Age verification built to Germany's JMStV requirements
Germany runs the strictest youth-protection regime in Europe. Meet JMStV obligations with on-device age estimation and a documented fallback — without turning Jugendschutz into a biometric database.
Germany's Jugendmedienschutz-Staatsvertrag (JMStV) requires providers of age-restricted online content to use a closed age-verification system (Altersverifikationssystem, AVS) — historically a two-step model of identity verification plus per-access authentication. The Kommission für Jugendmedienschutz (KJM) assesses concepts and publishes positively-evaluated systems.
For operators, the bar is high and the privacy stakes are higher: collecting and storing identity data to satisfy Jugendschutz online creates exactly the kind of honeypot German data-protection authorities scrutinise. Xident's on-device approach is designed to meet the substance of JMStV — strong, repeatable age assurance — while keeping biometric data off your servers.
The regulator
What the law requires in Germany
What JMStV requires
Providers of content harmful to minors must ensure access is limited to adults through a closed system — typically initial identity/age verification followed by authentication on each access. Self-declaration ("I am 18") is not sufficient.
The role of the KJM
The KJM evaluates age-verification and youth-protection concepts and lists systems it has positively assessed. A positive evaluation is the recognised path to demonstrating an AVS meets the standard; operators remain responsible for their overall concept.
Data-protection overlay
Any AVS in Germany must also satisfy GDPR and German data-protection law. Storing identity documents or biometric templates to prove age increases breach exposure and regulatory risk — the opposite of data minimisation.
How on-device works
Verification that leaves nothing to store, breach, or hand to a regulator
Most users are cleared by a model that runs in their own browser. The image never reaches our servers — only a pass/fail age signal does.
Age is estimated on the device
An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.
Nothing leaves the device
No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.
Document fallback only for borderline cases
Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.
The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.
How Xident maps to it
A privacy-first path to Germany compliance
Strong age assurance without an identity store
On-device age estimation clears most users in the browser; only a pass/fail signal reaches the server. Where a stricter standard or a borderline case demands it, a document check runs and is deleted immediately — leaving an auditable age result, not a stored ID.
Re-authentication for returning users
A reusable Xident credential lets returning users re-authenticate per access with a fast token Check — aligning with the JMStV expectation of authentication on each access, without re-collecting data.
Audit trail for your JMStV concept
Every verification records timestamp, geolocation, device and result, giving you a documented chain of evidence to support the age-verification concept you submit and operate.
Frequently asked questions
Is Xident KJM-certified?
Does on-device age estimation satisfy JMStV?
Where is data processed?
Related solutions
Compliance without a biometric honeypot
Meet Germany's age-assurance requirements with on-device estimation, document fallback, and reusable credentials.
Book a 20-minute demoThis page is provided for general information only and does not constitute legal advice. Age-verification law changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations with qualified legal counsel.