We may earn commissions from products we recommend. Learn more.
Is age verification safe? What really happens to your ID and your selfie
Is age verification safe? What really happens to your ID and your selfie
Most people used to think of age verification as something you did when buying alcohol, going to a club, or opening a bank account. Now, it is much harder to avoid online.
More websites and apps now have to check if a visitor is an adult or a child, or they choose to do so. In the UK, for example, sites with adult content must use strong age checks as of July 25, 2025. Similar rules and proposals are emerging in the US and elsewhere. The European Commission is also working on a way for people to prove they are over a certain age without sharing their identity or full birth date.

This means regular internet users now face a new choice. A website might ask for your passport, driver’s license, selfie, credit card, phone number, or other proof. You might just want to read something or change a setting, but suddenly you are asked for information you usually keep private.
So, is age verification safe?
Age verification can protect your privacy, but there is no single type of technology or one-size-fits-all answer. For example, a system that checks your age on your phone and only tells a website you are "over 18" is very different from one that uploads your passport and selfie to another company and keeps them for months. Facial age estimation is another separate method.
This difference is important. At PCrisk, we do not think you should panic every time you see an age check, but we also do not suggest treating every verification as safe. Government IDs, facial images, birth dates, addresses, and account details are valuable personal data. The best approach is to know what is collected, who gets it, and how long it is kept.
In this article, we will use this approach and explain what really happens after you take a photo of your ID or face.
Bypass age verification with NordVPNSpecial deal30-day money-back guarantee→
Table of Contents:
- Introduction
- The rise of age verification
- How online age checks work
- What happens to your ID and selfie?
- Privacy concerns to consider
- What can I do to protect my data?
- Conclusion
- Frequently asked questions (FAQs)
The rise of age verification
Age assurance is a broad concept. It covers strict age verification, where a service checks your real age, and age estimation, where software estimates your age range without confirming your identity.
This distinction matters for a practical reason. Governments and platforms want to keep children away from age-restricted content, but asking every adult to prove their identity raises privacy issues. So, regulators and tech companies are testing systems that only need to answer questions like "Is this person over 18?" instead of "Who is this person?"
The UK provides one of the clearest examples of why users are seeing more age gates. Under its Online Safety Act regime, Ofcom says sites and apps that allow pornography have needed strong age checks since July 25, 2025.
The EU is taking a slightly different approach. The European Commission's age-verification work focuses on verifying someone's age while sharing as little personal information as possible. Their goal is to provide an "over 18" proof instead of giving every website your full identity and birth date.
Platforms are also creating their own systems. For example, in September 2026, Discord introduced a new global age-assurance system that tries to sort most users into age groups using account signals. Discord says over 90% of users should not need to provide proof of age themselves. For those who do, options include app-store age ranges, a credit card, an ID scan, a video selfie on your device, Google Wallet, or a reusable age credential.
It's important to notice this variety. "Verify your age" does not always mean you have to upload your passport.
Our top recommendation for streaming and privacy. NordVPN consistently leads our tests with fast speeds, reliable geo-unblocking, and a strict no-logs policy.
- ✔ Unblocks geo-restricted streaming services reliably
- ✔ 202+ locations across 111 countries
- ✔ 30-day money-back guarantee · Special deal available
How is age verification data collected?
Depending on the service, age data can come from several sources.
The most common way to verify your age is by using a government document. You take a photo of your passport, driver's license, or national ID card. Software checks the document, pulls out your date of birth, and sometimes compares the photo on the ID with a selfie to make sure it matches you.
An ID is just one way to check your age. Other systems might use facial age estimation, payment card details, your mobile provider, an existing digital identity, app store info, account activity, or age-related databases. For example, Yoti lists methods like facial age estimation, document checks, credit card verification, mobile provider checks, and matching your name, date of birth, and address in a database.
Each method has different privacy risks. A card check might keep your passport private but share info with a payment processor. Database checks may not require a photo, but they do require several personal details. Facial age estimation might only need a selfie, but privacy depends on whether the image stays on your device or is sent to a server.
How online age checks work
A document-based check usually happens in a few steps.
First, you take a photo of your ID. Some systems also ask for a photo of the back, a scan of an NFC chip, or a selfie or short video. The verification provider checks the document and reads details like your date of birth. If they need to confirm you own the ID, they might compare your selfie with the photo on your ID using biometric data.
But this doesn't always mean the website gets those files directly.
Often, an age-assurance provider sits between you and the website. You send your info to this provider, which checks your age and then reports the result to the website. Ideally, the website only receives a simple answer, such as "18+" or "age requirement satisfied."
This separation can really help protect your privacy. For example, Yoti says that with its direct document-verification system, your document is not shared with the website, and the system deletes both the document and your facial image after checking. Its reusable digital ID is meant to show only if you are above or below the required age. Keep in mind, these are claims from the vendor, so treat them as descriptions of how Yoti says it works, not as guarantees for every site using age assurance.
Discord offers another good example. For ID checks, Discord says its age-assurance vendor processes your ID and selfie, deletes them after verification, and only sends Discord your age group. For video-selfie age estimation, Discord says this runs on your device, so your facial data does not leave your phone or computer.
Other systems may work differently. The EFF found that some age-assurance tools send facial images to third-party servers, while others do the estimation on your device. Deletion practices also vary between providers.
Some systems do not need a new ID or selfie. For example, an app store or digital wallet might already know your age range and only share that information. A reusable credential can also prove that you meet the age requirement without requiring a full identity check every time. This idea is a key part of the EU's new privacy-focused approach.
From a privacy perspective, we prefer this approach: show only the necessary fact and share as little personal information as possible.
Top VPN reviewsExclusive dealsExpert-tested · hands-on reviews→
What happens to your ID and selfie?
There is no single place where your age-verification photo always goes. Your ID or selfie might stay on your device, go straight to the website, be sent to an age-verification company, pass through other service providers, or be used in a manual review.
So, when you see statements like "we don't store your ID," read them carefully. Who does "we" mean? Is it the website, the verification vendor, a subcontractor, or a customer-support provider?
A website might honestly say it never gets your passport, even if a third party processes it. This setup can be reasonable, but what matters most is the full path your data takes, not just whether the website itself stores your file.
The best systems try to keep this data path as short as possible. For example, Discord says that with its current manual confirmation methods, it only gets your age group, not your name, card details, ID documents, or facial scans. Discord also says its age-assurance vendors must delete uploaded verification data after checking your age.
Yoti similarly says that images used in its facial age estimation are deleted after the check and that direct ID verification does not share the identity document with the requesting website.
There is another important detail. Even if a provider deletes your original photo, the system might still retain some information about the transaction, such as the result, account status, fraud checks, or logs. What stays depends on the service. That’s why privacy notices should clearly separate the original ID or selfie from the results or other data created during the check.
Facial analysis vs. facial recognition: What's the difference?
These terms are often mixed together, but they describe different operations.
Facial age estimation is a type of facial analysis. The software looks at features of your face to guess your age or age range. It does not need to figure out who you are. NIST makes a clear distinction between face-analysis technology, which measures facial features, and face-recognition technology, which is used to identify people.
Facial recognition, or biometric matching, works differently. In ID verification, the software checks if your selfie matches the photo on your passport or driver’s license. The ICO says this process creates biometric templates from both images and compares them to make sure the person showing the ID is the same as the one in the picture.
This is usually a one-to-one comparison, not like police systems that search one face against millions. Still, because the goal is to make a unique match, the ICO considers this biometric identification under UK data-protection rules.
Age-estimation systems have another limitation: they can be wrong.
When NIST tested six facial age-estimation systems, none was clearly the best. Results varied depending on image quality, age, gender, and birthplace. NIST also found that factors like facial expressions or wearing glasses could affect the estimated age, and that the systems worked differently across groups.
So a selfie-only check may expose less identity data than a passport upload, particularly if processing happens on-device, but that does not mean it is perfectly accurate or appropriate for everyone.
Privacy concerns to consider
One of the biggest privacy concerns is having too much personal data stored in one place.
A typical account may include your email, username, and IP logs. If you add an ID and a selfie, the process might also collect your legal name, date of birth, photo, document details, and more. Depending on the document and process, this can be much more sensitive than just confirming if someone is an adult.
This is why it is important to collect only the data that is truly needed. If a website just needs to know you are over 18, it should only get that information, not your full identity. Both the EFF and the European Commission recommend systems that avoid sharing extra details.

Another concern is linkability. The age verification provider might know a check happened, and the website knows which account was checked. The more details shared, the easier it is to connect your real identity to your online actions. The EFF suggests thinking about not just what data is kept, but also who can see that a check happened and which service was used.
Retention is another issue. If sensitive files are deleted quickly, there is less risk of exposure. Keeping files for months or years increases the chance of leaks, unauthorized access, legal requests, or breaches. That is why having a clear and specific deletion policy is so important.
Secondary use is also a concern. Before you send a face photo or ID, check whether the information is used only for age verification or could be used for other purposes, such as training models, fraud checks, advertising, or profiling. It is better when the purpose is clearly limited to just verification.
Accuracy is another factor. Facial age checks are not perfect, and NIST has found that results can vary between algorithms and groups. Good systems should offer a way to appeal or use another method if someone is wrongly classified.
Bypass age verification with NordVPNSpecial deal30-day money-back guarantee→
What are the biggest privacy risks associated with age verification?
The main risks are clear: sharing more personal information than needed, sending it to more companies than you expect, keeping it longer than necessary, linking your identity to private browsing, and having your data exposed in a breach.
Not all age-verification systems have these risks. For example, a check done on your device that just says "over 18" is very different from sending your government ID to a server.
That is why we would not say that a selfie check is always safe or that an ID check is always unsafe. The way the system is built makes a big difference.
Data breaches and identity theft
No company can truly guarantee that a database will never be breached. The real question is how much harm a breach could cause if it happens.
Identity documents often hold enough details to be useful for impersonation or fraud. These can include your name, date of birth, address, photo, signature, or document number. The more of this data a verification service keeps, the bigger the risk if someone gets unauthorized access.
The same idea applies to facial data. If your password is stolen, you can change it, but you cannot change your face. While not every leaked selfie leads to identity theft, it is still wise to avoid creating extra copies of your facial data.
Could your photo end up on a leaked database?
Yes. There is already a particularly relevant real-world example.
In 2025, Discord reported that a third-party customer service provider was compromised. About 70,000 users may have had their government ID photos exposed. These IDs were used in customer support for age-related appeals. The compromised system might also have included contact details, IP addresses, support messages, and other customer service data. Discord stressed that the incident was with a third-party provider, not Discord’s main systems.
This case is helpful because it shows how complex data flows can get. The issue was not just that someone hacked an age-verification system. Sensitive documents ended up in a larger support process, and a third-party system was where the exposure happened. Discord has since stopped using that manual review process and changed its age-assurance system so it now only gets age-group results from its verification vendors.
The takeaway is not that every age-check provider will leak your ID. Instead, it’s that keeping data and giving third parties access are real security risks, not just theoretical concerns.
What can I do to protect my data?
At PCrisk, we suggest starting with the least intrusive option that still meets the site’s requirement.
If a service offers several options, don’t just pick "scan passport" because it’s listed first. Choose an option that shares less information. A digital-age credential, app-store age range, facial-age estimate done on your device, or another method that only proves your age might reveal less than sending a new copy of your ID. The best choice depends on the service and your situation.
Before uploading an ID or selfie, we recommend asking yourself the following five questions:
- What exactly am I sending?
- Who receives it?
- How long is it retained?
- What result does the website receive?
- Is there credible evidence that the system works as described?
These questions usually give you more insight than a simple "secure age verification" badge. We also suggest reviewing what data is collected, who can access it, how long it’s retained, whether there are audits, and who can see the verification process.
Pay close attention to phrases like "we do not store your ID." Make sure you read enough of the policy to know if "we" means just the website or if another company still gets and keeps your ID.
We also prefer systems that only tell the site whether you meet the age requirement. Usually, an adult-content site doesn’t need your address, document number, or full birth date - just confirmation that you’re old enough.
If you need to take a selfie, try to use a plain background. Don’t include mail, badges, computer screens, photos, your workplace, or anything else that could identify you unless it’s needed for verification. Only share what’s required for the check.
Always verify your age through the service’s official website or app. Age-verification prompts are a common target for phishing, since scammers can ask for the same information you’d usually never share with a stranger. Be extra cautious with unexpected emails or messages asking you to "reverify" by uploading your passport.
Where local privacy law gives you applicable deletion or access rights, you can also ask the service or verification provider what it retains after the transaction and request deletion when appropriate.
What about using a VPN to avoid an age check?
A VPN can be useful, but it’s important to explain how it works.
A service like NordVPN sends your internet traffic through a VPN server, which changes the public IP address that websites see. This means the website may think you are in the location of the VPN server instead of your real location. The EFF explains that a VPN hides your original IP address, so your connection looks like it comes from the VPN server.
If you are an adult and it is legal in your area, changing your IP location can sometimes stop a website from showing an age check when you access content or services you are allowed to use. For example, NordVPN lets you pick servers in different places. Using a VPN is legal in many countries, like the US, UK, and much of Europe, but some countries do not allow it. Also, note that using a VPN does not make illegal actions legal.
So, we would not call a VPN a guaranteed way around age checks. Always check your local laws and the service’s rules before using a VPN to try to avoid a verification step.
A VPN does not always remove age checks. Websites can still determine your location using other methods, such as GPS, cookies, mobile ad IDs, tracking pixels, or browser fingerprinting. Some services can also spot and block known VPN servers.
A good VPN helps protect your privacy by hiding your real IP address from websites and encrypting your internet traffic. This is helpful, especially on public Wi-Fi, but it does not make you completely anonymous. You also need to trust the VPN provider with your data.
Our advice is straightforward: use a VPN to protect your privacy and, if it is legal, to change your IP location. But do not expect it to bypass laws, website rules, account details, GPS, or other methods sites use to find your location.
Conclusion
Age verification is neither inherently safe nor inherently unsafe.
The most privacy-friendly systems only answer a simple question, like whether someone is over 18, without sharing much else with the website. On-device age checks, digital credentials, app store age settings, and systems that only verify a minimum age prove that websites do not need to collect passports for age verification. The EU is now working toward this kind of minimal-disclosure system.
On the other hand, some age checks require a government ID, a selfie, biometric matching, third-party involvement, and may retain your data for a long time. The 2025 Discord customer-service breach showed that ID photos collected for age checks can be exposed if they are stored in a weak third-party system.
That is why we do not just ask, "Do I trust age verification?" Instead, we ask, "Do I trust how my data is handled in this case?"
Who receives the ID? Does the website see it directly? Is my face analyzed on my device or sent elsewhere? Does the website get my full date of birth, or just a yes or no for "18+"? Is the original image deleted right away? What happens if the check fails or if I appeal? Are there independent audits? These details decide the real privacy risk.
We prefer methods that collect the least sensitive information, share it with as few organizations as possible, and keep it for the shortest time.
It is also important to keep the risk in perspective. Just because a facial scan exists does not mean your face is being added to a permanent recognition database. In the same way, a claim of "privacy-preserving age verification" should not make you upload your passport without checking. Always look beyond the marketing and see what the system really does.
At PCrisk, we believe users should have both online safety and privacy. These goals can go together. The best age-assurance systems show that a service can find out what it needs to know without seeing all the details on your ID.
And until that becomes the norm, the safest habit is still the simplest one: share no more information than necessary.
Frequently asked questions (FAQs)
Is it safe to upload my ID for age verification?
It can be safe, but it depends on the service. Before you upload your ID, check which company will receive it, whether the website itself will see your document, how long it will be kept, and whether it will be used for anything else. A system that quickly deletes your ID and only returns an age result usually poses less risk than one that retains full documents.
Do age-verification companies keep copies of my ID?
Some companies say they do not keep copies, but there is no single rule. Yoti says it deletes images after checking them, and Discord says its current verification partners must delete data after deciding on an age group. Other systems may retain data for different periods or have exceptions. Always check the policies of the provider and the website you use.
Does a website see my passport when I verify my age?
Not always. Some systems send your document to a specialist who only tells the website your age result. Yoti says its process works like this, and Discord says its current ID check only gives them your age group, not your actual ID. Other services may work differently.
Can my age-verification selfie be used for facial recognition?
It depends on how the system uses your selfie. Facial age estimation can check your age without knowing who you are. But an ID check might compare your selfie to your ID photo, which is a type of biometric matching.
What is the safest way to verify my age online?
There isn’t one method that works for everyone. From a privacy standpoint, I recommend using systems that only confirm if you meet the age requirement without sharing extra personal details. On-device checks and privacy-focused digital credentials help keep your data from being shared between companies.
Can a VPN prevent age verification?
A VPN can sometimes get around an age check that relies only on your IP address, since the website will see the VPN server’s location instead of yours. However, this doesn’t always work. Some sites use other ways to check your location or can tell if you’re using a VPN.
Is it legal to use a VPN to change my location and avoid an age check?
VPNs are legal in many places, such as the US, the UK, and much of Europe, but some countries have restrictions. Using a VPN doesn’t make illegal actions legal. If it’s allowed where you live, you can use a VPN to connect to a different server location, which might help you bypass an age check based solely on your IP address. Always follow your local laws and check the website’s terms of service.
Share:

Rimvydas Iliavicius
Researcher, author
Rimvydas is a researcher with over four years of experience in the cybersecurity industry. He attended Kaunas University of Technology and graduated with a Master's degree in Translation and Localization of Technical texts. His interests in computers and technology led him to become a versatile author in the IT industry. At PCrisk, he's responsible for writing in-depth how-to articles for Microsoft Windows.

▼ Show Discussion