Age assurance without mandated privacy-preserving architecture

openclaimed ·shipped ·
outcome →your data, yours
What is missing

Ofcom's highly-effective-age-assurance criteria under the Online Safety Act judge efficacy rather than privacy, and the ICO-Ofcom joint statement of March 2026 restates data-minimisation expectations without binding technical force. The Age Check Certification Scheme is ICO-approved and voluntary. Millions of ID and selfie uploads now sit with third parties, VPN use surged more than 1,400 per cent, and breaches have exposed verification IDs, around 70,000 through Discord's third-party provider and more through the Tea app. The EU has published a zero-knowledge age-verification blueprint with a reference app. The UK has no equivalent public infrastructure.

Why it matters

Age checks are now a permanent feature of the UK internet. Every regulated service without a required data-minimising architecture spawns a new honeypot of identity documents, and users learn that privacy and safety trade off against each other, which erodes compliance.

What would fill it

A binding UK age-assurance privacy standard from Ofcom and the ICO, requiring double-blind or zero-knowledge age proofs and prohibiting ID retention. A publicly funded open-source reference implementation and mandatory certification for providers complete it.

// State-led: Instrument: binding Ofcom/ICO privacy standard with mandatory AV-provider certification.

Why urgency 4

Age checks are permanent across the UK internet and the ID honeypots breached this year, while a ready EU zero-knowledge blueprint sits unadopted.

ATTEMPTS · 0 ACTIVEnon-exclusive
// nobody on this yet: be first
// no account: your claim posts publicly and lands in the thread below
THREAD · 0 POSTSremark42 threads launch soon · replies via github until thenopen on github ↗
// quiet so far. the dossier is the first post: reply below or take the gap.
One gap, several dossiers: entries folded into this one (1)

The research pass surfaced this gap independently in more than one domain. Those entries are merged here so the map counts it once: the same binding privacy regime for age-assurance providers; certification was one clause of the same instrument.

83 · No privacy and security certification regime for age assurance providers (Surveillance)

Since July 2025, Online Safety Act enforcement has pushed millions of UK users into face scans and ID-document uploads with third-party verifiers (used by Reddit, Discord, X, Spotify and adult sites), triggering VPN sign-up surges of over 1,000%. The risk is concrete: Discord's October 2025 third-party breach exposed about 70,000 government ID photos collected partly for UK age compliance. Ofcom assesses whether age assurance is 'effective' (report due June 2026) but does not regulate providers' security; ICO oversight is generic UK GDPR; certification (e.g. Age Check Certification Scheme) is voluntary and market-driven. No one mandates data-minimising architectures, breach transparency specific to identity documents, or on-device verification.

Its fill: Mandatory certification for age assurance providers serving UK users: data-minimisation and deletion standards, preference for on-device/zero-knowledge age proofs, identity-document breach notification duties, and a joint Ofcom-ICO audit power, all deliverable through Ofcom guidance plus targeted amendment, informed by Ofcom's June 2026 effectiveness report.

More in Privacy

Candidate entry from the July 2026 research pass, not yet validated by practitioner interviews. Added 2026-07-07 · last verified 2026-07-07 · review by 2026-10-07. Facts citing live processes (bills, consultations, contracts) decay quickly; re-verify against sources before acting.