How to Navigate Age Assurance: The New Ofcom and ICO Joint Statement
9th April 2026
If your online service is likely to be accessed by children, the regulatory landscape has just become much clearer, and stricter. On 25 March 2026, Ofcom and the Information Commissioner’s Office (ICO) published a landmark joint statement. This statement outlines the interaction between online safety duties and data protection obligations when implementing age assurance.
Put simply, regulators expect platforms to protect children from harmful content, but not at the expense of their privacy. Let us break down the key takeaways from the statement and what it means for your compliance strategy.
A Common Approach to Age Assurance
Historically, many organisations relied on users simply ticking a box to confirm they were over 18. The joint statement makes it explicitly clear: self-declaration in isolation is no longer sufficient.
Both regulators are adopting a ‘tech-neutral’ and risk-based approach. This means they do not mandate one specific software, but they expect you to choose a method that is proportionate to the risks your service poses to children. The higher the risk, the higher the level of certainty required. Furthermore, your chosen method must address anti-circumvention, ensuring users cannot easily bypass the checks.
Obligations Under the Online Safety Act 2023 (OSA)
Under the OSA, if your platform is a user-to-user service likely to be accessed by children and hosts primary priority content (including pornography, suicide, or self-harm material), or if you are a service that publishes or displays your own pornographic content, you must implement Highly Effective Age Assurance (HEAA).
To meet the HEAA standard, your methods must be technically accurate, robust, reliable, fair, easy to use, and work for all users. Methods like general contractual restrictions or standard debit card checks, which do not strictly require the user to be 18 or over, are not considered highly effective. While the OSA does not force you to set a minimum age, if your terms of service state a minimum age (e.g. 13), you must enforce it consistently. If you do not use HEAA to enforce your minimum age, you must assume underage children are using your service and mitigate the risks accordingly within your children’s risk assessment.
Obligations Under Data Protection Legislation
Implementing age assurance inherently involves processing personal data. The ICO expects this processing to comply fully with the UK GDPR and the Data Protection Act 2018. Key data protection themes include:
Lawful Basis
You must establish a valid lawful basis for the age check. Where age assurance is required under the OSA, ‘legal obligation’ is likely to be the most appropriate lawful basis.
Data Minimisation
Only collect the data strictly necessary to confirm a user’s age or age range, and do not retain it for longer than necessary.
Transparency
Your privacy notice must clearly explain why age assurance is required, what data is collected, how long it is stored, if it is shared with any third parties, and how users can exercise their data protection rights.
The Children’s Code
If you cannot establish a user’s age with certainty, you must apply the standards of the Children’s Code to all users as a default baseline of protection.
Practical Next Steps
The joint statement provides a roadmap for compliance. To ensure your organisation meets both safety and privacy standards, consider the following practical steps:
Review Your Current Methods
Evaluate your current age assurance mechanisms against Ofcom and ICO guidance, ensuring self-declaration is not used in isolation. The ICO points to facial age estimation, digital ID, and one-time photo matching as current viable technologies for services enforcing a minimum age requirement.
Conduct a DPIA
Because age assurance involves significant data processing, carrying out a Data Protection Impact Assessment (DPIA) is highly recommended, and often mandatory, to map and mitigate privacy risks.
Update Your Documentation
Ensure your privacy notices and terms of service reflect your age assurance mechanisms and state any minimum age rules clearly.
How Griffin House Consultancy Can Help
Navigating the overlap between the Online Safety Act and the UK GDPR can feel complex. At Griffin House Consultancy, we specialise in helping organisations build compliant frameworks that protect both their users and their reputation.
Whether you need support drafting a DPIA for a new age assurance tool or reviewing your privacy notices, we are here to help. Get in touch with us here or call us on 01673 885533 for expert advice.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources
Ofcom and ICO Joint Statement on Age Assurance (PDF)
ICO News: Joint Statement from ICO and Ofcom on Age Assurance
Simmons & Simmons: ICO & Ofcom on Age Assurance – Key Data Protection Issues