Dating apps

Age verification requirements for dating apps: Australia

· 8 min read

Applies to
Services with a significant purpose of enabling online social interaction, available to Australians
In force
Social media minimum age since 10 December 2025; platform rules amended 26 March 2026
What to do
Never make government ID the only route through the age check, and destroy what the check collects

Every other jurisdiction writing age assurance rules has pushed services toward stronger identity checks. Australia wrote the opposite into statute. Under section 63DB of the Online Safety Act 2021, a provider covered by the social media minimum age "must not collect government-issued identification material" for the purpose of complying with the age requirement. The maximum civil penalty is 30,000 penalty units.

There is an exemption, and it is the whole design brief: the prohibition does not apply if the provider "provides alternative means" for a person to demonstrate they are not underage, and "those means are reasonable in the circumstances." An Australian age check may use ID. It may not be an ID check.

For a dating app the first question is whether any of this applies, and the answer is less obvious than it looks.

Whether a dating app is covered

Part 4A of the Act creates the social media minimum age. Section 63D requires a provider of an "age-restricted social media platform" to take reasonable steps to prevent age-restricted users having accounts. An age-restricted user is defined as "an Australian child who has not reached 16 years." The duty commenced on 10 December 2025.

Section 63C defines the platform. An electronic service qualifies where the sole or a significant purpose "is to enable online social interaction between 2 or more end-users", where it "allows end-users to link to, or interact with, some or all of the other end-users", where it "allows end-users to post material on the service", and where it meets any further condition set by legislative rules.

A dating app satisfies the first three by description rather than by argument. Matching is linking; messaging is interacting; a profile is posted material.

The fourth condition is where the Online Safety (Age-Restricted Social Media Platforms) Rules 2025 do the work, and they were amended on 26 March 2026 to add one. Rule 4A now requires that the service have a recommender feature or a logged-in feature. A service has a recommender feature if it "can select material by reference to any information that the service has associated with an end-user's account" and display that material to the end-user. That is a description of a matching queue.

Rule 5 then lists the classes of service that are excluded: messaging, email, voice and video calling; online gaming; sharing reviews or technical advice; professional networking and development; education; health support; and communications between institutions and students or clinicians and patients. Dating is not among them, and the rule directs you to disregard advertising purposes when classifying a service.

On the face of the definition a dating app is in scope: the section 63C conditions are met, Rule 4A adds one that a matching queue satisfies, and Rule 5 does not exclude dating. That is a reading of the text rather than a determination about any particular service, and each provider has to assess its own against the current Rules.

The practical position is stranger than the legal one. The floor Part 4A sets is 16, and every mainstream dating product already enforces 18. A dating app is regulated by a scheme whose substantive threshold is below its own, which means the obligation that actually bites is not the number. It is the manner of the check.

The three prohibitions

Australia legislated limits on age assurance itself, at the same penalty level as failing to do it at all. Each carries a maximum of 30,000 penalty units.

Section 63D — take reasonable steps to prevent age-restricted users having accounts. The positive duty.

Section 63DA — do not collect information "of a kind specified in the legislative rules" for the purpose of complying with 63D. Note the mechanism: the Minister may put categories of information out of bounds, and before doing so "must seek advice from the Commissioner" and "must seek advice from the Information Commissioner". Subsection (3) closes the loop — if the rules leave no reasonable steps available, section 63D does not apply. The Act would rather you did nothing than over-collect.

Section 63DB — do not collect government-issued identification material, and do not use an accredited service within the meaning of the Digital ID Act 2024, unless reasonable alternative means are offered. The definition of government-issued identification material reaches copies of documents and government-issued digital IDs. Australia built a national digital ID scheme and then told platforms they cannot make it the only door.

Read together, these say something the UK's "highly effective" standard and the US app store statutes do not. Australia does not treat the age check as an unqualified good to be maximised. It treats it as a hazard to be bounded.

What happens to the data

Section 63F is the reason. Where an entity holds personal information collected for the purpose of taking reasonable steps under the minimum age, and uses or discloses it other than for determining whether the person is an age-restricted user, under specified Australian Privacy Principle 6.2 exceptions, or with consent, the use "is taken to be an interference with the privacy of the individual for the purposes of the Privacy Act 1988."

That is a deliberate piece of plumbing. It converts a misuse of age assurance data into a privacy complaint under section 36 of the Privacy Act, which means a second regulator with its own remedies. The consent exception is narrow by design: section 63F(2) requires consent that is "voluntary", "informed", "current", "specific" and "unambiguous", and withdrawable "in a manner that is easily accessible to the individual".

The OAIC describes the resulting obligation as one to "ringfence and destroy" any personal information collected for age assurance, and confirms the scheme "specifically prohibits age-restricted social media platforms from compelling Australians to use government-issued identification" — ID may be offered, but a reasonable non-ID alternative must always be available too.

The OAIC also sets out what age assurance tends to touch in practice: name, date of birth, contact details, government ID, identifiable images, voice recordings and video, and sensitive information including "biometric information such as 'biometric templates' which analyse physical characteristics." Facial age estimation is not a way around the ID prohibition. It is a way into the biometric one.

The shape of a compliant check

Nothing in Part 4A tells a provider which method to use, and that omission is consistent. The Act constrains inputs and outputs and leaves the middle open. What survives those constraints looks like this:

An age signal that is not a document. Facial age estimation, an inference from a mobile carrier, a third-party attestation — any of them can be the primary route, provided the artefacts are destroyed. A government ID path may exist beside it, and for many adults it will be the easiest option, but it cannot be the only one, and offering it as the only one is the penalty.

Then a single-purpose store with automatic destruction, because section 63F makes retention a privacy interference rather than a records decision.

The convergence with Europe is worth noticing. Australia arrived at data-minimised, non-document age assurance by prohibition; the EU arrived at substantially the same place through Article 28(3) of the Digital Services Act and a wallet standard. A product built for one is most of the way to the other. The UK and the US are the outliers, and a global dating app that starts from a document-first design will find Australia the hardest of the four to retrofit.

What this looks like in practice

  • Assume you are in scope. A matching queue is a recommender feature under Rule 4A, and dating is not in the Rule 5 exclusions.
  • Make a non-ID route the default path, not a fallback. Section 63DB penalises the reverse arrangement.
  • Do not treat the Digital ID scheme as a safe harbour. Using an accredited service as the sole means is prohibited on the same terms as collecting ID.
  • Ringfence age assurance data in its own store and destroy it on completion. Section 63F turns any other use into a Privacy Act matter.
  • Keep enforcing 18. The statutory floor of 16 does not displace your own terms, and the reasonable steps you must take are measured against the platform you actually run.
  • Re-check the Rules rather than the Act. The Act has been stable; the platform definition moved on 26 March 2026 and can move again by ministerial instrument.

Everywhere else, the compliance risk is that your age check is too weak. In Australia it is also that your age check is too much.

ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust

ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.

See how it works