md.guidance-highly-effective-age-assurance
Draft guidance on highly effective age assurance – For Part 3 Services
Additional Safety Measures Consultation – Annex 10¶
Consultation Published 30 June 2025
Contents¶
Section¶
1. Overview ............................................................................................................................. 6
2. Introduction ........................................................................................................................ 7
3. Age assurance methods and processes ........................................................................... 10
4. Criteria to ensure an age assurance process is highly effective ...................................... 13
5. Privacy and data protection ............................................................................................. 25
6. Glossary ............................................................................................................................ 28
Table 1: Key changes from the current guidance text to the proposed new guidance text Current guidance text Proposed new guidance text
2. Introduction [All paragraphs identical except those below]
2.6 Background to the guidance 2.6 Background to the guidance The Code also includes other recommended The Protection of Children Code also includes measures which may be relevant to the way other recommended measures which may be that service providers implement and operate a relevant to the way that service providers highly effective age assurance process on their implement and operate a highly effective age service – for example, measures relating to the assurance process on their service – for clarity and accessibility of terms of service, and example, measures relating to the clarity and reporting and complaints. accessibility of terms of service, and reporting and complaints.
1 Measures PCU B1-PCU B7 of Annex 9. 2 Measures PCU B1-PCU B7 of Annex 9.
Current guidance text Proposed new guidance text
Background to the guidance 2.9 – 2.12 Background to the guidance No text The Illegal Content Codes of Practice for User-to-user services (the “Illegal Content Codes”) set out recommended measures service providers may take to address illegal harm on their services and to comply with relevant illegal content safety duties under the Act. The illegal content safety duties do not require a service provider to use highly effective age assurance for the purpose of fulfilling their duties under the Act. Nevertheless, Ofcom has recommended the use of highly effective age assurance for particular measures in the Illegal Content Codes. The Illegal Content Codes also sets out the definition of highly effective age assurance for these recommended measures and lists the steps that service providers should take to fulfil each of the criteria. This guidance will help service providers in adopting recommended measures that relate to the implementation of highly effective age assurance, by providing additional technical detail and examples on how to meet the standard.
3. Age assurance methods and processes [All paragraphs identical except those below]
Current guidance text Proposed new guidance text
Section 1 Overview¶
What this guidance covers¶
This is our guidance to assist providers of regulated user-to-user and search services (“Part 3 services”) in implementing highly effective age assurance for the purpose of fulfilling their regulatory obligations under the Online Safety Act 2023 (“the Act”). This guidance is applicable for the purposes of: • stage 1 of the children’s access assessment, as explained in the Children’s Access Assessment Guidance; and • understanding how highly effective age assurance should be implemented where applicable to recommended measures set out in Ofcom’s Protection of Children Code of Practice for user-to-user services and the Illegal Content Codes of Practice for user-to-user services.
This guidance sets out additional detail to assist service providers in i) understanding whether an age assurance process is highly effective and ii) complying with the recommended measures.
Our approach to highly effective age assurance aligns, where appropriate, with the approach taken in our Guidance for service providers publishing pornographic content under Part 5 of the Act. This is to ensure that service providers in scope of Part 5 and / or Part 3 of the Act have a clear and consistent understanding of how to implement highly effective age assurance to prevent children from encountering harmful content. This guidance was originally published on 16 January 2025. This updated version was published on 24 April 2025. We have replaced references to the draft version of the Protection of Children Code for user-to-user services with references to the final version.
Section 2 Introduction¶
Background to the guidance¶
Children’s Access Assessment¶
Protection of Children Codes¶
3 Section 35(2) of the Act. 4 We use the term "access controls" to describe a technical mechanism(s) which prevents users who have not been age assured, or having been age assured, did not meet the requirements of the age assurance process, from accessing a service (or part of it) or certain content.
5 Children’s Access Assessments Guidance, April 2025. 6 Measures PCU B1-PCU B7 of the Annex 9. 7 Measure PCU B1.2-1.6 of the Protection of Children Code for user-to-user services. 8 See the ‘Index of Recommended Measures’ in the Protection of Children Codes for user-to-user services for a full list of the recommended measures and which services they apply to.
taken to comply with their duties.9 Service providers should consult our Record Keeping and Review Guidance for this purpose.10
Illegal Content Codes¶
Section 3 Age assurance methods and processes¶
12 The kinds of age assurance in this list may be referred to by different names, and each kind may be implemented in a number of ways. We have used high-level descriptions to assist service providers in understanding the options that are available to them, but it is for each provider to consider which age assurance methods and processes will be most appropriate for complying with the duties under the Act.
use to distinguish between children and adults on their service, for example, involving providers of devices, app stores, browsers operating systems, or relevant kinds of authentication systems. Regardless of where the age assurance occurs in the ecosystem or whether it is implemented by the service provider or by a third-party, it is the responsibility of the regulated user-to-user service provider to ensure that age assurance is implemented in such a way that it is highly effective at determining whether or not a user is a child. Should service providers opt to use wider system-level age assurance, they must ensure the initial age check and the process to share this information with the regulated service (e.g. through age tokens) are highly effective. 13
Kinds of age assurance that are capable of being highly effective¶
Open banking¶
Photo-identification (photo-ID) matching¶
Facial age estimation¶
Mobile-network operator (MNO) age checks¶
Credit card checks¶
13 Age tokens are reusable digital tokens that act as a digital proxy or representation of a completed age check. They can be shared by users across multiple services over a defined period of time as evidence that an age check has been completed.
14 ‘Relying party’ refers to the service that is trying to establish the age of the user. In this context, the relying party is likely to be the regulated service. 15 There are several ways to remove a CRF, depending on the MNO. 16 We are aware that in the US, the term ‘credit card’ can be used to refer to debit cards. For clarity, when we refer to ‘credit card’ we mean cards tied to an account where money is borrowed and repaid, and not debit cards tied to current or ‘checking’ accounts, which often do not have the same 18+ requirements.
after which a payment processor sends a request to check the card is valid by the issuing bank. Approval by the issuing bank can be taken as evidence that the user is over 18.17
Email-based age estimation¶
Digital Identity Services¶
Kinds of age assurance that are not capable of being highly effective¶
Self-declaration of age¶
Age verification through online payment methods which do not require a user to be over the age of 18¶
General contractual restrictions on the use of the regulated service by children¶
17 Possession of credit card details is not evidence that the user is the credit card holder. 18 Section 230(4) of the Act.
Section 4 Criteria to ensure an age assurance process is highly effective¶
Table 4.1: Summary table of the criteria service providers should fulfil and how they can do so.¶
criteria than others. For example, one age assurance method could produce a highly reliable result due to limited variance, but it may provide greater opportunities for children to circumvent, therefore reducing its robustness. We expect to see that, when determining which age assurance method(s) to implement, service providers have satisfied themselves that the age assurance process as a whole fulfils each of the criteria.
The technical accuracy criterion¶
What is technical accuracy?¶
Why is technical accuracy important?¶
19 Office for Digital Identities and Attributes and Department for Science, Innovation and Technology, ‘UK digital identity and attributes trust framework’. A register of certified services can be found on GOV.UK.
How can service providers have regard to the technical accuracy criterion?¶
Ensure the method(s) has been evaluated against appropriate metrics and the results indicate that the method(s) is able to correctly establish whether or not a particular user is a child¶
Use a challenge age approach for age estimation methods¶
20 The estimation of the user’s age will usually be accompanied by a confidence interval or range, which conveys the algorithm’s level of uncertainty regarding the prediction. For example, where an age estimation method predicts that a user is 25 years old with a confidence interval of ±2 years, this means that the method estimates the user’s age to fall within the range of 23 to 27 years.
21 We define each of the metrics set out in the technical glossary in Annex 1 of this document. 22 We define each of the metrics set out in the technical glossary in Annex 1 of this document. 23 Drink Aware, Challenge 25. 24 ACCS, 2022. Measurement of Age Assurance Technologies.
manage this risk a buffer can be set above the age by 8 years, so if the relevant age is 18 then the Challenge Age would be 25. For users estimated to be over the age of 25, no additional verification will be required. Where the method estimates that the user’s age is under the challenge age, the user could be required to undergo another age check by a second method that is more technically accurate for that age group.
Periodically review the technical accuracy of the age assurance method(s) and make changes where necessary¶
The robustness criterion¶
What is robustness?¶
Why is robustness important?¶
How can service providers have regard to robustness when implementing age assurance?¶
Where relevant, ensure the technology has been tested in a range of conditions¶
Identify and take appropriate steps to mitigate against methods of circumvention that are easily accessible to children and where it is reasonable to assume that children may use them¶
25 Liveness detection is used to ensure that the face being analysed is not a photograph, video, or any other form of spoofed representation. The primary goal is to prevent attackers from using static images (print attack) or pre-recorded videos (replay attack) to trick the system into making inaccurate age estimates.
someone’s identity (“GPG45”) provides some useful indicators on how a document can be scored to detect certain levels of faked documentation.26
The reliability criterion¶
What is reliability?¶
Why is reliability important?¶
26 Cabinet Office and Government Digital Service, 2023, Guidance – How to prove and verify someone’s identity. Subsequent references to this document are referred to as ‘GPG45.’ 27 ICO, 2023. Data protection by design and default 28 Gundersen OE, Kjensmo S, 2018, State of the art: Reproducibility in artificial intelligence in Proceedings of the AAAI Conference on Artificial Intelligence 32(1), p. 1645. 29 ‘Strength’ refers to evidence being harder to forge or counterfeit, as defined in GPG45.
How can service providers have regard to reliability when implementing age assurance?¶
Ensure that methods with a degree of variance have been suitably tested and that ongoing performance is measured and monitored¶
Ensure that the evidence used is derived from a trustworthy source¶
30 For example: 1) Age Verification Accuracy Rate (AVAR): the percentage of users correctly identified as belonging to the appropriate age group; 2) Age Verification Efficiency (AVE): the time taken to complete the age verification process; 3) Drift Threshold: establish predefined thresholds for AVAR and AVE beyond which significant model drifting is considered to have occurred.
The fairness criterion¶
What is fairness?¶
Why is fairness important?¶
How can service providers have regard to fairness when implementing age assurance?¶
Ensure the technology has been tested on diverse datasets¶
31 Further examples and information on checking that evidence is genuine or valid can be found in GPG45.
32 Office for Digital Identities and Attributes and Department for Science, Innovation and Technology, ‘UK digital identity and attributes trust framework’. A register of certified services can be found on GOV.UK. 33 Fairness is a separate principle in data protection law, which states that that data should be processed lawfully, fairly and transparently. For more information, see ICO, Principle (a): Lawfulness, fairness and transparency and ICO, 2023. Guidance on AI and data protection. 34 There may also be obligations for service providers under the Equality Act 2010 and guidance on this can be found at Equality and Human Rights Commission Guidance.
Consider the outcome / error parity¶
Additional principles for providers to consider¶
Table 4.2: Summary table of the principles that services providers should consider in addition to the criteria.
Accessibility principle¶
What is accessibility?¶
Why is accessibility important?¶
How can service providers have regard to accessibility when implementing age assurance?¶
35 The Act, Schedule 4, paragraph 12(2)(e). 36 The Act, Schedule 4, paragraph 12(2)(f). 37 For example, those without credit cards will be unable to complete a credit card check. Those without a driving licence or passport will be unable to undergo a photo-ID check that relies on these documents.
ensuring that all functionality is available from a keyboard for users with limited motor control.
• Making information about the age assurance process available in the form of a pop up prior to completing the age check, for example, as a smaller, new window that appears overlayed on top of the webpage, drawing the user’s attention. The text could be included in this window, or the pop up could feature a button prompting users to click for more information.38
Interoperability¶
What is interoperability?¶
Why is interoperability important?¶
How can regulated services have regard to interoperability?¶
Stay up to date with developments in interoperability
38 This could be part of a service provider’s publicly available statement, which we provide more guidance on in Section 6 (5.28-5.5.30). 39 Further guidance on businesses’ legal obligations in this area can be found at Equality and Human Rights Commission Guidance. 40 The Act, Schedule 4, paragraph 12(2)(g).
Section 5 Privacy and data protection¶
The Data Protection Regime¶
ICO guidance on data protection and age assurance¶
41 ICO, 2023. A guide to the data protection principles; ICO, A guide to lawful basis; and ICO, Individual rights – guidance and resources. ICO Guidance on controllers/ processors. 42 For an overview of each principle, see the ICO’s guide to the data protection principles. 43 ICO, Principle (a): Lawfulness, fairness and transparency. 44 ICO, Principle (b): Purpose limitation.
• Data minimisation;45 • Accuracy;46 • Storage limitation;47 • Security;48 and • Accountability.49
Having regard to privacy under the Act¶
45 ICO, Principle (c): Data minimisation. 46 ICO, Principle (d): Accuracy.
47 ICO, Principle (e): Storage limitation. 48 ICO, Principle (f): Integrity and confidentiality (security). 49 ICO, Accountability and governance. 50 A summary of the 15 standards can be found at ICO, ‘Code standards’ in Age appropriate design: a code of practice for online services. 51 ICO, Children’s code guidance and resources. 52 Section 22(3) of the Act.
• Conducting a Data Protection Impact Assessment (DPIA). These are required by data protection law where processing is likely to result in a high risk to the rights and freedoms of individuals. DPIAs will assist service providers in identifying and mitigating the risks arising from their processing of personal data, which can help demonstrate that they have had regard to the importance of protecting users from a breach of any statutory provision or rule of law concerning privacy. As set out in Standard 2 of the Children’s code, a DPIA can also help services to minimise and identify the specific risks to children who are likely to access the service which arise from the processing of their personal data.53 Detailed guidance on how to carry out a DPIA, and a sample template, can be found on the ICO website. • Providing privacy information to users. Service providers should give users information about why they need to provide any personal data, how it will be processed, how long it will be retained, and if it will be shared with anyone else. Doing so in a child-friendly way will also help services to meet Standard 4 of the Children’s code: transparency.54 More information on privacy notices can be found on the ICO website.55 • Keeping written records of processing activities. Most organisations that process personal data must document their processing activities to some extent.56 • Having up to date data protection policies along with a record of how providers make staff aware of them. This provides staff with clarity and consistency around their data protection obligations.57 • Having a record of which staff have completed any data protection training programme that is in place. This helps to ensure all staff have adequate knowledge of data protection, as appropriate for their role.58 • Clearly documenting technical and organisational security measures.59
53 ICO, 2. Data protection impact assessments 54 ICO, 4: Transparency 55 See ICO, Transparency (cookies and privacy notices) and ICO, How to write a privacy notice and what goes in it.
56 ICO, Records of processing and lawful basis. Also see ICO, Governance and Accountability in Age appropriate design: a code of practice for online services. 57 ICO, Policies and procedures. Also see ICO, Governance and Accountability in Age appropriate design: a code of practice for online services. 58 ICO, Training and awareness. Also see ICO, Governance and Accountability in Age appropriate design: a code of practice for online services. 59 ICO, A guide to data security.