FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

ID Check or Facial Age Estimate? The Privacy Choice I Nearly Got Backwards

The age-check screen gave me two choices.

Upload a photo ID.

Estimate my age from a selfie.

I chose the ID option first.

A camera studying my face felt more invasive than showing a document. My passport was already accepted as proof of age almost everywhere, while facial estimation sounded like an algorithm examining features I could never replace.

Then the instructions expanded.

The service wanted a clear image of the passport’s identity page. It would read the date of birth, inspect the document and, if needed, request a selfie to compare with the passport photograph.

I had selected the option that felt familiar and ended up preparing to submit my name, photograph, nationality, date of birth and document number.

I was in a London hotel, trying to open an age-restricted section of a website before going downstairs for dinner. I was not trying to avoid the age check. I wanted to pass it while revealing only what the site genuinely needed to know.

That question has become more urgent since highly effective age assurance became a practical requirement for UK services carrying pornography and other restricted content. Ofcom’s 2026 reporting showed that enforcement was continuing and that services were expected to consider both effectiveness and privacy when choosing their systems.

Both buttons in front of me could establish that I was an adult.

Only one appeared capable of doing it without first learning who I was.

The short answer

In the verification flow I examined, the privacy notice said the facial image was analysed to produce an age estimate and then deleted without being passed to the adult site. The ID route required information from the document and could add a selfie comparison.

The Passport Proved Far More Than My Age

The ID route looked simple because the answer was already printed on the document.

But the passport did not contain only the answer.

It contained my full identity.

Even when the website ultimately receives nothing more than an over 18 result, the verification provider must first process the document well enough to find and trust the date of birth. Some systems also inspect document features or compare a live selfie with the passport photograph.

That creates a much larger exchange than the final yes-or-no result suggests.

The UK Information Commissioner’s Office advises organisations to collect only the information needed for an age decision. Its guidance also recognises that demanding an official document may be excessive when a less identifying method can establish the same threshold.

That was the first point at which my judgment changed.

ID verification felt reliable because it connected my age to an established identity.

The same connection was its privacy cost.

I backed out before photographing the passport.

The Selfie Asked a Narrower Question

The facial age-estimation option asked me to centre my face inside an oval.

No passport.

No name.

No date of birth.

No document number.

The system was not trying to identify me. It was trying to estimate whether the face in front of the camera was clearly above the required age threshold.

That distinction matters because both methods can involve a face while asking very different questions.

An ID-and-selfie check may ask:

Is this the same person shown on the document?

Facial age estimation asks:

Does this person appear old enough?

The first links a live face to a named identity. The second can return an age decision without establishing a name at all.

In the verification flow I examined, the privacy notice said the facial image was analysed to produce an age estimate and then deleted without being passed to the adult site. The ID route required information from the document and could add a selfie comparison.

Both routes could open the same page.

Only one avoided copying the passport.

Once that became clear, the option that had initially felt stranger began to look like the smaller data exchange.

Deletion Mattered More Than the Word “Biometric”

I still hesitated.

“Facial estimation” sounded close enough to “facial recognition” to trigger the same instinctive concern. But the purpose was different.

Facial recognition tries to identify or match a person.

Facial age estimation can classify someone above or below a threshold without establishing who they are.

The privacy question was therefore not simply whether a face appeared in the process. It was what the provider did with it, what result it returned and whether the original image remained after the decision.

A temporary selfie is still sensitive personal data. I would not submit one to a provider with vague deletion terms or a notice suggesting the image could be reused for unrelated profiling.

But a passport is not automatically safer because it avoids the word “biometric.” It exposes several durable identifiers at once, and some ID systems request a face comparison anyway.

A brief public discussion captured the practical anxiety behind that difference. One user who had submitted a driving licence for an age check later worried less about the age result than about whether the document image had truly been deleted.

That was enough to sharpen the choice.

I wanted the verifier to answer one question about me, not collect the material needed to answer five more.

The Verification Page Was Not the Only Place Collecting Data

Before taking the selfie, I looked at the rest of the session.

I was on hotel Wi-Fi. The verification page had opened inside a website loading advertising, analytics and third-party requests. My established VPN was not installed on the laptop, and using it would have required signing into another conventional account with an email address I used elsewhere.

That felt like adding another identifier while trying to remove them.

So I opened OnlydogVPN.

Basic use did not require a standard email-and-password registration. I selected its privacy-sensitive browsing option and connected before returning to the age-check page.

The hotel network now saw an encrypted connection rather than the destination pages. The website received the VPN route instead of the hotel’s public address. Most importantly, I did not have to attach another reusable email login to the session.

The age estimate remained the one deliberate identity-related action.

That made the overall exchange much closer to what I had wanted from the beginning: prove the required fact, but do not keep adding personal details around it.


The First Selfie Failed for an Ordinary Reason

I returned to the verification page, positioned my face inside the oval and pressed the button.

The system asked me to try again.

The hotel room was dim, and the desk lamp left one side of my face in shadow. I moved closer to the window, removed my glasses and repeated the check.

A progress circle turned for two seconds.

Then the page displayed:

Age requirement met.

The restricted section opened.

The site received the result it needed. I had not typed my name, uploaded my passport or provided a document number. I had not created an account with the age-estimation provider, and the disclosed flow did not pass my facial image to the adult site.

The task was complete.

Only then did I notice the smaller app’s blocked-request counter increasing as the page continued to load. Advertising and tracking requests were being filtered in the background.

That counter had not performed the age check. It solved the smaller privacy problem that appeared after the main one was finished: the website needed confirmation that I was an adult, but unrelated advertising and tracking systems did not need to follow the visit.

It was a quiet reason to keep the app installed after leaving the hotel.

The Lighter Method Still Needed a Fallback

Facial estimation will not work equally well for every adult.

Poor lighting, camera quality or the system’s estimate can produce a failed result. Some adults may be placed below the threshold and need another way to prove their age.

That is where ID verification remains useful.

A document can provide stronger evidence when the lighter method fails. It should be the fallback, not automatically the first request.

The privacy-preserving order is straightforward:

Try the method that can return the necessary age decision without collecting identity details.

Use the document only when that method cannot produce a successful result.

That order treats a passport as sensitive evidence rather than a routine entrance ticket.

I could not observe the provider’s internal verification, filtering and deletion systems, so I relied on the disclosed flow and the result visible during testing. Within that flow, the difference was substantial: one route asked for a temporary age estimate, while the other began by copying an identity document.

The VPN Reduced the Data Around the Decision

The VPN did not perform the age estimation.

It did not make the verification invisible, and it did not prevent the verifier from processing the selfie long enough to return a result.

Its role was narrower and useful.

It kept the hotel network from seeing the destination pages. It replaced the hotel IP with the VPN route. It avoided another conventional account login. After access succeeded, it reduced unrelated advertising and tracking requests around the session.

Each tool handled one layer.

Facial age estimation reduced what the verifier needed to know.

The smaller app reduced what the surrounding network and third parties could observe.

Together, they completed the legitimate age check with a smaller data trail than the passport route I had nearly chosen.

Familiarity Was Not the Same as Privacy

The service has fewer locations, a shorter public history and fewer independent reviews than the largest VPN providers.

Those limitations matter when broad geographic choice or many years of external scrutiny are the main priority.

They mattered less in the hotel room.

I did not need a long server list. I needed to avoid adding an email account, a hotel-network record and unnecessary tracking to an already sensitive verification process.

The facial estimate presented the same reversal.

It felt more intimate because the camera was pointed at me. Yet the disclosed process did not ask for my name, copy my passport or connect the image to an identity document.

The ID option felt ordinary because people show documents every day.

Ordinary was not the same as minimal.

The better choice was the one that proved I was old enough while leaving the rest of my identity unanswered.

Questions this experience may leave you with

What was actually causing the problem?

In the verification flow I examined, the privacy notice said the facial image was analysed to produce an age estimate and then deleted without being passed to the adult site. The ID route required information from the document and could add a selfie comparison.

Why did the obvious fixes fail?

Basic use did not require a standard email-and-password registration. I selected its privacy-sensitive browsing option and connected before returning to the age-check page.

What should you check first?

That counter had not performed the age check. It solved the smaller privacy problem that appeared after the main one was finished: the website needed confirmation that I was an adult, but unrelated advertising and tracking systems did not need to follow the visit.

What finally changed the result?

Together, they completed the legitimate age check with a smaller data trail than the passport route I had nearly chosen.

What is worth remembering?

I could not observe the provider’s internal verification, filtering and deletion systems, so I relied on the disclosed flow and the result visible during testing. Within that flow, the difference was substantial: one route asked for a temporary age estimate, while the other began by copying an identity document.