OneID® | News and Events

Age assurance records: what a regulator can ask for

Written by The OneID Team® | 24/08/2026, 11:27

Ofcom fined Fenix International, the operator of OnlyFans, £1.05 million for failing to provide accurate information about its age assurance measures. Ofcom lists that penalty in its guidance on responding to information requests, updated 11 April 2025.

Compliance plans tend to be built around keeping a log of every check. Age assurance records do a narrower job. They let a service give a regulator an accurate written description of the methods it uses, by the deadline the notice sets.

Do you have to keep records of every age check?

No. As at 17 August 2026, no regulator has imposed a per-user, per-check audit trail for age assurance. What UK law requires is a written record of the methods a service uses and how it uses them, its risk assessment, its children’s access assessment, and an accurate and timely answer to any information notice Ofcom serves.

What the Online Safety Act actually requires you to keep

Three record duties matter here, and they sit in different parts of the Act.

Section 36(7) requires a provider to make and keep a written record, in an easily understandable form, of every children’s access assessment. Those assessments are needed at intervals of no more than a year where a service is not treated as likely to be accessed by children, before any significant change to design or operation, and where evidence shows a significant increase in child users.

Section 23 carries the record-keeping and review duties for user-to-user services. A provider must keep a written record of all aspects of every risk assessment, and a record of any measures taken or in use to comply with a relevant duty described in a code of practice. Where a provider uses something other than a measure the code recommends, it must record which measure it did not take, what it did instead, how that achieves compliance, and how it satisfies the freedom of expression and privacy requirements. It must also review compliance regularly, and as soon as reasonably practicable after any significant change to the design or operation of the service.

Age assurance is not named in section 23. It arrives as a measure taken or in use, which means the record of your age assurance is part of your measures record rather than a document of its own. Our guide to the Online Safety Act age verification duties sets out the underlying duties those measures answer to.

Section 81 is the only place in the Online Safety Act where a record duty names age checks directly, and it applies to Part 5 services alone. For services publishing their own pornographic content, a provider must make and keep a written record of “the kinds of age verification or age estimation used, and how they are used”, and of how it had regard to protecting UK users from a breach of privacy law when deciding. It must also summarise that record in a publicly available statement.

What Ofcom can compel

Section 100 lets Ofcom require a person to provide any information it needs to exercise, or to decide whether to exercise, its online safety functions. It can require a person to obtain or generate information that does not already exist, to provide information about the use of a service by a named individual, and to permit remote viewing of systems, processes, functionalities and algorithms in real time, including information generated by a test or demonstration.

Section 102 turns that into an information notice, and section 102(8) sets the duty: a recipient must act in accordance with the requirements of the notice, and must ensure that the information provided is accurate in all material respects. Accuracy sits alongside timeliness as a separate limb, which is why a penalty can follow a full and punctual response that turns out to be wrong.

The maximum penalty Ofcom can impose is the greater of £18 million and 10 per cent of qualifying worldwide revenue. Section 109 creates criminal offences including providing information known to be false or with reckless disregard for whether it is false, and section 110 extends criminal liability to a named senior manager who failed to take reasonable steps to prevent such an offence.

Section 100(2) creates no standing duty to log anything. In practice a service can be told to produce something it never collected, to Ofcom’s timetable.

Which age assurance records are required, and where each duty sits

What Where What it covers
Children’s access assessment record Online Safety Act 2023, s36(7), Part 3 services Every assessment, in writing, in an easily understandable form
Risk assessment and measures record s23, Part 3 user-to-user services All aspects of every risk assessment, and any measures taken or in use, including alternatives to code measures and why they work
Age assurance record s81, Part 5 services only The kinds of age verification or estimation used and how they are used, plus a public summary
Accurate answer to an information notice s102(8) Complete, accurate in all material respects, by the deadline
Data protection impact assessment UK GDPR, where age assurance is likely to be high-risk processing, read with ICO expectations The age assurance process assessed against the data protection principles, and reassessed for continued fitness
Review cadence s23 Regularly, and after any significant change to design or operation

No regulator requires a log of every check

As at 17 August 2026 there is no per-check audit duty in the Online Safety Act 2023, in Ofcom’s guidance, in the Australian Online Safety Act 2021, in eSafety’s guidance, in the Digital Services Act, or in ICO guidance. Where a vendor or a guide says otherwise, ask which provision it is relying on.

The Information Commissioner has been explicit in the other direction. Its opinion on age assurance for the Children’s code, published in January 2024 and under review following the Data (Use and Access) Act 2025, states that where a hard identifier is used to assess age, a service may only need to retain a yes or no output once the check is complete. The same opinion says that in many cases seeing an official document such as a passport or driving licence may be excessive, because a method processing less personal information can still be proportionate to the risk.

The record duties call for documents that describe a system. Ofcom’s information powers are wider, and they reach information about the use of a service by a named individual. The limit lies in what a service is obliged to have kept in advance, which does not include the evidence behind each check, and data protection law points away from holding it.

Australia asks for the evidence and requires the data destroyed

Australia pairs an active regulator with a statutory duty to destroy. Under the social media minimum age provisions of the Online Safety Act 2021, as set out in Australian Information Commissioner guidance dated 23 October 2025, platforms and age assurance providers must not use or disclose personal information collected for age assurance for any purpose other than determining whether the individual is age-restricted, and must ringfence and destroy it. The same provisions bar a platform from collecting government-issued identification for age assurance unless a reasonable alternative method is also offered.

At the same time, eSafety issued 23 legally enforceable information-gathering notices to 10 platforms in the first three months of its social media minimum age obligation, and five of those platforms became the subject of active investigations. Those figures come from its compliance update of March 2026, and no later update was published as at 17 August 2026.

A platform served with one of those notices has to describe its methods and its escalation behaviour while holding almost none of the underlying personal data. That leaves its method-level records and its documented process.

Australia’s bill and Ofcom’s October deadline

A bill before the Australian Parliament would roughly double the maximum penalty and let the Commissioner issue directions requiring platforms to produce evidence demonstrating the steps they have taken to prevent under-16s obtaining accounts. The power would extend to third parties, including age assurance providers and app stores. A Senate-referred inquiry is due to report by 25 August 2026. As at 17 August 2026 it remains a bill and not law, and it is the closest any jurisdiction has come to a produce-the-evidence power on age checks.

In the UK, Ofcom must deliver a rapid assessment to Parliament by the end of October 2026 on what highly effective age checks look like in practice for determining whether someone is over 16. Its July 2026 report already tells services to conduct vendor due diligence and to review their existing age assurance against identified areas for improvement as a matter of urgency.

Records worth keeping that no rule requires

None of the following is a legal duty as at 17 August 2026. Services that answer an information notice comfortably tend to hold most of it anyway.

Prudent practice Why a service keeps it
Per-check metadata: method used, timestamp, outcome, escalation path Answers a question about a specific period without generating the answer from scratch
Vendor due diligence files, including certification evidence for every provider in the chain Ofcom’s July 2026 report asks services to conduct this due diligence
A retention schedule covering what is kept and for how long Makes the data protection impact assessment checkable against actual behaviour
Completion and failure rates by method The only way to know whether a check is refusing eligible users
A written record of how a threshold or challenge age was chosen The reasoning is what a regulator asks about, and it is rarely written down at the time
A documented escalation policy for an inconclusive result eSafety treated repeated identical attempts as insufficient in its March 2026 compliance update

Where OneID fits

As at 17 August 2026, OneID Limited is listed on the UK digital verification services register for the identity, attribute, orchestration and holder service provider roles, certified against the DVS trust framework. It covers five of the seven methods Ofcom names as at August 2026 as capable of being highly effective: open banking, photo ID matching, facial age estimation on-device through Regula, mobile network operator age checks, and digital identity services.

Because a check is routed across methods from one integration, a service describes one process to a regulator instead of one process for every method it has added separately. The platform receives an age result rather than a document, and the check runs without the platform collecting or retaining identity documents. Nothing in the written description a service produces depends on keeping personal data. Our piece on the Data (Use and Access) Act 2025 and age checks covers what certification against the framework does and does not tell a buyer.

For the person being checked, none of that is visible. Someone who has verified once confirms through their banking app or a credential they already hold, with no document to photograph and nothing to upload.

Work out which age assurance records you could produce today if an information notice arrived tomorrow. Our six criteria for choosing an age assurance method treats that as one of six things worth scoring, and our global briefing on age assurance records and requirements sets out what each of the jurisdictions it covers currently expects.

Frequently asked questions

How much notice does Ofcom have to give? Section 102(3) requires an information notice to specify the information sought, why Ofcom require it, and the form, manner and timing of the response. Where the notice requires remote viewing of systems under section 100(3), section 102(5) sets a minimum of seven days’ notice. Other deadlines are set in the notice itself.

What records does Ofcom require about age assurance? For user-to-user services, age assurance sits inside the section 23 record of measures taken or in use, alongside the written risk assessment. Section 36(7) requires a written record of every children’s access assessment. Only section 81, covering services publishing their own pornography, names age verification and estimation directly.

What is an Ofcom information notice? A notice under section 100 requiring a person to provide information Ofcom needs for its online safety functions. The information does not have to exist already: Ofcom can require it to be generated, and can require remote viewing of systems in real time. Section 102(8) obliges the recipient to comply, accurately in all material respects.

What happens if we get the information wrong rather than late? Accuracy is a separate limb of the duty, so a response that is inaccurate in a material respect breaches it even when it arrives on time. Ofcom has fined the operator of OnlyFans £1.05 million for failing to provide accurate information about its age assurance measures. Section 109 also creates criminal offences for knowingly false information.

Should we store the documents used to verify a user’s age? The Information Commissioner’s position points the other way. Its 2024 opinion on age assurance, now under review, says that where a hard identifier is used, a service may only need to retain a yes or no output once the check is complete, and that seeing an official document may in many cases be excessive. Australia’s social media minimum age rules require such data to be destroyed.

Is a per-check record worth building if no regulator requires it? It is a commercial judgement, and no regulator requires it as at 17 August 2026. Both Australia and the UK are moving that way. An Australian bill would let the regulator direct platforms to produce evidence of the steps they have taken, and a Senate inquiry on it reports by 25 August 2026. Assembling that record under a notice costs considerably more than holding it.