{"id":4638,"date":"2026-02-26T05:37:29","date_gmt":"2026-02-26T05:37:29","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2026\/02\/26\/icos-14m-reddit-fine-highlights-age-check-privacy-concerns\/"},"modified":"2026-02-26T05:37:29","modified_gmt":"2026-02-26T05:37:29","slug":"icos-14m-reddit-fine-highlights-age-check-privacy-concerns","status":"publish","type":"post","link":"https:\/\/ft365.org\/index.php\/2026\/02\/26\/icos-14m-reddit-fine-highlights-age-check-privacy-concerns\/","title":{"rendered":"ICO\u2019s \u00a314m Reddit Fine Highlights Age Check Privacy Concerns"},"content":{"rendered":"<div id=\"layout-ec76039a-c934-46ca-ab8b-125789e20b0c\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>The UK\u2019s Information Commissioner\u2019s Office (ICO) has issued a multimillion-pound fine to Reddit for GDPR non-compliance, but experts have warned that its rules pose a risk to user security and privacy.<\/p>\n<p>The UK\u2019s data protection regulator said on February 24 that its \u00a314.47m ($19.6m) fine was levied for two main reasons.<\/p>\n<p>First, Reddit failed to put \u201crobust\u201d age verification measures in place, which meant it did not have a lawful basis for processing the personal information of children under the age of 13.<\/p>\n<p>Second, it failed to carry out a data protection impact assessment (DPIA) to assess and then mitigate risks to children on the platform before January 2025.<\/p>\n<p>The fine took into account the large number of children using the site, the degree of potential harm caused, the duration of the failings\u00a0and Reddit\u2019s global turnover, the ICO said,<\/p>\n<p><em>Read more on ICO fines: UK ICO Fires GDPR \u201cWarning Shot\u201d Over Use of Children\u2019s Data.<\/em><\/p>\n<p>\u201cChildren under 13 had their personal information collected and used in ways they could not understand, consent to or control. That left them potentially exposed to content they should not have seen. This is unacceptable and has resulted in today\u2019s fine,\u201d said information commissioner, John Edwards.\u00a0<\/p>\n<p>\u201cLet me be clear. Companies operating online services likely to be accessed by children have a responsibility to protect those children by ensuring they\u2019re not exposed to risks through the way their data is used. To do this, they need to be confident they know the age of their users and have appropriate, effective age assurance measures in place.\u201d<\/p>\n<p>Reddit introduced age verification to access \u201cmature content\u201d in July 2025\u00a0and now asks users to state their age when opening an account, although the ICO noted that the latter is too easy to bypass.<\/p>\n<h2><strong>Sympathy for Reddit<\/strong><\/h2>\n<p>Reddit has defended its decision, saying in a statement that it \u201cdidn&#8217;t require users to share information about their identities, regardless of age, because we are deeply committed to their privacy and safety.&#8221;<\/p>\n<p>Some experts agreed that the ICO\u2019s intrusive age verification checks, as per those for users of adult content sites, put user security and privacy at risk.<\/p>\n<p>Paul Bischoff, consumer privacy advocate at Comparitech, said he hoped Reddit would stand firm.<\/p>\n<p>\u201cThe problem with mandatory identity verification is that it places an undue burden of proof on the vast majority of people not suspected of any wrongdoing,\u201d he added.<\/p>\n<p>\u201cIt has a chilling effect on our freedoms and there&#8217;s little evidence that it achieves its stated purpose. Parents need to take responsibility and stop shifting their burden onto private companies, the government, and the general public.\u201d<\/p>\n<p>Pieter Arntz, senior researcher at Malwarebytes, agreed that such checks potentially expose user data.<\/p>\n<p>\u201cWhether it\u2019s facial age estimation relying on biometrics, open banking checks querying financial data, digital ID wallets adding new layers of infrastructure, or photo-ID matching concentrating high-value identity data, each approach introduces fresh privacy and security concerns,\u201d he added.<\/p>\n<p>\u201cEven simpler methods, like credit card checks, email-based inference, or mobile network verification, raise issues around exclusion, profiling, or reliability.\u201d<\/p>\n<p>If the ICO supported \u201cdouble-blind\u201d verification, it could potentially allay these concerns, Arntz added.<\/p>\n<p>\u201cIn this model, a trusted third party confirms a user\u2019s age and issues a simple \u201818+\u2019 (or similar) token to the relying site, without revealing the user\u2019s identity or which service they are accessing,\u201d he continued.<\/p>\n<p>\u201cThis reduces data exposure, limits cross-service tracking, and avoids creating new honeypots of sensitive personal information, offering stronger privacy protections than most current approaches while still meeting regulatory objectives.&#8221;<\/p>\n<h2><strong>A Warning to Others<\/strong><\/h2>\n<p>However, others\u00a0were less sympathetic to Reddit\u2019s cause.<\/p>\n<p>Chris Linnell, associate director of data privacy at\u00a0Bridewell, argued that when processing children\u2019s data, a DPIA is simply not optional.<\/p>\n<p>\u201cIt is a statutory requirement designed to force organizations to properly assess, document and mitigate risk before harm occurs. The absence of a robust DPIA suggests that the risks to children were not adequately identified or addressed at the outset,\u201d he said.<\/p>\n<p>\u201cEqually, relying on terms and conditions to state that under-13s should not use the service is not, in itself, a protective measure. If no effective technical or operational controls are in place to enforce that rule, the organization cannot credibly argue that it has taken reasonable steps to prevent access. Compliance cannot sit solely in contractual wording; it must be reflected in practical safeguards.\u201d<\/p>\n<p>The Reddit fine comes just weeks after Imgur parent company MediaLab was fined over \u00a3247,000 for failing to use children\u2019s information lawfully.<\/p>\n<p>Linnell urged online service providers to avoid similar regulatory action by focusing on the basics, namely:<\/p>\n<ul>\n<li>Identify where children are likely to access your services \u2013 even if they are not your intended audience<\/li>\n<li>Conduct DPIAs for high-risk processing, with regular reviews<\/li>\n<li>Establish and document a lawful basis for processing children\u2019s data<\/li>\n<li>Implement proportionate, effective controls rather than relying solely on policy statements<\/li>\n<\/ul>\n<p><em>Image credit: Charles-McClintock Wilson \/ Shutterstock.com<\/em><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The UK\u2019s Information Commissioner\u2019s Office (ICO) has issued a multimillion-pound fine to Reddit for GDPR non-compliance, but experts have warned that its rules pose a risk to user security and privacy. The UK\u2019s data protection regulator said on February 24 that its \u00a314.47m ($19.6m) fine was levied for two main reasons. First, Reddit failed to<\/p>\n","protected":false},"author":2,"featured_media":4639,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"thumbnail":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284-150x150.jpg",150,150,true],"medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"medium_large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"1536x1536":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"2048x2048":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"morenews-featured":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"morenews-large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"morenews-medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284.jpg",300,300,false],"crawlomatic_preview_image":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/02\/4638-c0892c82-3cc9-4917-b568-bd52daa65284-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"https:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"https:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=4638"}],"version-history":[{"count":0,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/4639"}],"wp:attachment":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=4638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=4638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=4638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}