Age verification built to Germany's JMStV requirements

Germany runs the strictest youth-protection regime in Europe. Meet JMStV obligations with on-device age estimation and a documented fallback — without turning Jugendschutz into a biometric database.

Built to JMStV requirements; KJM validation in progress. Xident does not claim to be a KJM-positively-evaluated system at this time.
Book a 20-minute demo

Germany's Jugendmedienschutz-Staatsvertrag (JMStV) requires providers of age-restricted online content to use a closed age-verification system (Altersverifikationssystem, AVS) — historically a two-step model of identity verification plus per-access authentication. The Kommission für Jugendmedienschutz (KJM) assesses concepts and publishes positively-evaluated systems.

For operators, the bar is high and the privacy stakes are higher: collecting and storing identity data to satisfy Jugendschutz online creates exactly the kind of honeypot German data-protection authorities scrutinise. Xident's on-device approach is designed to meet the substance of JMStV — strong, repeatable age assurance — while keeping biometric data off your servers.

The regulator

What the law requires in Germany

What JMStV requires

Providers of content harmful to minors must ensure access is limited to adults through a closed system — typically initial identity/age verification followed by authentication on each access. Self-declaration ("I am 18") is not sufficient.

The role of the KJM

The KJM evaluates age-verification and youth-protection concepts and lists systems it has positively assessed. A positive evaluation is the recognised path to demonstrating an AVS meets the standard; operators remain responsible for their overall concept.

Data-protection overlay

Any AVS in Germany must also satisfy GDPR and German data-protection law. Storing identity documents or biometric templates to prove age increases breach exposure and regulatory risk — the opposite of data minimisation.

How on-device works

Verification that leaves nothing to store, breach, or hand to a regulator

Most users are cleared by a model that runs in their own browser. The image never reaches our servers — only a pass/fail age signal does.

01

Age is estimated on the device

An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.

02

Nothing leaves the device

No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.

03

Document fallback only for borderline cases

Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.

The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.

How Xident maps to it

A privacy-first path to Germany compliance

Strong age assurance without an identity store

On-device age estimation clears most users in the browser; only a pass/fail signal reaches the server. Where a stricter standard or a borderline case demands it, a document check runs and is deleted immediately — leaving an auditable age result, not a stored ID.

Re-authentication for returning users

A reusable Xident credential lets returning users re-authenticate per access with a fast token Check — aligning with the JMStV expectation of authentication on each access, without re-collecting data.

Audit trail for your JMStV concept

Every verification records timestamp, geolocation, device and result, giving you a documented chain of evidence to support the age-verification concept you submit and operate.

Frequently asked questions

Is Xident KJM-certified?
No. Xident is built to JMStV requirements, and KJM validation is in progress. We do not claim to be a KJM-positively-evaluated system at this time; operators remain responsible for their own JMStV concept and any KJM submission.
Does on-device age estimation satisfy JMStV?
JMStV requires a closed system with strong age assurance and per-access authentication. Xident provides the age-assurance and re-authentication building blocks with data minimisation; whether a specific deployment meets JMStV is assessed as part of the operator's concept (and, where sought, KJM evaluation).
Where is data processed?
On the fast path, age estimation runs in the user's browser and no image is transmitted. Document fallbacks are processed and deleted; only the age-bracket result is retained for your audit trail.

Compliance without a biometric honeypot

Meet Germany's age-assurance requirements with on-device estimation, document fallback, and reusable credentials.

Book a 20-minute demo

This page is provided for general information only and does not constitute legal advice. Age-verification law changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations with qualified legal counsel.