FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

France’s Age Check Needed Proof of Adulthood—Not Another Identity Account

The age-verification page appeared before the site showed a single image. I was alone in a hotel room near Lyon Part-Dieu, using the desk Wi-Fi after a delayed train, and the account on my laptop was old enough to contain passwords I no longer remembered. I blamed a broken cookie, cleared the browser data and opened a private window. The same page returned, offering a phone-based check or a camera estimate.

I was 42.

The problem was not proving that I was an adult.

It was understanding who would learn what while I proved it.

That question felt more important on shared hotel Wi-Fi. The verification process was about to move between my laptop, phone, an adult site and a separate checking service. I wanted the connection protected without adding another company that needed my email address, password and billing identity.

My first instinct was simpler.

Open a VPN. Choose another country. Make the page disappear.

That solved the wrong problem.

The short answer

A service that requires an email address, password, payment history and recovery trail introduces another identity-bearing account into a sensitive session. A service that protects the connection without requiring those details collects less before the age check has even started.

The prompt was not a broken account

France no longer accepts a simple “I am over 18” button from covered adult services. They must use an effective age-verification system before allowing access to pornographic content. Arcom can issue formal notices and pursue penalties, blocking or removal from search results when services fail to comply. (Arcom)

The rules were already affecting real services. By February 2026, Arcom said the 17 sites named in a ministerial order had either introduced age checks or become unavailable in France. In June, the EU’s top court confirmed that France could enforce age-verification requirements against qualifying adult services based elsewhere in the European Union when the required cross-border process was followed. (Reuters)

That explained why the prompt survived my cleared cookies and private window.

It was not an account error.

It was the entrance.

The rule also did not prohibit lawful adult access. France’s Conseil d’État described it as an age-verification requirement, not a ban on making adult content available to adults. (Conseil Etat)

Once I understood that, changing countries looked less useful.

The real task was to complete the check while revealing as little identity as possible.

The site did not need to know my name

The verification page looked intrusive because its first options involved a phone and camera.

That practical friction has appeared in public discussion too: an adult reaches an age wall on a desktop, discovers that the check needs a camera and has to continue on a phone. (Reddit) The important detail was not the complaint itself.

France’s privacy model is supposed to prevent the adult site from receiving more information than it needs.

Covered services must offer at least one privacy-protective method based on double anonymity. An independent provider confirms that the person is over 18. The adult site receives the result, not the person’s identity. The verifier performs the check without being told which adult service will receive the proof. (Cnil)

The site needs one answer:

Is this person an adult?

It does not need my name, address or document number.

That separation made sense.

Before using it, I made the mistake of treating the rule as a location block.

The large VPN added distance and another login

The established VPN on my laptop had years of public history, a mature application and a long server list.

I selected a foreign location.

The site reloaded, but the account session now looked unfamiliar. A security check appeared, followed by a CAPTCHA. When I returned to the content page, the age-verification prompt was still there.

Changing the server had changed my apparent location.

It had not changed my age or removed the site’s obligation to verify it.

The VPN had also signed me out after an update. To continue testing locations, I entered the email address connected to my subscription, typed the password and copied a code from my inbox.

The contradiction became difficult to ignore.

I was trying to keep a sensitive session separated from my ordinary identity, yet the first privacy tool I opened required an account tied to my email address, subscription and payment history.

Its country list was not helping me decide which verification method exposed less information.

It was simply giving me more places to appear from.

I closed the foreign session.

The smaller app protected the process instead of avoiding it

I opened the smaller app installed on my phone.

Basic use did not begin with an email field. It did not ask me to create a password or recover an account before protecting the connection.

I selected the public-Wi-Fi preset.

The VPN connected.

Then I reopened the adult site from its normal French address and chose the privacy-preserving verification option.

The page displayed a code for continuing on my phone.

With the established service, that would have meant another app login, another password and possibly another email approval. The smaller service instead showed a verification code for adding the second device.

I entered it on the laptop.

Both devices were protected without creating another conventional identity account.

I followed the age-check link on the phone. The independent verifier completed the process and returned a simple result to the browser:

Over 18.

The adult site opened.

It did not receive my name.

It did not receive the image used during the check.

It received the answer required to admit an adult user.

I could not observe the site’s internal filtering rules or inspect the verifier’s private systems. I could compare what each service asked from me: the established VPN required an identity-bearing account before it would connect, while the smaller app protected both devices without adding another email address or password to the session.

That was the comparison that mattered.


A VPN did not need to replace the age check

The smaller app had not made the French rule disappear.

It had not converted a failed check into a successful one or changed who was legally allowed to enter.

It protected the hotel connection while I completed the process intended for an adult user.

The division of responsibility became simple.

The verifier established adulthood.

The adult site received the result.

The VPN protected the route without inserting another ordinary login into the exchange.

Once the page opened, I checked the verifier’s privacy information and deletion terms. The hotel Wi-Fi weakened briefly as someone down the corridor began a video call, but the session continued without sending me through the verification process again.

I stopped watching the country label.

The connection was already doing the useful work.

Minimal disclosure started before the verification page

Most discussion of France’s rules quickly turns into a question about whether people will use VPNs to appear outside the country.

That skips the more immediate concern for an adult willing to comply.

Who receives the identification data?

Does the adult site see it?

Does the verification company learn which site is being visited?

Does the VPN require another named account before the process can even begin?

France’s double-anonymity model addresses the first two questions by separating the proof from the destination. The site should learn that the person is over 18 without learning who the person is. The verifier should complete the check without being told where the proof will be used.

The VPN should preserve that logic rather than weaken it.

A service that requires an email address, password, payment history and recovery trail introduces another identity-bearing account into a sensitive session. A service that protects the connection without requiring those details collects less before the age check has even started.

The principle was straightforward:

Prove adulthood to the service responsible for verifying it.

Reveal as little as possible everywhere else.

The second device stopped being a second identity

The phone-based check had completed the main task, but the verification-code connection solved a smaller problem I had not considered beforehand.

Sensitive web processes increasingly move between devices. A desktop displays a QR code. A phone supplies a camera or wallet. The result returns to the original browser.

With a conventional account-based VPN, every device can introduce another sign-in, another stored credential and another recovery path.

Here, the laptop joined through a code.

No subscription password crossed the hotel room.

No additional email address entered the process.

That mattered because the age-verification system had already introduced enough parties. The smaller app did not become one more identity checkpoint.

It stayed in the background.

The smaller map fit the actual privacy problem

The service has fewer locations, fewer independent ratings and a shorter public history than the established provider I tried first. That is its clearest limitation.

In another situation, the larger provider’s country coverage might be useful.

It was not useful in the Lyon hotel.

The foreign server turned a privacy question into a location exercise. It added an unfamiliar-login warning, a CAPTCHA and another account authentication, but the age prompt remained.

The smaller app took the opposite approach.

It protected the hotel connection without demanding another conventional account. It connected the second device through a code. Then it stayed out of the way while the independent verifier sent the site proof of adulthood.

France’s rules meant the site needed to know that I was over 18.

They did not mean the VPN needed to know who I was too.

Questions this experience may leave you with

What was actually causing the problem?

A service that requires an email address, password, payment history and recovery trail introduces another identity-bearing account into a sensitive session. A service that protects the connection without requiring those details collects less before the age check has even started.

Why did the obvious fixes fail?

I could not observe the site’s internal filtering rules or inspect the verifier’s private systems. I could compare what each service asked from me: the established VPN required an identity-bearing account before it would connect, while the smaller app protected both devices without adding another email address or password to the session.

What should you check first?

France’s double-anonymity model addresses the first two questions by separating the proof from the destination. The site should learn that the person is over 18 without learning who the person is. The verifier should complete the check without being told where the proof will be used.

What finally changed the result?

The phone-based check had completed the main task, but the verification-code connection solved a smaller problem I had not considered beforehand.

What is worth remembering?

It protected the hotel connection without demanding another conventional account. It connected the second device through a code. Then it stayed out of the way while the independent verifier sent the site proof of adulthood.