https://enablingdigitalidentity.blog.gov.uk/2026/08/18/how-can-a-business-be-confident-that-a-digital-proof-of-age-belongs-to-the-person-presenting-it/

How can a business be confident that a digital proof of age belongs to the person presenting it?

Posted by: and , Posted on: - Categories: Digital identity

The Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026 (“the Mandatory Licensing Conditions”), once it is approved by Parliament and has come into force, will enable retailers and hospitality venues in England and Wales to accept digital proofs of age when selling or supplying alcohol, provided the statutory conditions are met and subject to any local licensing conditions.  

As part of the new statutory conditions, licence holders must ensure that the digital proof of age being presented is both: 

  • of sufficient quality – that it “reaches at least a medium level of confidence”, and  
  • that it belongs to the person presenting it – a process we refer to as “binding”. 

This blog post may be helpful for licence holders and digital verification service (DVS) providers. It explains how DVS could be used to help ensure those requirements are met. 

The regulations are technology-agnostic 

The Mandatory Licensing Conditions do not prescribe a specific operational or technical implementation approach to confirming that someone is old enough to purchase alcohol.  

There are different ways that a DVS could be used to reach “a medium level of confidence” in someone’s age. There are also different ways to confirm whether the person in front of a licence holder that is trying to purchase alcohol is who they claim to be and that they are “bound” to that age information. 

OfDIA intends to publish, soon and as appropriate, some “service patterns” that will demonstrate different possible approaches. For the purposes of this blog post, and to make explaining the concepts of “level of confidence” and “binding” simpler to understand, assume that: 

  • A licence holder has contracted with a DVS provider which offers software and hardware that enables the licence holder to accept a digital proof of age. This could be similar to the way a licence holder might partner with a payment services company to enable them to accept debit and credit card payments.  
  • A customer has a digital wallet on their phone which contains a digital proof of age. This is similar to how customers might store payment cards and store cards on their phone today. 

You can’t tell if digital proof of age is good enough only by looking at it 

It is increasingly easy to create convincing replicas of identity documents that confirm your age; with digital proofs of age, this could be even easier thanks to generative AI. For that reason, licence holders must not rely on visual checks of a digital proof of age – for example by visually inspecting a customer’s phone. 

Good quality digital proofs of age can be reliably verified for their authenticity. The only reliable way to check digital proofs of age is using technology, something we refer to as a “programmatic check”.  

Instead of visual inspection, licence holders must use a registered DVS to check that the digital proof of age being presented by their customers is genuine. Only DVSs that appear on the government’s DVS register can be used for those checks. Think of this as the equivalent of asking a user to make a contactless payment or to enter their PIN code on a card terminal. 

In addition, the identity that has been used to create the digital proof of age must have been verified to at least a medium level of confidence by a registered DVS provider.  

“Medium level of confidence” 

The “level of confidence” you have in the age and identity information being claimed by a customer is a measure of how sure you can be that the claim is true. The Mandatory Licensing Conditions prescribe that a “medium” level of confidence is provided according to government guidance. This level of confidence can be met in a variety of ways, and DVS providers will be assessed as part of their trust framework certification on which levels of confidence they are able to meet. 

Licence holders do not need to understand levels of confidence in detail. DVS providers will be able to confirm to a licence holder whether their services are registered to provide information about someone’s age at a medium level of confidence or higher.  

Licence holders can also confirm the level of confidence a provider is able to offer, by looking at the DVS register

DVS providers take different technical approaches to “binding” 

When they build their services, DVS providers must ensure that information about a person relates to the person presenting it.  

Different providers may achieve this in different ways. The amended licensing conditions do not specify a particular approach. Similarly, different service models may be used to deliver a digital proof of age. What matters is that licence holders can satisfy themselves that the proposed approach ensures compliance with the terms of the agreement required under the legislation . In many cases, this may involve contractual arrangements and agreement that a registered DVS will be used across all parts of the service chain.  

For example, some DVS providers may choose to use biometric authentication to help establish that a person is the legitimate holder of a digital proof of age. This could involve a real-time comparison of the customer’s face against a reference image that was captured when they set up their digital proof of age. 

Another approach could involve PIN codes and transmission of a photo to a licence holder’s point of sale device, so that the staff member behind the counter can visually compare the photo with the person in front of them.  

Some stakeholders have also asked about the risk of a person deliberately sharing a device or credential with somebody else, for example an older sibling sharing a proof of age with a younger sibling. Providers are expected to manage impersonation risks appropriately and demonstrate that their approach is sufficiently robust. Licence holders should conduct their own due diligence to assure themselves that the DVS providers they work with deliver DVS in line with their legal obligations. 

The legislation does not mandate a particular technology. This flexibility supports innovation while maintaining trust. 

What matters is whether the provider can demonstrate that it delivers the required level of assurance. This includes confidence that the person meets the required age and that the age information relates to the person presenting it, while sharing only the information necessary for the digital age verification.  

Every service on the DVS register is audited, so licence holders can trust it 

By requiring the use of a registered DVS, we can be more confident that a proof of age is reliable, technically robust and is not being used by an impostor.  

Services on the DVS register are regularly, independently audited and certified against the UK digital verification services trust framework, which are the minimum quality standards for digital verification in the UK set by the government for those service providers who choose to be certified and appear on the DVS register. The registration and certification process is designed so that relying parties can trust services on the register without needing to conduct extensive assessments of the underlying technologies themselves. 

Licence holders still need to do due diligence 

Appearing on the DVS register means that a service meets the requirements of the DVS trust framework. It does not mean that a DVS provider offers a service that is compliant with the requirements of the Mandatory Licensing Conditions.  

Licence holders will need to satisfy themselves that a DVS they work with meets their business needs. We anticipate that licence holders will use contractual mechanisms and other controls to ensure, on an ongoing basis, that DVSs they use meet their business needs and can meet their regulatory obligations. 

Sharing and comments

Leave a comment

We only ask for your email address so we know you're a real person

By submitting a comment you understand it may be published on this public website. Please read our privacy notice to see how the GOV.UK blogging platform handles your information.