On the one hand, providers may need to establish whether users are children in order to restrict access to age-inappropriate content, features or services. On the other hand, doing so will often require the collection and processing of additional personal data, which must comply with UK data protection legislation. How can age verification be implemented in a way that satisfies both online safety and privacy requirements?
What do the regulators say?
The joint statement issued by Ofcom and the Information Commissioner's Office (ICO) in March 2026 provides important clarification on how organisations can comply with both the Online Safety Act (OSA) and UK data protection legislation when implementing age assurance measures. The statement is aimed at services likely to be accessed by children and confirms that age assurance plays a central role in both regulators' shared objective of protecting children from harm online.
The joint statement makes clear that the OSA and data protection legislation are intended to operate alongside one another. Ofcom's focus is on protecting children from harmful content and experiences online, while the ICO's main focus is on ensuring children's personal data is processed lawfully and with appropriate safeguards. Age assurance sits at the intersection of these obligations.
Ofcom and the ICO emphasise a shared approach to age assurance. In particular, organisations are expected to adopt measures that are risk-based, proportionate and effective. The regulators also acknowledge that age assurance necessarily involves the processing of personal data but confirm that such processing can take place where it is necessary for the purpose pursued, proportionate to the risks identified and compliant with data protection requirements.
The joint statement provides a number of practical examples of how these obligations may operate in practice. It identifies methods such as facial age estimation, digital identity solutions and other forms of robust age assurance as potentially capable of providing the level of assurance required under the OSA. By contrast, Ofcom and the ICO agree that self-declaration alone is not an effective means of determining age and should not be relied upon where organisations need confidence that users are above or below a particular age threshold.
The statement also includes examples of regulatory expectations for different services. For example, a pornography service should ensure that users are subject to age assurance before pornographic content becomes accessible. Similarly, where a social media service operates a minimum age requirement, robust age assurance measures may be necessary to identify users who are below that minimum age and prevent access where appropriate. In both examples, the regulators emphasise the need to apply data protection principles, including data minimisation and transparency.
The Role of the Children's Code
The joint statement should be read alongside the ICO's Children's Code. The Code requires providers of online services likely to be accessed by children to place the best interests of the child at the centre of their design and operation and to ensure that children's personal data receives appropriate protection. The ICO's age assurance guidance explains that organisations should either establish the age of their users with an appropriate level of certainty or apply the protections in the Code to all users.
Viewed together, the Children's Code and the OSA create complementary obligations. The OSA uses age assurance to support the protection of children from harmful content, while the Children's Code uses age assurance to support the protection of children from harmful or inappropriate processing of their personal information. The joint statement expressly recognises this overlap and seeks to provide a coherent framework for organisations operating under both regimes.
Circumvention and Ongoing Effectiveness
The importance of robust age assurance is reflected in the government's recent research into children's circumvention behaviours online. The study found that many children reported encountering and attempting to bypass age checks, with common methods including providing false dates of birth. The research also found that children regarded more advanced age assurance methods, such as government ID checks and facial age estimation, as more effective than basic self-declaration measures.
These findings align with the expectations set out in the joint statement. Ofcom and the ICO state that age assurance methods should address risks of circumvention and be capable of guarding against fake inputs or other attempts to undermine their effectiveness. The regulators also stress the importance of monitoring and reviewing age assurance measures to ensure that they remain appropriate and effective over time.
Conclusion
Taken together, the Ofcom/ICO joint statement, the OSA and the Children's Code demonstrate an increasingly aligned regulatory approach to age assurance. Organisations are expected not only to implement measures that protect children from harmful content but also to ensure that any personal data used for those purposes is processed in accordance with UK data protection law.
As regulatory expectations continue to develop, organisations should ensure that their age assurance strategies are capable of satisfying both safety and privacy requirements. Get in touch with our commercial team if you need assistance in these areas.


