Header illustration for "Age assurance without handing over your licence: how Australia's under-16 social media law actually limits ID collection"

"Age assurance without handing over your licence: how Australia's under-16 social media law actually limits ID collection"

Age assurance without handing over your licence

Australia's under-16 social media ban has been news since it took effect on 10 December 2025, and most of that coverage has been about the ban itself. The more interesting half of the law is what it says about how age can be checked — because Parliament wrote privacy limits into the enforcement machinery, and those limits are now being tested against five major platforms.

It's easy to read a law like this and assume the worst version: everyone uploads a passport to a database that never forgets. Parliament clearly anticipated that outcome and wrote against it. Whether those safeguards survive contact with five platforms that profit from knowing everything about everyone is the live question of 2026.

The two-sided duty

The Online Safety Amendment (Social Media Minimum Age) Act 2024 requires designated platforms to take "reasonable steps" to keep under-16s off their services. But it contains a matching prohibition: under section 63DB, a platform cannot collect government-issued identification material as the sole means of age assurance. If ID is offered as one option, a reasonable non-ID alternative must always exist. The penalty regime is the same size on both sides — breaching the obligation or compelling ID as the only route can each attract the maximum fine. That symmetry wasn't accidental; it exists to stop platforms from treating the ban as a licence to build national identity databases.

In March 2026, the eSafety Commissioner flagged five platforms — Facebook, Instagram, Snapchat, TikTok and YouTube — for compliance concerns, citing observed practices like prompting children to attempt age checks even when their declared age was already under 16, and letting under-16s retry the same method until they cleared it. In her own words at the time, the regulator was "moving into an enforcement stance", and the media release was candid that the evidence threshold is systems-based, not headcount-based: a platform won't be fined merely because some children slipped through, but for failing to implement appropriate systems and processes.

In September 2026, Parliament doubled the maximum penalty to $109.2 million and strengthened eSafety's information-gathering powers, including the ability to summon platform executives to give evidence. The amendments also lifted the infringement notice ceiling — breaches of the minimum age obligation or the ID prohibition can now draw a $21.8 million fine without ever reaching a courtroom, and ignoring an information-gathering notice costs $364,000. eSafety's compliance report is the running scorecard; the March edition is where those observed poor practices are documented in detail.

The privacy plumbing most people missed

Three mechanisms in the scheme do quiet privacy work:

The ID prohibition. Platforms can't build a "upload your driver's licence or you don't get in" gate. The guidance encourages a layered approach — behavioural signals, facial age estimation, document checks only as one lane among several. eSafety's guidance also states it doesn't expect providers to retain personal information as a record of individual age checks. In other words, the check is meant to evaporate once it's done: pass, delete, move on.

Ringfencing and destruction. The OAIC's guidance for individuals describes the obligation as one to "ringfence and destroy" information collected for age assurance, and confirms platforms are prohibited from compelling government ID. If a platform uses or discloses that data for anything else — advertising, profiling, model training — outside narrow exceptions, section 63F deems it an interference with privacy under the Privacy Act 1988. That's a second regulator with its own remedies, watching the same data. In practice this means the AgeCheck data and your behavioural profile are legally two different objects: the platform can't quietly stitch them together without the OAIC having a cause of action.

The consent bar. Where consent is used to justify secondary use, it must be voluntary, informed, current, specific and unambiguous — and withdrawable easily. That's a much higher bar than a pre-ticked box, and it bites the platforms' favourite pattern: bury a data-sharing toggle in the signup flow and treat "accepted" as agreement. Under this scheme, "accepted" doesn't count.

The trade-off is real, not hidden

None of this makes age assurance privacy-friendly. Facial age estimation — the alternative to ID — is its own biometric collection, and the government's Age Assurance Technology Trial put numbers on the trade-off. The trial consortium led by the Age Check Certification Scheme assessed 60-plus systems from 48 providers, and its age estimation findings reported mean absolute errors around one year in controlled conditions, with accuracy degrading in poor lighting and edge-case conditions, and "underrepresentation of Indigenous populations" still flagged as a challenge vendors are only beginning to address. The trial did observe, on the positive side, that most providers held temporary biometric processing with no image retention and sent binary age signals instead of raw data — privacy-by-design is appearing in the vendor base, unevenly.

A law that bans the lazy ID gate but requires checking everyone's age has pushed platforms toward face scans instead, with all the retention and security questions that entails. If you minimise the personal data you feed platforms in the first place — as our degoogled phone guide covers — you reduce what any age-assurance system can collect about your household.

The trial also noted a subtler hazard: a risk of "unnecessary data retention in the absence of clear guidance". Translation — without a regulator drawing the line, vendors will keep data because it might be useful. That is precisely the gap the OAIC's ringfencing guidance is meant to close, and it's why the two-regulator arrangement matters more than it sounds.

One detail the March enforcement move settled: "the kids can still get accounts" is not itself the offence. eSafety was explicit that the evidence must establish the platform failed to implement appropriate systems and processes — a deliberate standard that shifts the argument from outcomes to design. For the platforms, that's actually the harder standard to dodge, because system design is documented, discoverable, and hard to conceal behind statistical noise about accounts created by overstated birthdates. For anyone watching the docket, it means the interesting documents will be the internal age-assurement architecture reviews, not the monthly account-removal figures.

Practical takeaways

This article is general information, not legal advice. Legislative status and regulator positions checked on 7 October 2026.

← All posts