Age segmentation, not age gates.
DSA Article 28 and Ofcom children's-code compliance that keeps your signup flow intact.
Book a 20-minute demoGame and social platforms face a patchwork of obligations that increasingly ask you to know a user's age band rather than simply block them: the EU DSA's Article 28 minor-protection guidelines, Ofcom's Children's Codes under the UK Online Safety Act, app-store age-signal laws, and the industry normalization set by Roblox and Discord's facial age checks.
The right answer is rarely "ID everyone at the door." Xident lets you apply graduated, on-device age assurance — a lightweight age signal that sorts users into 13 / 15 / 18 tiers at the feature level (chat, spending, social) — so you segment experiences instead of walling off signup, while keeping children's data out of your systems by design.
Why now
Age-verification law for gaming, by country
How the major markets regulate age assurance in this sector — and what each one requires of operators.
| Country | Law / Regulator | Min. age | Requirement | Status |
|---|---|---|---|---|
| European Union | DSA Article 28 + GDPR Art. 8 | 13–16 | Minor-protection measures and age-appropriate experiences; consent age varies by member state. | In force |
| United Kingdom | Ofcom Children's Codes + OSA | 13 / 18 | High-privacy defaults for minors; age assurance for risky features. | In force |
| United States | COPPA + state app-store acts | 13 / 16 | Verifiable parental consent under 13; app-store age signals (UT, TX). | Phasing in |
| Belgium | Gaming Commission ruling on loot boxes | 18 | Paid loot boxes treated as gambling — effectively banned / age-gated. | In force |
| Australia | Classification + social-media age rules | 15 / 16 | Loot-box labelling; under-16 social-feature restrictions phasing in. | Phasing in |
| South Korea | Game Industry Promotion Act | 18 | Real-name & age verification; loot-box probability disclosure. | In force |
- Law
- DSA Article 28 + GDPR Art. 8
- Min. age
- 13–16
- Requirement
- Minor-protection measures and age-appropriate experiences; consent age varies by member state.
- Law
- Ofcom Children's Codes + OSA
- Min. age
- 13 / 18
- Requirement
- High-privacy defaults for minors; age assurance for risky features.
- Law
- COPPA + state app-store acts
- Min. age
- 13 / 16
- Requirement
- Verifiable parental consent under 13; app-store age signals (UT, TX).
- Law
- Gaming Commission ruling on loot boxes
- Min. age
- 18
- Requirement
- Paid loot boxes treated as gambling — effectively banned / age-gated.
- Law
- Classification + social-media age rules
- Min. age
- 15 / 16
- Requirement
- Loot-box labelling; under-16 social-feature restrictions phasing in.
- Law
- Game Industry Promotion Act
- Min. age
- 18
- Requirement
- Real-name & age verification; loot-box probability disclosure.
The cost of getting it wrong
- UK/EU: data-protection fines up to 4% of global turnover for mishandling children's data (GDPR / DPA); DSA penalties up to 6% for systemic minor-protection failings.
- COPPA: FTC penalties per violation (per child) for under-13 data without verifiable parental consent.
- Loot-box markets (Belgium, Netherlands): fines and forced feature removal / market withdrawal.
- App-store delisting and platform-policy enforcement for missing age signals.
How on-device works
How Xident verifies age for this sector
The same privacy-first flow underpins every vertical: clear most users on-device, fall back to documents only when needed, and re-use the credential for returning visits.
Age is estimated on the device
An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.
Nothing leaves the device
No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.
Document fallback only for borderline cases
Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.
The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.
The benefits
Why operators choose Xident for gaming
Meet your age-assurance obligations without becoming a store of biometric or identity data.
13 / 15 / 18 tiers at the feature gate — not a front-door wall
Unlock spending, chat or social features with a fast age signal that places each user in the right band, applying friction only where a feature's risk and the local law require it. Signup stays intact; the segmentation happens behind it.
On-device privacy (GDPR Art. 8, parent-friendly)
Age is estimated in the browser — no images sent to your servers — so data minimisation is built in. Where verifiable parental consent is required (COPPA, GDPR Art. 8), Xident can establish the adult in the loop without retaining the child's biometrics.
Per-check vs reusable-credential economics
Pay per Check for one-off feature gates, or issue a reusable credential so frequent players clear instantly — letting you tune cost against engagement rather than re-verifying on every session.
Privacy by design — faces never leave the browser
On the fast path, age is estimated client-side with on-device models; only a pass/fail age signal reaches the server, never the image. You meet age-assurance duties without becoming a honeypot of biometric data — the single biggest objection regulators and users raise.
Frequently asked questions
Do I need to verify the age of every player?
How do you handle under-13 / parental consent?
Is this different from gambling verification?
Related solutions
Ready to verify age the privacy-first way?
Integrate in minutes. Clear most users on-device in seconds. Re-use the credential so returning users never re-verify.
Book a 20-minute demoThis page is provided for general information only and does not constitute legal advice. Age-verification law in this sector changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations in each market with qualified legal counsel.