Regulatory Landscape

Age assurance,
jurisdiction by jurisdiction.

Age checks moved from a policy debate to an operating requirement in the space of two years. This is what applies where, who carries the obligation, and how ProntoID verification maps onto it.

General information, not legal advice  ·  Last reviewed 4 August 2026

Start Here

The duty stays with you

This is the single most misunderstood point in age assurance procurement, so it is worth stating before anything else. Ofcom has been explicit: regardless of whether age assurance is implemented by the service itself or outsourced to a third-party vendor, it is the responsibility of the regulated service to ensure the process is highly effective.

So treat any vendor promising to make you compliant with suspicion, including us. What a verification provider can actually offer is a method that meets the regulator’s criteria, evidence that each check took place, and documentation you can put in front of a regulator. The decision that the method is right for your risk profile remains yours.

By Jurisdiction

What applies where

Six regimes that between them cover most platforms serving European, UK and US users.

United Kingdom

Online Safety Act 2023

Enforcing

Highly effective age assurance has been required since 25 July 2025. Two routes into scope: Part 5 services that publish their own pornographic content, and Part 3 user-to-user services likely to be accessed by children that carry primary priority content — which includes pornography as well as suicide, self-harm and eating disorder material.

  • Ofcom and the ICO issued a joint statement on age assurance in March 2026 covering the overlap with data protection duties
  • Ofcom reported in July 2026 that it had opened investigations into providers of adult services and issued fines to non-compliant operators
  • Penalties reach £18 million or 10% of qualifying worldwide revenue, whichever is greater
European Union

Digital Services Act, Article 28(1)

Phasing in

Article 28(1) requires online platforms accessible to minors to put in place appropriate and proportionate measures ensuring a high level of privacy, safety and security. The Commission's guidelines, final since July 2025, are not binding in themselves but function as the evaluation standard supervisors apply.

  • An open-source age verification blueprint — the mini-wallet — was published alongside the guidelines, using zero-knowledge proofs so a user proves they are over 18 and nothing more
  • The blueprint shares technical specifications with the European Digital Identity Wallet, with a Member State pilot running through 2026
  • A Commission recommendation in April 2026 encouraged Member States to have age verification available by the end of 2026
Germany

Jugendmedienschutz-Staatsvertrag (JMStV)

Enforcing

Germany has required a closed user group — a geschlossene Benutzergruppe — for adult content since well before the current European wave, and its two-stage structure is stricter than most. Identification must reach a standard equivalent to a face-to-face check, and authentication must recur at every use so that credentials cannot be handed to a minor.

  • Stage one: identify the person once, to a reliable standard, at enrolment
  • Stage two: authenticate the same person at each subsequent login, not merely restore a session
  • Concepts are assessed against KJM criteria; the FSM provides an assessment pathway for providers
Switzerland

revFADP and youth protection law

Enforcing

The revised Federal Act on Data Protection applies to processing with effects in Switzerland and is broadly aligned with GDPR. Article 7 requires privacy by design and privacy-friendly default settings — a direct constraint on how an age check is built, not just on what it produces. Separate Swiss youth protection legislation covers age controls for films and video games.

  • Privacy by design and by default is a statutory requirement, not a best practice
  • ProntoID is operated from Sion by Brooks & Keitt Sàrl and processes under Swiss and EU frameworks
  • Transparency obligations attach to automated processing that produces a decision about a person
United States

State statutes

Varies by state

There is no federal age verification statute; there is a patchwork. Roughly half of US states have enacted requirements covering adult content, social media, or both. In Free Speech Coalition v. Paxton, decided 27 June 2025, the Supreme Court upheld the Texas statute, removing the principal First Amendment obstacle and accelerating state activity through 2025 and 2026.

  • Most statutes attach where a threshold share of content — commonly one third — is harmful to minors, but thresholds and definitions differ
  • Enforcement models differ too: some states rely on a private right of action, others on a state regulator
  • Litigation and effective dates continue to move; check the current text of each statute before relying on any summary
Card schemes and § 2257

Contractual and record-keeping obligations

Enforcing

For adult content platforms, scheme rules often bite before legislation does. Mastercard's standards for adult content merchants and Visa's integrity risk programme require age and identity verification of people depicted in and uploading content, alongside consent records and complaint handling. In the United States, 18 U.S.C. § 2257 imposes separate record-keeping duties on producers.

  • Loss of acquiring is a faster and more existential commercial risk than a regulatory fine
  • Consent and identity records for depicted persons are a distinct requirement from gating viewer access
  • ProntoTag covers identity-verified consent and release records; age verification covers viewer access

This summary is general information and not legal advice. Age assurance law is moving quickly, effective dates shift, and several statutes are under active litigation. Confirm the current position against the applicable text, or with your own counsel, before relying on it. Last reviewed 4 August 2026.

The Standard

What “highly effective”
actually means

Ofcom sets four criteria for an age assurance method. Ofcom and the ICO have since added that a method must also be easy to use and work for all users.

Technically accurate

The method correctly determines whether a user meets the age threshold, measured against a defined standard rather than asserted.

Robust

The method resists circumvention — the borrowed document, the photograph of a face, the recorded video replayed to a camera.

Reliable

It produces consistent, reproducible results over time and across conditions, not just in the vendor demo.

Fair

It works across demographics without systematic bias, and does not exclude users who have a legitimate right of access.

Recognised as capable of being highly effective
  • Photo-ID matching
  • Facial age estimation
  • Open banking checks
  • Mobile network operator age checks
  • Credit card checks
  • Reusable digital identity services

ProntoID sits in the first and sixth categories: photo-ID matching with biometric confirmation, reusable on subsequent checks.

Not accepted on its own
  • Self-declaration of age
  • A click-through “I am 18” button
  • A date-of-birth entry field
  • Contractual age restrictions in terms of service
  • Age inference, for services required to prevent child access
The Mapping

Requirement,
and what answers it

Written as capability rather than guarantee. Whether a given capability satisfies a given obligation on your service is a judgement you and your counsel make.

Determine age to a standard beyond self-declaration
A government-issued document is authenticated and the date of birth is read from the machine-readable zone, which ProntoID treats as the highest-confidence source and never overwrites with an optical read.
Confirm the document belongs to the presenter
A selfie is matched one-to-one against the portrait printed in the document. This is what closes the borrowed-document gap that document authentication alone leaves open.
Resist circumvention and presentation attacks
A 3D liveness check confirms a live person is present in the session, defending against still photographs, printed images, screen replays, masks and synthetic faces.
Re-authenticate at each subsequent use
Log in with Pronto re-binds a returning user to the face enrolled at verification through a single liveness check. This is the pattern ISO/IEC 27566-1 calls successive validation, and what the JMStV closed user group model requires at stage two.
Process only what the decision requires
The response to your platform is an age attribute, a method, a confidence indicator and a session reference. The document image, selfie, document number, name and exact date of birth stay with ProntoID.
Evidence that a check took place
Each verification produces an audit record you can point to. ProntoID acts as an independent controller for the underlying identity data, so subject access and erasure requests over that data land with ProntoID.
Work for all users, including edge cases
Support spans ICAO 9303 passports, national identity cards including EU cards whose machine-readable zone sits on the reverse, driving licences and US state IDs across 195+ countries.
Standards

A shared vocabulary,
at last

ISO/IEC 27566-1:2025, published in December 2025, is the first international standard for age assurance systems. Until it arrived, every vendor evaluated itself against its own criteria, which made honest comparison close to impossible.

The standard separates four things that had been routinely conflated in the market, and describes the characteristics a system should be assessed on: functionality, performance, privacy, security and acceptability.

Age verification
Confirming age from official documentation — a passport, identity card or driving licence.
Age estimation
Inferring a likely age from technical analysis, such as facial age estimation.
Age inference
Predicting age from behavioural signals. Ofcom has ruled this out as highly effective where child access must be prevented.
Successive validation
Checking through the session or at each return, rather than once at the door. This is the returning-user problem.
ProntoID standards position
ISO/IEC 27566-1:2025
Aligned
Age assurance framework. ProntoID performs age verification and successive validation as the standard defines them.
Certification via ACCS
Roadmap
Independent certification against the age assurance standard.
FSM / KJM assessment
In progress
German closed user group approval covering both enrolment and recurring login.
GDPR & revFADP
Aligned
Data minimisation, privacy by design, and attribute-only release to platforms.

Items marked Roadmap or In progress are not yet certified and are shown so you can plan against them, not rely on them.

Privacy Framework

Checking age is not
a licence to collect

Every age assurance method processes personal data, and that processing has to be necessary and proportionate in its own right. Regulators have been clear that an online safety obligation does not suspend data protection law.

Attribute-only response

Your platform receives whether the threshold is met, the method, a confidence indicator and a session reference. Not the document, not the selfie, not the name, not the exact date of birth.

Privacy by design and default

Article 7 of the revised Swiss FADP and Article 25 GDPR both require it. Collection is scoped to what the eligibility decision needs, and images are retained only as long as the legal basis supports.

Clear controller boundaries

ProntoID acts as an independent controller for the identity data it processes, rather than as your processor. A subject access or erasure request over that data reaches ProntoID, not your support queue.

On DPIAs. Deploying age assurance on a service likely to be accessed by children will usually warrant a data protection impact assessment. We can supply the processing detail you need to complete one — what is collected, where it is processed, how long it is held and on what basis — but the assessment itself is yours to make and to document.

Elsewhere in the Platform

Adjacent obligations,
adjacent tools

Frequently Asked Questions

Compliance questions,
answered plainly

Does buying an age verification service make my platform compliant?

No. Under the UK Online Safety Act the regulated service remains responsible for ensuring its age assurance process is highly effective, whether that process is built in house or outsourced to a third-party vendor. The same principle holds elsewhere: the obligation attaches to the service offering the content, not to the vendor supplying the check. A verification provider supplies capability and evidence; it cannot absorb your legal duty.

What does "highly effective age assurance" mean under the UK Online Safety Act?

Ofcom's guidance sets four criteria: an age assurance method must be technically accurate, robust, reliable and fair. Ofcom and the ICO have added that a method must also be easy to use and work for all users, which brings accessibility and interoperability into scope. Self-declaration alone is not accepted, and Ofcom has ruled out age inference as highly effective for services required to prevent children accessing pornography.

Is a date-of-birth field or a click-through age gate still acceptable?

Not for regulated content. UK regulators have stated plainly that self-declaration alone is not effective for verifying age or restricting underage access. In the United States, the Supreme Court decision in Free Speech Coalition v. Paxton in June 2025 removed the principal constitutional obstacle to state age verification mandates, and a click-through button does not satisfy those statutes either.

What is the EU age verification blueprint?

Alongside its July 2025 guidelines under Article 28(1) of the Digital Services Act, the European Commission published an open-source age verification blueprint, sometimes called the mini-wallet. It is built on the same technical specifications as the European Digital Identity Wallet and uses zero-knowledge proofs so that a user can demonstrate they are over 18 without revealing anything else. A pilot with front-runner Member States is running through 2026.

What does the German JMStV require?

Access to content restricted to adults must run through a closed user group, a geschlossene Benutzergruppe. That means two distinct stages: identification of the person at enrolment to a standard equivalent to a face-to-face check, and authentication at each subsequent use so that access credentials cannot simply be passed on. Concepts are assessed against KJM criteria, with the FSM providing an assessment pathway.

What is ISO/IEC 27566-1?

ISO/IEC 27566-1:2025, published in December 2025, is the first international standard framing age assurance systems. It establishes shared vocabulary across four concepts — age verification, age estimation, age inference and successive validation — and describes core system characteristics including functionality, performance, privacy, security and acceptability. It gives platforms a recognised benchmark for evaluating vendors rather than relying on each vendor's own criteria.

How does age verification sit alongside GDPR?

Every age assurance method processes personal data, and that processing must be necessary, proportionate and lawful in its own right. Article 8 GDPR sets the age at which a child can consent to information society services somewhere between 13 and 16 depending on the Member State. Running an age check is not a licence to collect more than the check requires, which is why ProntoID returns an age attribute rather than an identity.

Do payment card scheme rules matter here?

For adult content merchants, yes, and they often bite sooner than legislation does. Mastercard's standards for adult content and Visa's integrity risk programme require verification of the age and identity of people depicted in and uploading content, together with consent and complaint handling. These are contractual obligations, and losing acquiring is a faster commercial risk than a regulatory fine.

Protect your users.
Protect your business.

Tell us which jurisdictions you serve and what you publish. We will tell you plainly what we can evidence and what remains yours to decide.

Talk to Our Compliance Team See How It Works

Swiss-operated  ·  Privacy by design  ·  Attribute-only responses