age checks must meet defined levels. Some flows need video or in-person checks, but newer approved methods allow strong remote proof with low data share.
Australia: The eSafety Commissioner supports risk-based age assurance. It notes harm, privacy, and inclusion. Trials with over-X proofs are under way. High-risk content may need higher assurance.
Need a wider legal lens across markets and privacy law? See the IAPP resources on digital identity for ongoing updates.
Keep it simple for users. Use deep links and app links that open the wallet, show the ask, and return a signed claim fast. Use standard protocols, so you can swap vendors. Favor device-bound keys for replay safety.
Core stack tips:
Privacy risk is real. Groups like the Electronic Frontier Foundation warn against over-collection. Over-X claims, short logs, and on-device checks help meet that bar while still blocking minors.
Gambling sites must be fast and right. Users will not wait. But laws are strict. A good flow asks for “over 18” first. If the wallet can prove it, the site lets the user see more. Full KYC can happen later, when the user deposits or cashes out. For a real look at how flows feel in the wild for French players, independent guides like nos avis sur les casinos mobiles pour les joueurs français track sign-up speed, pass rates, and drop-off. This kind of data helps choose methods that work for both users and rules.
What to watch:
The best age check is boring. It is fast, clear, and private. It gives a clean “yes” when you are of age. It gives a clear “no” when you are not. And it shares almost nothing else.
This guide draws on open standards, regulator notes, and trust frameworks. See links to W3C VC, OID4VC, ISO mDL, NIST, EU EUDI, ICO, NCSL, CNIL, KJM, eSafety, EFF, FIDO, World Bank ID4D, and IAPP above. We focus on low-data designs that still meet law. We review flows on real devices and in live markets.
Compliance note: Laws change. Check local rules and get legal advice before you ship. Keep this page updated when standards or rules move.