Earlier quoted context omitted.
Age verification is not (should not be) the same as ID verification / storage / etc; the US needs laws similar to EU ones where companies can only get the minimum required PII. In the case of age verification that's zero, or a boolean value "yes this person is over 18" that they get from a trusted party like a bank.
> or a boolean value "yes this person is over 18" It would be detrimental to the cause, which is to collect everyone's ID.
Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.
Better to not hold the data in the first place.