10 min read

Spain Designed the Most Privacy-Forward Age Check in Europe. The App Is Beta and the Law Is Stalled.

Spain's data protection regulator wrote the smartest rulebook for age verification in Europe: the AEPD decalogue proves someone is an authorized adult without ever revealing who they are, and the Cartera Digital Beta wallet issues single-use keys so a site learns 'over 18' and nothing else. The design is world-leading. The delivery isn't finished. The wallet is still literally named Beta, the flagship Organic Law for the Protection of Minors in Digital Environments is stalled in parliament, and neither reaches a tourist, an EU visitor, or a returning user on a new device. Here is what actually binds a platform operating in Spain today, and why wiring your age gate to a government beta is a plan with a coverage hole the size of everyone who isn't a resident with the app installed.

Editorial illustration on a deep slate-navy background: on the right, a verification gate showing a QR panel with a bright emerald check mark, glowing to signal it is live. On the left, a translucent dashed 'wallet' card emits a single small key token toward the gate, but the connecting line is broken with a visible gap, signalling a beta that is not fully wired in. A faint anonymity shield sits over the passing token so no identity travels with it. No faces, no real people, no flags, no brand marks, no readable text.

Spain quietly wrote the best rulebook for age verification in Europe, then didn’t finish shipping the product that runs on it. The idea is genuinely ahead of everyone else. The delivery is a testing app and a bill that hasn’t passed. If you operate a platform that reaches Spanish users, the gap between those two things is exactly where a compliance team gets caught: pointing at the elegant future system the government keeps announcing, while the obligation that already applies sits under an older law nobody quotes.

Here is the tension in one line. The Spanish Data Protection Agency’s decalogue shows how to prove a visitor is old enough without learning who they are. The tool built to deliver it, the Cartera Digital Beta, still carries the word Beta in its name. And the sweeping law everyone cites when they talk about Spain, the Organic Law for the Protection of Minors in Digital Environments, is not in force. It’s parked in parliament.

The idea Spain got right: verify the adult, never accredit the minor

Most age checks are built backwards. They collect an identity, read a date of birth off it, and then let the person through. The by-product is a record: this person, at this time, wanted access to this content. That record is the liability. It’s the thing that leaks in a breach and the thing that turns a safety measure into surveillance.

In December 2023 the AEPD published a different model. Its decalogue of principles inverts the usual logic. The system should verify that someone is an authorized adult, not accredit that someone is a minor. It should be impossible to identify, track, or locate a minor through the check. And the proof that unlocks restricted content should be anonymous to the site and to any third party in the chain. The regulator paired the principles with a technical note and working proofs of concept on Android, iPhone, and Windows, then took the design to the Global Privacy Assembly, where it won two awards. This wasn’t a policy wish. It was a buildable spec.

The reason this matters beyond Spain is that it settles an argument the rest of the market keeps having. You do not have to choose between protecting children and keeping adults anonymous. A well-designed check can do both, which is the same conclusion we reached in double anonymity or compliance theater and the architecture we described in age verification without surveillance. Spain’s regulator wrote it into official guidance first. Credit where it’s due.

The Cartera Digital Beta: elegant cryptography, unfinished product

The delivery vehicle is a government wallet app. It has been in testing since September 2024, and the mechanics are clean. You verify your identity document once, inside the app. The wallet then issues an adult-age credential and generates roughly thirty single-use key pairs a month. When you hit a restricted site, you scan a QR code, spend one key, and the site learns one fact: this visitor is over 18. Not your name, not your date of birth, not which document you hold. The single-use design means two sites can’t compare notes and reconstruct where you’ve been, which is the whole point of the anonymity principle in the decalogue.

Architecturally this is close to what a reusable, cryptographically held credential should look like, and it’s the same direction the EU Digital Identity wallet is heading. So the criticism that follows is not about the design. It’s about the state of the thing.

It’s a beta. The name says so. A government-issued age credential is only as useful as the number of adults who actually hold it and the number of sites wired to accept it, and a testing app that issues thirty keys a month to early adopters is not yet either of those. Spain has built a proof that the privacy-preserving model works. It has not yet built the infrastructure that makes it the default way a Spanish adult proves their age. Those are different milestones, and the distance between them is measured in years, not weeks.

The law everyone quotes hasn’t passed

Read almost any summary of “age verification in Spain” and you’ll see the Organic Law for the Protection of Minors in Digital Environments described as if it governs today. It doesn’t. The government approved the draft in the Council of Ministers in March 2025 and registered it in the Congreso, and despite an urgency procedure the bill has stalled in parliamentary scrutiny. A draft under debate is not a rule you’re breaking.

What it would do, if enacted, is substantial. It raises the digital age of consent from 14 to 16, so under-16s would need verified parental permission to open an account. It forces manufacturers of internet-connected devices, phones, tablets, computers, and smart TVs, to ship free parental controls switched on by default out of the box. Prime Minister Pedro Sánchez then went further at the World Governments Summit in February 2026, announcing a plan to bar under-16s from social media outright. All of it is real intent. None of it is an operative obligation yet.

The trap is treating the announcement as the deadline. Teams read “Spain is raising the age to 16 and mandating verification” and either panic-build against a spec that keeps changing in committee, or, more often, decide they can wait until the law lands before doing anything at all. Both readings miss the same fact. The thing that binds you in Spain is older, quieter, and already in force.

So what actually binds a platform in Spain today

Two instruments are operative right now. The first is the General Law on Audiovisual Communication, Law 13/2022, which requires audiovisual platforms to keep the most harmful content, pornography and gratuitous violence, behind effective age controls. The second is the AEPD’s own position, expressed through the decalogue and its guidance: a checkbox is not a control. Self-declaration does not satisfy a regulator that has published a working design for real verification and now expects the market to meet it.

That last point is not a Spanish quirk. It’s the same conclusion the UK’s ICO reached when it fined Reddit’s approach, which we covered in self-declaration is not enough. A date-of-birth field that any 12-year-old clears by typing 1990 is not age assurance in Spain, in the UK, or anywhere a regulator has looked closely. If your Spanish-facing service still gates restricted content behind “I confirm I am over 18,” you’re not waiting for the Organic Law. You’re already short of Law 13/2022 and the AEPD’s stated bar.

The coverage hole a national wallet cannot close

Even after the Cartera Digital Beta graduates from beta, it solves one signal for one population: Spanish residents with a national ID and the app installed. That leaves a large set of real users unaddressed. The French tourist. The EU citizen visiting for a conference. The new arrival who hasn’t been issued a Spanish document. The adult who simply hasn’t downloaded a government app to watch legal content. The returning user on a borrowed laptop the wallet has never seen. A national credential is a single point of failure with a coverage gap shaped like everyone outside the issuing country’s resident population.

The pan-European answer, the EU age-verification mini-app built on the same technical framework as the EUDI wallet, is in pilot across several member states including Spain, with full rollout targeted for the end of 2026. It’s the right long-term direction and it will genuinely help. But it’s also a pilot with a year-end target, and even at full maturity a relying party still has to accept an attestation, verify a signature, and handle every user the wallet doesn’t cover. This is the same structural problem Ireland is betting its way around, which we walked through in Ireland is Big Tech’s home regulator: a government promises a wallet, and platforms quietly assume it relieves them of building anything themselves. It doesn’t.

There’s a commercial edge to this too. Getting Spain wrong is not only a fine. It’s the choice between serving Spanish users at all and geoblocking your way out of the market the way several adult platforms did in France and the UK once real enforcement arrived. Spain’s enforcement posture is still warming up, but the direction of travel across Europe is one way only, toward more verification and stricter regulators, not less.

Where Spain sits, and where it’s going

It’s tempting to file Spain as “softer than France.” On paper its standalone-porn rules are less prescriptive than France’s double-blind referential, which we detailed in how Xident meets the France ARCOM standard. But that reading confuses design maturity with enforcement intensity. Spain’s regulator has arguably the most sophisticated privacy-preserving verification model in Europe. What it lacks is a shipped product and a passed law, and both of those are in motion. The AEPD isn’t going to publish an award-winning spec for anonymous age proof and then accept a checkbox indefinitely. The gap you can exploit today by pointing at “the wallet” and “the coming law” is a closing window, not a permanent exemption.

What Xident does here, and what it does not

We built Xident for exactly this shape: a country with the right idea, an unfinished tool, a bill in limbo, and an older law that binds you now. The answer is not to wire your compliance to a government beta and hope it ships on time. It’s to run a layer that meets the operative standard today, honors the AEPD’s anonymity principles rather than working against them, and can consume the Cartera Digital or the EU wallet as an extra signal the day either is real.

Xident runs two operations and keeps them deliberately separate. A Check is the cheap, fast path: a browser-based age signal, a liveness pass, a returning-user lookup. It’s what most of Law 13/2022’s general obligation actually needs, a defensible age decision that beats self-declaration without demanding a document from every visitor. A Verification is the heavy path, a document read and a face match, roughly ten times the cost of a Check, reserved for the narrow cases that genuinely need to establish identity rather than an age band. Each returns a structured decision with an audit trail, so when a regulator asks you to show the gate was working during a given window, you can, without having built a surveillance log to prove it.

That last part is what matters in a country whose regulator wrote the anonymity rulebook. A vendor that satisfies Law 13/2022 by collecting and retaining a document scan on every user has met the letter of “effective” while manufacturing precisely the risk the AEPD decalogue exists to prevent. Xident’s posture is the opposite: collect only what the check requires, discard the source material once the decision resolves, and bind returning users to a cryptographic credential so re-proving is a lookup, not a fresh upload. If you’re still deciding whether to build this in-house or buy it, the build-versus-buy math is worth running, and the zero-knowledge approach to age proof is the same principle Spain’s regulator endorsed first.

Spain got the theory right before anyone else. The obligation is real now, the elegant tool is still a beta, and the law behind it is stalled. Build for the standard that’s in force, keep as little data as the check allows, and stay ready to accept the wallet the day it stops being a pilot. The clock in Spain isn’t the app or the bill. It’s Law 13/2022 and a regulator that already told you a checkbox won’t do.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo