Compliance

Age Verification Requirement Checker

Work out which age assurance obligations apply to an online service across the UK Online Safety Act, the Age Appropriate Design Code, COPPA, GDPR Article 8 and state laws, and what level of assurance each demands.

Last reviewed by the Radiatus Cloud team

Applicable requirements appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Age assurance is not one requirement but several, at different strengths

Asking a user to type a birth date, inferring age from behaviour, and verifying identity against a document are three different things, and the regimes ask for different ones. The UK Online Safety Act requires highly effective age assurance for pornographic content, which self-declaration does not satisfy. GDPR Article 8 requires reasonable efforts to verify parental consent, which is a lower bar. Treating them as one requirement leads either to over-collecting identity data or to a control that does not meet the standard.

The age of consent for data differs by country

Article 8 sets sixteen as the default age at which a child can consent to information society services, and lets member states lower it to no less than thirteen. They have chosen differently: thirteen in several, fourteen, fifteen and sixteen elsewhere. A service operating across the EU faces different thresholds in different countries for the same feature, and applying the highest is the only practical approach unless the service can localise reliably.

Verifying age means collecting data about children

The uncomfortable part of age assurance is that it requires processing personal data, often identity documents, from the people the rules exist to protect. Data minimisation applies with particular force here: a system that confirms someone is over eighteen without retaining what document proved it is materially better than one that stores a scan, and regulators have said so. A verification system that becomes a database of children's identity documents has created a larger risk than it removed.

Related tools

Frequently Asked Questions

What is "highly effective" age assurance?

A standard under the UK Online Safety Act that self-declaration does not meet. It contemplates methods such as document verification, facial age estimation or verified payment data, and the regulator assesses the method rather than the intention.

What age applies under GDPR Article 8?

Sixteen by default, which member states may lower to no less than thirteen. They have chosen differently, so a service operating across the EU faces different thresholds for the same feature in different countries.

Does COPPA apply outside the United States?

It applies to services directed to children under 13 that are used by children in the United States, regardless of where the operator is based.

Should I store the identity documents I check?

Almost never. A system that confirms an age without retaining what proved it is materially better, and regulators have said so. A verification system that becomes a database of children’s identity documents has created a larger risk than it removed.

Is this legal advice?

No. It maps published obligations onto what you described so you can see which regimes are in play and at what strength. Whether a specific service falls within a given regime is a legal question.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Describe your service to see which age rules apply.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.