LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A.
You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. Can you explain what sort of data companies are actually collecting when they check for age and whether there are any real threats to my safety?
EFF’s Answer: Age verification is a process where a website or service checks your age to determine whether a user is over a certain age, in the UK this age is 18.
As of July 2025, all platforms in the UK that host content considered by the UK government and the country’s telecommunications regulator Ofcom to be harmful are legally obligated to check that their users are over the age of 18. If not, users cannot access the content.
There are various privacy implications for data sharing with age verification. Unfortunately, because services may use different methods to verify users’ ages, you’ll usually have to do a little digging to learn how each provider you have verifies their users, and consider what information might be harmful to your personal safety:
- The data itself: What info does each method require users to disclose?
- Access: Who can see the data during the course of the verification process? Does anything other than the age result leave your phone or device? Is the provider told your date of birth, or just if you’re over 18? Which third party services see the information you send?
- Retention: Who will hold onto that data after the verification process, and for how long? Sometimes it’s deleted immediately. Sometimes it hangs around forever, waiting for a data breach.
- Audits: How sure are we that the provider’s stated claims around data access and retention will happen in practice? For example, are there external audits confirming that data is not accidentally leaked to another site along the way? Ideally these will be in-depth, security-focused audits by specialized auditors like NCC Group or Trail of Bits, instead of audits that merely certify adherence to standards.
- Visibility: Who will be aware that you’re attempting to verify your age, and will a third party provider know which platform you’re trying to verify for? Will they hang onto that data to build a profile of you?
Last year, Ofcom outlined a number of methods for online services and platforms to check users' ages. Let's look at some methods in more detail.
Facial Age Estimation
First up we have facial age estimation, where you show your face via photo or video, and a technology provided by a company like Yoti or Persona analyses it to estimate your age. Most of these third-party verification services upload your photo to their servers during this process. Yoti claims that “as soon as an age has been estimated, the facial image is immediately and permanently deleted.”
You might not want to use facial age estimation if you’re worried about a current picture of your face accidentally leaking—for example, if elements in the background of your selfie might reveal your current location. Some services like k-ID and Private ID will analyse your face directly on the device, so only the age result will leave your phone.
If you do choose (or are forced to) use the face check system, be sure to snap your selfie without anything in the background that you'd be concerned with identifying your location or embarrassing you, in case the image leaks.
Photo-ID Matching
Photo-ID matching checks whether your photo matches a document that confirms your identity, such as a driving license or passport. This is usually considered the most sensitive, since your ID has quite a bit of information on you. For example, if you upload an image of a document that shows your face and age, and an image of yourself at the same time, these are compared to confirm they match. Like with facial age estimation services, you’ll usually be sent to a third-party provider, such as Yoti or Incode. You’d hope that they’d delete the data immediately, but that’s not always the case. Incode for example doesn’t automatically delete the data you give it once the process is complete; though if you’re reaching them through TikTok, TikTok does claim to “start the process to delete the information you submitted,” which should include telling Incode to delete your data once the process is done.
If you want to be sure, you can ask Incode to delete that data yourself. But you’re relying on a service you don’t generally have a choice about doing the right thing, and we’ve already seen how that can fail. A previous system that Discord used to verify age had you send a picture to their general help forum, where all of the IDs sat around forever, until they got exposed in a massive data breach. Discord no longer uses that system to verify users’ ages. So, it might be fine, but unless you look into the exact company and all their practices, it’s hard to know. You can check out EFF’s guide for a few of the major platforms.
Open Banking
Next is open banking, where you give permission for the age-check service to securely access information from your bank about whether you are over 18. The age-check service then confirms this with the online service. The user's full date of birth is not shared. Credit card age checks are also used for pornography services, where you provide your credit card details and a payment processor checks if the card is valid. As you must be over 18 to obtain a credit card in the UK, this shows you are over 18 and can therefore access a service.
Email Verification
Email-based age estimation is also quite prevalent, where users provide an email address, and a third party technology analyses other online services where it has been used—such as banking or utility providers—to estimate your age. That third party will aggregate some data on you in the process, but the only new information they’ll find out is that you want to verify your age using a particular email address.
Mobile Operator Checks
Mobile network operator age checks give your permission for an age-check service to confirm whether or not your mobile phone number has age filters applied to it. If there are no restrictions, this confirms you are over 18.
There is no perfect, privacy protecting verification serviceUnfortunately, none of these verification options are perfect in terms of protecting information, especially when this is compounded by the additional risks that LGBTQ+ people face with data sharing. The data can reveal someone’s sexual orientation, gender identity, or HIV status that can be used by employers, governments, family members, scammers, or bad actors to inflict harassment, discrimination, arrest, or violence.
There is still no widely available way to verify age online without compromising privacy—but even if there were, broad restrictions on social media will inevitably limit access to lawful speech, and valuable online communities, and arts and culture. These are just a few of the reasons that EFF is against age-gating mandates and is working to stop and overturn them in the UK and around the world.