Age Verification Requirement Checker
Work out which age assurance obligations apply to an online service across the UK Online Safety Act, the Age Appropriate Design Code, COPPA, GDPR Article 8 and state laws, and what level of assurance each demands.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Age assurance is not one requirement but several, at different strengths
Asking a user to type a birth date, inferring age from behaviour, and verifying identity against a document are three different things, and the regimes ask for different ones. The UK Online Safety Act requires highly effective age assurance for pornographic content, which self-declaration does not satisfy. GDPR Article 8 requires reasonable efforts to verify parental consent, which is a lower bar. Treating them as one requirement leads either to over-collecting identity data or to a control that does not meet the standard.
The age of consent for data differs by country
Article 8 sets sixteen as the default age at which a child can consent to information society services, and lets member states lower it to no less than thirteen. They have chosen differently: thirteen in several, fourteen, fifteen and sixteen elsewhere. A service operating across the EU faces different thresholds in different countries for the same feature, and applying the highest is the only practical approach unless the service can localise reliably.
Verifying age means collecting data about children
The uncomfortable part of age assurance is that it requires processing personal data, often identity documents, from the people the rules exist to protect. Data minimisation applies with particular force here: a system that confirms someone is over eighteen without retaining what document proved it is materially better than one that stores a scan, and regulators have said so. A verification system that becomes a database of children's identity documents has created a larger risk than it removed.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What is "highly effective" age assurance?
A standard under the UK Online Safety Act that self-declaration does not meet. It contemplates methods such as document verification, facial age estimation or verified payment data, and the regulator assesses the method rather than the intention.
What age applies under GDPR Article 8?
Sixteen by default, which member states may lower to no less than thirteen. They have chosen differently, so a service operating across the EU faces different thresholds for the same feature in different countries.
Does COPPA apply outside the United States?
It applies to services directed to children under 13 that are used by children in the United States, regardless of where the operator is based.
Should I store the identity documents I check?
Almost never. A system that confirms an age without retaining what proved it is materially better, and regulators have said so. A verification system that becomes a database of children’s identity documents has created a larger risk than it removed.
Is this legal advice?
No. It maps published obligations onto what you described so you can see which regimes are in play and at what strength. Whether a specific service falls within a given regime is a legal question.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Describe your service to see which age rules apply.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.