AgeAssuranceReady FR

HEAA and privacy-by-design vendor checklist

Questions to ask before connecting an age estimation or verification solution.

Effectiveness

Request accuracy by age band, false positives/negatives and testing protocols.

  • Independent reports
  • Geographic coverage
  • Drift monitoring

Privacy-by-design

Minimize data, separate verification from the user account, document retention and deletion.

  • DPIA available
  • Configurable retention
  • No marketing reuse

Accessibility

Plan alternatives, appeals, inclusive journeys and no unjustified discrimination.

  • Alternative channels
  • User support
  • Drop-off measurement

Auditability

Check logs, evidence, SLAs, incidents and regulator response capability.

  • Evidence export
  • Security SLA
  • Incident process

Reserved vendor affiliate link, enabled by environment variable without hardcoded secrets.