means , , or both. Under the Online Safety Act, the required method and certainty depend on the duty: preventing children from accessing a service or content, or applying child-safety measures by age. Start with that legal trigger, then test effectiveness, privacy, accessibility, and circumvention.
1
Section 1
Age assurance basics under the UK Online Safety Act
Ofcom uses as the collective term for and . Under section 230, age verification verifies a user's exact age, while age estimation estimates a user's age or age range. The Act does not require one universal technique, and the method must be assessed against the duty it supports.
The main triggers differ. A children's access assessment may rely on when a provider seeks to conclude that children cannot normally access the service. Services likely to be accessed by children may need to apply child-safety measures by age. Services within the pornography duties must use highly effective age assurance to prevent children from encountering regulated pornographic content.
The current Ofcom code and guidance for the duty determine what requires. The complete process, including fallback and the downstream restriction, needs implementation-specific evidence; a supplier's product name or general accuracy claim does not establish compliance.
and can use different evidence and expose users to different privacy or exclusion risks. Compare candidate methods against the named duty, the relevant threshold, the actual population, the data collected, and the route offered when the primary method cannot produce a usable result.
Place the check before a user can encounter the protected content. If is used, document the decision boundary and route uncertain results to another method. Test previews, embeds, logged-out access, alternate clients, account sharing, recovery, and VPN or other foreseeable bypass routes.
Online-safety and data-protection duties apply together. Define the purpose, minimise the personal data used, assess lawful processing and children's interests, secure transfers and templates, limit retention, control vendors, provide usable information, and offer an accessible alternative where the primary method excludes a user.
Scope record: service, content or feature, statutory trigger, age threshold, user group, and required outcome.
Method record: verification or estimation inputs, decision rule, fallback, retries, manual review, downstream control, and deletion event.
Test record: threshold-specific errors, demographic performance, spoofing, account sharing, bypass routes, accessibility, abandonment, and production monitoring.
Who should own age assurance, and what evidence should prove the decision?
Product owns the user journey and downstream access control; safety and legal identify the duty and threshold; privacy maps processing and retention; security tests circumvention; accessibility and equality owners test exclusion; an accountable decision-maker accepts residual risk.
Evidence should show the service scope, statutory trigger, method and supplier, threshold-specific testing, attack testing, demographic performance, fallback, data flow, deletion, user information, complaints route, approval, and production monitoring.
Name one accountable owner and one reviewer for the workflow.
Keep source links, decision notes, implementation tickets, and approval records together.
Use dated evidence for notices, risk assessments, user journeys, and regulator-facing records.
Review the evidence after product changes, new markets, new vendors, or material changes in the source text.
Age assurance edge cases to check before you rely on a decision
Boundary issues arise where logged-out or embedded access bypasses the check, one account is shared, a user is near the threshold, a supplier cannot cover a population, an uncertain result has no fallback, or the same age signal is reused for another purpose.
Test every access path and state what happens after failure, retry, challenge, account recovery, supplier outage, or a change in the age result. A successful age check is ineffective if the downstream content or feature gate can be bypassed.
Check whether the rule changes for different service types, audiences, or access paths.
Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
How should teams implement age assurance with proportionate controls?
Use a workflow that starts with the statutory purpose and ends with a tested downstream restriction. Capture service scope, user groups, children's-access and risk-assessment links, method choice, data flow, fallback, test results, owner, approval, monitoring, and escalation.
The output should include a decision record, method test pack, privacy and security assessment, implementation evidence, monitoring plan, complaint route, and change trigger.
Create a short intake question that identifies the scenario.
Map the answer to a required action, evidence field, owner, reviewer, and review date.
Link related artifact pages with descriptive anchors so users can move from scope to deadlines, controls, penalties, and templates.
Update the workflow when official source material changes or when non-public evidence shows recurring exceptions.
Which legal sources and final checks control age assurance?
Section 230 of the Online Safety Act supplies the binding definitions of and . Ofcom uses as the collective term for those methods. The duty that triggers age assurance depends on the service and content. Current Ofcom codes and guidance explain the regulator's effectiveness expectations, while ICO guidance and the joint Ofcom and ICO statement explain the separate data-protection duties.
Confirm the current Ofcom code and guidance for the service and duty before relying on a control design. Keep the version and date reviewed with the decision record.
Assess the deployed system and user journey instead of relying on a generic method approval list or an unsupported numerical buffer. Record the performance evidence, decision threshold, uncertainty handling, bypass testing, privacy and security controls, accessibility checks, and reassessment triggers.