What Ofcom Found XGroovy Did Wrong

Ofcom has fined the adult website XGroovy £730,000 for failing to implement effective age verification for UK users and for ignoring the regulator's formal requests for information. The penalty was issued under the Online Safety Act, which requires pornographic and other high-risk platforms operating in the UK to put in place "highly effective" age assurance measures to keep children from accessing adult content.

According to the reporting on this case, XGroovy did not have adequate systems in place to verify that its UK visitors were actually adults. On top of that, the site failed to cooperate when Ofcom sought details about its compliance efforts, an added violation that regulators have treated as seriously as the underlying age check failure itself. The combination of both failures pushed the fine to £730,000, a sum that lands squarely in the range Ofcom has been imposing on similar cases over the past year.

A Pattern, Not an Outlier

XGroovy is not the first adult site to be penalized this way, and it almost certainly won't be the last. Ofcom has now issued a string of comparable fines against adult platforms since the Online Safety Act's child safety duties took effect, each one following a similar script: a site skips or fumbles age verification, then compounds the problem by refusing to answer the regulator's questions. Just recently, Ofcom fined the adult site Fapello £630,000 for nearly identical reasons, showing that Ofcom's enforcement machinery is now running at a steady pace rather than issuing occasional one-off penalties.

The repetition matters. It suggests Ofcom has settled into a predictable enforcement rhythm: identify noncompliant sites, request information, and when providers stall or ignore those requests, escalate to a fine that often includes a separate penalty specifically for the lack of cooperation. For an in-depth look at how this enforcement regime has evolved since the law's child safety provisions came into force, the one-year retrospective on the Online Safety Act's privacy fallout lays out the broader regulatory trajectory that fines like this one are part of.

The Privacy Trade-Off Behind Age Checks

While fines like XGroovy's grab headlines, they obscure a more consequential question for ordinary users: what happens to the personal data collected during age verification. Effective age assurance under the Online Safety Act typically means uploading a government ID, submitting a facial scan, or linking a verified account through a third-party provider. Each of these methods creates a record tying a real identity to visits on an adult website, information that is far more sensitive than a simple age confirmation.

Unlike a fine, which is a one-time cost a company absorbs and moves past, a data collection system is a standing liability. Centralized age verification databases become attractive targets for hackers, and even well-intentioned verification providers can suffer breaches, sell data to third parties, or retain records longer than necessary. For users, the risk isn't that a site gets fined; it's that their identity documents or browsing habits end up exposed, sold, or leaked with no easy way to undo the damage. This is the trade-off regulators rarely emphasize when touting compliance numbers: stronger age checks often mean a wider attack surface for personal data.

Where VPNs Fit Into the Age-Gating Landscape

As UK enforcement tightens, some users turn to VPNs to avoid submitting identification altogether, effectively routing around geographic age-gating requirements rather than complying with them. This is a legal gray area with real consequences: it can violate a platform's terms of service, and it doesn't address the underlying issue of how sites handle the data of users who do verify their age through legitimate channels. It also doesn't stop enforcement, since regulators are targeting the platforms' compliance systems, not individual workarounds. The broader debate over how identity should be verified online, and at what layer of the technology stack, is unfolding well beyond the UK. Proposals like the ones covered in the look at KOSA's return to the Senate and Illinois's device-level age verification law show that similar tensions between child safety and data privacy are playing out across the United States as well.

What This Means For You

If you're a UK user of adult content platforms, expect age verification requirements to keep expanding rather than disappear. The XGroovy fine confirms that Ofcom is actively monitoring compliance and is willing to penalize both the failure to verify age and the failure to respond to its inquiries. Before submitting any identity document or biometric scan to a verification service, check whether the provider states how long it retains data, whether it stores documents at all after verification, and whether it uses a third-party processor. Reputable age verification systems should confirm your age without retaining a permanent copy of your ID.

Key Takeaways

Ofcom's £730,000 fine against XGroovy is another entry in a growing list of enforcement actions tied to the Online Safety Act's age verification rules, and it won't be the last. For users, the more important question isn't whether a site gets fined for noncompliance, but what happens to your personal data when a site does comply. Read the privacy policy of any age verification tool before using it, favor services that confirm age without storing your ID, and stay informed as UK and US regulators continue to reshape how identity and age get verified online.