Three kinds of check
The OAIC explains the methods in plain words for families.
| Kind | What it looks at | What it does |
|---|---|---|
| Age inference | Information already shared: who you follow, how you speak, when you post, when the account was created | Suggests an age from that evidence, often in the background |
| Age estimation | A task such as a selfie or video: your face, how you move, your voice | Uses artificial intelligence and statistics to guess an age or age range |
| Age verification | An image of a government ID such as a learner’s licence or passport, or signing in with another service that knows your age | Confirms age against systems that already know it |
The law doesn’t require one method, so each platform may use different checks, sometimes more than one, and sometimes through outside companies the OAIC calls “third parties”. Inference can feel as though no check happened at all; estimation and verification take longer and ask for more.
Not everyone has to be checked. eSafety doesn’t expect a platform to put every account holder through a check if it has other accurate data showing they are 16 or older. Its example is someone who has had a Facebook account since Facebook started in Australia in 2006.
Signals that can trigger a check
eSafety lists the kinds of signal platforms may use to work out whether an account holder could be under 16, or could be in Australia while appearing not to be, for example through a VPN.
Signals about age
- how long the account has been active
- interacting with content aimed at under-16s
- the language level and style of the account and its contacts
- facial age analysis of photos and videos
- age estimation from the voice
- activity that follows school timetables
- connections with users who seem to be under 16
- membership of youth-focused groups
Signals about place
- IP addresses
- location from GPS or similar services
- the language and time settings on a device
- an identifier for the device
- whether the phone number is Australian
- settings in the app store, operating system or account
- photos, tags, connections and activity
These signals are expected to start an age check, or a fresh look at an account that has already passed one. So passing a check once doesn’t settle it: an under-16 account can still be removed or deactivated later. Platforms are also expected to stop people faking their age with false documents, AI tools or deepfakes.
No one can be made to use a government ID
eSafety says the law “specifically prohibits platforms from compelling Australians to provide a government-issued ID or use an Australian Government accredited digital ID service to prove their age”. A platform may offer ID as one option, but must also offer a reasonable alternative, including when another method gives a result the person doesn’t accept.
If someone aged 16 or over loses an account by mistake, or because of a false report, platforms are expected to have a way to ask for a review and to correct errors.
What the law says about the data
The privacy rules sit in section 63F of Part 4A of the Online Safety Act, alongside the Privacy Act 1988 and the Australian Privacy Principles. The OAIC describes them as “additional, more stringent obligations” for platforms and age-check providers.
- One purpose. Personal information collected for the age requirement must not be used or disclosed for any other purpose, except in limited circumstances set by the Privacy Act, or with the person’s “voluntary, informed, current, specific and unambiguous consent”.
- Then destroyed. Once it has been used for the purposes it was collected for, it must be destroyed. The OAIC notes this is stricter than the usual Privacy Act rule in two ways: de-identifying the information is not enough, and it can’t be kept because of some other possible business use.
- Told, and asked. Platforms and providers must tell you your information is being looked at. They don’t always need your permission for the check itself, but they must ask before using the information for something else, such as advertising.
The OAIC’s guidance to platforms says inputs such as ID images and selfies collected for an age check should be destroyed as soon as their purpose is met, including from caches and storage, and that people should be told at the moment it matters what is collected, why, by whom, for how long, and what alternatives and reviews are open to them. Information a platform already held for other reasons, and reuses to infer age, falls under the ordinary Privacy Act rules rather than section 63F, though any new record made from it for the age check, such as a “16+” flag, is covered.
If you think your data was mishandled
A breach of section 63F counts as an interference with privacy under the Privacy Act, so a person can complain to the Information Commissioner. The OAIC’s advice is to complain first to the platform or age-check provider. To help, it publishes contact details for the named age-restricted platforms and common age assurance providers. If they don’t resolve the complaint, you can take it to the OAIC.
Telling a real check from a fake one
eSafety warns that scammers send fake age-check requests, often with a sense of urgency, threatening to delete an account unless you act quickly. Its advice:
- trust only what the platform itself says, in its Help or Support section, opened through the app or your browser
- if a text, email or other message asks you to prove your age, don’t click its links or open its attachments unless you can verify where they came from
- go back in the app or website to see what triggered the request
- a request to pay a fine for being under 16 on social media is a scam: do not pay.
eSafety also points to the Australian Government’s Scamwatch site for the latest scams.