The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced this month. Behind the headlines sits a critical infrastructure question.
The Bill expressly rules out self-declared dates of birth as a reasonable step. Typing ‘1998’ was never meaningful age assurance.
This is therefore not simply a ban. It creates a legal requirement for population-scale age assurance on infrastructure the Bill does not describe, run by parties it does not name, under an accreditation regime it does not reference.
That regime already exists: the Digital Identity Services Trust Framework.
Leave the gap unfilled and the market is likely to fill it with document uploads and face scans; held offshore, contracted by platforms and collected from every adult New Zealander seeking an account, not only the children the Bill aims to protect.
Fill it properly and the alternative is far more privacy-enhancing: a credential held by the person, answering one question only (over 16 or under?) while disclosing nothing else.
There is no central store of identity documents. There is no need to overshare. And there should be no toll on proving who you are. The same trusted layer can support scam prevention, eligibility checks and stronger ways to establish whether online actors are human.
The protection envisaged in this Bill rests on a trust layer New Zealand can determine for itself.