{"id":548104,"date":"2026-04-24T10:36:10","date_gmt":"2026-04-24T10:36:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/548104\/"},"modified":"2026-04-24T10:36:10","modified_gmt":"2026-04-24T10:36:10","slug":"age-assurance-in-2026-what-do-digital-businesses-operating-in-the-uk-and-eu-need-to-know-privacy-protection","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/548104\/","title":{"rendered":"Age Assurance In 2026: What Do Digital Businesses Operating In The UK And EU Need To Know? &#8211; Privacy Protection"},"content":{"rendered":"<p>&#13;<br \/>\n            To print this article, all you need is to be registered or login on Mondaq.com.&#13;\n    <\/p>\n<p>        Article Insights<\/p>\n<p>Lewis Silkin are most popular: <\/p>\n<p>                    &#13;<br \/>\n                            within Cannabis &amp; Hemp topic(s)&#13;<br \/>\n                            in United Kingdom&#13;<\/p>\n<p>The regulatory landscape for age assurance is changing more rapidly than ever. Globally, legislators and regulators are intensifying efforts to protect children online.<\/p>\n<p>At the very heart of the debate is making sure that age assurance is fit for purpose: it should protect children from harmful content while preserving free expression, privacy and anonymity for users wishing to access lawful content. Age assurance is effectively how services decide if a user is a child and if they should apply enhanced protections.<\/p>\n<p>Regulators, governments and industry alike have acknowledged age assurance technology is still developing but it\u2019s clear that it\u2019s no longer acceptable for global businesses operating digital products or services that may be accessed by children to simply ask users to declare their own age.<\/p>\n<p>We look at the key legal and regulatory developments shaping age assurance across the UK and EU and suggest practical steps for businesses to meet their current and forthcoming obligations.<\/p>\n<p>UK developments: the regulatory bar is rising<\/p>\n<p>The UK\u2019s regulatory framework centres on the\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/childrens-information\/childrens-code-guidance-and-resources\/introduction-to-the-childrens-code\/\" target=\"_blank\" rel=\"noopener nofollow\">ICO\u2019s Age Appropriate Design Code<\/a>\u00a0(Children\u2019s Code) and the\u00a0<a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2023\/50\" target=\"_blank\" rel=\"noopener nofollow\">Online Safety Act 2023<\/a>\u00a0(OSA)\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2023\/11\/08\/the-online-safety-bill\" target=\"_blank\" rel=\"noopener nofollow\">enforced<\/a>\u00a0by Ofcom. The\u00a0<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/contents\" target=\"_blank\" rel=\"noopener nofollow\">UK GDPR<\/a>\u00a0and the\u00a0<a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2025\/18\/contents\" target=\"_blank\" rel=\"noopener nofollow\">Data (Use and Access) Act 2025<\/a>\u00a0further strengthen protections for children online.<\/p>\n<p>Ofcom and the Online Safety Act 2023<\/p>\n<p>The OSA requires service providers to implement age assurance to ensure that children are not normally able to encounter harmful content. The age assurance deployed must be &#8220;highly effective&#8221; at correctly determining whether a user is a child \u2013 a standard with significant implications for the technologies businesses choose to deploy (see our article\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/07\/24\/online-age-checks-and-childrens-safety-measures-must-be-in-place-from-25-july-102kv96\" target=\"_blank\" rel=\"noopener nofollow\">here<\/a>).<\/p>\n<p>In 2025, Ofcom required services in scope of the OSA to complete children\u2019s access assessments, children\u2019s risk assessments and to have measures in place to ensure that children could not access pornography and harmful material.<\/p>\n<p>Ofcom&#8217;s enforcement position has hardened considerably. It has extended its\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/07\/24\/online-age-checks-and-childrens-safety-measures-must-be-in-place-from-25-july-102kv96\" target=\"_blank\" rel=\"noopener nofollow\">age assurance enforcement programme<\/a>\u00a0to all platforms allowing users to share pornographic material and has launched a dedicated monitoring and impact programme for the largest platforms. Ofcom has also issued its first OSA financial penalty \u2013 a\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/12\/05\/ofcom-fines-adult-website-provider-1-million-for-not-having-robust-age-checks-102lwzu\" target=\"_blank\" rel=\"noopener nofollow\">\u00a31 million fine<\/a>\u00a0for an adult website provider for failing to have robust age checks in place.<\/p>\n<p>Perhaps most significantly, on 12 March 2026,\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/03\/12\/tech-companies-operating-in-the-uk-told-to-make-sure-their-age-assurance-works-102mmpw\" target=\"_blank\" rel=\"noopener nofollow\">Ofcom<\/a>\u00a0wrote to major technology platforms requiring them to enforce their minimum age policies using highly effective age assurance, giving the platforms until 30 April 2026 to report on the specific actions they intend to take.<\/p>\n<p>Businesses should regard this not as a routine piece of regulatory correspondence but as a clear precursor to enforcement action against platforms that fail to act.<\/p>\n<p>On 26 March 2026, Ofcom and the ICO issued a joint statement on the interaction between online safety and data protection as they relate to age assurance\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/insights\/2026\/04\/17\/age-assurance-in-2026-what-do-digital-businesses-operating-in-the-uk-and-eu-need-to-know#joint\" target=\"_blank\" rel=\"noopener nofollow\">(see below).<\/a><\/p>\n<p>The regulators are collaborating and clarifying their enforcement approach, reducing any potential wiggle room for businesses. If you are in scope, you need to act now. Beyond monetary penalties, the reputational damage from non-compliance may be significant.<\/p>\n<p>The ICO&#8217;s Children&#8217;s Code and finally fines!<\/p>\n<p>The ICO&#8217;s\u00a0<a href=\"https:\/\/www.iaaglobal.org\/public-policy\/video\/the-age-appropriate-design-code-a-k-a-the-children-s-code\" target=\"_blank\" rel=\"noopener nofollow\">Children&#8217;s Code<\/a>\u00a0translates data protection duties into practical design principles and privacy features. Its core requirement is appropriate age assurance.<\/p>\n<p>After the Children\u2019s Code took effect, the ICO initially adopted a collaborative approach, working with platforms to drive compliance. It has some\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/childrens-information\/childrens-code-guidance-and-resources\/protecting-childrens-privacy-online-our-childrens-code-strategy\/children-s-code-strategy-progress-update-march-2025\/\" target=\"_blank\" rel=\"noopener nofollow\">success stories<\/a>\u00a0where the ICO\u2019s intervention has driven meaningful behavioural change, as well as international collaboration, e.g. an agreed common international approach to\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/childrens-information\/childrens-code-guidance-and-resources\/joint-statement-on-a-common-international-approach-to-age-assurance\/\" target=\"_blank\" rel=\"noopener nofollow\">age assurance<\/a>\u00a0with ten national data protection regulators. The ICO also issued an updated Opinion on Age Assurance explaining how services and age assurance providers can use the technology in compliance with data protection law in a risk-based and proportionate way.<\/p>\n<p>On 1 December 2025, the ICO published its\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/childrens-information\/childrens-code-guidance-and-resources\/protecting-childrens-privacy-online-our-childrens-code-strategy\/children-s-code-strategy-progress-update-december-2025\" target=\"_blank\" rel=\"noopener nofollow\">Children&#8217;s Code Strategy progress update<\/a>, reporting on its review of age assurance practices across 17 platforms popular with children in the UK. It also announced a targeted monitoring programme focused on platforms relying primarily on self-declaration as their sole age assurance mechanism.<\/p>\n<p>2026 heralded a new phase, the time for talking is over and the ICO is ready to enforce. The UK Government launched a consultation on whether to\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/01\/27\/uk-government-announces-consultation-on-social-media-ban-102me9r\" target=\"_blank\" rel=\"noopener nofollow\">ban social media for under 16s<\/a>\u00a0and the Prime Minister met senior leaders from major social media companies to demand they &#8220;step up and take responsibility&#8221; for children\u2019s online safety, signalling if they fail to do so new powers will be used to address parents\u2019 concerns and strengthen protections for children.<\/p>\n<p>The ICO is also actively enforcing with a\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/02\/11\/the-ico-steps-up-on-protecting-children-online-102mi48\" target=\"_blank\" rel=\"noopener nofollow\">\u00a3247,590<\/a>\u00a0fine for MediaLab\/Imgur for failing to implement any age checks and Reddit fined\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/02\/26\/ico-continues-to-show-teeth-when-it-comes-to-protecting-childrens-data-will-th-102mkhg\" target=\"_blank\" rel=\"noopener nofollow\">\u00a314.47 million<\/a>\u00a0for failing to implement age assurance measures and processing children&#8217;s personal information unlawfully. The Reddit decision is particularly significant as despite maintaining a policy prohibiting users under 13 from using the platform, Reddit failed to implement any age verification measures until July 2025 and even then, relied only on self-declaration.<\/p>\n<p>On 12 March 2026, the ICO issued an\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/03\/12\/tech-companies-operating-in-the-uk-told-to-make-sure-their-age-assurance-works-102mmpw\" target=\"_blank\" rel=\"noopener nofollow\">open letter<\/a>\u00a0to social media and video-sharing platforms, calling on them to strengthen age assurance measures and move beyond self-declaration. On 25 March the ICO and Ofcom published their joint statement on age assurance\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/insights\/2026\/04\/17\/age-assurance-in-2026-what-do-digital-businesses-operating-in-the-uk-and-eu-need-to-know#joint\" target=\"_blank\" rel=\"noopener nofollow\">(see below)<\/a>\u00a0and on 7 April the ICO launched the\u00a0<a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2026\/04\/one-click-too-many-75-of-parents-fear-their-kids-arent-making-safe-choices-online\/\" target=\"_blank\" rel=\"noopener nofollow\">Switched on to privacy campaign<\/a>\u00a0to help parents discuss protecting children\u2019s personal information online, including age settings. It is clear the ICO is taking a holistic approach to protecting children online.<\/p>\n<p>Joint statement from Ofcom and the ICO<\/p>\n<p>The Ofcom\/ICO\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2026\/03\/26\/another-milestone-in-drive-for-increased-age-assurance-reached-as-ofcom-and-ico-i-102mo76\" target=\"_blank\" rel=\"noopener nofollow\">joint statement<\/a>\u00a0resolves much of the uncertainty around how service providers should reconcile their OSA duties with data protection obligations. It deserves careful analysis by any business deploying or considering age assurance technology.<\/p>\n<p>Unsurprisingly, the statement confirms, in unequivocal terms, that self-declaration alone is not considered effective for verifying age, nor restricting underage access. This co-ordinated position signals businesses cannot play one regulator off against the other, e.g. by arguing that data protection concerns justify a lighter-touch approach to age assurance.<\/p>\n<p>Both regulators set out a shared flexible, technology-neutral approach, confirming that services may choose the most appropriate age assurance method for their context, as long as it is effective and proportionate to the risks involved. They use four criteria to assess highly effective age assurance (HEAA): technical accuracy, reliability, robustness and fairness, alongside broader considerations of accessibility and interoperability.<\/p>\n<p>Helpfully, the statement says that open banking verification, photo ID matching, facial age estimation, mobile network operator age checks and digital identity wallets can meet the HEAA standard. By contrast, the regulators confirm that self-declaration, debit card verification and general contractual restrictions in terms of service are not acceptable.<\/p>\n<p>Where a service cannot reliably establish a user&#8217;s age that is appropriate to the risks that arise from the data processing, the regulators expect the Children&#8217;s Code standards to apply to all users as a default baseline. This creates a powerful incentive for businesses to invest in robust age assurance, as the alternative is to apply child-safe defaults to the entire user base.<\/p>\n<p>The statement also emphasises the importance of conducting and reviewing data protection impact assessments (DPIAs) that you must conduct before you process data. If you haven\u2019t looked at your DPIA recently, now would be the time to revisit it and make sure that you\u2019ve addressed the evolving risks and that you comply with the recent regulatory statements.<\/p>\n<p>EU developments: towards a harmonised framework<\/p>\n<p>The EU is building a harmonised framework for age assurance driven by the\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2065\/oj\/eng\" target=\"_blank\" rel=\"noopener nofollow\">Digital Services Act<\/a>\u00a0(DSA), the\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\/eng\" target=\"_blank\" rel=\"noopener nofollow\">GDPR<\/a>, the European Data Protection Board\u2019s (EDPB)\u00a0<a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/statements\/statement-12025-age-assurance_en\" target=\"_blank\" rel=\"noopener nofollow\">Statement on Age Assurance<\/a>\u00a0and the European Commission&#8217;s\u00a0<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/eu-age-verification\" target=\"_blank\" rel=\"noopener nofollow\">age verification blueprint<\/a>. Its approach differs from the UK in certain respects, most notably in its emphasis on privacy-preserving technical architecture. However, the direction of travel is strikingly consistent, service providers must do more to identify and protect children.<\/p>\n<p>GDPR and the EDPB Statement on Age Assurance<\/p>\n<p>Under\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679&amp;from=EN#art_8\" target=\"_blank\" rel=\"noopener nofollow\">Article 8<\/a>\u00a0of the GDPR processing personal data of children under 16 (or as low as 13, depending on the Member State) by information society services requires parental consent, implicitly requiring service providers to make reasonable efforts to assess users&#8217; ages.<\/p>\n<p>On 11 February 2025, the\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/02\/28\/age-assurance-key-insights-from-the-edpb-and-ico-102k2cl\" target=\"_blank\" rel=\"noopener nofollow\">EDPB adopted a statement on age assurance<\/a>, setting out high-level principles derived from the GDPR, including lawfulness, data minimisation, risk-based approaches and data protection by design and default. The EDPB&#8217;s approach complements the\u00a0<a href=\"https:\/\/ico.org.uk\/about-the-ico\/what-we-do\/information-commissioners-opinions\/age-assurance-for-the-children-s-code\/\" target=\"_blank\" rel=\"noopener nofollow\">ICO&#8217;s Opinion on age assurance<\/a>, though the ICO provides more detailed guidance on particular age assurance methods and examples of implementation through published\u00a0<a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/childrens-information\/childrens-code-guidance-and-resources\/age-assurance-case-studies\/\" target=\"_blank\" rel=\"noopener nofollow\">case studies<\/a>.<\/p>\n<p>The DSA and the protection of minors<\/p>\n<p>The DSA places binding obligations on online platforms to mitigate risks to children, including exposure to harmful or inappropriate content.\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2065\/oj\/eng#art_28\" target=\"_blank\" rel=\"noopener nofollow\">Article 28<\/a>\u00a0of the DSA requires online platforms to take appropriate and proportionate measures to ensure a high level of safety, privacy and security of minors and prohibits the targeting of minors with personalised advertising.<\/p>\n<p>On 14 July 2025, the EU Commission published its\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/07\/15\/european-commission-issues-dsa-guidance-on-protecting-children-online-and-release-102kt7n\" target=\"_blank\" rel=\"noopener nofollow\">DSA guidelines on protecting children online<\/a>, clearly setting out its expectations. The guidelines recommend age verification for adult content platforms and other platforms posing high risks to minors and specify that age assurance methods should be accurate, reliable, robust, non-intrusive and non-discriminatory. The EU Commission also issued a prototype of an age verification app, known as the age verification blueprint\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/insights\/2026\/04\/17\/age-assurance-in-2026-what-do-digital-businesses-operating-in-the-uk-and-eu-need-to-know#blueprint\" target=\"_blank\" rel=\"noopener nofollow\">(see below)<\/a>, work on which is ongoing.<\/p>\n<p>For businesses operating across both the UK and EU, there is significant alignment between the two regimes. A provider complying with Ofcom\u2019s guidance under the OSA is likely to meet most DSA requirements though nuances exist, e.g. EU guidance covers loot boxes, while the OSA does not. For more details see our legislative comparison table\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2023\/11\/14\/comparison-between-the-digital-services-act-and-the-online-safety-act-2023\" target=\"_blank\" rel=\"noopener nofollow\">here<\/a>.<\/p>\n<p>The EU Age Verification Blueprint<\/p>\n<p>The EU Commission\u2019s\u00a0<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/eu-age-verification\" target=\"_blank\" rel=\"noopener nofollow\">age verification blueprint<\/a>\u00a0outlines a common technical framework for privacy-preserving age checks. Its core principle is that a user&#8217;s age status should be verified without disclosing the user&#8217;s identity to the service provider. In other words, no underlying identity data is transmitted to websites or platforms and the system is designed in accordance with data minimisation and privacy by default principles.<\/p>\n<p>A\u00a0<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/news\/commission-releases-enhanced-second-version-age-verification-blueprint\" target=\"_blank\" rel=\"noopener nofollow\">second version<\/a>\u00a0of the blueprint was published in October 2025, adding onboarding using passports and ID cards and support for the Digital Credentials API. Pilot testing is underway in Denmark, France, Greece, Italy, Spain, Cyprus and Ireland. On 15 April 2026, the EU Commission\u00a0<a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/statement_26_817\" target=\"_blank\" rel=\"noopener nofollow\">announced<\/a>\u00a0its free age verification app was \u201ctechnically ready\u201d and would be \u201csoon available\u201d to citizens to use, stating \u201cthere are no more excuses\u201d and the EU is ready to enforce and hold accountable online platforms that do not protect children.<\/p>\n<p>The blueprint is also closely linked to the\u00a0<a href=\"https:\/\/ec.europa.eu\/digital-building-blocks\/sites\/spaces\/EUDIGITALIDENTITYWALLET\/pages\/694487738\/EU+Digital+Identity+Wallet+Home\" target=\"_blank\" rel=\"noopener nofollow\">EU Digital Identity Wallet<\/a>, which is due to be rolled out by the end of 2026. It could offer a single, interoperable age verification solution, but the timeline for full deployment is uncertain and businesses should not delay compliance action in anticipation of the wallet&#8217;s arrival.<\/p>\n<p>National regulatory activity across the EU Member States<\/p>\n<p>Notwithstanding the EU&#8217;s push towards harmonisation, several Member States have moved ahead with national age assurance requirements that in some cases go beyond the DSA and GDPR, e.g. in December 2023, the Spanish DPA published\u00a0<a href=\"https:\/\/www.aepd.es\/guides\/decalogue-principles-age-verification-minors-protection.pdf\" target=\"_blank\" rel=\"noopener nofollow\">guidance on age verification and protection of minors from inappropriate content<\/a>\u00a0and Germany issued joint guidance in October 2024\u00a0<a href=\"https:\/\/www.bundesnetzagentur.de\/DE\/Fachthemen\/DSC\/1_Themen\/StudienundForschung\/downloads\/Papier.pdf?__blob=publicationFile&amp;v=1\" target=\"_blank\" rel=\"noopener nofollow\">proposing nine principles for building an age verification system<\/a>.<\/p>\n<p>France has been particularly proactive, with the CNIL publishing an\u00a0<a href=\"https:\/\/www.cnil.fr\/en\/online-age-verification-balancing-privacy-and-protection-minors\" target=\"_blank\" rel=\"noopener nofollow\">analysis<\/a>\u00a0of online age verification in September 2022, and more recently adopting the\u00a0<a href=\"https:\/\/www.legifrance.gouv.fr\/loda\/id\/LEGISCTA000049565777\" target=\"_blank\" rel=\"noopener nofollow\">SREN Law<\/a>\u00a0requiring providers of adult content to verify that users are over 18. Arcom\u2019s\u00a0<a href=\"https:\/\/www.arcom.fr\/en\/find-out-more\/legal-area\/legal-resources\/technical-guidelines-age-verification-protection-persons-under-18-online-pornography\" target=\"_blank\" rel=\"noopener nofollow\">mandatory technical standard<\/a>\u00a0for age verification systems for pornographic sites became applicable in January 2025, with penalties of up to \u20ac150,000 or 2% of worldwide annual turnover, whichever is higher, for non-compliance.<\/p>\n<p>A growing number of EU Member States are pursuing minimum age requirements for social media. The European Parliament&#8217;s IMCO Committee has urged an EU-wide &#8220;digital minimum age&#8221; of 16, without parental consent, for social media, video-sharing platforms and AI companions. Proposed national minimum ages include Austria (14), Denmark (15), France (15), Spain (16) and Greece (15).<\/p>\n<p>Looking ahead, the forthcoming\u00a0<a href=\"http:\/\/www.mondaq.com\/redirection.asp?article_id=1777224&amp;company_id=3442&amp;redirectaddress=https:\/\/www.lewissilkin.com\/en\/insights\/2025\/11\/03\/european-parliamentary-committee-pushes-for-tougher-rules-to-make-online-services-102lrvb\" target=\"_blank\" rel=\"noopener nofollow\">Digital Fairness Act<\/a>, expected in 2026, will address manipulative design, dark patterns, loot boxes and the protection of vulnerable groups, including children. Businesses should anticipate further obligations regarding platform design features that may exploit or harm younger users.<\/p>\n<p>What should I be doing now?<br \/>\n&#13;<br \/>\nAudit your current age assurance mechanisms.\u00a0As should now be clear, self-declaration alone is insufficient where children are likely to access your service.&#13;<br \/>\nClose the gap between policy and practice.\u00a0The ICO\u2019s Reddit decision shows that a minimum age policy must be meaningfully enforced. If your terms of service state a minimum age, you must deploy age assurance mechanisms that are reasonably capable of preventing underage access. We\u2019d advise that you assess if your current measures would withstand this level of regulatory scrutiny.&#13;<br \/>\nConduct or refresh your DPIA.\u00a0Under the Children\u2019s Code if you offer an online service likely to be accessed by children, you must do a DPIA. The Ofcom\/ICO joint statement makes clear that businesses must conduct DPIAs before they process data &#8211; and keep them under review. Your DPIA should explicitly address risks to children and document the mitigation measures you have adopted.&#13;<br \/>\nMap your obligations across jurisdictions.\u00a0Global businesses must track both UK (OSA, UK GDPR and Children&#8217;s Code) and EU (DSA and GDPR) requirements, as well as applicable national laws in key markets with active age verification regimes, e.g. France, Australia and the US states.&#13;<br \/>\nVet your age assurance providers.\u00a0If you are using a third-party age assurance solution, check that it meets the HEAA standard. Consider using ICO-approved certification schemes, such as the Age Check Certification Scheme, to identify providers that meet UK data protection standards.&#13;<\/p>\n<p>What should I be doing in the next 6 to 12 months?<br \/>\n&#13;<br \/>\nTrack the UK\u2019s and EU Member States\u2019 proposed action on children\u2019s online wellbeing.\u00a0The outcome of these consultations\/actions may include a statutory minimum age for social media access. Businesses should begin internal discussions now about how they would implement such a requirement.&#13;<br \/>\nAnticipate the EU Digital Fairness Act.\u00a0As mentioned above, this is likely to impose additional requirements on platform design, dark patterns and features that exploit children. Include product and design teams in compliance planning now, not after the legislation is adopted.&#13;<br \/>\nEvaluate the EU age verification blueprint.\u00a0If you operate in the EU the blueprint and the forthcoming EU Digital Identity Wallet may offer an interoperable, privacy-preserving solution that reduces the complexity of multi-jurisdictional compliance. Consider engaging with the pilot programmes and technical specifications now to assess feasibility.&#13;<br \/>\nBuild cross-functional governance.\u00a0Compliance is not solely a legal or compliance function. Children&#8217;s data remains a global priority, with a clear expectation that platforms will demonstrate end-to-end accountability, i.e. by mapping child journeys, evidencing proportionate age assurance measures and aligning content safety controls with legislative obligations and duties. This requires collaboration across legal, compliance, design, product, engineering, audit and safety teams.&#13;<\/p>\n<p>How do I deal with the online safety versus data protection debate?\u00a0<\/p>\n<p>A key challenge is the tension between verifying users&#8217; ages (an online safety obligation) and minimising the collection and processing of personal data (a data protection obligation). Age assurance processing must be necessary, proportionate and lawful.<\/p>\n<p>The Ofcom\/ICO joint statement provides helpful guidance on how to navigate this tension in practice. Businesses should collect only the information strictly necessary to confirm a user&#8217;s age or age range, be transparent about how they use age assurance data and provide clear privacy notices. Users must be able to challenge inaccurate decisions.<\/p>\n<p>The privacy-preserving methods favoured by both UK and EU regulators, particularly the EU&#8217;s emphasis on solutions where no underlying identity data is transmitted to service providers, represent the regulatory ideal. Businesses that adopt these approaches now will be best positioned to meet the requirements of multiple jurisdictions simultaneously.<\/p>\n<p>Conclusion<\/p>\n<p>The direction of travel globally is clear: regulatory scrutiny of protecting children online is intensifying and regulators intend to hold services to account. Inaction is no longer a defensible strategy.<\/p>\n<p>If you are subject to UK and\/or EU age assurance requirements you should treat these developments as a clear signal that compliance cannot be a last-minute tick box exercise. Minimum age policies must be backed by meaningful technology, DPIAs must be current, thorough and kept under review, compliance maps must be multi-jurisdictional and governance must be cross-functional.<\/p>\n<p>The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.<\/p>\n<p>                    <a href=\"https:\/\/www.mondaq.com\/home\/redirect\/original\/1777224?location=sourceoriginal\" target=\"_blank\" rel=\"nofollow noopener\"> [View Source] <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"&#13; To print this article, all you need is to be registered or login on Mondaq.com.&#13; Article Insights&hellip;\n","protected":false},"author":2,"featured_media":15222,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[59,57,58,50,56,54,55],"class_list":{"0":"post-548104","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-united-kingdom","8":"tag-gb","9":"tag-great-britain","10":"tag-greatbritain","11":"tag-news","12":"tag-uk","13":"tag-united-kingdom","14":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/548104","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=548104"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/548104\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/15222"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=548104"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=548104"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=548104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}