Age verification requirements for dating apps: UK
· 8 min read
- Applies to
- Dating and social discovery services with UK users, wherever the company is based
- In force
- Children's access assessments since 16 April 2025; children's safety duties since July 2025
- What to do
- Run highly effective age assurance at sign-up, gate access on its result, and keep the written assessment
In December 2025, more than one in ten 15 to 17-year-olds in the UK were still visiting and spending time on three of the most used dating apps. The figure is Ofcom's, published on 15 July 2026, and the number itself is not the interesting part. The interesting part is that those apps had age checks in place.
So the useful question for a dating product in the UK is not whether it checks age. Nearly all of them do, and have for years. The question is whether the check is the kind the Online Safety Act recognises — because under the Act an age check is not a feature bolted onto the sign-up screen. It is the mechanism that decides which body of duties applies to the service at all.
Where a dating app sits in the Act
The Act regulates "user-to-user" services: internet services that let users generate, share or upload content that other users may encounter. A dating app qualifies several times over — profiles, photos, matching, direct messages, voice and video. Ofcom's sector guidance for dating and social discovery, published on 18 May 2026, is explicit that the rules reach a service with UK links "even if their business is based outside of the UK."
That puts a dating app in Part 3 of the Act, carrying two tracks of duty at once. One concerns illegal content, and it is where Ofcom's sector research lands hardest: 29% of adult internet users have experienced romance or dating scams, and 6% have encountered fraud on a dating site or app. The other track concerns children. Age assurance lives on the second track, and it does not behave like the rest of the compliance surface.
The fork in the road
Most regulatory work is a list of things to do. The children's track is not a list. It is a fork, and which side a service comes out on decides how much of the Act it has to implement.
The mechanism is the children's access assessment, required by s.36 and framed by s.35 and s.37. Ofcom runs it in two stages.
Stage one asks whether it is possible for children to normally access the service. There is exactly one way to answer no, and it has two halves: age verification or estimation that is highly effective, and "access control measures that prevent users from accessing the service if they have not been identified as adults." Both halves are load-bearing. A check that runs at sign-up but does not gate anything — the result logged, the user waved through — satisfies the first and fails the second.
Stage two is reached by everyone who cannot exclude children at stage one. It asks whether the "child user condition" is met: whether a significant number of children use the service, or whether the service is of a kind likely to attract a significant number of children. The Act does not define "significant number", and Ofcom's advice is that providers "should err on the side of caution."
Come out of stage two with children likely to be accessing the service and two more sections switch on — s.11, children's risk assessment duties, and s.12, safety duties protecting children — along with the measures in Ofcom's Protection of Children Code of Practice. Come out of stage one having genuinely excluded children and the outcome is a written record, a repeat assessment within twelve months, and none of that second body of duty.
This is why the age check is not a feature. Risk assessments, content controls, recommender constraints, reporting flows: all of it hangs off which side of the fork the service lands on. Existing services had to complete the first assessment by 16 April 2025.
What "highly effective" rules out
Ofcom's criteria are that a method be technically accurate, robust, reliable and fair. It declined to publish numerical accuracy thresholds, calling the approach "flexible, tech-neutral and future-proof", and instead published a non-exhaustive list of methods capable of clearing the bar: open banking, photo ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services, and email-based age estimation.
The exclusions are more useful than the list, because they describe what most dating apps were already doing:
- Self-declaration. A date-of-birth field is a question, not a check.
- Terms and conditions stating the service is for over-18s only. A stated rule, unenforced.
- Payment methods that do not themselves require the user to be over 18. A debit card is available to children, so a card on file proves nothing about age.
- Age inference. Ofcom ruled this out in July 2026 on the ground that an inference can only be drawn after a child has already signed up and used the service long enough to be profiled.
The last one deserves a moment. Inference is the pattern a data-rich platform reaches for first, because it is invisible and costs the user nothing. It fails for a structural reason rather than an accuracy one: by the time the model is confident, the child is already inside and has already been messaged.
An 18+ minimum in the terms is not worthless — it is the thing the check enforces. But on its own it does not get a service past stage one, and Ofcom notes that a service seeking to limit access below a certain age may still attract a significant number of children anyway.
The second trigger, in the DMs
Running underneath the access assessment is a separate duty that fires on content rather than on audience. A Part 3 service that allows pornographic content, including content its users generate, must use highly effective age assurance to stop children encountering it. (Services publishing their own pornographic content are covered separately, by s.81.)
Most dating products do not think of themselves as being in this category. Ofcom's dating guidance closes that gap directly: the duty "applies both to public spaces such as user profiles, and private interactions, such as direct messages." A service can moderate profile photos perfectly and still be in scope because of what two matched users send each other.
Where the bar moved in 2026
The first year of enforcement changed the baseline. Ofcom counted over 69 million age checks across a sample of 32 UK services between July and December 2025, a 23-fold rise on the preceding six months, and the share of children who met a highly effective check rose from 25% to 43% between July 2025 and January 2026.
Having established that checks work, Ofcom raised what it expects of them. For dating services specifically it wants two additions. A challenge age — a verification threshold set above 18, so that the margin of error in age estimation is absorbed by the buffer instead of admitting 17-year-olds. And liveness detection, which stops a child presenting a still photograph of an adult or a pre-recorded video to a camera-based check.
Two further expectations apply to everyone. Run regular due diligence on third-party vendors. And understand that responsibility for the check being highly effective stays with the regulated service whether the check is built in-house or bought.
The data-protection half
An age check processes personal data, usually a face or an identity document, so UK GDPR and the ICO's Children's code apply alongside the Online Safety Act. The two regimes pull in the same direction more than teams expect, and the design consequence is a narrow one.
Age assurance answers "is this user old enough". Identity verification answers "who is this user". The second question is heavier, and its answer is heavier to hold: a dating service that retains passport scans has traded a child-safety problem for a breach-notification one. Verify, keep the verdict and the evidence that the verdict was properly reached, discard the document.
What this looks like in practice
- Gate at sign-up, before a profile exists — not at first message, and not at first payment.
- Pick a method from Ofcom's list and make access conditional on its result. The gate is the half that fails audits.
- Set a challenge age above 18 wherever age estimation is used.
- Add liveness detection to any camera-based check.
- Treat direct messages as in scope for the pornographic content duty.
- Write the access assessment down, and repeat it within twelve months.
- Keep the verification record. Do not keep the document.
Get the check right and the fork closes behind you. Get it wrong and every children's duty in the Act stays open, whatever the terms of service say.
ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust
ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.