Case study

Age assurance: verify once, not on every platform

The UK's Online Safety Act now requires many platforms to check users' ages, and regulators are actively enforcing that requirement. The question this raises is not whether age checks happen, but how many times the same proof of age — and the identity document, face scan, or card behind it — has to be handed to a different company.

The regulatory pressure is current, not hypothetical

Under the Online Safety Act, services that allow content harmful to children must put "highly effective age assurance" in place, and Ofcom has been actively enforcing this. In March 2026, Ofcom and the Information Commissioner's Office published a joint statement setting out shared expectations for age assurance, covering both the online-safety duty to check ages and the data-protection duty to do so without over-collecting personal data. Ofcom has since written to Facebook, Instagram, Roblox, Snapchat, TikTok, and YouTube with further compliance demands, and the UK government announced new social media restrictions for under-16s in June 2026. This is a live, escalating compliance regime, not a future possibility.

What "highly effective" age assurance means today

Ofcom's guidance lists the methods it considers capable of being highly effective: open banking checks, photo ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services, and email-based age estimation. Each of these establishes a person's age by examining some piece of identifying evidence — a document, a face, a financial account, a network record.

Ofcom and the ICO have flagged the tension this creates directly: the methods that are accurate enough to satisfy the online-safety duty tend to involve exactly the kind of sensitive personal data that the data-protection duty says should be minimised. Every platform that independently runs its own age check accumulates its own copy of that evidence — a passport scan here, a face scan there, a card number somewhere else — multiplying the number of places a person's identity documents and biometrics now sit, in the name of protecting children.

Where Databanking fits — and where it doesn't

Databanking is not a substitute for any of the methods on Ofcom's list. Establishing a person's age in the first place still requires some underlying evidence — a document, a biometric estimate, a financial or network record — checked once by a custodian regulated and qualified to do so. Databanking does not change that first step.

What it changes is everything downstream of that first step. Once a Databank has established and holds the age fact, every subsequent platform that needs an age check submits a query — "is this person over 13? Over 16? Over 18?" — rather than a request to re-run a new identity check of its own. The Databank answers with a yes/no predicate, not the underlying document, face scan, or birth date. The same mechanism set out in the worked example for an over-18 retail check applies directly: one bit crosses the boundary, the evidence never does.

The claim is not "Databanking performs highly effective age assurance." The claim is "Databanking lets highly effective age assurance happen once per person, rather than once per platform."

Why this case is different from a generic privacy argument

Most data-minimisation arguments require persuading people that a hypothetical, distant risk justifies giving up convenience today. Age assurance doesn't have that problem. The discomfort of submitting a passport scan or a live face scan to a dating app, a games platform, and three social networks in the same month is not hypothetical — it is exactly what current implementations are already asking of users, and exactly what the regulators' own joint statement identifies as a tension still to be resolved. A custodian that proves an attribute once and discloses only a threshold result afterward answers that tension directly, on a timeline measured in months rather than years.

The core argument, restated

The Online Safety Act needs platforms to know whether a user is old enough — not to hold a copy of that user's identity. Today's implementations conflate the two, because every platform runs its own check from scratch. Separating the verification of an attribute from its repeated disclosure is the general principle behind the rest of the Databanking proposal; age assurance is simply the case where the regulatory deadline, the privacy cost, and the user-facing discomfort are all visible right now.

← Back to the concept overview