(“Joint Assertion”). The Joint Assertion is geared toward providers more likely to be accessed by youngsters that fall inside the scope of the On-line Security Act 2023 (“OSA”) and UK knowledge safety laws, and is designed to assist suppliers adjust to each their on-line security and knowledge safety obligations when deploying age assurance.
The Joint Assertion arrives alongside a broader push from each regulators—together with Ofcom’s latest name to motion directed at main tech companies, an open letter from the ICO urging platforms to strengthen their age checks, and several other enforcement actions by each regulators.
Some key takeaways from the Joint Assertion embrace:
1. The Joint Assertion Emphasises a Shared, Danger-Primarily based and Tech-Impartial Method.
The Joint Assertion emphasises a number of areas of alignment between Ofcom’s and the ICO’s approaches to age assurance:
- Self-declaration isn’t ample. The regulators agree that self-declaration alone—resembling a tick-box age affirmation—isn’t an efficient means to find out customers’ ages or forestall underage entry. Notably, the ICO goes additional, stating that presently out there profiling-based approaches are additionally not sufficiently efficient.
- Anti-circumvention. Age assurance strategies should deal with dangers of circumvention that might undermine the accuracy and robustness of the method.
- Knowledge safety compliance is required. Each regulators acknowledge that each one age assurance strategies contain the processing of private knowledge, and ensure that such processing is allowed offered the tactic chosen is important, proportionate to the dangers, and compliant with knowledge safety laws.
- Versatile, tech-neutral, possible options. Each regulators undertake a technology-neutral strategy, giving providers flexibility to pick strategies applicable to their context—together with measurement, person base, and out there sources—offered these strategies meet the relevant authorized necessities. The regulators underscore that they don’t count on providers to deploy age assurance strategies that aren’t technically possible or that introduce dangers to rights and freedoms outweighing the advantages.
2. Beneath the OSA, Sure Providers Should Use “Extremely Efficient” Age Assurance.
The Joint Assertion highlights the OSA’s necessities for “extremely efficient age assurance” relevant to: (1) Person-to-user providers which might be more likely to be accessed by youngsters and that enable “major precedence content material” (together with pornography, self-harm, suicide, and consuming dysfunction content material), regulated beneath Half 3 of the OSA; and (2) Half 5 providers that publish their very own pornographic content material.
Per Ofcom’s steering (see right here and right here), an age assurance methodology have to be technically correct, strong, dependable, and truthful to be thought-about extremely efficient—and should even be straightforward to make use of and work for all customers. The Joint Assertion gives the next abstract of age assurance strategies and their capability to be thought-about “extremely efficient”:

Supply: Joint Assertion, web page 5.
The Joint Assertion highlights that the OSA doesn’t require providers to set a minimal age. Nonetheless, providers that select to take action should state the minimal age of their phrases of service and apply it persistently. Providers that don’t use extremely efficient age assurance to implement their minimal age should assume that underage youngsters are utilizing the service and should replicate this of their youngsters’s danger assessments and corresponding mitigations.
3. The ICO Emphasises that Age Assurance Can Assist Defend Kids’s Private Info.
From an information safety perspective, the ICO’s place is that age assurance may also help organizations keep away from illegal processing of youngsters’s private info by stopping youngsters from accessing providers not appropriate for them, in addition to implement age-appropriate protections in accordance with the ICO’s Kids’s Code.
Stopping underage entry. The place a service isn’t appropriate for kids beneath a sure age—as an illustration, the place a minimal age of 13 is said within the phrases of service—the ICO explains that the service will usually lack a lawful foundation for processing the private knowledge of youngsters beneath that threshold. The Joint Assertion identifies the implementation of an efficient “age gate” as one of the best ways to minimise the chance of illegal processing. Whereas the ICO doesn’t mandate particular applied sciences, it factors to facial age estimation, digital ID, and one-time photograph matching as present viable examples for providers imposing a minimal age requirement.
Kids’s Code protections. The place a service is appropriate for kids (or youngsters above a sure age), the ICO maintains that the organisation’s focus must be on guaranteeing an age-appropriate expertise in line with the ICO’s Kids’s Code. In these instances, providers ought to use age assurance strategies which might be proportionate to the dangers of the platform and supply ample confidence to use the Kids’s Code requirements in keeping with the person’s age. The ICO’s Age Assurance Opinion additional explains how providers can use age assurance in a risk-based, proportionate method that complies with knowledge safety regulation. Within the Joint Assertion, the ICO reiterates that providers that lack dependable age info should apply the Kids’s Code requirements to all customers as a default baseline of safety (in a method that also displays no matter age info is on the market to the group).
Whatever the particular age assurance methodology adopted, the Joint Assertion underscores that providers should adjust to the complete set of UK GDPR knowledge safety ideas. In apply, which means that organizations might want to take measures resembling establishing a lawful foundation (and acquiring parental consent if required), guaranteeing equity and transparency (together with by way of age-appropriate transparency notices), and demonstrating accountability (together with by way of Knowledge Safety Influence Assessments (“DPIAs”). On DPIAs, the ICO has printed detailed steering on DPIAs within the context of the Kids’s Code, together with instance DPIAs (out there right here). Within the Joint Assertion, the ICO additionally highlights the provision of the Age Test Certification Scheme (“ACCS”) to assist providers determine age assurance suppliers that meet UK knowledge safety requirements.
4. Two Sensible Examples Illustrate How the UK’s Security and Knowledge Safety Regimes Work together.
The Joint Assertion contains two hypothetical compliance situations—one for a user-to-user pornography service and one for a big social media platform. The examples illustrate how a service can implement age assurance that meets each on-line security and knowledge safety necessities by setting out the hypothetical approaches to compliance in a side-by-side, two column chart.
Within the first instance, a user-to-user pornography service makes use of extremely efficient age assurance to forestall entry to pornographic content material, ensures that no such content material is accessible earlier than the age examine is accomplished, and takes steps to scale back circumvention danger. From an information safety perspective, the instance states that the service depends on authorized obligation as its lawful foundation for the age assurance processing, applies the information safety ideas, gives clear privateness info, provides mechanisms to problem inaccurate age selections, and opinions its DPIA as dangers evolve.
Within the second instance, a big social media service with a minimal age of 13 makes use of extremely efficient age assurance to limit entry to a “Not Protected For Work” part (which incorporates pornography) and, individually, makes use of strong age assurance on the account-creation stage to determine and block customers beneath 13. The instance additionally emphasizes accountability measures, together with conducting a DPIA, making use of the information safety ideas to the age assurance course of, and persevering with to evaluate whether or not the chosen strategy stays match for goal.
* * *
The Joint Assertion arrives at a second of intensifying regulatory give attention to age assurance, each within the UK and throughout Europe. Because the starting of the 12 months, each UK and European regulators have introduced a number of enforcement actions and investigations beneath method pertaining to age assurance. The Joint Assertion enhances Ofcom’s name earlier this month for main platforms to report by April 30, 2026 on the steps they’re taking throughout 4 precedence areas—minimal age insurance policies, anti-grooming controls, safer algorithmic feeds, and danger assessments of recent AI options earlier than deployment. Individually, the UK Authorities’s session on youngsters’s on-line experiences stays open till Could 26, 2026 and can possible feed into the additional improvement of further guidelines on this space (as described in our earlier weblog submit right here). On the EU stage, the European Fee has printed pointers on the safety of minors beneath the Digital Providers Act (as described right here) and has launched a blueprint for a privacy-preserving age verification answer—interoperable with the forthcoming EU Digital Id Wallets—that’s presently being piloted in a number of Member States. As these cross-jurisdictional items of the privacy-protective age-assurance “puzzle” come collectively, organisations could have a number of sources of knowledge to think about as they design and undertake their very own options.