Privacy by design

Prove “this is a verified minor in this age band” without turning the proof into a new child-tracking database.

UuLApp should separate the school’s authoritative student record from the minimal attributes a participating digital service needs for a child-safety decision.

Recommended data model

The school knows the student. The service should know only what it needs.

School-held identity

Legal name, enrolment record and other school data remain under the school’s normal governance and should not be distributed merely because UuLApp is used.

UuLApp credential

A pseudonymous identifier plus only the verified attributes needed for the protocol, such as minor status, age/education band and validity state.

Participating service

Receives the minimum result required to enforce age-appropriate access and interaction. It should not repurpose verification data for unrelated profiling or advertising.

Privacy principles

Design rules for a lawful implementation.

  • Purpose limitation: child-verification attributes are used for the defined safety/access purpose, not unrelated marketing.
  • Data minimisation: if an age band is sufficient, do not disclose exact birth date.
  • Pseudonymisation: services should not need the school’s full identity record to know the account is a verified minor.
  • Retention control: age-verification and audit data should be retained only as long as justified for their specific purpose and legal obligations.
  • Security: credential issuance, storage, transmission, authentication and revocation require appropriate technical and organisational safeguards.
  • Transparency: children and parents should receive clear, age-appropriate explanations of what is processed and why.
  • No behavioural profiling of minors as a protocol purpose: UuLApp verification data should not become an advertising profile.

Each participating organisation remains responsible for its own legal role, lawful basis, retention rules, security and any required impact assessment. UuLApp is designed around privacy-by-design principles, but adoption of the protocol is not by itself a legal-compliance certification.