The question of how to keep children safe online has long been a pressing issue, and recent concerns in Australia and the UK have reignited the debate about age verification on social media.
Reports suggest that many children are gaining access to online platforms by registering using false dates of birth, allowing them to access content intended for older users. This raises a crucial question: are social media platforms doing enough to verify users’ ages, and if not, what should be done?
Why Does Age Verification Matter?
Many social media platforms, including Facebook, Instagram, TikTok, and Snapchat, have a minimum age requirement of 13. However, this is largely self-regulated. Users simply enter their date of birth during registration. Unless there is clear evidence to the contrary, platforms simply accept those details as being true.
Younger children can, therefore, operate on those platforms appearing to be older than they are. Conversely, an adult could register using a false birth date – as if they were a child – with a view to befriending minors.
The risks associated with underage access are significant. Children may be exposed to inappropriate content, cyberbullying, online grooming, and privacy risks. Furthermore, requirements such as those contained in the UK Information Commissioner’s Children’s Code (a set of data protection standards for online services likely to be accessed by children) compel platforms to take child protection seriously.
Concerns in Australia about the number of children younger than 13 using social media or messaging services that are intended for children aged 13 and above have led to plans to implement – by the end of 2025 – legislation that imposes a total social media ban for anyone aged under 16.
If the situation in Australia leads to tougher global enforcement, social media companies in many other jurisdictions may be forced to rethink their approach.
Current Age Verification Methods
At present, most social media platforms rely on:
- Self-Declaration: users input their birthdate manually (easy to falsify);
- AI-Based Behavioural Analysis: some platforms monitor user activity and flag behaviour that appears inconsistent with their declared age;
- Parental Controls: some services, like YouTube Kids, offer age-appropriate content under parental supervision; and
- Photo ID Uploads: some platforms, such as Instagram, request ID verification in certain cases, but this is not a standard requirement for all users.
These measures, while helpful, are clearly not foolproof. Children who are determined to bypass age restrictions can, currently, often do so with minimal effort.
What More Can Be Done?
Platforms could consider introducing stricter, more reliable verification measures. Potential solutions include:
- AI-Powered Facial Age Estimation
Some companies, like Yoti, have developed AI tools that estimate a user’s age based on facial analysis without storing personal data. This could provide a balance between privacy and verification. - Third-Party Age Verification Services
Similar to online gambling regulations in the UK, social media platforms could use external providers to verify a user’s age against official records. - Stronger Identity Verification for Young Users
Requiring users under a certain age to submit a verified form of ID (such as a passport or government-issued card) before gaining access to a platform. - Enhanced Parental Consent Mechanisms
Some platforms already allow parents to approve their child’s account, but a more robust system could include two-factor parental authentication or integration with school records. - Monitoring & Adaptive AI
Platforms could proactively monitor accounts for suspicious behaviour, such as younger-looking users engaging in adult activities, and request additional verification when necessary.
The Balancing Act: Privacy vs. Protection
While stronger verification tools would help to prevent underage access, they come with challenges. Any processing of personal data by UK based companies needs to comply with UK GDPR, and any additional or enhanced checks would also need to be compliant.
In practice, this means doing things such as:
- ensuring lawfulness, fairness, and transparency, both in terms of the processing an organisation is doing and any sharing they may want to do with other organisations;
- minimising the data that is being processed and ensuring that it is only processed for the purposes for which it was collected;
- ensuring that data is stored securely and not kept for any longer than necessary;
- complying with the legal rights of the individuals whose data is being processed;
- building data privacy into any platforms from the outset so as to achieve ‘privacy by design’;
- identifying and analysing risks by completing data protection impact assessments, particularly if implementing new age verification technologies;
- having appropriate safeguards (such as an International Data Transfer Agreement) in place if required by law, for example if data will be stored or otherwise processed in a territory outside of the UK and EEA; and
- if facial recognition technology is being used, this could qualify as biometric data, which is considered ‘special category data’ under the UK GDPR and requires additional levels of protection and consideration to ensure its security and integrity are maintained.
In addition to the above noted legal privacy concerns, there are other risks to take into account such as the potential misuse of personal data and excluding legitimate users who may not have ID readily available. Many different factors must be carefully considered – striking the right balance is key.
Recommended reading
- Creating Deepfakes To be Criminalised in UK
- Ofcom Introduces Over 40 New Online Safety Measures
- Children First See Violent Online Content at Primary School Age
As a data protection lawyer, the requirement to respect and protect people’s data – particularly that of children – is at the forefront of my mind.
However as a parent, strict legal concerns pale in comparison to worries about the safety of our children when it is almost inevitable that they will gain access to unsuitable online content at some point.
While it is ultimately a parent’s responsibility to manage their child’s access to social media (and to devices that facilitate such access), having appropriate legal and other requirements in place will help to reduce risks and make it easier for parents and carers to navigate this minefield.
Looking Ahead
As regulatory pressure mounts and public concern grows, social media companies will likely be expected to step up their efforts. If Australia’s current scrutiny turns into global action, we may see widespread adoption of more sophisticated verification measures in an attempt to better control who can use social media platforms.
The core issue remains: keeping children safe online without compromising privacy and accessibility. The debate is far from over, but it is clear that doing nothing is no longer an option.





