Key takeaways

  • Age assurance implementation triggers dual-regime compliance obligations under both the UK's Online Safety Act 2023 (the OSA) and the UK's data protection framework, consisting mainly of the UK GDPR and the Data Protection Act 2018.
  • The regulatory regimes under the OSA and data protection laws operate from different perspectives, so complying with one does not necessarily mean compliance with the other.
  • Both regimes have extra-territorial effect and businesses outside the UK are potentially within scope, if their services are available to UK users and they have sufficient links to the UK.
  • Facial age estimation is emerging as the developing market standard for age assurance.

Facial age estimation: the developing standard for age assurance

On 15 June 2026, the UK Government proposed a social media ban for under-16s that it plans to commence in early 2027.

This announcement is predicted to make the implementation of highly effective age assurance (HEAA) the top of many online services' compliance agendas. For platforms planning age verification or age estimation for the first time, the choice of tool now carries real regulatory risk. This article explains the compliance risks of choosing the wrong age assurance tool.

While there are many options for the implementation of HEAA, facial age estimation is emerging as the go-to market standard, given its ability to estimate a user's age without needing to establish their identity (and therefore reducing privacy risks to the user). Facial age estimation is also generally regarded as being a method that has lower friction for users than other types of HEAA, such as those that require the upload of government-issued ID documents. Facial recognition is not the same as facial age estimation and, by contrast, is designed to determine identity, not age, and is not, on its own, as effective a method of age assurance. Given the sensitivity of the personal data processed by any facial-based tool, HEAA implementation is likely to straddle two regulatory regimes: those for online safety and for data protection.

In the UK, these regimes are governed respectively by the OSA and by UK data protection law, in particular UK GDPR and the Data Protection Act 2018. Implementation of any form of HEAA is therefore likely to have to comply with both regimes. Similarly, the protection of children online is also regulated to a significant extent by both regimes, though from different perspectives, so any alternatives to these tools are also likely to be required to comply with both.

Online safety and HEAA

Part 3 of the OSA places duties on providers of regulated user-to-user (U2U) services (i.e., where content is generated, uploaded to, or shared on the service by a user, and may be encountered by another user or users of the service). In practice, this covers social media platforms, messaging apps, and other user-generated content services operating in the UK. These providers must assess whether children access their services and encounter illegal or harmful content.

Where that risk exists, Ofcom, the UK's online safety regulator, requires certain mitigations to be implemented to reduce this level of risk. The OSA also requires certain services (such as Part 5 pornography services) to implement HEAA to reduce the likelihood of children accessing such content. Other services, including some Part 3 services, while not required to implement such measures, are free to implement HEAA to reduce the regulatory and compliance burden posed by children accessing their services. Examples of such "other services" include online gaming platforms, dating apps, and discussion forums that carry a risk of children encountering age-inappropriate content even though HEAA is not mandated for them. While Ofcom does not prescribe specific technologies that services must use to implement HEAA, it does require that HEAA tools comply with certain requirements, including that the tools must be technically accurate, robust, reliable, and fair.

Data protection and age assurance

The Information Commission's Office (ICO), the UK's data protection regulator, has developed a comprehensive framework for children's data protection, anchored in the Age Appropriate Design Code (also known as the Children's Code), which sets out 15 standards that online services likely to be accessed by children must meet. These include requirements to configure default privacy settings to high, limit data collection to what is strictly necessary, and ensure that children's data is not used for profiling or targeted advertising by default. Following Ofcom's HEAA guidance, the ICO has updated its dedicated age assurance guidance making clear that any age assurance tool, whether or not it is highly effective under Ofcom's guidance, must itself comply with data protection principles. In particular, it requires that the implementation of any age assurance is proportionate, in line with data protection principles such as data minimisation, and does not expose individuals to new data risks.

A dual-regime compliance approach to HEAA

The Joint Statement on Age Assurance by Ofcom and the ICO clarifies how organisations must satisfy both the OSA and data protection regulatory regimes simultaneously when planning to implement age assurance measures. The Joint Statement confirms that neither regulator considers the following to be an effective method of preventing underage access:

  • self-declaration of age
  • age verification through online payment methods (debit cards can be issued to under 18s)
  • contractual restrictions on the age of users to receive services

The regulators suggest that organisations should instead deploy other technologies such as facial age estimation, credit card checks, open banking, digital identity, mobile-network operator age checks, email-based age estimation, or one-time photo matching.

There is, however, a structural tension between Ofcom's requirements for HEAA and the ICO's focus on upholding the fundamental principles of data protection for all users, not just children. While Ofcom's HEAA framework is performance-based and focuses on the degree to which the tool correctly determines age, reliably and without bias, the ICO's requirements are design-based, focusing on issues such as how much data the tool processes, for what purpose, and for how long. A HEAA tool involving facial age estimation / facial recognition can easily satisfy one regime's requirements and fail the other.

Notably, the ICO goes further than Ofcom by emphasising that age assurance measures must comply with the "data minimisation" principle. This means organisations must collect and process only the personal data strictly necessary to confirm whether a user meets the relevant age threshold.

An approach that collects more data than required, even if it satisfies Ofcom's HEAA criteria, will not be compliant with UK data protection law. This point is reiterated in the Joint Statement where the ICO and Ofcom state that:

"You can process personal data for age assurance, as long as the method you use is necessary, proportionate to your risks and complies with data protection principles." (emphasis added)

It is not yet clear how the ICO will enforce the data protection principles in the deployment of Ofcom-compliant HEAA. When the ICO brought enforcement proceedings in 2024 in relation to deployment of facial recognition technology (albeit not in an online setting), its focus was on the necessity and proportionality of collecting biometric data for employee monitoring purposes. The ICO found that insufficient attention had been paid to whether there had been alternative means of achieving the same outcome. As a result, the use of facial recognition was held not to be a targeted and proportionate way of achieving the purpose and the controller in question was ordered to stop using facial recognition. With the media and regulatory focus on children and digital ID, it is likely that compliance with the necessity and proportionality principles will continue to be a focus for the ICO.

What does this mean for facial age estimation as HEAA?

Before considering how the regulatory regimes apply to facial age estimation, it is worth noting a fundamental distinction between facial age estimation and facial recognition solutions:

  • Facial recognition: This is used to determine a user's identity by taking biometric identifiers and comparing them against an existing record, whether this is an identity document or an existing database. Such processing of biometric data which is used to identify an individual is special category data under the UK GDPR and therefore requires that a specific Article 9 condition is met, along with an appropriate lawful basis under Article 6.
  • Facial age estimation: This is used to determine a user's age only, using tools to analyse facial features in order to predict someone's age. It is likely that this will only require a lawful basis under Article 6 of the UK GDPR, as long as biometric data is not processed specifically to identify the individual.

By contrast with facial age estimation, some facial recognition tools are likely to be designated as HEAA under Ofcom's guidance, because they can prove that they are technically accurate and robust. However, the processing and retention of biometric data in this manner is exactly what the data minimisation and storage limitation principles of the data protection regime caution against, making facial recognition a less attractive option than facial age estimation for most services.

Bias in facial recognition tools is a recognised regulatory concern. Some tools may have been trained on biased datasets, resulting in a tool which treats individuals of a particular gender or race differently from others. For example, the Law Society's 2019 report on Algorithms in the Criminal Justice System noted that "commercially available facial recognition software has been shown to have error rates which differ based on demographic. Such systems have been demonstrated to perform poorly on Black individuals, and in particular on Black women". In this case, it is likely that the tool would fail to satisfy the fairness requirements under both regimes.

If a facial age estimation tool can achieve Ofcom's HEAA standard without creating a persistent biometric template or enabling actual identity verification, it is more likely to be able to satisfy the requirements of both regimes in relation to the degree of technical accuracy and data minimisation.

However, every tool must be carefully considered, as it is possible that a facial age estimation tool might still fail to satisfy the fairness requirements of the data protection regime (and also, potentially, the Equality Act 2010), where it is unable to assess all individuals on an equally accurate basis regardless of gender or race.

Assessing the appropriateness of a tool to a specific service and its users is therefore central to ensuring compliance with both regimes. While some tools may be marketed as a "one-stop-shop" solution, the reality is that some services may be able to deploy a mix of less invasive tools to achieve a compliant solution, without deploying more invasive ones like facial recognition.

Is facial age estimation GDPR compliant?

Facial age estimation can be GDPR compliant, but compliance depends on how the tool is built and deployed, not on the technology label alone. A facial age estimation tool is more likely to meet UK GDPR requirements where it: (1) estimates age only, without creating a persistent biometric template or verifying identity; (2) processes no more personal data than necessary to confirm the relevant age threshold; (3) is tested for accuracy across different genders and ethnicities; and (4) is backed by a Data Protection Impact Assessment and a clear transparency notice. A tool that meets Ofcom's HEAA standard will not automatically satisfy the ICO's data protection requirements, so each tool needs to be assessed against both regimes separately.

HEAA in practice

So, what steps should online services take to comply with both the Online Safety Act and UK GDPR when implementing age assurance? In short: map the service against both regimes, select a tool proportionate to the data it needs to collect, document the decision, and monitor regulatory updates. Each of these steps is set out below.

Both the OSA and UK data protection law should be considered at every stage of the age assurance design process, from identifying the purpose for implementation and selecting an appropriate solution, through to considerations relating to data retention and transparency for users.

Services that may be in scope need to be prepared to comply with the proposed under-16 ban, along with regulatory obligations. We suggest taking at least the following steps:

  • Assess whether services are in scope: map the service against the OSA's U2U and search services definitions, and against the scope of the proposed under-16 ban.
  • Select the appropriate tool for service's risk profile: consider whether facial age estimation can meet the HEAA standard before reaching for full facial recognition. Facial age estimation is faster, less data-intensive, and less likely to engage Article 9 of the UK GDPR, but accuracy at the specific age margin that matters should be tested, with a fallback for borderline cases.
  • Document compliance: commission a Data Protection Impact Assessment before procurement of any services, ensure the transparency notice is clear and accessible, and give users a mechanism to challenge an incorrect age determination. OSA record-keeping duties also require a written record of age assurance methods and how data protection has been considered.
  • Watch out for Ofcom's October 2026 update: Ofcom is expected imminently to publish its assessment of what constitutes HEAA for the under-16 ban, which is expected to address facial age estimation specifically. Organisations should build flexibility into their age assurance plans now.

EU KIDS Act and age assurance

The practical steps set out above are focused on the UK's dual-regime framework under the OSA and UK data protection law. But the EU has also recently turned its attention to children's online safety, with the European Commission adopting the EU Keeping Internet Digital Spaces Accountable and Trustworthy Act (EU KIDS Act) as a proposal on 17 September 2026. The EU KIDS Act is the EU's answer to age verification regulation, and platforms operating across both the UK and EU will need to track both frameworks. This EU KIDS Act sets out proposed EU-wide measures including:

  • A requirement that users prove that they are above the minimum age of 15 to be able to open their own social media accounts;
  • Access to social media for 13- to 15-year-olds to be limited to a "mini" account connected to their guardian's own account, with access further limited to one hour per day; and
  • A prohibition on platforms allowing children under 13 to access social media.

The proposal requires that social media platforms make use of privacy-preserving age assurance methods, raising similar questions to those being considered in the UK around how online safety objectives interact with data protection obligations under EU GDPR. Platforms operating in both the UK and the EU will need to consider both regimes and assess what appropriate age assurance is for their service.

In summary

Online services planning age assurance for UK users should treat the OSA and UK GDPR as two separate tests, not one. Facial age estimation is currently the technology best placed to satisfy both, provided it is deployed without creating a persistent biometric record and with proper data protection documentation in place. Facial recognition remains available for services that need identity verification, but it carries a higher data protection burden and should be chosen deliberately, not by default. Mishcon de Reya's Online Safety and Data Protection teams advise on exactly this kind of dual-regime assessment, from tool selection through to Data Protection Impact Assessments and regulatory engagement.

How can Mishcon de Reya help?

Mishcon de Reya's Online Safety team and Data Protection team advise digital platforms, technology companies, and businesses on their obligations under the OSA and data protection in the UK, including on age assurance strategy, HEAA tool selection, and compliance with both regulatory regimes. Our lawyers regularly advise clients on choosing between facial age estimation, facial recognition, and other age verification methods, and on documenting that choice for Ofcom and the ICO. For questions about how to comply, please get in touch with our team.