At a Glance
- Age verification is now a binding requirement under the EU’s Digital Services Act, GDPR-K, and the UK’s Online Safety Act.
- The European Commission has set a 31 December 2026 target for Member States to make privacy-preserving age verification available, backed by a free, open-source EU age verification app.
- The Court of Justice of the European Union ruled in June 2026 that a Member State can require age verification from a service established elsewhere in the EU, narrowing the country-of-origin principle as a shield against national child-protection rules.
- Ofcom has issued a fast-escalating series of fines against platforms that fail to deploy “highly effective” age assurance, with penalties reaching up to 10 percent of global turnover.
- Self-declared age no longer meets the regulatory bar in the EU or the UK; age verification must be built into the consent flow, not bolted on as a separate check.
Age verification requirements are expanding fast across the EU and UK, from the Digital Services Act and GDPR-K to the UK Online Safety Act and France’s SREN law. This article covers the regulations, the cost of non-compliance, and building an auditable, privacy-preserving age verification process for European and UK markets.
Age verification has moved from a niche compliance question for adult content and gambling into a mainstream obligation for almost any digital service accessible to minors in Europe. Among the Digital Services Act (DSA), GDPR’s child-specific provisions, the UK’s Online Safety Act, and a wave of national laws led by France, European and UK regulators are converging on the same message: good intentions and a date-of-birth field are not enough.
The pressure is coming from multiple directions at once. The European Commission has preliminarily found Meta and TikTok in breach of the DSA over how they handle minors.
Ofcom, the UK communications services regulator, has fined a growing list of platforms under the Online Safety Act, with penalties that now reach into seven figures. And in June 2026, the EU’s top court handed down a ruling that changes how far a single Member State’s age-verification rules can reach across borders.
This article sets age verification compliance requirements across the EU and UK, the enforcement risks businesses now face, and how to put a defensible, privacy-preserving process in place.
What Is Age Verification, and Why Does It Matter Now in Europe?
Age verification is the process of confirming that a person attempting to access digital content or services meets a defined age threshold before that access, or data collection, is granted. It has historically been associated with regulated industries like alcohol, gambling, and adult content, but European and UK regulators have expanded its reach dramatically over the past two years.
Children’s data has long been subject to heightened protection under the GDPR. What has changed is enforcement. The Digital Services Act now treats minors’ safety as a platform-wide duty, France has built the toughest national age-verification standard in force anywhere in the EU, and the UK’s Online Safety Act has moved from statute into an active, fining regulator within a single year.
Who Counts as a Minor Across the EU and UK?
The answer varies by jurisdiction and by law, which creates real complexity for any business operating across multiple European markets. For example:
GDPR / GDPR-K (EU)
Art. 8 GDPR sets the age of digital consent at 16 by default, but Member States may lower it to as young as 13, so the applicable threshold depends on which EU country a visitor is in. Germany, France, and several others have set it at 16, but others, including Ireland, at 13.
UK GDPR
The UK’s data protection framework sets the age of digital consent at 13.
UK Online Safety Act
Applies child-safety protections to everyone under 18, regardless of the GDPR consent age.
France (SREN law)
Sets 18 as the threshold for accessing pornographic content, enforced independently of GDPR’s consent-age provisions.
EU age verification framework (2026)
The Commission’s Recommendation defines a “minor” as anyone under 18 for the purposes of its common age-verification approach, while leaving individual member states free to set the relevant age for specific content categories anywhere from 13 to 18.
For businesses with a pan-European footprint, designing for the most protective standard in play is increasingly the only workable approach. That’s typically 18, or the lowest GDPR consent age among the countries served. A single “EU-wide” age isn’t something the current framework offers.
Age Verification Laws: The EU and UK Regulatory Landscape
The regulatory frameworks governing age verification in Europe span EU-wide law, UK statute, and a growing set of national rules led by France. The GDPR remains the foundation.
GDPR and GDPR-K: The Foundation of EU Children’s Data Protection
The GDPR’s child-specific provisions — often shorthanded as GDPR-K — require age-appropriate consent mechanisms and grant children, and their parents or guardians, significant rights over how their data is used.
GDPR-K violations carry the same penalty ceiling as the wider Regulation: up to EUR 20 million or four percent of global annual turnover, whichever is higher.
Because the age of digital consent floats between 13 and 16 depending on the Member State, a service that treats “16” as a single EU-wide threshold is applying the wrong age in several countries. This is precisely the kind of patchwork that has pushed many businesses toward a single, more protective internal standard rather than trying to track two dozen national variations.
The Digital Services Act: A Platform-Wide Duty to Protect Minors
The Digital Services Act prohibits profiling-based advertising directed at minors and requires platforms accessible to minors to assess and mitigate risks to their privacy, safety, and mental wellbeing. That includes risks from addictive design features such as infinite scroll and autoplay. The Commission published detailed guidelines on protecting minors in July 2025, and enforcement has followed quickly.
Notably, no article of the DSA names age verification itself as a mandatory, standalone measure. The obligation is to take “appropriate and proportionate” steps to protect minors. Regulators are increasingly treating self-declared age and weak estimation methods as falling short of that standard. DSA non-compliance can result in fines of up to six percent of a provider’s total worldwide annual turnover.
The EU’s Common Approach: The Age Verification App and the December 2026 Deadline
In April 2026, the European Commission announced that it had developed a free, open-source EU age verification app, built to work like a digital proof of age. Users verify their identity once using a passport or national ID, then prove they meet an age threshold for any participating service without disclosing their date of birth or identity.
The Commission has encouraged Member States to make effective, privacy-preserving age verification available to all EU citizens by 31 December 2026, either as a standalone app or integrated into national European Digital Identity Wallets.
France, Denmark, Greece, Italy, Spain, Cyprus, and Ireland are piloting the app during 2026 as front-runner Member States. The Recommendation is non-binding, and it does not resolve the underlying question of whether age verification is legally mandatory under the DSA. But it does set a clear direction of travel, and it means “we’re waiting for an EU standard” is no longer a credible reason to delay.
France’s SREN Law and Arcom: Europe’s Toughest National Standard
France’s SREN law (Loi n° 2024-449) gives the audiovisual and digital regulator Arcom the power to fine, block, or delist pornographic services that fail to verify users’ ages, including services established in other EU or EEA countries.
Arcom’s technical standard requires at least two age-verification methods, at least one operating under a “double-blind” model that keeps the verifying third party and the content platform from ever both holding a user’s identity and their browsing activity.
Penalties reach EUR 150,000 or two percent of worldwide annual turnover, whichever is higher, plus the power to order blocking within 48 hours.
The law has been tested repeatedly in court. Aylo (owner of Pornhub, YouPorn, and RedTube) withdrew its sites from the French market twice in 2025 rather than comply, and the underlying legal question of whether France can impose these rules on services established elsewhere in the EU went all the way to the EU’s top court.
The UK: Online Safety Act and the Children’s Code
The Online Safety Act came into full force for child-protection duties on 25 July 2025, requiring platforms that host pornography or other primary priority content to use “highly effective” age assurance to keep children out. Ofcom has been explicit that self-declared age does not meet that bar.
Separately, the UK’s Children’s Code (Age Appropriate Design Code) requires protective default settings for any service likely to be accessed by under-18s, regardless of whether it hosts adult content. Non-compliance with the Online Safety Act’s child-protection duties carries penalties of up to GBP 18 million or 10 percent of global turnover, whichever is higher, and, in the most serious cases, personal criminal liability for senior managers.
Age Verification Failures: The Real Cost of Non-Compliance
Regulatory penalties are the most visible consequence of weak age verification, but they’re no longer the only one. A single landmark court ruling, a run of confirmed platform fines, and an EU enforcement docket that’s grown busier by the month all point to the fact that regulators expect documented processes and working systems, not policy statements.
The CJEU’s Landmark Cross-Border Ruling
On 16 June 2026, the Court of Justice of the European Union’s Grand Chamber ruled in Joined Cases C-188/24 (WebGroup Czech Republic and NKL Associates) and C-190/24 (Coyote System) that a Member State can require age verification from a pornographic service established in another EU country, where doing so is a proportionate measure to protect minors.
The ruling arose directly from France’s dispute with Aylo and other cross-border operators, referred by the French Conseil d’État.
For roughly 25 years, the “country-of-origin” principle underpinning EU digital services law meant a business generally only had to satisfy the rules of the Member State where it was established. This judgment doesn’t abolish that principle, but it confirms that child protection can justify a destination state imposing its own age-verification requirements regardless of where a service is based.
The same ruling also found that algorithmic control over content distribution can remove a platform’s hosting-liability protection. Businesses that have relied on establishing in a more permissive Member State should treat this as a live compliance signal, not adult-industry news that doesn’t apply to them.
For scale, the largest child-privacy penalty for an FTC violation anywhere in the world to date remains the USD 275 million COPPA penalty against Epic Games in 2022 (USD 520 million once a separate dark-patterns billing settlement is included), but the CJEU ruling, and the enforcement activity below, show European and UK regulators closing that gap quickly.
DSA Enforcement: Meta, TikTok, and X
The European Commission has moved from guidance to active enforcement against some of the largest platforms operating in Europe.
Meta (April 2026)
The Commission preliminarily found Facebook and Instagram in breach of the DSA for failing to diligently identify, assess, and mitigate the risk of minors under 13 accessing the services, despite Meta’s own terms setting 13 as the minimum age.
The Commission noted that children could enter a false date of birth with no effective check, and that Meta’s own reporting tool for underage users required up to seven clicks to reach. This is a preliminary finding and Meta can respond before any final decision or fine.
TikTok (February 2026)
The Commission preliminarily found TikTok in breach of the DSA over addictive design features and risks to teenagers.
Snapchat (March 2026)
The Commission opened a formal investigation into whether Snapchat adequately prevents under-13s from accessing the app and assesses whether users are under 17.
X (around December 2025)
X received the first confirmed DSA non-compliance fine issued by the Commission, of EUR 120 million, which is a marker of how large a final DSA penalty can be once a preliminary finding is confirmed.
A confirmed DSA non-compliance decision can carry a fine of up to six percent of a provider’s total worldwide annual turnover.
Ofcom’s Escalating Fines Under the Online Safety Act
Ofcom has issued a fast-growing string of penalties against services that failed to deploy “highly effective” age assurance, and against those that ignored its information requests during investigations.
8579 LLC (February 2026)
GBP 1.35 million — the largest fine yet in this enforcement strand — plus a separate GBP 50,000 for failing to respond to a statutory information request.
Kick Online Entertainment S.A. (February 2026)
GBP 800,000 for failing age-assurance duties across 34 adult websites, plus GBP 30,000 for non-cooperation.
AVS Group (December 2025)
GBP 1 million for failing to implement highly effective age assurance across 18 adult websites, plus GBP 50,000 for failing to respond to information requests.
4chan (November 2025–March 2026)
An initial GBP 20,000 fine for failing to provide an illegal-content risk assessment, followed by a further GBP 520,000 in March 2026 across failures to implement age assurance, complete a risk assessment, and set out user protections in its terms of service, with daily penalties layered on top until the underlying failures were resolved.
XGroovy (2026)
GBP 730,000 for age-verification failures and non-cooperation, plus a daily penalty until information was provided.
Ofcom’s own reporting shows the impact: the proportion of children encountering highly effective age checks rose from 25 percent to 43 percent between July 2025 and January 2026, and more than 69 million age checks were completed in the second half of 2025 alone. That’s a 23-fold increase on the prior six months.
Criminal Liability in the UK and EU
The UK’s Online Safety Act is the clearest example currently in force. Senior managers of an in-scope service can face criminal liability if their company fails to comply with a confirmation decision from Ofcom relating to children’s safety duties, or fails to see that the company responds to Ofcom’s information requests. These are active provisions, as Ofcom’s enforcement program is already running.
The EU’s Digital Services Act allows national Digital Services Coordinators to impose sanctions on individuals responsible for compliance failures at Very Large Online Platforms (VLOPs), though no individual criminal prosecution under the DSA has been publicly confirmed to date.
Reputational Damage and Consumer Trust
Quantifying reputational harm is difficult, but the pattern holds across markets. Enforcement actions attract sustained media coverage, and coverage focused on child-safety failures is difficult for a brand to recover from.
Usercentrics’ own State of Digital Trust Report has found that consumers, and parents in particular, are increasingly attentive to how companies handle children’s data. This is a trend that makes the reputational stakes of getting age verification wrong more commercially significant than ever.
Emerging Risks Making Age Verification More Critical Than Ever
Age verification is not a problem businesses can solve once and set aside. The risk landscape in Europe is expanding on three fronts at once.
AI-Generated Content and the EU AI Act
Generative AI has sharply lowered the cost of producing persuasive, personalized, and potentially harmful content at scale, including content that can reach minors without robust age gating in place.
The EU AI Act requires that AI-generated content, including deepfakes, be clearly disclosed under its Article 50 transparency obligations, which took effect on 2 August 2026 as originally scheduled.
Following the EU’s Digital Omnibus on AI, which was adopted 29 June 2026 and in force from 27 July 2026, the more demanding high-risk system obligations under Annex III were pushed back to 2 December 2027, but the core Article 50 disclosure duty was not delayed.
A related watermarking sub-obligation under Article 50(2) does carry a short grace period, to 2 December 2026, but only for systems already on the market before August 2026.
The AI Act separately recognizes children as a distinct vulnerable group requiring specialized protection, and the European Parliament has proposed an EU-wide minimum age of 16 for access to AI companion services.
The Attention Economy Under the DSA and Children’s Code
Behavioral design features, such as infinite scroll, autoplay, push notifications, and algorithmically curated feeds, are now directly within scope of European child-safety regulation, not just data protection law.
The DSA requires platforms to assess and mitigate the risks these features pose to minors’ mental health and wellbeing, and the Commission’s preliminary finding against TikTok was built specifically around addictive design. The UK’s Children’s Code requires protective default settings for any service likely to be accessed by under-18s.
The Commission has signaled it will propose a Digital Fairness Act, potentially by Q4 2026, to extend obligations around dark patterns, addictive design, and manipulative personalization.
Third-Party Data Ecosystems Under the GDPR and the DSA
Most digital services rely on networks of analytics, advertising technology, and data-management tools that collect their own data from visitors. Under the GDPR, processing a minor’s data through these third-party tools requires the same age-appropriate consent basis as first-party processing. A business cannot outsource that obligation to its vendors. The DSA adds a platform-level duty to assess how third-party integrations contribute to risks facing minors.
For businesses running standard tag-based marketing and analytics stacks, the practical implication is the same one regulators keep repeating. An age gate that isn’t connected to the systems governing what data gets collected, shared, and processed doesn’t achieve much on its own. For a minor, most of that processing needs to be blocked or restricted automatically, from a single source of truth, not reassembled after the fact from two separate tools.
What Effective Age Verification Looks Like Under EU and UK Standards
Regulators across Europe have converged on broadly the same expectations, even where their specific legal bases differ. An effective, defensible age-verification process shares several characteristics.
It Operates Before Any Data Collection Begins
Nothing should be collected, processed, or shared before a visitor’s age status is confirmed. Ofcom and the European Commission have both made clear they’ll examine what a system actually does technically, not simply whether a gate is present on the page.
It Is Configurable by Jurisdiction and by Content Type
The range of thresholds in play is notable. The GDPR-K’s 13–16 range by Member State, the UK’s 18 under the Online Safety Act and Children’s Code, France’s 18 for adult content under the SREN law — all these age thresholds and the obligations they trigger need to be adaptable, not hard-coded to a single number.
It Is Auditable
Regulators increasingly expect documented evidence that a system is working, not just an assertion that it exists. Ofcom’s pattern of pairing a substantive age-assurance fine with a separate fine for failing to respond to an information request shows how far this has moved. Providers are now expected to be able to show their work.
It Automatically Applies Appropriate Protections
Identifying a minor is only the first step. Once a minor is detected, data collection needs to be blocked and age-appropriate defaults applied. This needs to be done automatically, not as a manual follow-up step.
It is integrated, not bolted on
A standalone age-verification tool operating separately from a business’s consent management infrastructure creates gaps between the two systems. Age status and consent should be managed from a single source of truth.
How Usercentrics Age Verification Gate Supports Compliance
Usercentrics Age Verification Gate is built directly into the Usercentrics Consent Management Platform, which already supports compliance with the GDPR, the UK GDPR, and other regulations.
When a visitor arrives at a site, the Age Verification Gate presents a simple age prompt before any content is accessed or data is collected. Visitors who confirm they meet the age threshold proceed to the standard consent banner as usual. Visitors who don’t are redirected to a page the business configures, such as a children’s privacy notice.
When configured for the EU and UK, visitors identified as minors are automatically redirected, with data collection blocked and applicable rights applied. Age thresholds, redirect behavior, branding, and audit logs are managed from within the existing Admin Interface, the same one already in use for consent management, with no separate tool to integrate and no engineering resources required for configuration.
The built-in age prompt is a self-declaration step. As this article notes, EU and UK regulators increasingly treat self-declaration alone as insufficient for higher-risk services, so businesses subject to the Online Safety Act’s “highly effective” age-assurance duty or comparable national standards should assess whether additional or complementary verification methods suit their specific risk profile.
