UK Regulators Issue Joint Statement on Age Assurance for Online Services
Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office (“ICO”) and the UK Office of Communications (“Ofcom”), the UK’s online safety regulator, released a joint statement addressing the intersection of online safety and data protection in relation to age assurance (the “Joint Statement”). The Joint Statement targets online services likely to be accessed by children that are subject to both the Online Safety Act (OSA) and UK data protection legislation.

The Joint Statement outlines that organizations in scope must adopt age assurance methods that are risk-based, flexible, and technology-neutral. It also confirms that self-declaration alone is not considered effective for verifying user age or restricting underage access. According to the Joint Statement, all age assurance methods necessarily involve the processing of personal data, and such processing is required to be necessary, proportionate, and compliant with data protection law. The regulators also highlight the need for organizations to address risks of circumvention and avoid age assurance methods that are technically unfeasible or present undue risks to users’ rights and freedoms.

For user-to-user services regulated under the OSA that are likely to be accessed by children and which make harmful content available (including pornography, self-harm, suicide, or eating disorder material), the Joint Statement confirms that highly effective age assurance (“HEAA”) must be used to prevent children from accessing such content. The regulators refer to Ofcom’s HEAA guidance, which identifies technical accuracy, robustness, reliability, and fairness as key criteria, alongside accessibility and interoperability. The Joint Statement also includes a non-exhaustive list of methods capable of being highly effective at determining user age, while making clear that self-declaration, certain payment methods, and generic contractual restrictions do not meet the HEAA standard.

Where services are suitable for children, the Joint Statement notes the importance of providing an age-appropriate user experience and complying with the ICO’s Children’s Code. In cases of high-risk data processing, the use of age assurance methods with the highest possible accuracy is expected. When user age cannot be reliably established, Children’s Code standards should apply to all users. The Joint Statement also includes practical scenarios demonstrating how compliance may be achieved by different types of services, such as social media networks.

Read the press release here. Read the Joint Statement here.

You May Also Be Interested In

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 3, 2026, the Virginia Attorney General appealed a federal court’s grant of a preliminary injunction barring the enforcement of a new Virginia law requiring age verification and a time limit on social media use by minors under the age of 16 pending a final determination on the merits.    

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 3 Minute Read

On February 27, 2026, the UK ICO announced a public consultation on proposed updates to its guidance concerning research, archiving and statistics to reflect the changes introduced by the Data (Use and Access) Act 2025.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page