Skip to news

Digital proof of age in UK pubs is a choice with conditions

New rules allow certified digital services to verify age for alcohol sales, but adoption, interoperability and inclusion remain unresolved.

By THE COLDAI TIMES deskPublished 5 min read1,096 words
Smartphone in a folio case; contextual file photo, not an approved digital-ID app.
Smartphone in a folio case; contextual file photo, not an approved digital-ID app.Acabashi · Blackview A60 Smartphone Android mobile phone and folio case.jpg · Wikimedia Commons · CC BY-SA 4.0

England and Wales have added a new route for proving age when alcohol is sold: customers may use a digital proof of age from a certified Digital Verification Service (DVS), alongside existing physical identification. The change is practical, but its significance depends less on the novelty of a phone-based check than on how the system distributes responsibility among government, technology providers, venues and customers.

A legal option, not a national mandate

The rules came into force on 15 September 2026 under the Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026. They do not change the legal drinking age, and they do not require a pub, shop, restaurant or festival to adopt digital verification. Businesses may continue to use physical documents, and customers may continue to present them.

That distinction matters. Public discussion of digital identity often collapses an optional service into a universal identity system. The government’s announcement is narrower: it permits certified digital proof of age for alcohol sales in England and Wales. It is separate from the government’s digital driving licence and GOV.UK Wallet, although the government says a wallet may eventually be one way people prove age digitally.

The immediate change is therefore permissive rather than compulsory. A venue can decide whether the operational benefits justify adoption, while a customer can decide whether to use a phone-based credential. The policy’s real test will be whether that choice remains meaningful in busy venues where staff, software and local procedures may differ.

Certification is the central safeguard

The system is not intended to accept a screenshot or a convincing image of an identity document. Government guidance says an alcohol seller must use a DVS that appears on the statutory register at the point of sale. Registered services are certified against the UK digital verification services trust framework and are independently audited.

The government’s explainer makes an important operational distinction: appearing on the register means that a service meets the framework’s requirements, but it does not mean that a particular venue’s entire implementation automatically satisfies its licensing responsibilities. The licence holder must still decide whether the service works for its business, provides sufficient assurance and is supported by appropriate controls.

That division prevents certification from becoming a blanket transfer of responsibility. A registered provider supplies part of the trust infrastructure; the venue remains responsible for preventing underage sales, proxy purchases and sales to people who are intoxicated. Existing licensing duties do not disappear because a customer uses a phone.

The guidance also says that visual inspection of a digital proof is not permitted. Staff must use a technological, or programmatic, check. This is a significant detail because a digital image can be copied or manipulated even when it looks authentic. The integrity of the transaction depends on the registered service and the checking process, not on a bartender’s ability to judge an app screen.

Privacy promises and their limits

The strongest consumer argument is data minimisation. A physical driving licence or passport can reveal a name, address, photograph and other information when the immediate question is simply whether someone is at least 18. The government says a certified service can allow the customer to disclose confirmation of age without handing over unnecessary details.

That is a privacy promise, not proof that every implementation will disclose only the minimum. The amount of information processed depends on the certified service, its interface, the venue’s systems and the data-protection practices behind them. The guidance says licence holders and providers must comply with data-protection law and process only what is necessary for age verification, but customers will still need clear information about what is stored, by whom and for how long.

The programmatic requirement also creates a trade-off. Stronger checks can reduce the risk of borrowed or fake credentials, but they may require account recovery, biometric matching or another form of identity assurance. The BBC reported that some services use a facial scan to match the person logging in with the identity associated with the account. That may improve confidence that the credential belongs to the presenter, while also raising understandable questions about biometric data, false matches and access for people who cannot or do not want to use such systems.

Inclusion is an implementation question

The government says digital proof should be convenient, interoperable and, where possible, usable without mobile data or Wi-Fi. Those are important design goals. They are not the same as demonstrated availability in every pub or shop.

A customer without a suitable phone, battery, connectivity, digital skills or a registered credential may still need a physical route. Digital-rights campaigners warned the BBC that the option could become exclusionary if businesses effectively required it. The legal framework described by the government keeps physical identification valid, but the experience on the ground will depend on staff training, venue policy and whether alternatives are offered without embarrassment or delay.

The system must also work in the real conditions of hospitality: queues, noisy rooms, poor connectivity, damaged screens, self-service equipment and staff turnover. Government guidance says digital proof may be used at self-service checkouts, but those checkouts cannot be completely unsupervised because venues remain responsible for preventing proxy purchases and refusing sales to intoxicated customers. This illustrates the broader point: age verification is one component of a sale, not a complete substitute for human judgment.

What success would actually mean

The policy should not be judged by launch-day excitement or by the number of providers listed. Useful measures would include whether customers can use more than one certified service across venues, how often checks fail for legitimate users, whether physical alternatives remain available, how much personal data is retained and whether businesses experience lower friction without weakening safeguards.

The government and industry groups describe interoperability and multiple suppliers as important to avoiding fragmented adoption. That is sensible, but it remains an implementation challenge. If one pub accepts one service and another accepts a different service, the theoretical convenience of digital proof may become another form of carrying the right credential.

The policy is therefore best understood as a controlled expansion of age-verification choices. Its benefits are plausible: less disclosure of personal information, faster checks and stronger resistance to forged documents. Its risks are also concrete: exclusion, unclear data practices, inconsistent venue acceptance and overconfidence in certification.

The legal change creates permission and standards. It does not yet establish universal acceptance, measured effectiveness or a mandatory digital identity. Those outcomes will depend on how providers, venues and regulators implement the framework, and on whether customers can use it without losing a genuine physical alternative.

Related stories