- regulation
- minors
- data
Age checks and consent: what to review on your website
· 7 min read
The new rules on age checks and consent target big platforms, but part of it lands on your site. What actually applies to a small business, and what to check.
The headline comes round every few weeks: social media banned under 16, official apps for proving your age, enormous fines for platforms. And every few weeks someone asks us the same question: "do I need to put an age check on my website?"
Almost always, no. But some of the noise does land on your business, and it isn't the part people expect. Here's a short read on what is actually moving, which bits apply to a small business, and a thirty-minute review you can run yourself this week.
What's actually moving, minus the headlines
Three things, and it's worth keeping them apart because they're travelling at very different speeds.
In Europe. On 14 July 2025 the Commission published its guidelines on the protection of minors under the Digital Services Act. They recommend age assurance methods — from plain self-declaration to strong verification — scaled to how risky the service is, and they come with a technical blueprint for an age-verification app designed so someone can prove they're over 18 without handing over their whole ID.
In Spain. The bill on protecting minors in digital environments is still working its way through parliament. Among other things it would raise the age for consenting to the processing of personal data, and for opening social accounts, from 14 to 16. It is not law yet, so every figure you read about it is an "if it passes as drafted", not an obligation.
And separately, the plumbing. Cartera Digital Beta, the Spanish government's app for proving you're of age, is still in beta while it waits to line up with the EU identity wallet. It works for what it does, and it is not something you'll be plugging into your site any time soon.
The part that doesn't apply to you — and knowing that saves money
Here's the detail almost nobody mentions, and it changes the whole conversation: the Commission's guidelines explicitly exclude micro and small enterprises. They're also aimed at "online platforms" — sites where users upload content and show it to other users.
Your services website isn't that. Neither is your parts shop, your clinic's page, your garage, your training centre. Strong age verification — proving you're 18 with a credential — is aimed at adult content, gambling and social networks. Nobody designed it so a customer has to identify themselves before reading your prices.
Put bluntly: if a vendor calls with regulatory urgency to sell you an age-verification system "because Europe requires it", ask which article obliges you, and for which kind of service. That conversation tends to end quickly.
What does apply — and already did, long before any of this
Three things. None of them new. All three broken daily on the websites of businesses that are doing perfectly well.
- The cookie banner. Spain's data protection authority is unambiguous in its cookie guidance: refusing must be as easy as accepting, in the same place and in the same format. A big green "Accept all" next to a small grey "Manage settings" doesn't comply, however normal it looks by now.
- Your forms. Every field you ask for has to do a job. A clear legal basis, plain information about who's processing the data and why, and no pre-ticked boxes.
- The age of consent. In Spain it's 14 today; the bill would make it 16. This only really bites if your customers include teenagers — tutoring centres, gyms, language schools, sports clubs, summer camps, game shops. If that's you, this is the one to keep an eye on.
The thirty-minute review
Open your own site in a private window and behave like a first-time visitor. No tools, no consultant.
- The banner. Is there a reject button at the same visual level as accept? Click reject and confirm that analytics and the ad pixel genuinely don't load. A surprising number of banners are decorative.
- What happens before the banner. Open the browser's network tab and see whether third-party scripts have already fired before you chose anything.
- Every form, field by field. Are you asking for a phone number so someone can download a PDF? A date of birth "just in case"? Every field you don't use is data you have to look after and risk you carry if it leaks.
- Where the data ends up. This is the one. Follow the whole route: the form sends an email, someone copies it into a shared spreadsheet, the spreadsheet is linked in a WhatsApp group, and the inbox receiving it is read by six people, two of whom stopped working on that months ago.
Of the four, the banner is rarely what gives people a fright. The last one is. Most small-business sites are reasonably tidy at the front and messy behind, where nobody looks.
Hardly any small business has an age-verification problem. Almost all of them have a "where does this data end up" problem.
If you've got a chat or an agent answering, three more questions
The EU guidelines mention, in passing, safeguards around AI chatbots built into platforms. They don't bind you, but you can see which way the wind is blowing. Three questions worth putting to your provider today:
- What does it store, and for how long? In a lot of tools the default is keeping the entire conversation indefinitely. You almost never need that — the booking, the order or the quote is usually enough.
- Does it ask for things it doesn't need? An agent that books appointments needs a name, a way to reach you and a slot. It doesn't need an ID number, an address or a date of birth unless your service genuinely requires them.
- What does it do when someone who's obviously a minor writes in? No interrogation required. One rule does it: if the conversation moves to booking, paying or signing anything, the agent says an adult needs to handle that and hands over to a person. That's a line of instructions, not a project.
An agent that asks for less isn't a worse agent. It's an agent with far less to explain on the day something goes wrong.
When to do nothing
Two honest brakes, because the reflex after a regulatory headline is to overcorrect.
Don't build an age check you don't need. To verify someone's age you have to collect something you weren't collecting before. You go from having no problem at all to holding identity documents, and you lose half the people who were about to fill in the form. More risk, fewer customers, to solve something that didn't apply to you.
Don't get ahead of a law that doesn't exist yet. The sensible move on the Spanish bill is to jot down on one page what you'd have to change if it passes — a minimum age on your forms, parental consent for certain services — and go back to that page when it's actually law. Adapting to a draft means doing the work twice.
And to be clear: this isn't legal advice, it's what we tell a client before they ring their lawyer. If you handle health data, work with minors as a matter of course, or sell age-restricted products, that call is one you should make.
Where to actually start
By the end of this review, the uncomfortable part is rarely the website. It's that nobody in the business has a list of what data comes in, through which door, and who can see it. And if your team is already using AI on its own — everyone with their own tool and their own personal account — that map doesn't exist for conversations either.
Sorting that out is exactly what AI for teams is for: a clear perimeter, shared criteria, and you deciding what leaves the building.
