LGBT Q&A: Understanding Age Verification Data Collection in the UK
EFF Deeplinks
- As of July 2025, UK platforms hosting content deemed "harmful" by Ofcom must verify that users are over 18.
- Age verification processes carry significant privacy risks, including potential data leaks, unauthorized profiling, and long-term data retention.
- LGBTQ+ users face heightened risks, as compromised data could expose sexual orientation, gender identity, or health status, leading to discrimination or violence.
Verification Methods and Risks
- Facial Age Estimation: Uses services like Yoti or Persona. Some systems upload photos to servers; others like k-ID or Private ID process data on-device. Risks include potential image leaks revealing location or sensitive background details.
- Photo-ID Matching: Involves uploading documents like passports or licenses. This is highly sensitive; while some services claim to delete data, others (like Incode) may retain it unless explicitly requested otherwise.
- Open Banking & Credit Cards: Services access bank info to confirm age without sharing full birth dates. Credit card checks verify age by confirming the user is old enough to hold financial accounts.
- Email & Mobile Operator Checks: Third parties aggregate data from other accounts linked to an email or confirm with mobile carriers that no age-based filters are applied to the user's phone number.
Critical Privacy Considerations
- Data Handling: Users should query how much data leaves their device, who holds it, and for how long.
- Auditing: Legitimate providers should undergo security-focused audits (e.g., NCC Group, Trail of Bits) rather than mere compliance certifications.
- Visibility: Consider whether third-party verifiers are building a profile of which platforms a user is attempting to access.
EFF Stance
- The EFF opposes mandatory age-gating, arguing that no current system fully protects user privacy and that these mandates limit access to lawful speech and online communities.