Regulation

The UK Online Safety Act and Age Verification

The UK Online Safety Act requires services to assess and reduce children’s access to pornography and other harmful material. Ofcom oversees a phased regime that increasingly relies on highly effective age assurance while raising significant privacy questions.

The UK Online Safety Act 2023, commonly called the OSA, creates safety duties for online services available to UK users. Its age assurance provisions are intended to stop children from encountering pornography and certain content that is harmful to children, while allowing adults to continue accessing lawful material.

Age assurance is the broader term for estimating or establishing whether a user is above or below a relevant age. It can range from age estimation to age verification, where a service checks evidence such as an identity document or a payment method. The Act does not mandate one universal technical method, but the required outcome can be demanding.

Who has age assurance duties

The OSA applies different duties to different categories of service. Providers that publish or make pornographic content available to UK users must ensure that children cannot normally encounter it. This includes dedicated pornography services and can also affect platforms where users share pornography, depending on the service and the legal duties that apply to it.

User-to-user services and search services must also assess whether children are likely to access their services. Where children can access a service, providers must carry out children’s access and risk assessments and use proportionate measures to protect them from content that is harmful to children. The precise measures depend on the service’s risk profile, features, user base and the kinds of content it hosts or surfaces.

The framework distinguishes between illegal content, content harmful to children, and content that may be lawful for adults but unsuitable for minors. Age assurance is especially important where a provider relies on restricting access, rather than removing the content for everyone.

Ofcom’s role

Ofcom, the UK communications regulator, enforces the Online Safety Act. It publishes codes of practice, guidance and risk-assessment materials that explain how providers can meet their statutory obligations. Following an Ofcom code is not always the only route to compliance, but a provider choosing another approach must be able to show that it meets the legal duty at least as effectively.

Ofcom can request information, investigate suspected non-compliance and impose substantial financial penalties. In serious cases, it can seek court-backed business disruption measures. The regulator’s approach places responsibility on services to understand and mitigate risks, rather than treating compliance as a one-time age-checking exercise.

The highly effective age assurance standard

Ofcom uses the phrase “highly effective age assurance” for systems expected to distinguish children from adults with a high degree of confidence. A simple tick box, a date-of-birth field without meaningful checks, or a statement that a user is over 18 will generally not meet that standard for pornography or similarly restricted material.

Appropriate methods may include document-based verification, age estimation technologies, checks through trusted third parties, or other approaches that produce reliable results. The method should be robust against easy circumvention, work before a child gains access to restricted content, and account for likely errors, including the risk of incorrectly treating a child as an adult.

  • Self-declaration alone is unlikely to be highly effective for adult content restrictions.
  • Providers should assess accuracy, resistance to fraud, accessibility and the risk of exclusion.
  • Age assurance should be applied at the point at which restricted content can be accessed, not only after exposure.
  • Services remain responsible for their compliance when they use an age assurance vendor.

Privacy and data protection

Age assurance creates a difficult privacy trade-off. Stronger checks can require users to provide sensitive information, such as an identity document, biometric-derived age estimates or payment data. That information can reveal or be linked to a person’s use of sensitive services, including adult-content sites.

Providers must therefore consider UK data protection law, including the UK GDPR and the Data Protection Act 2018. Key principles include data minimisation, clear information for users, security safeguards, limited retention and a lawful basis for processing. A well-designed system should obtain only the age-related result needed by the content provider, such as confirmation that a user is 18 or over, rather than sharing an identity record or browsing history.

Privacy does not remove an OSA duty, but it affects how a provider should meet it. Ofcom’s expectations emphasize methods that are both effective and privacy-preserving, with particular care for children and for people who may lack conventional identity documents.

Rollout and key date

The OSA is being phased in through staged duties, consultations, codes and enforcement activity rather than a single universal launch. 1 January 2025 is a key date in the wider implementation period. Providers should monitor the duties and Ofcom materials relevant to their service type, since timing and detailed expectations can differ between pornography providers, user-to-user services and search services.

For compliance purposes, the central question is practical: can children realistically reach restricted content through the service? If the answer is yes, a provider needs evidence-based safeguards, documented assessments and an age assurance approach that is effective enough for the risk involved.