Take a risk-based approach to recognising users' ages so the standards are applied effectively to children: either establish age with certainty appropriate to the risks of the processing, reduce the risks, add age assurance, or apply the standards to all users. Methods include self-declaration (for low risk or combined with others), AI age estimation (with upfront notice, minimal data and no reuse), third-party age verification (with due diligence, for example against PAS 1296), confirmation by an adult account holder, technical measures against false declarations, and hard identifiers only where risk justifies them; data collected for age assurance must not be reused for other purposes such as targeted advertising. The code uses age bands 0-5, 6-9, 10-12, 13-15 and 16-17, and parental authorisation is needed for consent-based processing of under-13s.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.