New Zealand Privacy Commissioner flags risks in under-16 social-media ban
Key Takeaways
- 01New Zealand’s Privacy Commissioner has raised privacy and cybersecurity concerns about mandatory age assurance for an under-16 social-media ban.
- 02The Commissioner called for consultation on privacy protections before any such system is implemented.
- 03Age-assurance tools may require sensitive personal data and create risks of breaches, incorrect age determinations and reuse of data for unrelated purposes.
- 04Any future framework will need safeguards governing data collection, retention, access and reuse.
New Zealand’s Privacy Commissioner has warned that a proposed ban on social-media access for children under 16 could create significant privacy and security risks if it relies on mandatory age-assurance systems.
In a statement published on 25 August 2026, the Commissioner called for consultation on privacy protections before such measures are implemented. The concern is that platforms may need to collect or process sensitive information—such as identity documents, facial images or other age-verification data—to determine whether a user is under 16.
The Commissioner identified three principal risks: data breaches involving age-assurance information, inaccurate age-estimation results, and secondary use of the data for purposes beyond checking a user’s age. Secondary use means using data collected for age verification for advertising, profiling, identity-related services or other unrelated purposes.
The statement puts privacy safeguards at the centre of the policy debate over an under-16 social-media ban. Any future regime would need to address what data platforms can collect, how long they may retain it, who can access it, and whether it can be reused. The Commissioner’s call for consultation indicates that the privacy requirements and implementation model remain to be determined.