Age segmentation, not age gates.

DSA Article 28 and Ofcom children's-code compliance that keeps your signup flow intact.

Book a 20-minute demo

Game and social platforms face a patchwork of obligations that increasingly ask you to know a user's age band rather than simply block them: the EU DSA's Article 28 minor-protection guidelines, Ofcom's Children's Codes under the UK Online Safety Act, app-store age-signal laws, and the industry normalization set by Roblox and Discord's facial age checks.

The right answer is rarely "ID everyone at the door." Xident lets you apply graduated, on-device age assurance — a lightweight age signal that sorts users into 13 / 15 / 18 tiers at the feature level (chat, spending, social) — so you segment experiences instead of walling off signup, while keeping children's data out of your systems by design.

13 / 15 / 18
Common age tiers for data, spending & social features

Why now

Age-verification law for gaming, by country

How the major markets regulate age assurance in this sector — and what each one requires of operators.

European Union In force
Law
DSA Article 28 + GDPR Art. 8
Min. age
13–16
Requirement
Minor-protection measures and age-appropriate experiences; consent age varies by member state.
United Kingdom In force
Law
Ofcom Children's Codes + OSA
Min. age
13 / 18
Requirement
High-privacy defaults for minors; age assurance for risky features.
United States Phasing in
Law
COPPA + state app-store acts
Min. age
13 / 16
Requirement
Verifiable parental consent under 13; app-store age signals (UT, TX).
Belgium In force
Law
Gaming Commission ruling on loot boxes
Min. age
18
Requirement
Paid loot boxes treated as gambling — effectively banned / age-gated.
Australia Phasing in
Law
Classification + social-media age rules
Min. age
15 / 16
Requirement
Loot-box labelling; under-16 social-feature restrictions phasing in.
South Korea In force
Law
Game Industry Promotion Act
Min. age
18
Requirement
Real-name & age verification; loot-box probability disclosure.

The cost of getting it wrong

  • UK/EU: data-protection fines up to 4% of global turnover for mishandling children's data (GDPR / DPA); DSA penalties up to 6% for systemic minor-protection failings.
  • COPPA: FTC penalties per violation (per child) for under-13 data without verifiable parental consent.
  • Loot-box markets (Belgium, Netherlands): fines and forced feature removal / market withdrawal.
  • App-store delisting and platform-policy enforcement for missing age signals.

How on-device works

How Xident verifies age for this sector

The same privacy-first flow underpins every vertical: clear most users on-device, fall back to documents only when needed, and re-use the credential for returning visits.

01

Age is estimated on the device

An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.

02

Nothing leaves the device

No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.

03

Document fallback only for borderline cases

Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.

The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.

The benefits

Why operators choose Xident for gaming

Meet your age-assurance obligations without becoming a store of biometric or identity data.

13 / 15 / 18 tiers at the feature gate — not a front-door wall

Unlock spending, chat or social features with a fast age signal that places each user in the right band, applying friction only where a feature's risk and the local law require it. Signup stays intact; the segmentation happens behind it.

On-device privacy (GDPR Art. 8, parent-friendly)

Age is estimated in the browser — no images sent to your servers — so data minimisation is built in. Where verifiable parental consent is required (COPPA, GDPR Art. 8), Xident can establish the adult in the loop without retaining the child's biometrics.

Per-check vs reusable-credential economics

Pay per Check for one-off feature gates, or issue a reusable credential so frequent players clear instantly — letting you tune cost against engagement rather than re-verifying on every session.

Privacy by design — faces never leave the browser

On the fast path, age is estimated client-side with on-device models; only a pass/fail age signal reaches the server, never the image. You meet age-assurance duties without becoming a honeypot of biometric data — the single biggest objection regulators and users raise.

Frequently asked questions

Do I need to verify the age of every player?
Usually not. Most studios gate only specific features (paid loot boxes, real-money-adjacent mechanics, social/chat). Xident's rules engine lets you scope age assurance to those features and the markets that require it, sorting users into tiers rather than blocking the door.
How do you handle under-13 / parental consent?
For under-13 flows, the requirement is verifiable parental consent. Xident can verify the consenting adult while keeping the minor's data out of your systems, supporting COPPA and GDPR Article 8.
Is this different from gambling verification?
Yes — gaming typically needs a lighter, faster age signal than licensed gambling. See our iGaming page for the full KYC-at-deposit flow.

Ready to verify age the privacy-first way?

Integrate in minutes. Clear most users on-device in seconds. Re-use the credential so returning users never re-verify.

Book a 20-minute demo

This page is provided for general information only and does not constitute legal advice. Age-verification law in this sector changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations in each market with qualified legal counsel.