Edition 2 · 02 / 08
What Would an Under-16 Ban Actually Require?
Age restrictions sound simple until identity, privacy, proportionality and circumvention become part of the design.

“No social media below sixteen” sounds like a clear rule. Enforcing it is a system design problem with consequences of its own.
A service needs some basis for deciding that a user is old enough. A self declared date of birth is easy to evade. Stronger assurance can involve payment records, identity documents, facial age estimation, checks by another provider or signals inferred from behaviour and devices. Each approach changes the information collected and the people who may be wrongly included or excluded.
Verification is part of the intervention
It is not enough for legislation to state an age threshold and leave implementation as a technical detail. The verification mechanism determines whether the policy works and what other risks it creates.
Useful questions include:
- What degree of certainty is proportionate to the risk?
- Is identity being established when only age is required?
- Who receives the evidence and how long is it retained?
- What happens when a child has no accepted document or device?
- How are errors challenged?
- Does the approach create a valuable new identity database?
The ICO’s opinion on age assurance explains that age assurance and data protection are not inherently incompatible. It also makes clear that services must consider proportionality, fairness, accuracy and data minimisation. That is a better foundation than claiming that every possible mechanism necessarily breaches data protection law.
Circumvention changes the calculation
Restrictions also create incentives to evade them. A child may use an adult’s account, enter a different age, move to a smaller service or use technology that obscures location. Attempts to block every route can lead to wider monitoring and restrictions that affect adults as well as children.
The policy should therefore be evaluated as a complete system: the rule, the assurance method, likely circumvention, enforcement and displacement into less visible spaces. A nominally strict rule may offer little protection if it moves activity away from the services most capable of providing safeguards.
A more direct control
Some harms can be addressed without identifying every user with high confidence. Services can make protective design the default, reduce contact risks, provide clear recommendation controls, create stopping points and limit the use of sensitive behavioural signals.
Age assurance may still be justified for particular functions. The point is to match the strength of the check to the risk being controlled and to compare it with measures that act directly on the product design.
A serious proposal must answer two questions together: how will the rule be enforced, and what new system will that enforcement create?