Skip to main content

Share story

Policy

EU Research Service Warns VPNs Are a 'Loophole' in Age-Verification Laws

EU Research Service Warns VPNs Are a 'Loophole' in Age-Verification Laws Image: primary
The European Parliamentary Research Service has warned that virtual private networks are increasingly being used to bypass online age-verification systems, describing the trend as a loophole in legislation that needs closing. The warning comes as governments across Europe and elsewhere continue expanding online child-safety rules that require platforms to verify users' ages before granting access to adult or age-restricted content. VPNs encrypt internet traffic and hide a user's IP address by routing connections through remote servers. While widely used for legitimate purposes such as protecting communications and enabling secure remote work, regulators are increasingly concerned that the same technology allows minors to circumvent regional age checks. The EPRS notes that VPN usage surged after mandatory age-verification laws took effect in countries including the United Kingdom and several US states. In the UK, VPN apps reportedly dominated download charts after the law came into force. The document explicitly frames VPNs as a regulatory gap, stating that some policymakers and child-safety advocates believe VPN access itself should require age verification. England's Children's Commissioner has also called for VPN services to be restricted to adults only. Privacy advocates have objected to restricting VPN access, arguing that forcing users to verify their identity before accessing VPN services could significantly weaken anonymity protections and create new risks around surveillance and data collection. Last month, researchers found multiple security and privacy flaws in the European Commission's official age-verification app shortly after its release. The app, promoted as a privacy-preserving tool under the DSA framework, was discovered storing sensitive biometric images in unencrypted locations and exposing weaknesses that could allow users to bypass verification controls entirely. The EPRS paper acknowledges that age verification remains technically difficult and fragmented across the EU. Current systems based on self-declaration, age estimation, or identity verification are described as relatively easy for minors to bypass. The report highlights emerging approaches such as "double-blind" verification systems used in France, where websites receive only confirmation that a user meets age requirements without learning the user's identity, while the verification provider does not see which websites the user visits. Regulators are beginning to address VPN use directly in legislation. Utah recently became the first US state to enact a law explicitly targeting VPN use in online age verification. The state's SB 73 defines a user's location based on physical presence rather than apparent IP address, even if VPNs or proxy services are used to mask it. The EPRS suggests VPN providers may face increasing scrutiny as the EU revises cybersecurity and online safety legislation, noting that future updates to the EU Cybersecurity Act could introduce child-safety requirements aimed at preventing VPN misuse to bypass legal protections.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from CyberInsider and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Policy Infrastructure
Policy Infrastructure

EU proposes energy and water ratings for large data centers

The European Commission proposed rating individual data centers drawing more than 500 kW on their energy and water use beginning in 2027. The labels would also account for recovered heat, added clean generation and the ability to ...

AI Products
AI Products

Amazon blocks Meta's Muse and expands lawsuit against Perplexity

Amazon blocked Meta's Muse shopping agent from Amazon.com and asked Meta to remove the retailer from the service, saying the agent did not identify itself and appeared to capture and store customer credentials. Meta has said Muse ...

AI Policy
AI Policy

British Columbia sues OpenAI over alleged failure to warn of shooting

British Columbia has sued OpenAI in California, alleging the company could have used ChatGPT logs to warn police and prevent a mass shooting in the Canadian province earlier this year. The case raises a direct legal challenge over...

Policy AI
Policy AI

OpenAI proposes U.S.-led global standards for frontier AI research

OpenAI proposed that the United States lead an international effort to create technical standards for frontier AI, including systems that automate work on successive generations of AI. The company wants common methods for measurin...

Policy Products
Policy Products

Court orders Google to open its ad-tech systems to rivals

A federal court's remedies for Google's ad-tech monopoly bar the company from enforcing contracts that tie its AdX exchange to its publisher ad server and from favoring its own products in auctions. The provisions apply globally a...