Age assurance without mandated privacy-preserving architecture
Ofcom's highly-effective-age-assurance criteria under the Online Safety Act judge efficacy rather than privacy, and the ICO-Ofcom joint statement of March 2026 restates data-minimisation expectations without binding technical force. The Age Check Certification Scheme is ICO-approved and voluntary. Millions of ID and selfie uploads now sit with third parties, VPN use surged more than 1,400 per cent, and breaches have exposed verification IDs, around 70,000 through Discord's third-party provider and more through the Tea app. The EU has published a zero-knowledge age-verification blueprint with a reference app. The UK has no equivalent public infrastructure.
Age checks are now a permanent feature of the UK internet. Every regulated service without a required data-minimising architecture spawns a new honeypot of identity documents, and users learn that privacy and safety trade off against each other, which erodes compliance.
A binding UK age-assurance privacy standard from Ofcom and the ICO, requiring double-blind or zero-knowledge age proofs and prohibiting ID retention. A publicly funded open-source reference implementation and mandatory certification for providers complete it.
// State-led: Instrument: binding Ofcom/ICO privacy standard with mandatory AV-provider certification.
Age checks are permanent across the UK internet and the ID honeypots breached this year, while a ready EU zero-knowledge blueprint sits unadopted.
One gap, several dossiers: entries folded into this one (1)
The research pass surfaced this gap independently in more than one domain. Those entries are merged here so the map counts it once: the same binding privacy regime for age-assurance providers; certification was one clause of the same instrument.
№ 83 · No privacy and security certification regime for age assurance providers (Surveillance)
Since July 2025, Online Safety Act enforcement has pushed millions of UK users into face scans and ID-document uploads with third-party verifiers (used by Reddit, Discord, X, Spotify and adult sites), triggering VPN sign-up surges of over 1,000%. The risk is concrete: Discord's October 2025 third-party breach exposed about 70,000 government ID photos collected partly for UK age compliance. Ofcom assesses whether age assurance is 'effective' (report due June 2026) but does not regulate providers' security; ICO oversight is generic UK GDPR; certification (e.g. Age Check Certification Scheme) is voluntary and market-driven. No one mandates data-minimising architectures, breach transparency specific to identity documents, or on-device verification.
Its fill: Mandatory certification for age assurance providers serving UK users: data-minimisation and deletion standards, preference for on-device/zero-knowledge age proofs, identity-document breach notification duties, and a joint Ofcom-ICO audit power, all deliverable through Ofcom guidance plus targeted amendment, informed by Ofcom's June 2026 effectiveness report.