ISO 27566 Clause 8.3 - Age Inference Methods
Implement age inference from contextual/behavioural data with documented methodology, privacy assessments, data-type restrictions, transparency, and defined confidence thresholds
Where this comes from
Provision: Clause 8.3 - Age Inference Methods
Instrument: ISO/IEC 27566-1:2025
Citation: ISO/IEC 27566-1:2025, Age assurance systems -- Framework, Clause 8.3: Age Inference Methods
Text version: ISO/IEC 27566-1:2025
Who it applies to
It applies when all of these are true:
- Service collects behavioral data
…unless:
- Age verification method is not Third-party age estimation or Multiple methods
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- The inference methodology and its accuracy are documented
- A privacy impact assessment covers the specific data sources used for inference
- The data types usable for inference are restricted; sensitive sources are excluded
- A confidence threshold governs when an inferred age is acted upon; low-confidence routes to stronger assurance
- System handles null/empty input gracefully (no 500 errors)
Questions people ask
- Does ISO 27566 Clause 8.3 - Age Inference Methods apply to my service?
- It applies when Service collects behavioral data. It does not apply where Age verification method is not Third-party age estimation or Multiple methods.
- From when does this apply?
- ISO 27566 Clause 8.3 - Age Inference Methods applies from 15 January 2025. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.