Fake profiles and banned users on dating apps: UK
· 8 min read
- Applies to
- Dating and social discovery services with UK users, wherever the company is based
- In force
- Illegal content safety duties and Codes of Practice since 17 March 2025; user-sanction measures proposed June 2025, statement due by autumn 2026
- What to do
- Treat a ban as a decision about a person, not an account, and record in the risk assessment how a removed user is kept out
When Ofcom published its guidance for dating and social discovery services on 18 May 2026, the example it chose for harassment on dating platforms was not an abusive message. It was a workaround: "creating fake profiles to continue contact after being blocked."
That sentence describes a gap in how dating products, and the rules written for them, are built. A block is attached to an account. A ban removes an account. The person behind it can open another one in the time it takes to receive a verification email, and the safety features stop at the account boundary.
Where a fake profile sits in the Act
Under the Online Safety Act 2023 a fake profile is not only a moderation problem. It is frequently the instrument of a priority offence. Schedule 7 lists the priority offences, and two of them describe what dating services see most. Paragraph 33 covers fraud by false representation under the Fraud Act 2006 — the legal shape of a romance scam run from an invented persona. Paragraph 7 covers harassment and stalking under the Protection from Harassment Act 1997.
That matters because the duty in s.10 is not confined to content. Section 10(2)(b) requires proportionate measures to "effectively mitigate and manage the risk of the service being used for the commission or facilitation of a priority offence". A persona built to defraud, or a second account opened to reach someone who blocked the first, is the service being used in exactly that way, whether or not any single message crosses a line.
Section 10(4) then lists the areas where measures are expected, and one of them is explicit: "policies on user access to the service or to particular content present on the service, including blocking users from accessing the service". Which of these a service needs is set by its illegal content risk assessment under s.9, which has to assess the risk of the service being used to commit priority offences and identify the functionalities that raise it.
The account is not the unit of harm
Ofcom's illegal content Codes of Practice for user-to-user services, issued on 24 February 2025 and in force since 17 March 2025, are the practical translation of s.10, and s.49 provides that a provider "is to be treated as complying" with a duty if it takes the measures a code recommends for it.
Read with a dating product in mind, the codes are built around accounts:
- ICU J1, user blocking and muting. Users should be able to block another account so that neither can message the other or see the other's content. It applies to large services — more than 7 million monthly active UK users — with user profiles and a medium or high risk of harms including harassment and stalking.
- ICU D14, a dedicated fraud reporting channel for nine named bodies, including the City of London Police, the National Crime Agency and the Financial Conduct Authority. Again, large services at medium or high risk of fraud only.
- ICU J3, notable user and monetised labelling schemes. If a large service at risk of fraud labels profiles as notable, or labels them because the user paid, it needs documented policies on who gets the label and when it is removed. A photo-verified badge on a dating profile does not obviously fit either definition.
- ICU H1, removing accounts. The only measure in the user access section, and it concerns accounts operated by proscribed terrorist organisations.
Nothing in the codes in force asks a service to stop a removed user from coming back. A dating service below the large-service threshold can block, ban and report with the codes satisfied, and still be the platform Ofcom's guidance describes, where the blocked user simply returns as someone else.
The measure that targets the person
Ofcom has already drafted the missing piece. Its Additional Safety Measures consultation, published on 30 June 2025, proposed to "address repeat offending through new user sanctions", in two new measures that would apply to every service regardless of size.
The first, ICU H2, asks for a written sanctions policy for users who share illegal content. In deciding how severe a sanction should be, the provider would have to consider "whether the user has previously generated, uploaded or shared illegal content", including whether they were sanctioned for it before. Repeat behaviour becomes an input to the decision rather than a coincidence.
The second, ICU H3, is narrower in subject and much sharper in mechanism. It covers users who share child sexual exploitation and abuse material, and it defines a ban by the person rather than the account. Where the provider has reasonable grounds to infer the user has more than one account, the ban covers all of them. The provider should then "take reasonable steps to ensure that while the ban is in force, the relevant user is prevented from regaining access to the service, or services, on a continuous basis." What counts as reasonable depends on the service, what is technically feasible and the provider's resources.
Both measures are still proposals. Ofcom's implementation roadmap says it will publish its statement "by autumn 2026". H3 is limited to child abuse material. But it is the first time the regulator has written down what keeping someone out means, and the definition — every account, continuously, for the length of the ban — is the one a dating service would need for fraud and stalking too.
The voluntary layer already says it
For fraud specifically, government got there first. The Home Office's Online Fraud Charter, published on 30 November 2023 and signed by Match Group among others, commits every signatory to "block users from creating new accounts when they have previously been removed for fraud, excluding those who have had their accounts taken over."
It also carries two commitments written for standalone dating services and nobody else. One is to give users "the choice to verify their identity on platforms to allow other users to know they are genuine, allowing users to opt to interact with verified people only." The other is to alert users who exchanged contact details with an account the platform has identified as likely to be involved in financial crime.
The charter is voluntary and binds only the firms that signed it. Its value to everyone else is as a description of what the sector told government it could do. A risk assessment that rates romance fraud as a high risk and then explains why none of these steps is proportionate has to make that argument against a standard the industry wrote itself.
Identity verification is a separate, narrower duty
The Act does contain an identity verification duty, and it is easy to assume it covers dating. Section 64 requires a provider to offer every adult user "the option to verify their identity", and s.15(9) requires features that let users filter out non-verified users — almost exactly the charter's dating commitment.
Both apply only to Category 1 services. The threshold regulations set that at more than 34 million monthly active UK users with a content recommender system, or more than 7 million with a recommender system and a function for resharing content. Ofcom's consultation on the Category 1 duties, published on 10 July 2026 and open until 2 October 2026, includes draft guidance on how the verification should work. Section 64(2) already says it "need not require documentation to be provided."
For a dating service outside Category 1, then, verification is not a statutory duty in its own right. It is one of the measures available for the s.10 duty to mitigate fraud and harassment, which is a different argument with the same practical result.
Recognising a person is a data protection question
Keeping a removed user out means recognising them when they return under a new name, email and phone number. The signals that survive that change are a document and a face, and processing a face to single someone out is "biometric data for the purpose of uniquely identifying a natural person" under Article 9 of the UK GDPR — special category data, prohibited unless a condition applies. Doing it at scale also triggers a data protection impact assessment under Article 35(3)(b).
An age check asks whether a user is old enough, and the UK age check rules for dating apps turn on that. A repeat-offender check asks whether this user is someone already removed, which means holding something about removed users that can be matched against. The charter's own carve-out shows the other risk: a match has to distinguish a fraudster from the victim whose account was taken over.
What this looks like in practice
- Write the repeat-account pattern into the illegal content risk assessment, for fraud and for harassment and stalking separately, and say what keeps a removed user out.
- Define a ban in your terms of service as applying to the person and every account they hold, not to the account that was reported.
- Keep the minimum needed to recognise a removed user, decide how long it is kept, and run the impact assessment before the first match.
- Exclude account-takeover victims from re-registration blocks, as the charter does.
- Offer optional identity verification and a way to talk only to verified users, even if s.64 does not reach you.
- Watch for Ofcom's statement on ICU H2 and H3, due by autumn 2026, and read the final definition of a ban against your own.
A block stops an account. The duty, and the harm Ofcom describes, follow the person.
Keep reading
ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust
ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.