Detailed research note

UK implementation: platform choice, overlapping regulators and a cancelled national programme

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

Read on9September2026. This is a bounded public-document account, not a live verification-flow experiment, source-code audit or proof of actual deletion.

Currentness correction

The March2026 Cabinet Office digital-ID consultation proposed online age proof as a use for younger teenagers and said the credential would not be the only permitted method (PDF51–52). It also considered a cross-government identifier (PDF33–34), with boundaries around government use. These are dated proposals. The House of Commons Library briefing dated4September2026 says the national scheme was cancelled21July2026, while OneLogin, Wallet and the private-sector DVS framework are separate. A ministerial answer dated8September explicitly confirms cancellation and says a full business case had not been finalised. Do not project the Marchproposal forward as current policy or claim cancellation removes online-age obligations. The recorded linkage is historical; current private and service-specific routes need separate tracing.

Original91page consultation PDF captured; scoped read PDF32–34,39–40,51–52,81–83. Library and minister pages read through web reader; originalGET403, no retry, derivative observations only. The Library statement about continuing other systems is an institutional summary, not verification of every component's live deployment.

Reddit: named processor and constrained claims

Current Reddit Help, updated24June2026, names Persona for ID/selfie verification, describes account-signal and third-party email inference, and lists app-store age signals depending on region/device. This generic page does not establish that every option is available to every UK user. Reddit says it stores verified age/status and receives no verification photos. The customer-specific Persona FAQ identifies Reddit as controller and Persona as processor under Reddit's instructions; it says ID-route birthdate or selfie-route estimated age is returned and personal information deleted within three days. These are published provider representations; contractual schedules and deletion evidence were not obtained. The date of birth return should not be reduced to a universal binary over18 token.

Persona's original FAQ HTML was captured; Reddit ordinaryGET403, readable web substitute retained as derivative. No guessed email-inference supplier, fee or link to VerifyMy is earned. Current provider summaries must not be backdated to2025 retention arrangements.

A second regulatory mechanism, with a specific period

The ICO's signed penalty notice23February2026 imposes GBP14,472,500 for specified UKGDPR infringements. Its processing period ends8July2025; its DPIA period ends31December2024. Paragraph74/PDF40 records Reddit's UK NSFW age-verification through Persona starting14July2025, after the relevant period. Paragraph301(a)/PDF152 expressly rejects treating later OSA compliance work as mitigation of those earlier infringements. Thus the fine was not an OSA fine for deploying Persona incorrectly, and the notice does not direct procurement of Persona.

The ICO's1April2026 update records an appeal. No tribunal disposition was established in the scoped current-source review. No receipt of penalty payment is claimed. The source includes a dispute over pseudonymity and additional data in paragraphs71–74/PDF38–40. This is an actual opposing platform position, not analyst speculation.

The ICO's separate FOIresponse24March2026 says it holds regular Ofcom meetings, varying by team from fortnightly to quarterly, while refusing a broad multi-year request on burden grounds. That establishes a reported coordination routine, not that every meeting concerned Reddit. It identifies normally generated records worth seeking with a much narrower time/topic boundary. The refusal is not evidence of concealed misconduct.

Original209page penalty and8pageFOI PDFs retained. Scoped penalty reading: PDF4–11 introduction/periods,38–40 age-gating and competing position,42–43 controller/period discussion,134 and152 mitigation. No full annex, statistical or tax/financial audit. ICOpressHTML captured and read for penalty and appeal update. FOIpp1–7read request, response, meeting description and assistance; individual requested categories are not all confirmed held.

Discord: feature gates rather than account-wide identity entry

The UK-specific help page updated28July2026 names k-ID and describes age checks to unblur flagged media, access age-restricted spaces and change certain settings, including MessageRequests. It says those declining retain account, DMs, voice, friends and servers, with the stated restrictions. It describes on-device facial estimation, document checks and a GoogleWallet test; methods are not interchangeable disclosures. This refines existing Discord/k-ID/Wallet edges rather than inventing another deployment. Its privacy and deletion statements are company claims, not tested properties.

OriginalGET403; web-reader body read, derivative only. Existing general Discord source and historic age-appeal support exposure remain separate. Do not treat the historic support breach as a new compromise of the normal UK verification path.

Maximum-value missing records

Reddit–Persona processing schedule, age-output schema and retention/deletion settings would identify the actual controller instructions and retained fields. The UK rollout/configuration record would establish which alternative routes work there. A dated ICO–Ofcom age-assurance meeting agenda/action log near July2025 would test specific coordination without requesting years of unrelated material. Discord's UK change/requirement mapping would show which feature restrictions were platform choices and how these relate to statutory duties. No outreach, submission, paid access or logged-in flow was undertaken.