The Data (Use and Access) Act 2025 and age checks

Part 2 of the Data (Use and Access) Act 2025 came into force on 1 December 2025, apart from four sections that are still not commenced. It gave the UK a statutory framework and a public register for digital verification services, plus a trust mark that only registered providers may use, and that no provider is entitled to display yet. That machinery lets a business check whether the provider running its age checks is certified, and against which version of the rules. It imposes no duty on anyone to verify a customer’s age.

The distinction gets lost regularly, including by people selling verification. Age-check duties come from the Online Safety Act 2023 and from sector rules. The Data (Use and Access) Act governs the reliability of the providers, not the obligations of the businesses buying from them. As at 17 August 2026 that division is unchanged, and most of Part 2 has been live for over eight months.

What does the Data (Use and Access) Act 2025 change for age checks?

Nothing directly. It creates no age verification duty and no requirement to use a certified provider. What changed on 1 December 2025 is that the UK’s framework and register for digital verification services became statutory, so a business can now check a provider’s certification against a public register maintained under an Act.

Part 2 in five mechanisms

Section 27(1) sets out the whole of Part 2 in one sentence. It contains provision to secure the reliability of digital verification services by means of “(a) a trust framework (see section 28), (b) supplementary codes (see section 29), (c) a register (see section 32), (d) an information gateway (see section 45), and (e) a trust mark (see section 50).”

Four of those five mechanisms are working.

Mechanism Section Status as at 17 August 2026
Trust framework s.28 In force. The statutory framework is the 0.4 gamma publication. Version 1.0 is published but not yet in force
Supplementary codes s.29 In force. Codes exist for digital right to work, right to rent and DBS identity checks
Register s.32 In force and public. 46 providers offering 64 certified services as at July 2026
Information gateway ss.45 to 48 Not in force. Would let public authorities share information with registered providers at a person’s request
Trust mark s.50 In force. The mark “UK CertifID” was designated in March 2026, and no provider is entitled to display it yet

Sections 45 to 48 are the ones to watch. They would allow public authorities, including HMRC and the devolved revenue authorities, to disclose information to a registered provider at an individual’s request. Until they commence, any claim that a verification provider can check you against government records on the strength of this Act is premature.

Digital verification services, as the Act defines the term

Section 27(2) defines digital verification services as “verification services provided to any extent by means of the internet”. Section 27(3) then defines a verification service as one provided at the request of an individual which consists in “ascertaining or verifying a fact about the individual from information provided otherwise than by the individual”, and confirming that fact to someone else.

Two things follow for age checks. An age is a fact about an individual, so an age check sits squarely inside the definition. Information provided by the individual is expressly outside it, which puts a self-declared date of birth outside the statutory description of verification before any regulator has assessed its effectiveness. Ofcom reached the same place from a different direction, naming self-declaration among the methods that are not highly effective. Our piece on why a date of birth age gate is not an age check sets out the regulatory side of that argument.

The Act does not define “verified identity”, “verified attribute” or “verified data”. Section 54 lists six defined terms for Part 2 and none of them is a description of an outcome. That matters if you are reading vendor material, because those phrases are marketing terms and carry no statutory meaning.

The DVS trust framework

Section 28 requires the Secretary of State to prepare and publish a document, “the DVS trust framework”, setting out rules for providing digital verification services, after consulting the Information Commissioner. The framework specifies when it comes into force, which is why version dates matter more here than commencement regulations do.

Two versions are current on GOV.UK. As at 17 August 2026 the one in force is the 0.4 gamma publication, which carries a note confirming it is now the statutory DVS trust framework under section 28. It is still titled with the framework’s older name, which is a source of confusion worth knowing about: the document that legally binds certified providers today reads as the digital identity and attributes trust framework and is legally the DVS trust framework.

Version 1.0 was published on 9 June 2026 under section 28 and is not yet in force. It comes into force on the later of two events: the accreditation of the first conformity assessment body to certify against it, and 1 September 2026. That makes 1 September 2026 the earliest possible date and not a fixed one.

When 1.0 does come into force, a few things change at once. Providers certified against it become entitled to use the trust mark for the first time, and any provider certifying from scratch will only be able to certify against 1.0. Existing certified services get at least fifteen months to uplift, with the option of staying on 0.4 for an additional year at the next evaluation.

Nothing about the register, the Act or any age-check duty changes on that date. A platform building its age assurance plan around 1 September 2026 has picked the wrong date.

The DVS register, and what registration actually means

The register sits in section 32. The Secretary of State must establish and maintain a register of persons providing digital verification services, and must make it publicly available. It has been statutory since 1 December 2025, replacing an earlier non-statutory list, and it is maintained by the Office for Digital Identities and Attributes, part of the Department for Science, Innovation and Technology. As at July 2026 it listed 46 providers offering 64 certified services.

Under section 33 the Secretary of State must register a provider that holds a certificate from an accredited conformity assessment body. Registration entitles a provider to three things and no more. It appears on the public register. It can carry supplementary notes recording certification against a specific supplementary code, which is how right to work, right to rent and DBS checks are distinguished. And once certified against version 1.0, it can use the designated trust mark.

Registration is voluntary. Part 2 does not prohibit an unregistered business from providing digital verification services, and it does not make a certified provider a legal requirement for a buyer. The only hard prohibition in Part 2 is section 50, which bars anyone not registered from using the designated mark, enforceable by injunction, or by interdict in Scotland.

What the register is genuinely useful for is due diligence. Every certified service has a public entry in the same format, so two providers can be compared field by field.

What the Act does not do

No part of the Act obliges a business to check anyone’s age. It does not mandate digital ID. It does not require any business to use a registered provider. And certification under the DVS trust framework is not compliance with the Online Safety Act.

That last point is the one most often blurred. As at August 2026 Ofcom names seven methods as capable of being highly effective age assurance, and digital identity services is one of them. Ofcom does not certify or approve providers, and no company appears on its list. Ofcom’s Part 3 guidance on highly effective age assurance, published on 24 April 2025, says that using a service certified against the trust framework “is not an automatic means of compliance, but it may help to evidence that a service provider has had regard to the four criteria to ensure that its approach is highly effective”. The duty stays with the service.

Three provisions that reach age checks

None of the three is an age-check duty.

Section 55 amends three immigration statutes so that orders can specify documents generated by, or steps taken using, a “DVS-registered person”. That is the clearest example of the register being wired into a rule that sits outside the Act, and the same pattern could be used elsewhere.

Section 81, which is not in Part 2, amends UK GDPR Article 25 to require controllers of services likely to be accessed by children to consider the children’s higher protection matters when designing a service. It came into force on 5 February 2026 and is the part of the Act that speaks most directly to designing an age check for children.

The data minimisation principle in Article 5(1)(c) is unchanged. Personal data must still be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. The Act amended other limbs of Article 5 and added a new subsection, but not that one. A check that returns a result and retains no documents leaves a platform with less personal data to justify against that principle. That is prudent design, and the Act does not require it.

What to ask a provider

The register turns most provider claims into something checkable. Before signing anything, look up the service and read five fields: the framework version it is certified against, the roles it holds, the supplementary codes attached, the conformity assessment body, and the certificate expiry date. Then ask what the person being checked actually does, and how many alternative methods exist when the first one does not resolve. Our six criteria for choosing an age assurance method cover that second half.

Where OneID fits

OneID is a UK digital verification services provider, certified against the statutory DVS trust framework. As at 17 August 2026 the DVS register lists it for identity, attribute, orchestration and holder services, with supplementary notes for right to work, right to rent and Disclosure and Barring Service identity checks. The register entry carries the certifying body and the certificate dates, so none of that needs taking on trust.

For age checks specifically, OneID covers five of the seven methods Ofcom names as capable of being highly effective: open banking, photo ID matching, facial age estimation on-device through Regula, mobile network operator age checks, and digital identity services. The orchestration role is the one that matters when a check does not resolve first time, because it routes the user to another accepted method inside the same session instead of refusing them.

For the person being checked, this is a few taps in their banking app, or a few seconds in front of their own phone camera. They confirm they are over the threshold using an account or a credential they already hold. The platform receives a yes or a no on the age threshold, and no passport image lands on its systems to be stored and secured.

Look up any provider on the DVS register under the Data (Use and Access) Act 2025 before you shortlist them, then read our global age assurance briefing for what thirteen jurisdictions now expect from the check itself.

Frequently asked questions

Does the Data (Use and Access) Act 2025 require age verification? No. The Act creates no age verification duty. UK age-check duties come from the Online Safety Act 2023 and from sector rules. Part 2 of the Data (Use and Access) Act governs the reliability of digital verification providers through a statutory framework and a public register. It does not govern the obligations of the businesses buying from them.

When did Part 2 of the Data (Use and Access) Act come into force? Most of Part 2 came into force on 1 December 2025. The exceptions are sections 45 to 48, the information gateway provisions that would let public authorities share information with registered providers at an individual’s request. Those are still not in force as at 17 August 2026.

What is the DVS trust framework? It is the statutory document, required by section 28, setting out the rules for providing digital verification services in the UK. As at 17 August 2026 the version in force is the 0.4 gamma publication. Version 1.0 was published in June 2026 and comes into force when the first conformity assessment body is accredited against it, no earlier than 1 September 2026.

Do I have to use a certified digital verification services provider? Not under this Act. Registration is voluntary and Part 2 does not prohibit unregistered providers. The only restriction is on the designated trust mark, which unregistered providers cannot use. Where another regime sets its own rules about who may run a check, those rules sit outside Part 2, so read the one that applies to your own service.

Does DVS certification mean a provider is Online Safety Act compliant? No. Ofcom names methods capable of being highly effective age assurance, including digital identity services, but it does not certify or approve providers. Ofcom’s April 2025 Part 3 guidance says that using a certified service may help evidence that a service has had regard to Ofcom’s criteria. The duty itself stays with the service, not the provider.

How many providers are on the DVS register? As at July 2026 the register listed 46 providers offering 64 certified services, according to the first annual report on the operation of Part 2. The register is public and searchable, and it shows each service’s framework version, certified roles, supplementary codes, certifying body and certificate expiry date.

Recent posts

Why a date of birth age gate is not an age check

A date of birth box is the cheapest age gate a product team can ship. Ofcom has excluded self-declaratio...

Age verification for existing users: the back-book problem

Australia’s regulator has already put existing accounts inside the duty. Its guidance of 16 September 20...

Six criteria for choosing an age assurance method

Thirteen jurisdictions are now regulating children’s access to social media, at five different age thres...