background image blur
background image

Remember When the Internet Didn't Ask Who You Were?

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 20 August, 2026
A green and black identity verification app interface

Key Takeaways

  • Online age screening began with a 1998 US privacy law; rigorous ID and facial-estimation checks are a much more recent development.
  • Requirements vary by country and by US state, from a simple self-declared checkbox to a mandatory ID scan.
  • Verification tools can collect government IDs, live facial images, or credit card data, and data retention rules differ by provider and jurisdiction.

There was a time the internet trusted you. You typed in an age, clicked a box, and that was that. No uploading documents, no forced, unflattering selfies, and no third-party company checking a database.

The shift from that one-click checkbox to a document scan didn't happen all at once, and it didn't happen everywhere for the same reasons. It's a twenty-eight-year story of privacy law, child-safety politics, and platform engineering catching up to each other. Here's how the internet went from taking your word for it to asking for your papers.

A Short History of "Prove It"

Online age and identity verification started as a data-protection measure, not face control. The rigorous stuff came later, in a wave that’s still building. The timeline below traces the milestones that matter, in order.

Date and JurisdictionLaw
🇺🇸 Effective since April 21st, 2000The Children's Online Privacy Protection Act of 1998 (COPPA) requires websites to post privacy policies, provide parents with direct notice of their information practices, and get verifiable consent from a parent or guardian before collecting personal information from children.
🇰🇷 Effective 2007, overturned in 2012The real-name system mandated that websites with 100k+ daily visitors had to record their real identities. The users' resident registration numbers were used as verification. The law was overturned in 2012 because it was deemed unconstitutional, not to mention ineffective.
🇬🇧 Effective since September 2021The Children’s Code applies to websites likely to be accessed by minors, requiring them to have the strongest privacy settings by default, collect the minimum amount of data,  and be designed in the best interests of children and their health, safety, and privacy.
🇫🇷 Effective since July 2023The “Digital Majority” law requires that social networking websites refuse access to children younger than 15 unless they have the consent of their parent or guardian.
🇬🇧 Effective since 2023Under the Online Safety Act, websites must review any threats to children from using their platforms and enforce appropriate age restrictions, ensuring that children have age-appropriate experiences and are protected from harmful content.
🇪🇺 Effective since 2024The Digital Services Act (DSA) requires websites to implement "appropriate and proportionate measures" to ensure the safety and privacy of children and young people accessing the website.
🇺🇸 Ongoing since January 2023 across multiple statesLouisiana was the first to introduce mandatory ID-based age verification for adult content. This snowballed across the United States; as of August, 2026, at least 25 states now require age verification for websites hosting content “harmful to minors”.
🇦🇺 Effective since December 2025Australia became the first country in the world to block children younger than 16 years old from using social media platforms. To enforce the law, measures of age verification are now taken by those platforms.
🇧🇷 Effective since March 2026The Digital ECA requires websites to design their services with children’s safety as a priority, protecting against harm. Age verification is described as a crucial element of this.
A timeline of age and identity verification laws

A few of these deserve a closer look, because they show how the logic changed over time.

  • COPPA (1998) is where the regulatory story begins. It didn't demand that anyone prove their age. It restricted how online services could collect personal information from children under 13 without parental consent, which is why sites began asking users to confirm they were 13 or older. 
  • South Korea's real-name law is the cautionary tale in the middle. The country required identity verification to post on popular websites, then its Constitutional Court struck the system down in 2012. The useless law is a useful reminder that verification mandates aren't permanent fixtures; sometimes, courts help to course-correct.
  • The 2023–present US state wave is where the honor system gave way to hard checks. Louisiana's law, effective since 2023, was the first to require ID-based verification for adult content, and a long line of states followed suit. In 2025, the US Supreme Court upheld Texas's version of the law, giving states the go-ahead to create their own version of the law.

Europe, Asia, and Africa – Regional Notes

Outside the US, the picture is uneven, and it's worth being precise about where concrete mandates exist and where they don't.

Europe

In Europe, the EU's Digital Services Act sets platform-wide obligations that include protecting minors, and the Commission has been pushing age-assurance tools on top of it. 

As of August, 2026, no EU-wide social media ban (and, in turn, mandatory age verification) laws are in place, but privacy experts anxiously await the 2026 State of the European Union address, hoping President Ursula von der Leyen doesn’t announce anything of the sort.

However, some individual members of the European Union have gone further on their own:

  • 🇬🇧 The United Kingdom: Announced a ban on social media use by children under the age of 16. Expected to go into effect in early 2027, the ban would require social media platforms to rely on age and identity verification as a method of ensuring compliance.
  • 🇫🇷 France: The country had plans to follow the United Kingdom and ban social media for those 15 and under, but the country’s top court blocked it on August 14th, 2026, stating it limited people’s freedom. No age or identity verification for France. Not yet.
  • 🇩🇰 Denmark: The government has agreed to ban children younger than 15 on certain social media platforms hosting harmful content. Although no method of enforcement has yet been confirmed, it’s safe to say that age or identity verification will come into play.
  • 🇬🇷 Greece: Announced plans to ban social media for under-15s at the beginning of August, 2026. The restrictions should go into effect starting January 2027. Age or identity verification will, of course, go hand in hand with the new regulations.

Other member nations, including Germany, Austria, Italy, Norway, Poland, Slovenia, Spain, Sweden, Lithuania, Latvia, and others, are either currently drafting their own version of a social media ban or at least actively toying with the idea.

Asia

In Asia, South Korea's 2007–2012 real-name experiment remains the strongest documented historical case. Similar to the EU, many countries within the region are implementing age and identity verification in the name of protecting children and their mental health:

  • 🇲🇾 Malaysia: The country’s social media ban, which came into effect in June 2026, bans users younger than 16 from using these platforms and is already being criticized by experts as undermining the privacy and security of users by making them identify themselves.
  • 🇦🇪 The United Arab Emirates: The first Arab country to introduce such mandates, the UAE set a minimum age of 15 for social media use in June, 2026. Users will be granted access to social media thanks to age and identity verification measures like digital identity checks ​and AI-supported technologies.
  • 🇹🇷 Türkiye: Turkish MPs passed a law in April 2026 that would restrict children younger than 15 from accessing social media. The law forces social media platforms to install age‑verification systems, provide parental control tools, and require companies to quickly respond to content deemed harmful.
  • 🇮🇩 Indonesia: The country announced back in March 2026 that it will ban children under 16 from social media to protect them from online abuse. Researchers pointed out that to protect children, they’ll have to identify their age and identity, but no other methods of compliance were discussed.

Other countries in the region, including Vietnam, Japan, and India, are considering similar measures in the name of protecting their vulnerable children. How their equally vulnerable data will be handled remains to be seen.

Africa

Although Africa has also joined the trend of age verification in the name of protecting children, some countries have had data-protection laws that also carried children's provisions. Let’s take a look:

  • 🇬🇦 Gabon: Starting in April 2026, Gabon enacted a strict social media law, making it the first African country requiring age and identity verification for online platforms. The law sets the digital age of majority at 16, requiring parental consent and formal ID verification for minors.
  • 🇬🇭 Ghana: Following in Gabon’s footsteps, Ghana is reportedly actively working on an age verification law for those wanting to access adult content. Currently, reports indicate that users may need a national ID or driver’s license to prove they’re not underage.
  • 🇿🇦 South Africa: POPIA, the Protection of Personal Information Act, bans processing a child's personal data unless a parent or legal guardian (named a "competent person") gives explicit consent, or a strict legal exception applies.

Other countries in the region, including Egypt, Nigeria, and Kenya, are currently discussing possible age verification measures, mostly tied to social media. Rwanda, on the other hand, has confirmed the country is currently drafting legislation.

A world map with highlighted countries with age verification laws

How Many Laws Are We Talking About?

So how big is this, really? Big enough that any number published here comes with a short shelf life. 

In the US alone, mandatory age verification for adult content went from exactly one state at the start of 2023 to at least 25 by August 2026, with more bills filed every legislative session. 

In the European Union, around half of the member nations have either passed age verification mandates or are in the process of getting there.

Given that one in three online users worldwide is a child, according to UNICEF, it may seem fair to want to protect them. But what gets overshadowed in this conversation are the remaining two-thirds of all online users – legal adults – who get caught in the crossfire and have to prove their age or identity to access websites and platforms they’ve been interacting with for years.

What This Looks Like in Practice Today

The history is abstract. The request on your screen is not. Here's what the common methods actually ask for, and what each one quietly collects along the way:

  • Self-declared age: Otherwise known as the honor system. You can either type a birthdate or tick a box. It collects a claim and little else, which is exactly why regulators stopped trusting it.
  • Credit or debit card check: A child can’t get a bank card, so your card stands in as proof of adulthood. It hands over payment details, which is a lot of identity to answer a yes-or-no question.
  • Facial age estimation: Software studies a live selfie of you and estimates your age range. It collects a biometric, your face, even when it never learns your name.
  • Reusable digital ID or third-party assurance: A separate company vouches that you're old enough. Your data then lives with them, under their retention rules rather than the website's. An infamous example of this is Persona, the verification company previously used by platforms like Discord until it suffered a data breach.
  • Government ID upload: You take a photo of your  ID, often alongside a selfie of you for matching. This identity verification method is the most drastic: a full, legal identity document, passed to whoever is on the other end. Your full name, DOB, and SSN/personal code, all to access Instagram or TikTok. Not exactly a fair trade.

This is also where two terms that get thrown around interchangeably actually part ways. Age verification only needs to confirm you clear a threshold, and some methods, like facial age estimation, can return an age range without ever attaching a name to it. It’s also the method that kids have fooled with Sharpies, glasses,  and fake moustaches.

Identity verification confirms who you actually are. An ID upload does both at once, which is why it gives away the most, and why the same identity signals end up feeding things that have nothing to do with age, from ad targeting to streaming and identity verification, where who a platform thinks you are shapes what it lets you watch.

If You're Not Paying, You're the Product

Age and identity checks don't sit in isolation. They bolt onto a data economy that was already running at full speed, one where the product being sold is a detailed picture of you. A verification step just staples a fresh, high-value layer of identity onto a profile that ad networks and data brokers had already largely assembled.

The full mechanics of that economy deserve their own piece, and they get one in our breakdown on how cookie consent connects to identity data. The short version: the data you hand over to prove your age rarely stays where you left it.

Mysterium VPN – Privacy, Not a Bypass

The regulation wave this timeline describes is about your age. The data collection pipeline it sits inside is not. Every website you visit, age-gated or not, can and does log your IP address, your location information, and your browsing pattern.

Age verification just added a new layer of identity exposure on top of tracking that was already thorough. The fix was never going to be skipping the checkbox. It's cutting down how much you hand over everywhere else. This is where VPNs play a part you may not have considered.

Mysterium VPN doesn't remove or bypass age verification requirements. What we do is reduce how much of your identity and location get logged by everything else – the sites that have no age-related reason to know who you are. 

It works on a few fronts at once: Mysterium VPN's no-logs policy means the service itself keeps no record of your browsing, your IP, or your identity; masking your IP keeps your location out of the hands of every site you pass through; and our residential IP network, built on decentralized infrastructure, means your traffic can look more like an ordinary home connection than a flagged commercial VPN range.

Mysterium VPN helps protect your identity and location from being logged by every site you visit – it's not a way around age or identity checks themselves. The specifics are all laid out in how Mysterium VPN handles your data, and if it's what you're after, you can get Mysterium VPN and keep the ordinary business of browsing to yourself.

In a world where data collection is inevitable, it’s up to you to decide how much of it you’re willing to hand over.

Where This Goes From Here

The through-line of the last twenty-eight years is simple, if a little bleak: proving who you are online keeps getting more expensive, and the cost isn't measured in money. It's measured in the pieces of yourself you have to surrender to do ordinary things. 

Age gates are just the newest tollbooth on that road, and the identity signals they run on are the same ones behind how geoblocking uses the same identity signals to decide what you're even allowed to see.

None of this is an argument against keeping kids safe online, which is a real goal with real stakes. It's an argument for keeping the price of everyday browsing low enough that privacy doesn't mean re-proving your identity every time you open a tab. That's the whole point of Nothing to Prove: you shouldn't have to.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img

Frequently Asked Questions

When did websites start requiring age verification?
Online age screening began with the US COPPA law, enacted in 1998, which led sites to add "are you 13 or older" checkboxes to comply with its rules on children's data. Rigorous ID-based and facial-estimation checks are far more recent, arriving largely from 2023 onward through US state laws.
Is online age verification the same everywhere?
No. Requirements vary significantly by country and, in the United States, by state. They range from a simple self-declared checkbox to mandatory government-ID uploads or facial age estimation, and some countries have no dedicated age-verification mandate at all.
What data do age verification tools collect?
It depends on the method. A self-declared age collects almost nothing, a credit card check collects payment details, an ID upload collects a full identity document, and facial age estimation collects a biometric image. Retention practices vary by provider and jurisdiction.
What is the difference between age verification and identity verification?
Age verification only confirms you meet an age threshold, and some methods return an age range without learning your name. Identity verification confirms who you actually are. An ID upload does both, which is why it exposes the most personal information.
Does a VPN help with online age verification?
A VPN doesn't remove or bypass age verification requirements. What it can help with is reducing how much of your identity and location get logged by the other sites you visit for reasons unrelated to age checks, such as ad trackers and data brokers.
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"