Dutch and EU privacy-first compliance infrastructure

The Netherlands is our home market — and a credibility anchor for EU-wide age assurance. Meet KSA gambling rules and the EU Digital Services Act with leeftijdsverificatie that keeps identity data to a minimum.

Dutch and EU privacy-first compliance infrastructure. Licensing obligations (e.g. KSA, CRUKS) remain the operator's responsibility; Xident provides the age-assurance layer.
Book a 20-minute demo

The Netherlands pairs a strict licensed-gambling regime with EU-level platform duties. The Kansspelautoriteit (KSA) requires licensed operators to verify identity and age and to check the CRUKS self-exclusion register before play. Across all platforms, the EU Digital Services Act adds systemic-risk and minor-protection obligations.

As a Dutch-founded provider, Xident treats the Netherlands as both a home market and a proving ground for EU compliance. The same privacy-first infrastructure — on-device age estimation, document fallback, reusable credentials — serves Dutch operators and any platform that needs to demonstrate DSA-aligned age assurance across the EU.

The regulator

What the law requires in Netherlands

KSA & the Koa Act

Under the Koa Act, the Kansspelautoriteit licenses online gambling and requires operators to verify a player's identity and age and to consult the CRUKS self-exclusion register before allowing play.

The EU Digital Services Act

The DSA imposes minor-protection and systemic-risk duties on online platforms across the EU, pushing services toward age-appropriate experiences and effective age assurance for higher-risk features.

Why the Netherlands is the EU anchor

A clear national regulator (KSA) plus EU-wide DSA duties make the Netherlands an ideal base to demonstrate a compliant, privacy-first approach that travels across the single market.

How on-device works

Verification that leaves nothing to store, breach, or hand to a regulator

Most users are cleared by a model that runs in their own browser. The image never reaches our servers — only a pass/fail age signal does.

01

Age is estimated on the device

An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.

02

Nothing leaves the device

No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.

03

Document fallback only for borderline cases

Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.

The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.

How Xident maps to it

A privacy-first path to Netherlands compliance

Age at registration, KYC at deposit

For KSA-licensed operators, on-device age estimation clears legal-age players fast at registration, while document KYC and CRUKS checks run where the licence requires them — keeping the heavy flow targeted.

DSA-aligned, data-minimising age assurance

On-device estimation produces an age signal for every user without sending images to your servers, supporting DSA minor-protection duties without building a surveillance database.

Reusable credential across the EU

A reusable age credential lets a verified user clear instantly across services and borders, lowering cost and friction while keeping identity data minimal.

Frequently asked questions

Does Xident handle CRUKS / KSA requirements?
Xident provides the age-assurance layer — fast on-device age checks plus a document/KYC fallback. CRUKS register checks and KSA licence obligations remain the operator's responsibility; Xident integrates alongside them.
How does Xident support the EU DSA?
On-device age estimation gives platforms an age signal for every user with data minimisation built in, supporting DSA minor-protection and age-appropriate-experience duties without a biometric honeypot.
Why position the Netherlands as the EU anchor?
Xident is Dutch-founded, and the combination of a clear national regulator (KSA) and EU-wide DSA duties makes NL a strong base to demonstrate privacy-first compliance that applies across the EU.

Compliance without a biometric honeypot

Meet Netherlands's age-assurance requirements with on-device estimation, document fallback, and reusable credentials.

Book a 20-minute demo

This page is provided for general information only and does not constitute legal advice. Age-verification law changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations with qualified legal counsel.