Compliance
Age assurance
Age assurance is the umbrella term for any method of establishing that someone is old enough to do something. It splits into age verification, which proves age from an authoritative source, and age estimation, which infers it from a face, a voice or behaviour. The difference matters legally, because a regulator asks not just whether you checked but how well.
Also called: age assurance, age checking, age gating
At a glance
- Age verification
- Proves age from an authoritative source. Determinate.
- Age estimation
- Infers age from a face, voice or behaviour. Probabilistic.
- Self-declaration
- A tick box. Age assurance in name only.
- UK test
- "Highly effective age assurance" under the Online Safety Act
- EU position
- Risk-based under the DSA; Article 28(3) resists extra data collection
The three words, and why the distinction is not pedantry
Age verification establishes age from something authoritative: a government identity source, a bank record, a credential issued by someone who checked. The answer is determinate. Age estimation infers age from a signal that correlates with it, usually a face scan, and gives a probability with an error margin, which is why estimation providers publish a "challenge age" buffer and refuse anyone near the threshold.
Age assurance covers both, and self-declaration sits at the bottom of the same ladder. Ticking a box that says "I am 18" is technically age assurance and is worth nothing, which is precisely why the regulators stopped using the word loosely.
What changes with a wallet
The older methods share a problem: to learn one fact about someone, they collect much more. An ID scan gives you a name, a document number and a photograph in order to answer a yes or no question about age. That solves the regulator's problem and creates a data protection one.
A wallet based check inverts it. The person holds a credential an authority already issued, and releases only the answer to the question asked. There is no document to store, no image to retain and no retention policy to audit, because the data never arrives. Whether that is available to you is a question about the rollout, not the technology: the credential exists, and the wallets are arriving between now and December 2027.
What a regulator actually assesses
Not the label. Under the UK Online Safety Act the test is whether the assurance is "highly effective", which has four named criteria, and Ofcom has been explicit that self-declaration and payment-card checks do not meet it. Under the EU Digital Services Act the duty is risk based, and there is no blanket age-check mandate, and Article 28(3) actively resists collecting extra personal data in order to check age.
So the compliance question is two part: is the method strong enough, and is it proportionate in what it collects. A method can fail either half. An ID scan is strong and often disproportionate; a checkbox is proportionate and useless.
Why it matters
If you're writing a compliance note, say which of the three you use and why it meets the standard that applies to you. "We do age assurance" answers nothing a regulator asked.
If you're choosing a vendor, the question that separates them is what they receive, not what they promise to delete. A method that never receives a document can't lose one.
Frequently asked
Is age estimation good enough on its own?
It depends on the threshold and the regulator. Estimation has an error band, so providers set a challenge age well above the legal one and fall back to another method for anyone inside the band. That fallback is part of the system, so judge the whole flow rather than the estimator alone.
Does asking for a date of birth count?
Asking is self-declaration. Verifying a date of birth against an authoritative source is verification. The words are close and the compliance distance between them is the entire subject.
Do I need age assurance if my users are mostly adults?
The duties are about risk and about what your service carries, not about your average user. That's a question for your counsel against your own risk assessment rather than one a glossary can answer.
Primary sources
This is a plain language explanation, not legal advice. Specifications and dates in this area move, so check anything you are going to rely on against the primary sources.
Keep reading
Age verification API
Or skip the theory and build against it
Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.