Social media age check: child protection or privacy invasion?

Author: Published 5 min de lectura 281 reading

The images in this article were generated with artificial intelligence. How we publish

The United Kingdom Government has announced that prohibit access to social networks for children under 16 years of age, with the regulations planned before Christmas and the entry into force in the spring of 2027. In practice this will require platforms to verify the age of new accounts open: if you register for the first time from the United Kingdom you are most likely to be asked for an identity document or biometric verification (selfie for age analysis), while old accounts will be largely "grandfathered" and will not need that immediate step.

The stated intention - to protect children and adolescents from online risks - runs into technical and privacy dilemmas that have already lit the alarms between researchers and digital rights organisations. Mass verification means mass collection of sensitive data:: passports, driving permits, facial images and metadata that, if stored or mismanaged, become a valuable target for attackers and a possible source of identity theft or blackmail.

Social media age check: child protection or privacy invasion?
Image generated with IA.

The experts also remember that many proposed techniques are easy to avoid. Recent studies by centres such as the Science Media Centre show that most verification methods - except for credit card-based checks with obvious limits - offer low or medium robustness and can be drawn by children motivated by accessible tools. You can read an expert reaction and references in the summary published after the official announcement in the UK: Government communiqué and the analysis of experts in Science Media Centre.

A key structural weakness is that the law is directed to services (sites and apps), not to users: anyone who navigates from outside the UK perimeter - for example through a VPN - will avoid control. The Australian experience, which was a pioneer in this way, showed that a significant proportion of children continued to use social networks after similar prohibitions; in addition, some VPN providers recorded demand peaks as controls were tightened. See coverage of these peaks as reference: BBC: rebound on VPN records.

From the point of view of computer security, there are two different but related risks: the actual effectiveness of controls and collateral damage if such controls fail. A database leak with identity documents or facial photos is a life-long problem for the people affected; unlike a password, you can't change your face. In addition, the normalization of mandatory verification erodes anonymity in the network and poses costs for freedom of expression, especially for activists, complainants or people in repressive environments.

Policy makers and regulators have also not closed the technical debate: Ofcom has been responsible for quickly studying how to verify age, but the quality of standards and audits will make the difference between a prudent implementation and a dangerous mechanism. Meanwhile, there is already a parallel road map in the Government towards digital credentials (e.g. GOVU.K Wallet and digital driving license) that could be integrated with these verifications, confirming a travel address to a web where age testing becomes increasingly common: GOVU.K on digital credentials.

What can citizens and families do now? First, be informed and demand transparency: before uploading documents to an app, check your privacy policy, how long you will retain those data and who processes them. Second, prioritize solutions that limit exposure: prefer platforms that offer verification on the device (local testations) or methods that emit an old "token" without keeping your full document. Third, strengthen personal cybersecurity practices: activate 2FA, use password managers and monitor identity theft alerts with reputable suppliers.

For parents and educators the practical recommendation remains to look beyond the prohibition: effective prevention combines technical controls, active monitoring and digital education. Talking to adolescents about real risks (grooming, disinformation, social pressure), teaching them how to set up privacy and use blocking and reporting tools is more effective than relying exclusively on easy to avoid barriers.

Social media age check: child protection or privacy invasion?
Image generated with IA.

Technology companies have their responsibility: they should prefer verification architectures that minimize data retention, support independent audits, publish penetration test results and provide safe and reversible ways to clear verification tracks. It is also essential for Governments to require minimum standards, reporting obligations and consistent sanctions if external verification providers treat data without guarantees.

Finally, for the technical and public policy community there is an opportunity: to invest in privacyconserving verification methods - such as zero-knowledge tests, reliable and regulated hardware tests or age emitters - and to evaluate their effectiveness independently. If the priority is to protect minors, the focus should be to reduce commercial incentives that amplify damage and build technically sound and audibly secure controls, not just regulatory theatre.

The UK proposal permanently alters the relationship between identity and digital presence. Before the rules arrive in 2027 it is appropriate for society to require clear standards, public effectiveness tests and mechanisms that minimize the creation of new risks while pursuing a legitimate objective: to keep children safe without mortgaging the privacy and security of the rest.

Coverage

Related

More news on the same subject.