E-commerce

What the Online Safety Act expects from age-restricted storefronts

· 3 min read

Applies to
UK storefronts selling age-restricted goods, and services likely to be accessed by children
In force
Age-assurance duties phased in from 2025
What to do
Run a document-backed check at checkout and keep the verification record on the order

For years, the working answer to age assurance online was a checkbox. A shopper confirmed they were over 18, the order went through, and the record of that confirmation was a boolean in a database. The Online Safety Act ends that arrangement for a large class of UK merchants.

What actually changed

The Act asks a different question than the checkbox does. A checkbox records that someone clicked. The OSA asks whether a merchant took proportionate steps to establish age — and whether they can demonstrate it afterwards. Those are evidentiary standards, not UX preferences, and a self-declaration produces no evidence at all.

Two consequences follow. First, the check has to interrogate something the shopper cannot simply assert: a document, a verified credential, or a trustworthy third-party signal. Second, the outcome has to be recorded in a way that survives the transaction, because the question "was this buyer age-eligible" usually arrives months later, from a regulator or a payment processor.

Where the check belongs

The instinct is to gate the front door — an interstitial on the homepage, before anyone sees the catalog. It is the wrong place, for reasons that are commercial rather than legal.

Most visitors to a storefront never buy anything. Verifying them costs money and adds friction to the exact moment when a browser is deciding whether to keep browsing. Verification at the door charges you for traffic; verification at checkout charges you for customers.

Checkout is also where the record belongs. A verification that happens three clicks before the cart is hard to tie to a specific order. A verification that happens between the cart and the payment step can stamp its ID directly onto the order, which is precisely the artifact you need when the question comes back.

What a defensible check looks like

A check that holds up has four properties:

  • Document-backed. The shopper presents an ID; the system reads it. 190+ document types covers most international traffic.
  • Recorded. Each verification produces an ID and an audit record that can be attached to the order.
  • Proportionate. Age thresholds are set per market and per product category, because 18 in one jurisdiction is 21 in another.
  • Repeatable. Returning customers who already verified should not start over on every order, or the check becomes a tax on loyalty.

Nothing in that list requires enterprise KYC onboarding. Full identity verification answers "who is this person", which is a heavier question than the one the OSA asks, and it carries heavier data-protection consequences. Age assurance answers "is this person old enough", and a well-designed flow discards everything it does not need.

The data question

An age check necessarily touches an identity document, which makes it a data-protection question as much as a compliance one. The defensible posture is minimal retention: process the document, produce the verdict, keep the record of the verdict, and discard the rest. A merchant who stores scans of customer passports has solved one regulatory problem by creating another.

Practical next step

If you sell age-restricted goods into the UK, the actionable version of all this is short. Move the check to checkout, make it document-backed, stamp the result on the order, and set your thresholds per market rather than globally. That is the shape of an age gate you can defend.

Checkout-Ready Age Verification for Regulated Ecommerce

Age verification that runs inside checkout for tobacco, vape, alcohol, CBD, and other age-restricted catalogs. White-label, sub-60-second, $0.30 per verified order through official Shopify and WordPress (WooCommerce) integrations.

See how it works