Age checks moved from a policy debate to an operating requirement in the space of two years. This is what applies where, who carries the obligation, and how ProntoID verification maps onto it.
General information, not legal advice · Last reviewed 4 August 2026
This is the single most misunderstood point in age assurance procurement, so it is worth stating before anything else. Ofcom has been explicit: regardless of whether age assurance is implemented by the service itself or outsourced to a third-party vendor, it is the responsibility of the regulated service to ensure the process is highly effective.
So treat any vendor promising to make you compliant with suspicion, including us. What a verification provider can actually offer is a method that meets the regulator’s criteria, evidence that each check took place, and documentation you can put in front of a regulator. The decision that the method is right for your risk profile remains yours.
Six regimes that between them cover most platforms serving European, UK and US users.
Highly effective age assurance has been required since 25 July 2025. Two routes into scope: Part 5 services that publish their own pornographic content, and Part 3 user-to-user services likely to be accessed by children that carry primary priority content — which includes pornography as well as suicide, self-harm and eating disorder material.
Article 28(1) requires online platforms accessible to minors to put in place appropriate and proportionate measures ensuring a high level of privacy, safety and security. The Commission's guidelines, final since July 2025, are not binding in themselves but function as the evaluation standard supervisors apply.
Germany has required a closed user group — a geschlossene Benutzergruppe — for adult content since well before the current European wave, and its two-stage structure is stricter than most. Identification must reach a standard equivalent to a face-to-face check, and authentication must recur at every use so that credentials cannot be handed to a minor.
The revised Federal Act on Data Protection applies to processing with effects in Switzerland and is broadly aligned with GDPR. Article 7 requires privacy by design and privacy-friendly default settings — a direct constraint on how an age check is built, not just on what it produces. Separate Swiss youth protection legislation covers age controls for films and video games.
There is no federal age verification statute; there is a patchwork. Roughly half of US states have enacted requirements covering adult content, social media, or both. In Free Speech Coalition v. Paxton, decided 27 June 2025, the Supreme Court upheld the Texas statute, removing the principal First Amendment obstacle and accelerating state activity through 2025 and 2026.
For adult content platforms, scheme rules often bite before legislation does. Mastercard's standards for adult content merchants and Visa's integrity risk programme require age and identity verification of people depicted in and uploading content, alongside consent records and complaint handling. In the United States, 18 U.S.C. § 2257 imposes separate record-keeping duties on producers.
Ofcom sets four criteria for an age assurance method. Ofcom and the ICO have since added that a method must also be easy to use and work for all users.
The method correctly determines whether a user meets the age threshold, measured against a defined standard rather than asserted.
The method resists circumvention — the borrowed document, the photograph of a face, the recorded video replayed to a camera.
It produces consistent, reproducible results over time and across conditions, not just in the vendor demo.
It works across demographics without systematic bias, and does not exclude users who have a legitimate right of access.
ProntoID sits in the first and sixth categories: photo-ID matching with biometric confirmation, reusable on subsequent checks.
Written as capability rather than guarantee. Whether a given capability satisfies a given obligation on your service is a judgement you and your counsel make.
ISO/IEC 27566-1:2025, published in December 2025, is the first international standard for age assurance systems. Until it arrived, every vendor evaluated itself against its own criteria, which made honest comparison close to impossible.
The standard separates four things that had been routinely conflated in the market, and describes the characteristics a system should be assessed on: functionality, performance, privacy, security and acceptability.
Items marked Roadmap or In progress are not yet certified and are shown so you can plan against them, not rely on them.
Every age assurance method processes personal data, and that processing has to be necessary and proportionate in its own right. Regulators have been clear that an online safety obligation does not suspend data protection law.
Your platform receives whether the threshold is met, the method, a confidence indicator and a session reference. Not the document, not the selfie, not the name, not the exact date of birth.
Article 7 of the revised Swiss FADP and Article 25 GDPR both require it. Collection is scoped to what the eligibility decision needs, and images are retained only as long as the legal basis supports.
ProntoID acts as an independent controller for the identity data it processes, rather than as your processor. A subject access or erasure request over that data reaches ProntoID, not your support queue.
The verification flow itself: ID check, selfie face match, 3D liveness, and Log in with Pronto for returning users.
Learn MoreIdentity-verified consent and model release records for depicted persons — the § 2257 and card scheme side of the obligation, distinct from gating viewer access.
Learn MoreWhere you have a regulated obligation to know the identity, not just the age, of the person in front of you.
Learn MoreNo. Under the UK Online Safety Act the regulated service remains responsible for ensuring its age assurance process is highly effective, whether that process is built in house or outsourced to a third-party vendor. The same principle holds elsewhere: the obligation attaches to the service offering the content, not to the vendor supplying the check. A verification provider supplies capability and evidence; it cannot absorb your legal duty.
Ofcom's guidance sets four criteria: an age assurance method must be technically accurate, robust, reliable and fair. Ofcom and the ICO have added that a method must also be easy to use and work for all users, which brings accessibility and interoperability into scope. Self-declaration alone is not accepted, and Ofcom has ruled out age inference as highly effective for services required to prevent children accessing pornography.
Not for regulated content. UK regulators have stated plainly that self-declaration alone is not effective for verifying age or restricting underage access. In the United States, the Supreme Court decision in Free Speech Coalition v. Paxton in June 2025 removed the principal constitutional obstacle to state age verification mandates, and a click-through button does not satisfy those statutes either.
Alongside its July 2025 guidelines under Article 28(1) of the Digital Services Act, the European Commission published an open-source age verification blueprint, sometimes called the mini-wallet. It is built on the same technical specifications as the European Digital Identity Wallet and uses zero-knowledge proofs so that a user can demonstrate they are over 18 without revealing anything else. A pilot with front-runner Member States is running through 2026.
Access to content restricted to adults must run through a closed user group, a geschlossene Benutzergruppe. That means two distinct stages: identification of the person at enrolment to a standard equivalent to a face-to-face check, and authentication at each subsequent use so that access credentials cannot simply be passed on. Concepts are assessed against KJM criteria, with the FSM providing an assessment pathway.
ISO/IEC 27566-1:2025, published in December 2025, is the first international standard framing age assurance systems. It establishes shared vocabulary across four concepts — age verification, age estimation, age inference and successive validation — and describes core system characteristics including functionality, performance, privacy, security and acceptability. It gives platforms a recognised benchmark for evaluating vendors rather than relying on each vendor's own criteria.
Every age assurance method processes personal data, and that processing must be necessary, proportionate and lawful in its own right. Article 8 GDPR sets the age at which a child can consent to information society services somewhere between 13 and 16 depending on the Member State. Running an age check is not a licence to collect more than the check requires, which is why ProntoID returns an age attribute rather than an identity.
For adult content merchants, yes, and they often bite sooner than legislation does. Mastercard's standards for adult content and Visa's integrity risk programme require verification of the age and identity of people depicted in and uploading content, together with consent and complaint handling. These are contractual obligations, and losing acquiring is a faster commercial risk than a regulatory fine.
Tell us which jurisdictions you serve and what you publish. We will tell you plainly what we can evidence and what remains yours to decide.
Swiss-operated · Privacy by design · Attribute-only responses