What UK Law Actually Requires Platforms to Log During Age Checks
A common misconception about the UK's age assurance rules is that every single age check gets logged, stored, and made available to regulators on demand. New industry guidance pushes back on that assumption directly: no regulator requires a log of every age check. That distinction matters, because it separates what UK age verification data records law genuinely mandates from what platforms simply choose to retain as a business practice.
Under the Online Safety Act framework, platforms that use age assurance tools (whether that's facial estimation, ID document checks, or third-party verification services) are required to demonstrate that their systems work as intended and meet the 'highly effective' standard Ofcom has set. That means providers need some evidence their process is functioning: audit trails showing the method used, whether it passed or failed, and enough documentation to prove compliance if challenged. What it does not mean, according to the guidance, is a legal requirement to permanently store granular records tying a specific individual to a specific check, complete with the underlying document or image, indefinitely.
That's an important nuance for anyone trying to understand what happens to their data after they upload a passport photo or submit to a facial scan. The law sets a compliance bar. It does not set a data retention floor.
What Ofcom Can Compel vs. What Is Optional Record-Keeping
Ofcom's enforcement powers are real, and the regulator has already shown it's willing to use them. The ongoing Ofcom TikTok age verification probe is a clear example: when Ofcom suspects a platform failed its child safety obligations, it can open a formal investigation and demand evidence of how age checks were actually conducted, not just policy documents describing how they're supposed to work.
But there's a difference between what Ofcom can compel during an investigation and what a company decides to retain proactively, just in case. Ofcom can require records that prove a platform's age assurance process meets the required standard, things like method logs, error rates, and audit documentation. What it cannot do is force companies to retain personal identity documents or biometric scans beyond what's needed to demonstrate compliance. Any additional retention, such as keeping a scanned ID on file for months after a check is completed, is a business decision, not a legal obligation. Some platforms may over-retain data out of caution, liability concerns, or simply poor data hygiene, and that gap between what's required and what's kept is where privacy risk tends to concentrate.
Privacy Risks of Age Assurance Data Retention for Users
This distinction has real consequences for ordinary users. If the law only requires proof that a check happened, but a platform chooses to store the underlying document or biometric image anyway, that data becomes a liability sitting on a server somewhere, indefinitely, for no regulatory reason. It's the kind of over-retention that turns a routine age check into a long-term privacy exposure.
Users navigating these systems generally have no visibility into which category their data falls into. Was a passport scan discarded after verification, or archived? Was a facial estimation image deleted immediately, or kept as a training sample? The guidance suggests users should ask providers directly what their retention policy is, since UK law itself doesn't set a uniform national standard beyond general data protection obligations. This uncertainty is part of why the parliamentary debate over the Online Safety Act's privacy impact has drawn attention from MPs concerned that age verification requirements are creating new data collection risks without matching transparency requirements.
Where VPNs and Encrypted DNS Can and Can't Help
A VPN can mask your IP address and general location, and encrypted DNS can prevent your internet service provider from seeing which sites you visit. Neither tool touches the age assurance process itself. If a platform requires a facial scan, ID upload, or bank record check to prove your age, a VPN does nothing to prevent that data from being collected, transmitted, or stored by the verification provider. VPNs protect network-level metadata, not the content of a form you submit directly to a website.
What a VPN can do is reduce the amount of ancillary data collected around the verification event itself, such as your approximate location or ISP-assigned identifiers, which some platforms may log alongside the age check as part of fraud prevention. That's a modest privacy benefit, not a way to avoid age verification requirements altogether, and users should be wary of any tool marketed as a bypass for legally mandated age checks.
What This Means For You
If you're asked to complete an age check on a UK platform, the safest assumption is that your data's fate depends entirely on that specific provider's retention policy, not a uniform legal mandate. Before submitting sensitive documents, look for a clear statement about how long the data is kept and whether it's deleted after verification. Favor services that use estimation methods over document upload where possible, since estimation typically requires less permanently identifiable material. And if a platform is currently under regulatory scrutiny, such as the ongoing Ofcom investigation into TikTok's practices, treat that as a signal to be extra cautious with what you share until the outcome is known.
Key Takeaways
- UK age verification data records law does not require providers to log every check indefinitely; it requires proof the process meets compliance standards.
- Ofcom can compel audit evidence during an investigation, but cannot force retention of personal documents beyond what compliance demands.
- Any long-term storage of ID scans or biometric images beyond the check itself is a business choice, not a legal requirement.
- VPNs and encrypted DNS protect network-level privacy but do not prevent age verification providers from collecting the data you submit directly.
- Ask providers directly about their retention policy before completing any age check, especially on platforms currently facing regulatory scrutiny.




