Can you prove your age without handing over your ID?

Can you prove your age without handing over your ID?

You hit an age gate. The site wants proof you are old enough, and for a second you weigh it up: photograph your passport, upload your driving licence, take a selfie, and trust a company you have never dealt with to hold all of it. Plenty of people close the tab at that point.

You can prove your age without handing over your ID. Age verification without ID relies on several accepted, regulator-recognised methods that confirm you are over a given age without ever sharing or keeping the document itself. The site learns one thing, that you clear the threshold, and nothing more.

That distinction matters more as age checks spread across social media, gambling, alcohol and adult content. The worry is less about any single check and more about scattering copies of your passport across dozens of websites.

Can you verify your age without ID?

Yes. You can confirm you are over an age threshold without uploading or storing an identity document. A bank can attest you are over 18 without sharing your date of birth, your device can estimate your age without keeping the image, and your mobile network can confirm you have no age restrictions. A reusable credential lets you verify once and reuse the result elsewhere.

Why people do not want to upload their ID to every site

The concern behind the age-check debate is straightforward. A single passport photograph sitting in one company’s database is a manageable risk. The same photograph copied to every social platform, shop and forum you visit is a different problem, and one you cannot take back once it is done.

Regulators have acknowledged this directly. The ICO and Ofcom exist on two sides of the same issue: children need protecting online, and the data collected to protect them needs protecting too. In March 2026 the ICO wrote an open letter to technology firms to strengthen age checks and protect children’s data at the same time. The message was that an effective age check must not turn into a mass ID-collection exercise.

For a parent, the tension is sharper still. A check meant to keep a 15-year-old off a platform should not require that same teenager to submit government identity documents to prove how old they are. The point of a good method is to answer the age question and collect nothing beyond it.

Four ways to confirm your age without sharing a document

Ofcom lists several methods it considers highly effective for age assurance. Some, like photo ID matching, are document-based by design. Others confirm your age from a signal you already have, without a document changing hands. Four of them share that data-minimising quality.

Open banking. With your permission, an age-check service asks your bank to confirm one fact: that you are over 18. Your full date of birth is not shared, and no document is uploaded. The bank already knows how old you are, so it attests the threshold and nothing else.

On-device facial age estimation. The features of your face are analysed to estimate your age, with no identity document involved. Where the analysis runs on your own device, the image need not be uploaded or retained at all. Ofcom found this was the method most commonly recalled by 8 to 17-year-olds asked to prove their age, and exposure to it rose from 25 per cent in July 2025 to 43 per cent in January 2026.

Mobile network operator age checks. Your mobile network already applies age filters to some numbers. An age-check service can confirm whether those restrictions are present. If there are none, that confirms you are over 18, with no document or selfie handed over.

Reusable digital identity credentials. Digital identity services include wallets that can securely store and share information proving your age in a digital format. You verify your age once, then reuse that confirmation elsewhere, rather than repeating a full check on every site.

The difference between these methods and a document upload is what the receiving site ends up holding.

Method

What it proves

What is shared or kept

Open banking

You are over 18

The bank confirms the threshold. Your date of birth is not shared and no document is uploaded.

On-device facial age estimation

You are over or under a given age

Where analysis runs on your device, the image need not be uploaded or retained. No identity document is used.

Mobile network operator check

You are over 18

The network confirms your number has no age restrictions. No document or selfie is handed over.

Reusable digital credential

Your age, from a credential verified once

You share a confirmation, not the underlying document, and reuse it across services.

What “nothing kept” actually means

The reason these methods can avoid storing your documents comes down to a principle in data protection law rather than a marketing promise.

Article 5(1)(c) of the UK GDPR sets out data minimisation. The ICO describes it as a requirement that personal data be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. In plain terms, a service should identify the minimum personal data it needs, hold no more than that, and not collect information on the off-chance it might be useful later.

Applied to an age check, the necessary fact is usually whether you clear a threshold. It does not need your date of birth, your address, or a stored copy of your passport. When facial age estimation runs on your device, the image can be processed and discarded without ever being uploaded, which is data minimisation working as designed rather than a claim about every implementation.

This is also why the regulators are working together. The ICO and Ofcom published a joint statement on age assurance in March 2026, setting out how services can meet the Online Safety Act 2023 and UK data protection law at the same time. An age check that collects only what the check needs satisfies both.

Does a privacy-friendly check still count as a proper age check?

Collecting less data does not mean settling for a weaker check. Ofcom sets a bar that any method has to clear, whatever data it collects. In Ofcom’s words, a method “must be technically accurate, robust, reliable and fair in order to be considered highly effective”.

Those four criteria mean the method is correct under test conditions, holds up in real-world use, produces reproducible results from trustworthy evidence, and avoids or minimises bias. A method can confirm a threshold without collecting a document and still meet every one of them. What does not meet the bar is self-declaration, a user simply ticking a box to say they are old enough.

The methods above are built to hold up as effective checks while collecting only threshold confirmation, which is the entire point of the regulators’ joint work.

What this means for the under-16 debate

Most of the current attention sits on younger users. Australia has brought in an under-16 restriction on social media, and the UK government has said it will legislate on minimum-age enforcement, with measures anticipated rather than in force today. The live duties come from the Online Safety Act, which already requires highly effective age assurance for certain services and is enforced now.

Whichever way the rules settle, the practical question stays the same. If platforms have to confirm that a user is old enough, the method used should confirm that fact and collect nothing beyond it. A reusable credential or an on-device estimate answers the age question for a 16-year-old without asking that teenager to upload government identity documents to every service they use.

For a fuller picture of the proposals and the current rules, see the social media age limit: what is changing and how age checks would work. To understand why different ages call for different checks, see why 18, 16 and 13 need different age checks.

Where this capability comes from

Confirming a threshold without storing documents depends on connecting several of these methods and routing each check to the one that fits. That is infrastructure work, and it is regulated.

OneID is certified under the UK’s Digital Verification Services Trust Framework, and is the first certified Holder and Wallet provider. It offers bank-verified identity, document authentication, on-device facial age estimation and mobile network age checks through a single connection, so a service can confirm the fact it needs without collecting a full identity dossier. The reusable age credential, verify once and reuse a certified age attribute, is a capability that certification supports rather than a finished consumer product you will find on every site today.

Document methods still have their place, and OneID provides them too. Data minimisation keeps documents in the picture where a check genuinely needs them, while making sure a check only ever collects what that particular check requires.

For the criteria that decide whether any of this counts as a proper check, see age assurance vs age verification vs age estimation. For how accurate these methods are at the tricky 16-to-18 boundary, see how accurate age verification is, and what happens at the 16-to-18 boundary.

Frequently asked questions

Can you verify your age without uploading ID? Yes. Methods such as open banking, on-device facial age estimation, mobile network operator checks and reusable digital credentials can confirm you are over an age threshold without you uploading or storing an identity document. The service learns only that you clear the threshold.

Does open banking share my date of birth? No. With open banking, you give permission for your bank to confirm one fact, that you are over 18. Ofcom’s guidance is clear that your full date of birth is not shared, and no document is uploaded to the service running the check.

Is my image stored when I use facial age estimation? It depends on how the method is built. Where the analysis runs on your own device, the image can be processed and discarded without being uploaded or retained. Under Article 5(1)(c) of the UK GDPR, a service should hold no more personal data than the check requires.

What is a reusable digital identity credential? It is a way to verify your age once and reuse the result. Digital identity wallets can securely store and share information proving your age in a digital format, so you share a confirmation rather than repeating a full check, and without re-sharing the underlying document each time.

Does a no-document age check still meet the rules? It can. Ofcom requires any highly effective method to be “technically accurate, robust, reliable and fair”. A method that confirms a threshold without collecting a document can meet all four criteria. Self-declaration, simply ticking a box, does not.

Is there a law banning under-16s from social media in the UK? Not currently. The Online Safety Act 2023 requires highly effective age assurance for certain services and is enforced now. Tighter minimum-age enforcement for under-16s has been proposed and is anticipated, but is not yet in force. Australia has brought in an under-16 restriction, which serves as a precedent only.

Recent posts

Age assurance vs age verification vs age estimation

Which age check are you actually asking your users to do?

How accurate is age verification, and what happens at the 16-to-18 boundary

Your check says a 19-year-old might be 16. Here is why, and what to do about it

Why 18, 16 and 13 Need Different Age Checks

One age gate can’t cover an 18-year-old buying wine and a 13-year-old signing up to an app