Ofcom Investigates TikTok Over Age‑Verification Failures, Citing Potential Harm to Children
What Happened — The UK communications regulator Ofcom has opened an investigation into TikTok for allegedly using ineffective age‑inference models that failed to correctly identify a significant proportion of child users. The regulator says this shortfall may expose minors to harmful content and could breach the Online Safety Act.
Why It Matters for Compliance & Audit Readiness
- Age‑verification is now a statutory control under the UK Online Safety Act; failure to meet it can trigger £18 million fines or a ban.
- SOC 2 CC6 (System and Communications Protection) and privacy‑related criteria (CC1, CC2) require documented, auditable processes for verifying user eligibility and protecting vulnerable groups.
- Verisq’s CookiePLUS Privacy capability provides a continuous, evidence‑backed framework for consent, age‑gate enforcement, and DSAR readiness that can be presented as audit‑ready proof of compliance.
Who Is Affected — Social‑media platforms, user‑generated‑content services, and any online service that must verify user age under UK law (e.g., Facebook, Instagram, YouTube, Snapchat).
Recommended Actions
- Map your age‑verification workflow to the “highly effective” methods listed in Ofcom’s guidance (document‑based ID, biometric checks, etc.).
- Capture and retain evidence of each verification step in a tamper‑evident log to satisfy SOC 2 audit requirements.
- Conduct a gap analysis against the Online Safety Act’s child‑protection checklist and remediate any mis‑configurations.
Technical Notes – Ofcom flags TikTok’s reliance on behavioral inference (browsing habits, interaction patterns) as insufficient; the regulator does not consider these models “highly effective.” No specific CVE or vulnerability is disclosed. Source: The Record