Check what an age check actually does with your data

Age verification is now a condition of entry to adult sites in several countries. Before you pass one, you can establish who receives your information.

Age verification is now a condition of entry to adult sites in several countries. Before you pass one, you can establish who receives your information, which third party performs the check, how long anything is kept, and whether a less revealing route exists.

Gather what you need before you start

The trigger for this guide is a live regulatory question. The BBC reports that a regulator is investigating Pornhub over its age checks, and that it has concerns about the site’s reliance on third-party checks supplied by Apple for some of its users. The material available does not name the regulator, spell out which users are routed through the Apple check, or say what outcome the investigation might reach. Those details are not known here, and nothing below assumes them.

What you need for the audit itself is modest: a browser you can open a second tab in, the patience to read two privacy notices rather than one, and an up-to-date note of which operating system version your phone or computer is running, because device-level age signals depend on it. It also helps to know, before you begin, which verification methods are generally treated as capable of being effective — document checks, facial age estimation, credit card or open banking checks, mobile network operator checks, and digital identity wallets — and which are not, such as simply ticking a box to declare yourself an adult.

What you do not need is your passport. Handing over an identity document is one route among several, and it is usually the most revealing. Treat it as a last resort rather than a default, and do not upload anything until you have finished the steps below.

Work out which method you are being offered

Sites do not all use one check, and the same site may use different checks for different users, devices or countries. Look at the interstitial page carefully. If it asks you to photograph a document, that is a document check. If it asks you to look into a camera, that is facial age estimation. If it asks you to sign in to a bank, that is an open banking check. If it simply says your device has confirmed you are over 18 without asking you anything, you are being given a platform or device-level signal.

That last category is the one at issue in the reported investigation. Device-level checks work by having the operating system or account provider pass an age range to the site, rather than the site inspecting evidence itself. The site learns only that you fall inside or outside a bracket. That is attractive from a privacy standpoint, and it is also the reason it draws regulatory scrutiny: the answer is only as good as the date of birth held on the account behind it.

Find out who the third party is

The site’s own privacy notice will rarely be the whole story. Age checks are usually contracted out, so there are at least two organisations handling your data: the site, and the verification provider. Find the provider’s name, which is normally disclosed on the check page itself or in a linked notice, then read that provider’s notice separately.

You are looking for three things. First, what the provider sends back to the site — a plain pass or fail, or something richer such as your name or exact date of birth. Second, whether the provider is told which site you are visiting, because a provider that knows both your identity and the destination holds a far more sensitive record than one that does not. Third, whether the check is described as double-blind or tokenised, meaning the two parties are deliberately prevented from combining what each knows.

Check what the device-level route shares

If you are offered a device or account-level check, find out what it actually transmits. The design principle behind these systems is minimisation: the site receives a bracket, not a birthday, and ideally cannot tell which account produced it. Confirm whether the signal is generated locally on your device or by a remote server, and whether the platform is told which site made the request.

Then consider the accuracy question from the other direction. The range reflects information already held on the account, which may have been entered years ago, may be wrong, and may belong to someone other than the person at the keyboard. A shared tablet, a hand-me-down phone, or a child signed in to an adult’s account all break the link between the signal and the person. This is the practical weakness a regulator would be expected to probe, and it is worth understanding whether or not the current investigation turns on it.

Choose the least revealing option available

Once you know the menu, rank it. A check that returns only a yes or no, and that does not tell the verifier where you are going, exposes less than one that requires a photograph of an identity document held in a provider’s database. Email-based estimation and mobile operator checks sit in between, in that they tie the result to an identifier you use elsewhere.

Where a site offers several routes, it is usually because different methods suit different users, not because one is officially preferred. If the only option is a document upload and you are not willing to make it, closing the tab is a legitimate outcome of this audit. If a site offers no check at all in a jurisdiction that requires one, that tells you something about how seriously it handles the rest of its obligations.

Check retention, deletion and re-use

Ask what happens after the check passes. The privacy notice should say how long verification data is held, whether images and documents are deleted once a result is produced, and whether any of it is re-used for fraud prevention, model training or analytics. Data protection law in the UK and EU pushes towards holding as little as possible for as short a time as possible, but the specific retention period is set by the provider, and you have to read it to know.

Look for a deletion mechanism and a contact route for data subject requests. Note the answers somewhere, along with the date and the provider’s name. If the provider is later breached, that record is what allows you to work out whether you were affected rather than guessing.

Avoid the mistakes people actually make

The most common error is auditing the site and stopping there, when the provider holds the sensitive material. The second is assuming a check that feels frictionless is therefore private: a one-tap confirmation can still involve a request that identifies the destination site. The third is treating an age check as an identity check, and volunteering a full document when a narrower option was available on the same page.

People also over-trust the appearance of security. Familiar branding, a padlock, or the phrase “we do not store your data” are not verification. Confirm the claim in the notice. And a persistent mistake is reaching for a circumvention tool instead: a free VPN or an unofficial mirror moves your traffic through an operator you know even less about than the verifier you were avoiding, which is a poor trade.

Finally, do not assume an audit done once stays accurate. Methods change with regulation, and a site may switch providers or routes without announcement.

Recognise when this approach is the wrong choice

This is a personal privacy audit, and it does not do three other jobs. It is not child protection: if your concern is what a young person in your household can reach, device-level parental controls, network filtering and account restrictions are the appropriate tools, and they work whether or not a given site checks ages properly.

It is not compliance work either. An organisation deciding how to meet age assurance duties needs legal advice, a data protection impact assessment and a documented assessment of whether its chosen method is effective, not a reader’s checklist.

Nor does the audit make an untrustworthy site safe. If a site distributes malware, hosts material that should not be there, or ignores takedown obligations, establishing that its age check is well designed changes nothing that matters. And in jurisdictions where accessing such material carries legal or personal risk, the safest analysis is that no configuration of the check removes that risk.

Frequently asked questions

Why do porn sites now ask for age verification?

Several jurisdictions have introduced rules requiring services that publish pornography to use age assurance capable of reliably distinguishing adults from children, rather than relying on a self-declaration box. In the UK, this duty sits in online safety legislation and is enforced by Ofcom, which has published guidance on which methods can meet the standard. The result is that users encounter document checks, facial age estimation, banking checks or device-level signals at the point of entry.

Does an age check mean the site knows my identity?

Not necessarily. Many checks are designed so the site receives only a pass or fail, while the verification provider — not the site — handles any document or image. Some designs deliberately prevent either party from holding both your identity and your browsing destination. But this varies by provider and method, and the only way to know what applies to you is to read the provider’s privacy notice alongside the site’s own.

Are device-based age checks reliable?

They are convenient and reveal little, because the operating system passes an age range instead of a document. Their weakness is that the range depends on information already held on the account, which can be inaccurate, outdated, or belong to a different person using the same device. The BBC reports that a regulator has raised concerns about one site’s reliance on third-party checks provided by Apple for some users; the substance of those concerns is not detailed in that report.

What happens to my ID photo after an age check?

That depends on the provider’s retention policy, which should be stated in its privacy notice. Some delete images immediately after producing a result; others retain data for fraud prevention or legal reasons for a defined period. Data protection law in the UK and EU requires that personal data not be kept longer than necessary, but the specific period and any secondary uses are set by the provider, so check before you upload.

Sources and further reading

  • BBC News technology reporting, for the report that a regulator is investigating Pornhub’s age checks and has concerns about reliance on third-party checks provided by Apple for some users.
  • Ofcom published guidance on age assurance under UK online safety legislation, for which verification methods are treated as capable of being highly effective.
  • The UK Information Commissioner’s Office, for guidance on data minimisation, retention and children’s data in the context of identity and age checks.
  • Apple developer documentation, for how device and account-level age range signals are intended to work and what they transmit.

Surfaced from the rss:bbc_tech signal “regulatory scrutiny of age checks”. AI-assisted draft, editorially reviewed.

Visited 1 times, 1 visit(s) today
share this recipe:
Facebook
X
WhatsApp
Telegram
Email
Reddit