Summary
- Licensed businesses in England and Wales can now accept certified phone-based proof of age for alcohol sales.
- Digital checks are voluntary and must use services within the government's regulated digital verification framework.
- The change gives the UK's digital identity regime an early high-volume commercial use case while allowing more selective disclosure of personal information.
Pubs, shops, restaurants, and other licensed businesses across England and Wales can now accept certified digital proof of age when selling alcohol, moving the UK’s regulated digital-identity framework into an everyday commercial transaction. Rules that took effect on 15 September allow customers to use eligible phone-based services instead of producing a passport, driving licence, or other physical document. Businesses remain free to continue with existing checks if they do not want to accept digital proof.
The Office for Digital Identities and Attributes has built the approach around the statutory digital verification framework rather than allowing any app displaying a date of birth or an “over 18” message. Eligible services must meet government trust requirements and sit inside the regulated system. The legal change therefore establishes an assurance mechanism rather than making visual inspection of a phone screen equivalent to checking a physical document.
Businesses using the system need a technology-based verification process, because a screenshot or copied interface can be forged as readily as another digital image. The relying business receives a proof through the certified service rather than deciding whether an application appears genuine. The legal drinking age and retailers’ obligations to prevent underage sales remain unchanged.
Physical documents also remain valid, which means digital identity has to compete with a process staff and customers already understand. Adoption will depend on whether providers and merchants can make the digital route faster, sufficiently reliable, and easy to integrate into existing point-of-sale processes. Permission to use the technology removes a regulatory barrier; it does not guarantee that every venue will adopt it.
Proof of age can reveal less identity
A physical passport or driving licence discloses considerably more information than a bartender or cashier needs to establish that somebody is over 18. Depending on implementation, a digital credential can return the relevant age attribute without requiring the customer to expose an address or exact date of birth. That gives selective disclosure a straightforward commercial use case rather than leaving it as an abstract privacy principle.
The privacy benefit depends on the design of individual services and the information merchants decide to retain. Digital credentials can minimise disclosure at the point of verification, but back-end systems still need appropriate rules around transaction logs, device information, and other metadata. A privacy-preserving front end would offer limited benefit if the surrounding service collected unnecessary information elsewhere.
Providers need independent certification against the UK digital verification services trust framework before eligible services can appear on the statutory register. The framework became part of a formal regulatory structure under the Data (Use and Access) Act 2025, creating a common basis for businesses to determine whether a provider meets the required standards. Not every registered provider will necessarily offer proof-of-age services, so merchants still need to understand the specific product they are integrating.
Retail adoption becomes an operational problem
Larger retailers can connect age credentials with existing checkout, fraud-prevention, and compliance systems, whereas independent pubs and shops will face different cost and training requirements. Staff need a procedure for digital verification, service outages, and customers whose credentials cannot be validated, while existing policies such as Challenge 25 still shape how age checks are carried out. The technology has to fit the pace of a checkout rather than turning a routine transaction into a support process.
Reliability will be particularly important because proof of age often occurs at busy service points where customers expect a decision within seconds. A system dependent on an unavailable provider, poorly configured device, or unreliable connection can create more friction than a physical card. Digital identity suppliers therefore have to operate a dependable transaction service as well as prove that their underlying assurance model is secure.
The change is separate from government authentication programmes such as GOV.UK One Login. One Login is expanding stronger authentication across public services, whereas digital proof of age allows a private business to verify a specific attribute. The distinction shows how different pieces of identity infrastructure can perform separate jobs without requiring one universal identity database.
Retail use will now provide evidence that consultation and technical standards cannot. Businesses will discover whether customers choose phone-based credentials, whether staff can process them consistently, and whether fraud controls work at transaction speed. The law has made digital identity usable at the alcohol checkout; adoption will depend on whether it proves more convenient than asking for a physical document.












