Age-Verification Laws by Country: A 2026 Comparison

TL;DR

This is the international companion to our US-state tracker. The UK has the most-developed age-assurance regime: the Online Safety Act 2023, with Ofcom's "highly effective" standard live across the largest platforms since March 2025. Australia brought in a binding under-16 social media age-assurance duty on 10 December 2025, with the eSafety Commissioner and the OAIC as co-regulators. France is the only jurisdiction with a porn-site age-verification reference framework actually in force (Arcom's framework, compliance required within three months of the 11 October 2024 publication). The EU's KIDS Act was proposed by the European Commission on 17 September 2026 and is now awaiting Parliament and Council. Canada's Bill C-63 died on the Order Paper at the dissolution of Parliament in January 2025.

If you live outside the US and want to know what your government is asking the internet to do about your age, here is the country-by-country picture in late 2026, with the primary statute for each and what data the regime actually puts in motion. We focus on the jurisdictions with active primary legislation or a formal regulator framework; we do not list the many countries still in consultation or with bills that did not pass.

Snapshot: Country-by-Country Comparison

The table below covers the five we have primary sources for. The "scope" column is what the law actually covers (adult content, social media, or both); the "status" column is the current phase as of October 2026.

CountryPrimary instrumentScopeStatusEnforcement body
United KingdomOnline Safety Act 2023 (c. 50); Ofcom codes of practicePornography + any service likely to be accessed by childrenIn force; largest-platform illegal-harms duties live from March 2025Ofcom; ICO for biometric age-estimation data
AustraliaOnline Safety Amendment (Social Media Minimum Age) Act 2024 (No. 127, 2024); inserted as Part 4A, section 63F of the Online Safety Act 2021Age-restricted social media platformsIn force from 10 December 2025eSafety Commissioner; OAIC for privacy
FranceLoi n° 2024-449 of 21 May 2024 ("SREN"); Arcom technical guidelines (adopted 9 October 2024, published 11 October 2024)Pornographic sites accessible to French usersCompliance deadline was 11 January 2025Arcom (Audiovisual and Digital Communication Regulatory Authority)
European UnionEU KIDS Act (also referred to as the "Protect Children Online Act")Proposed: phased social media access rulesProposed by the European Commission on 17 September 2026; awaiting Parliament and CouncilNot yet designated
CanadaBill C-63 (Online Harms Act), introduced 26 February 2024Would have covered social media and livestreamingDied on the Order Paper at dissolution of Parliament in January 2025Would have been Digital Safety Commission of Canada

The rest of this guide walks each row of that table. The TL;DR for each country follows the same shape: what the law actually demands, what age-assurance methods the regulator permits, what data the system collects and retains, and what is still being fought out.

United Kingdom: Ofcom's "Highly Effective" Age Assurance

The Online Safety Act 2023 (c. 50) is the UK statute. Section 230 of the Act defines "age verification" and "age estimation," and section 231 defines "proactive technology." Schedule 4, paragraph 12 sets out the content of codes of practice on age assurance, and Schedule 4, paragraph 13 the content of codes of practice on proactive technology.[1] Ofcom has codified an age-assurance standard under those codes, requiring services in scope to use methods that are "highly effective" at establishing that every user is not a child.[2]

The methods Ofcom treats as acceptable are facial age estimation, document upload (passport or driving licence), credit-card verification (an active credit card implies 18+), and open-banking identity checks. None of these are mandated. The "highly effective" wording is technology-neutral.[2]

What the regime puts in motion is a per-service stack. Every service likely to be accessed by children must operate an age-assurance implementation that the regulator can audit, with a documented lawful basis under the UK GDPR / Data Protection Act 2018 and, where facial estimation is used, a biometric-data special-category path.[2] The cumulative effect is that a UK user who reaches an in-scope service is, in practice, funnelled through a third-party age-assurance vendor whose audit trail Ofcom can inspect. The Investigatory Powers Act 2016 sits behind the stack as a backstop: connection-records retention and equipment-interference warrants can reach vendors who are themselves communications providers.[2]

Deep-dive coverage: UK Age Assurance Under the OSA 2023 (the per-service stack and the Ofcom standard) and UK Online Safety Act 2026: The Full Surveillance Picture (OSA + IPA + RIPA + GCHQ + the 2024-2026 enforcement record).

Australia: Under-16 Social Media Ban In Force 10 December 2025

The instrument is the Online Safety Amendment (Social Media Minimum Age) Act 2024 (No. 127, 2024), which inserted Part 4A, section 63F into the Online Safety Act 2021.[3] It received Royal Assent on 10 December 2024, and the age-restriction obligation commenced on 10 December 2025.[4]

What it requires: age-restricted social media platforms must take "reasonable steps" to prevent Australians under 16 from creating or keeping accounts. The eSafety Commissioner specifies what counts; the OAIC co-regulates the privacy path. Platforms must not compel government-issued ID, including under the Digital ID system, and where ID is offered as one option a reasonable non-ID alternative has to be available alongside it.[4]

The methods the OAIC names are age estimation (facial analysis, AI), age inference (account age, engagement patterns, linguistic analysis), and age verification (government-issued ID). The data side is governed by the Privacy Act 1988 and the Australian Privacy Principles. Platforms and age-assurance providers must ringfence and destroy personal information collected for the age-assurance purpose, may use or disclose it only for that purpose (with specific APP exceptions or voluntary informed consent), and breach triggers section 36 of the Privacy Act.[4]

The platforms covered are determined by legislative rules made by the Minister for Communications; the eSafety Commissioner publishes the definitive list.[4] The architecture runs on three pillars: the Assistance and Access Act 2018 (TAA) gives law enforcement a TAR/TAN/TCN regime for cryptographic capabilities; the Digital ID Act 2024 is opt-in at the federal level; and the Social Media Minimum Age amendment is the binding age-assurance layer.[5]

Deep-dive coverage: Australia Surveillance Laws 2026: The Full Picture (TAA + Digital ID + under-16 ban + eSafety + AUSTRAC + ASIO + TIA, with the 2024-2026 enforcement record).

France: Arcom's Reference Framework, Live Since January 2025

The instrument is Loi n° 2024-449 of 21 May 2024, the "SREN" law (Sécuriser et Réguler l'Espace Numérique). It repealed the prior Article 23 of law no. 2020-936 and gave Arcom the power to set "the minimum technical requirements applicable to age verification schemes" for access to pornographic services.[6] Arcom's board adopted the reference framework on 9 October 2024, following a favourable CNIL opinion on 26 September 2024, and published the technical guidelines on 11 October 2024.[7] The compliance deadline for pornographic sites serving French users was 11 January 2025.[8]

Scope: "online public communication services with editorial responsibility, and video-sharing platform services showing pornographic content." The framework is for age-verification schemes set up at the point of access to those services.[7] No pornographic content may be displayed until age has been verified.[6]

The earlier CNIL opinion on the 2020 law (deliberation No. 2021-069 of 3 June 2021) framed the data-minimisation principles that the Arcom framework inherits: no direct collection of identity documentation by the publisher of the pornographic site; no age estimates based on the user's web browsing history; no processing of biometric data for unique identification; local facial age estimation preferred to minimise data leakage; a trusted independent third party between user and site.[9] The CNIL, with Olivier Blazy and PEReN, built a proof-of-concept using zero-knowledge proofs so the visited site does not learn which proof-of-age provider was used.[9]

Enforcement: Arcom may issue a formal notice to comply; if the breach persists, a financial sanction; and for services that remain accessible to minors after notice under Article 227-24 of the French penal code, Arcom can administratively block the site under a procedure under the control of the administrative judge.[7] The prior three years saw Arcom serve formal notice on thirteen sites and refer the situation of five of them to the courts.[7]

Cross-border reach: a French user with a non-French porn provider is still in scope if the site has French users. The architecture works because Arcom's blocking power runs against French ISPs, not against the foreign sites themselves.

European Union: The EU KIDS Act Was Proposed on 17 September 2026

The EU KIDS Act (also referred to in earlier Commission communications as the "Protect Children Online Act") was proposed by the European Commission on 17 September 2026. Its stated goal is "to increase the online safety of children and teenagers across the EU."[10]

The proposal sets three age thresholds. Under 13: no social media accounts. Ages 13 and 14: parent-supervised limited accounts. 15: the EU-wide minimum age for a minor to open an independent account. The architecture is described as a "gradual approach to social media use for young people."[10]

Status as of October 2026: proposal stage. The proposal will now go to the European Parliament and Council for the ordinary legislative procedure; the trilogue and adoption timeline is not yet published. Until adoption, Member States are not bound by the proposed thresholds and platforms are not yet required to implement them.

Canada: Bill C-63 Died on the Order Paper

Canada's Online Harms Act (Bill C-63) was introduced in the House of Commons on 26 February 2024. It proposed seven categories: content that sexually victimizes a child or revictimizes a survivor; intimate content communicated without consent; content used to bully a child; content that induces a child to harm themselves; content that foments hatred; content that incites violence; and content that incites violent extremism or terrorism.[11]

Three duties for social media services: a duty to act responsibly, a duty to protect children, and a duty to make certain content inaccessible (specifically, child sexual victimization content and non-consensual intimate content). Platforms covered would have included social media services, livestreaming, and user-uploaded adult content services.[11]

Enforcement architecture: Bill C-63 proposed to create a Digital Safety Commission of Canada (oversight and enforcement), a Digital Safety Ombudsperson of Canada (advocate for users and victims), and a Digital Safety Office to support them.[11] The bill also proposed amendments to the Criminal Code, the Canadian Human Rights Act, and mandatory reporting of internet child pornography.

Where it stands. Bill C-63 died on the Order Paper with the dissolution of Parliament in January 2025.[11] As of October 2026 there is no federal age-verification regime in force in Canada. Age-of-consent rules around sexual content remain a matter of provincial criminal law, not a federal age-verification mandate.

What Every One of These Approaches Has in Common

Three patterns cut across the four jurisdictions with live or imminent enforcement. First, the verification path is age assurance, not mandatory government ID. The UK Ofcom standard is technology-neutral. Australia explicitly bans compelling ID, including Digital ID. France requires a third-party verifier between user and site. The EU KIDS Act proposal leans on age assurance and treats ID upload as a last resort.[2][4][9][10]

Second, the data side is governed by an existing privacy statute that runs in parallel. The UK uses the DPA 2018 and UK GDPR; the OAIC uses the Privacy Act 1988 and the Australian Privacy Principles; the CNIL frames the French framework; the EU uses the GDPR (and Article 8 in particular). Each privacy regime demands data minimisation, ringfencing of the age-assurance data, and an audit trail.[2][4][9]

Third, every jurisdiction names an enforcement body that runs the compliance regime. Ofcom in the UK. The eSafety Commissioner and the OAIC in Australia. Arcom in France. A Digital Safety Commission in the proposed Canadian regime. None of these bodies is the same agency that handles the underlying surveillance authority in each country, which means the age-verification regime sits as a parallel layer on top of the existing intelligence and law-enforcement perimeter.

What to Do If You Are Asked to Verify Your Age

If you are asked to upload a government ID to reach legal content, that is the trade being made, whether the law names it or not. The practical steps that survive every jurisdiction we covered.

  1. Prefer the age-estimation method (facial age estimation, behavioural inference) over document upload. The data side is lighter: no document copy, no name, no address.
  2. If you must upload an ID, find out whether the service uses a third-party verifier that holds the ID separately. France mandates this; the UK Ofcom standard allows it; Australia requires ringfencing and destruction of age-assurance personal information.
  3. Check whether the verifier is operating under your country's data-protection statute. In the UK that means the ICO; in Australia that means the OAIC; in France that means the CNIL. If you cannot find a regulator the verifier is accountable to, treat the upload as a permanent disclosure.
  4. Do not assume deletion. Even where the law requires destruction, you have no way to verify your data was actually deleted. The June 2024 AU10TIX breach is the standing example of what happens when the verifier's own controls fail.
  5. If you are a minor or a parent of a minor, take the regulator's list of acceptable non-ID methods seriously. The Australian OAIC and the French CNIL both explicitly prefer local facial age estimation to ID upload.

Related Reading

Sources

  1. Online Safety Act 2023, c. 50, contents (legislation.gov.uk, primary statute) (accessed 2026-10-03).
  2. UK Age Assurance Under the OSA 2023 (State of Surveillance, with Ofcom online-safety age-assurance guidance and the Online Safety Act 2023 c. 50 as primary anchors) (accessed 2026-10-03).
  3. Online Safety Amendment (Social Media Minimum Age) Act 2024, No. 127, 2024 (legislation.gov.au, primary statute) (accessed 2026-10-03).
  4. Office of the Australian Information Commissioner: Social Media Minimum Age (OAIC, regulator guidance) (accessed 2026-10-03).
  5. Australia Surveillance Laws 2026: The Full Picture (State of Surveillance, with Online Safety Act 2021, TAA Act 2018, and Digital ID Act 2024 as primary anchors) (accessed 2026-10-03).
  6. Law No. 2024-449 of 21 May 2024 (Better Internet for Kids, European Commission resource) (accessed 2026-10-03).
  7. Arcom: Technical guidelines on age verification for the protection of persons under 18 from online pornography (Arcom, French audiovisual and digital regulator) (accessed 2026-10-03).
  8. VerifyMy: French regulator Arcom announces age checks by 11 January 2025 (industry confirmation of the SREN three-month compliance rule from the 11 October 2024 Arcom publication) (accessed 2026-10-03).
  9. CNIL: Online age verification: balancing privacy and protection of minors (CNIL, French data protection authority) (accessed 2026-10-03).
  10. Better Internet for Kids (BIK+): EU KIDS Act proposed 17 September 2026 (Better Internet for Kids, European Commission knowledge hub) (accessed 2026-10-03).
  11. Government of Canada: Bill C-63, Online Harms Act (Canadian Heritage) (accessed 2026-10-03).