Free guide: How to use AI in compliance
Editorial illustration for the article "Digital proof of age is now valid for alcohol sales in England and Wales".

From 15 September 2026, licensed premises in England and Wales may accept a digital proof of age, but only through a registered provider, never by eye.

Table of contents

Since 15 September 2026, licensed premises in England and Wales may accept a digital proof of age for alcohol sales. The Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026 lets an age verification policy admit digital identification, but only through a registered provider that returns a verified age result.

  • Statutory Instrument 2026 No. 1022 was made on 14 September 2026 and came into force the next day, extending to England and Wales only.
  • Accepting a digital proof of age is optional for the venue and the customer, and physical documents remain valid under the unchanged part of the mandatory condition.
  • A venue may only accept the check where it has an agreement with a provider on the statutory digital verification services register that confirms the age and delivers at least a medium level of confidence.
  • Staff may not simply look at the screen: the Home Office says visual inspection alone does not satisfy the new conditions.
  • The Home Office Economic Note prices the check at a central 15 pence and puts the ten-year net gain to business at 38.5 million pounds, within a range that runs deeply negative.

What changed on 15 September 2026?

The Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026 amends paragraph 3 of the Schedule to the 2010 mandatory conditions order. It was made on 14 September 2026 by Sarah Jones, Minister of State at the Home Office, and comes into force "on the day after the day on which the Order is made". It extends to England and Wales only.

The mandatory condition attached to every relevant premises licence has required the venue's age verification policy to demand identification bearing a photograph, a date of birth, and either a holographic mark or an ultraviolet feature. That wording still stands. What the 2026 Order adds is a permission to treat a digital proof of age as evidence: the policy "may make provision permitting a responsible person to accept identification in digital form". The Order calls that a relevant ID, and wraps the permission in conditions that must all hold before a member of staff can rely on it.

Element of the age verification policyBefore 15 September 2026From 15 September 2026
Accepted evidencePhysical document with photo, date of birth and a hologram or ultraviolet featureThe same, plus digital identification if the licence holder opts in
Check methodVisual inspection by the responsible personConfirmation returned by a registered provider
Assurance standardDocument security featuresAt least a medium level of confidence
Precondition for the venueNone beyond the written policyA live agreement with a registered provider

The Home Office is explicit about the check-method row. Its Explanatory Memorandum states that "a mere visual inspection of the digital identification will not be sufficient" to meet the instrument's requirements. A screenshot of a wallet app, or a colleague's phone held up at the till, is not a lawful check.

How does a digital proof of age check actually work?

The Order engages where two things coincide: the responsible person has reason to believe the customer is under 18, or the higher age the policy sets, and the customer has indicated a wish to use a digital proof of age. At that point the policy must oblige the customer, on request, to make available the means by which the identification can be verified.

Acceptance then rests on an agreement with a digital verification services provider, plus four conditions inside it. The provider must confirm whether the customer has reached the relevant age. It must deliver identification reaching at least a medium level of confidence. That confidence level must have been verified by a registered provider, which the Order allows to be either the contracting provider or a different one. And the contracting provider must be registered against version 0.4 or version 1.0 of the DVS trust framework.

Registration is not a self-declaration. Section 32 of the Data (Use and Access) Act 2025 creates the register, and section 33 lets the Secretary of State enter a provider only where it holds a certificate from an accredited conformity assessment body confirming that its services follow the framework published under section 28. The Home Office says that accreditation comes from the UK Accreditation Service. Medium level of confidence carries a technical meaning: it maps to the identity profiles in the government's Good Practice Guide 45 (GPG 45), the same benchmark used for digital right-to-work checks.

The register is small: as of 14 September 2026 it listed 46 providers and 63 certified services. The Office for Digital Identities and Attributes (OfDIA) told businesses in August that age estimation "cannot be used to support alcohol sales and supply", and that licence holders are "not permitted to use other age assurance technology, even for testing purposes". The condition bites only once a customer is challenged, but OfDIA says adults of any age may present a digital proof of age, so Challenge 25 does not limit it.

What does this change for your age verification obligations?

The mandatory condition itself has not moved. The licence holder must still ensure an age verification policy is adopted, and the designated premises supervisor must still ensure that alcohol is supplied in accordance with it. What changes is what a compliant policy can say, and therefore what has to be rewritten, retrained and evidenced before a single digital check happens.

DutySourceWhat you must now be able to show
Policy wordingParagraph 3(4) to 3(7) of the 2010 Order as amendedThe policy permits digital identification and states the customer's obligation to enable verification
Provider agreementParagraph 3(8)(a) to (d)A live contract, the age confirmation output, the confidence level and the framework version
Local conditionsExplanatory Memorandum 8.2That no local licensing condition blocks acceptance, or that it has been amended
Statutory guidanceSection 182 guidance, updated 15 September 2026Training material that reflects the revised age verification section
Money laundering checksRegulation 28(19), Money Laundering Regulations 2017A separate assessment, because the licensing test does not satisfy the AML one

That last row is the one regulated firms get wrong. A medium level of confidence satisfies this licensing condition, but regulation 28(19) treats an electronic identification process as a reliable independent source only where it is secure from fraud and misuse and gives assurance "to a degree that is necessary for effectively managing and mitigating" money laundering and terrorist financing risk. The same supplier can serve both purposes, but the standards come from different instruments and are evidenced separately, a point we covered when the DVS trust framework reached version 1.0.

Data protection duties tighten rather than relax. The advertised privacy gain, that a customer proves an age without handing over a name or address, only materialises if the venue receives a yes-or-no result and keeps nothing else. A retailer that logs identity attributes returned during the check has recreated the very record the reform was meant to avoid.

What is still uncertain about digital proof of age?

The economics are the first open question. The Economic Note models a healthy central net benefit, but the pessimistic scenario is a loss, and four fifths of the modelled upside is time saved at self-checkouts rather than money earned.

Ten-year present valuePessimisticCentralOptimistic
Total costs971.8 million pounds459.2 million pounds276.3 million pounds
Total benefits682.0 million pounds888.5 million pounds1,206.5 million pounds
Net present social valueminus 289.8 million pounds429.4 million pounds930.2 million pounds

The scenarios pair opposite ends of each range, so the pessimistic column sets the highest modelled cost against the lowest modelled benefit. Technology costs are not monetised at all, so the downside is wider than the table shows.

The breakdown matters more than the totals. Provider charges account for 453.0 million pounds of the central cost, modelled at 15 pence per check within a range of 5 to 25 pence, with training and familiarisation making up the remaining 6.2 million. Of the 727.3 million in self-checkout time savings, retailers capture 468.4 million and customers the rest, while reduced violence against retail workers adds 131.9 million and extra sales only 29.3 million. Net of its own costs, business keeps 38.5 million pounds centrally, in a range from minus 576.1 million to 356.0 million, and in the high-cost case a check would have to fall to about 10 pence before business costs and benefits balanced.

The self-checkout saving carries a condition that rarely survives summary. OfDIA warns that "self-service checkouts must not be completely unsupervised", because duties to prevent proxy purchases and refuse intoxicated customers do not go away. A till that still needs a supervisor recovers less time than the model assumes.

Then there is liability. The Order permits acceptance of a check; it does not transfer responsibility. If an underage sale happens, the criminal exposure under the Licensing Act still sits with the venue and the person who served. Being on the register does not settle the matter either, and OfDIA has said licence holders must satisfy themselves that a provider meets their needs through contract and ongoing controls.

Three smaller uncertainties sit underneath. Two framework versions run in parallel, so medium level of confidence means whichever definition applies to the version the service is registered against. Fraud moves to the binding step rather than disappearing, because a borrowed unlocked phone defeats a credential that is cryptographically perfect. And the reform stops at the border of England and Wales, so national estates will run two policies until Scotland and Northern Ireland move.

How does this compare with the other uses of the DVS register?

Digital proof of age is the odd one out among the government-backed uses of the register. Digital right-to-work checks, right-to-rent checks and Disclosure and Barring Service identity checks each sit behind a published supplementary code, and the register lets you filter providers by those three codes. There is no supplementary code for alcohol.

Instead, the safeguards live in the licensing instrument itself: the agreement, the age confirmation, the confidence level and the registration requirement. A buyer cannot simply tick a box on the register, because the register tells you a service is certified, not that it returns an age decision in the form the Order requires. The consultation behind the change shows how deliberate that was. The Explanatory Memorandum records 251 responses, 72 per cent supporting digital identities for alcohol sales and 82 per cent agreeing that providers should be certified under the trust framework, with the government concluding that facial age estimation needed further work before retail use.

Set against age assurance rules elsewhere, England and Wales have taken a third route. Missouri's law, which we examined when section 407.3405 came into force, bans the verifier from retaining anything. The European approach, visible in the age verification trusted list on the eIDAS Dashboard, leans on wallets and trusted lists. England and Wales have chosen to certify the provider, mandate a programmatic check, and leave retention policy to the general law.

How should compliance teams respond?

Begin with the paperwork. Rewrite the age verification policy so it expressly permits digital identification and states the customer's obligation to make verification possible, put it through whatever governance owns licensing, and ask the licensing authority whether a local condition blocks acceptance.

Then do the supplier work. Check the register entry of any provider you are considering, confirm in writing that the service returns an age confirmation at a medium level of confidence, and record which framework version it is certified against.

Last comes the evidence. Retrain tills on one point: with a digital proof of age the decision comes from the provider, never from looking at a screen. Write down what the venue stores after a check, and make the honest answer nothing beyond a pass or fail and a timestamp.

That discipline is what we build for. Zyphe issues a reusable credential that a person carries and re-presents elsewhere, with personal data sharded across more than 60,000 nodes so no single party holds a complete record, and verification returned as an answer, not a copy of someone's documents. If you need to prove an attribute without accumulating identity files, book a demo and we will walk through the architecture with your KYC and data storage requirements in front of us.

The bottom line

The interesting part of this reform is the shape of the permission, not buying a drink with a phone. England and Wales have made a verified answer from a certified provider the legal unit of proof, and have ruled out the eyeball check that the physical document regime depends on. Treat it as procurement and you end up with a contract and an out-of-date policy. Treat it as control redesign and you get a thinner data footprint and an audit trail that records who asked, what was answered, and nothing else.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

On 15 September 2026. The Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026 was made on 14 September 2026 and came into force the following day. It extends to England and Wales only, so licensed premises in Scotland and Northern Ireland are not covered by the change.

No. Acceptance is optional for both sides. The Order permits an age verification policy to allow digital identification, but no venue is required to adopt it and no customer is required to use it. Physical documents bearing a photograph, date of birth and a hologram or ultraviolet feature remain valid.

No. The government states that digital proof of age is separate from the digital driving licence and the GOV.UK Wallet, although it expects that in time the wallet will become one of the ways people prove their age. Today the check must run through a service on the digital verification services register.

It is the assurance level defined in the version of the DVS trust framework that the service is registered against, and it maps to the identity profiles in the government's Good Practice Guide 45. The same benchmark applies to digital right-to-work checks, so many certified services already operate at that level.

No. The Home Office states that a mere visual inspection of the digital identification is not sufficient, and the Office for Digital Identities and Attributes has told businesses not to rely on visual checks. The confirmation must be returned by the registered provider through a programmatic check.

Not directly. The licensing condition and Regulation 28 of the Money Laundering Regulations 2017 set separate tests, and a check built for alcohol sales does not automatically satisfy customer due diligence. Firms can use the same registered provider for both, but must evidence each requirement on its own terms.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo