Enforcement & Fines

Ofcom Fines Xgroovy £730,000 for Age-Check and Information Failures

On 4 September 2026, the UK communications regulator Ofcom announced penalties totalling £730,000 against the operator of pornography website Xgroovy. According to the announcement, Xgroovy failed between July and November 2025 to implement highly effective age assurance to prevent children from encountering pornography on the website. Ofcom imposed a £700,000 penalty for that failure. During the subsequent investigation, the operator also failed to respond to Ofcom’s information request within the required timeframe and received a further £30,000 penalty. The website has since introduced age checks and blocked access from UK IP addresses.

Both penalties are based on the Online Safety Act 2023. Section 12 requires the relevant providers to use highly effective age assurance to prevent children from encountering pornography. This requirement concerns services under Part 3 of the Act that allow pornography and are likely to be accessed by children. Section 102(8) requires operators receiving a statutory information request to provide information as required.

1. Lack of age assurance measures

Ofcom requires age assurance measures to meet the standard of being highly effective. Its Guidance on Highly Effective Age Assurance further sets out four criteria: technical accuracy, robustness, reliability and fairness. In other words, the method a company uses should accurately determine users’ ages both during testing and in actual use. Its results should be based on sufficiently trustworthy information and be reproducible. Companies should also avoid or minimise bias and discriminatory outcomes affecting different groups of users.

Under this standard, asking users to enter their date of birth or click “I am over 18” is insufficient to meet age assurance duties. Users can simply enter an adult’s date of birth. Without further verification, the website cannot use that entry to determine their actual age. Ofcom therefore expressly states that self-declaration, or entering a date of birth without additional verification, does not meet the highly effective standard. Banning children in the terms of service or displaying an adult-content warning at the entrance also fails to satisfy the guidance.

Ofcom lists photo-ID matching, facial age estimation, credit card checks and digital identity services among the methods of age assurance. It does not prescribe a single method. Companies should assess their chosen method and its performance in actual use against the four criteria when making their selection.

Age estimation also needs to account for the possibility of incorrectly classifying a child as an adult. The guidance describes setting an additional checking threshold above 18, known as a challenge age, according to the accuracy of the technology used. Users whose estimated age falls below that threshold undergo a further check to establish whether they are adults. The threshold should reflect the method’s margin of error. An estimate above 18 should not, by itself, be treated as sufficient to rule out misclassification.

Whether the information used in a check belongs to the current user also affects the result. For example, a child might upload someone else’s identity document or a photograph of an adult. The guidance therefore expects providers to consider circumvention methods that children can readily obtain and may reasonably be expected to use, and to take appropriate steps to address them. For photo-ID matching or facial age estimation, liveness detection can help establish that the person being checked is present at the time, rather than simply submitting a still photograph of an adult.

The timing of an age check also affects its protective effect. Ofcom requires that pornography remain invisible to users before and during the checking process. For example, if a website displays pornographic images or videos first and checks age only when a user registers or pays, children may already have encountered that content. Testing therefore needs to begin with a user’s first visit and establish what they can see before passing the age check.

Companies using a third-party age assurance service should also note that Ofcom does not approve vendors or recommend particular verification applications. Its vendor due diligence resource, published on 2 September, suggests asking which metrics a vendor uses to evaluate performance, how often testing takes place, how the website is notified of problems, and how the vendor handles circumvention by children and user appeals. Even where the vendor performs the check, the website operator remains responsible for the effectiveness of the age assurance process as a whole.

Age assurance also involves the protection of personal data. Ofcom explains that privacy and data protection rules continue to apply when companies implement age assurance. For methods requiring identity documents or facial images, companies can establish before integration whether the website or the vendor collects the information, whether original materials are retained, how long they are kept, and whether they are used for purposes other than determining age. If a website only needs to establish whether a user is an adult, it should also assess whether receiving and retaining complete identity-document information is necessary, and explain to users how the relevant data is used and deleted.

2. Failure to respond to an information request on time

According to Ofcom’s published investigation record, the regulator opened its investigation on 10 September 2025 and issued an information notice on 23 September. It subsequently expanded the investigation to cover the failure to respond, but did not proceed with that part of the investigation at the time following correspondence with the operator. On 30 March 2026, Ofcom reissued the notice using updated contact details supplied by the operator, which again failed to respond within the deadline. Ofcom then issued a provisional notice of contravention on 16 June, allowing the operator 20 working days to make representations before reaching the present penalty decision.

Even after introducing age checks or restricting access by UK users, the website remains required to provide information in the investigation. In its Confirmation Decision of 3 September, Ofcom required Xgroovy to provide the information immediately. If it continues to fail to comply, a daily penalty of £200 applies from 3 September until it complies or 3 November 2026, whichever is earlier.

Ofcom says it will continue to monitor Xgroovy’s compliance. As of 8 September, the case announcement still states that a non-confidential version of the Confirmation Decision will be published in due course. The detailed calculation of the £700,000 penalty, and the effect of the website’s subsequent remedial measures on its amount, await further explanation in that decision.

References

Ofcom news announcement: https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/porn-site-deploys-age-checks-as-ofcom-fines-it-730000; Ofcom investigation record: https://www.ofcom.org.uk/online-safety/protecting-children/investigation-into-the-provider-of-xgroovy.coms-compliance-with-the-duty-to-prevent-children-from-encountering-pornographic-content-through-the-use-of-age-assurance; Ofcom Part 3 guidance on highly effective age assurance: https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/statement-age-assurance-and-childrens-access/part-3-guidance-on-highly-effective-age-assurance.pdf?v=395680; Ofcom age assurance overview: https://www.ofcom.org.uk/online-safety/protecting-children/age-assurance; Ofcom frequently asked questions: https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/enforcement/highly-effective-age-assurance—frequently-asked-questions-faq.pdf?v=393828; Ofcom explanation of age-check implementation: https://www.ofcom.org.uk/online-safety/protecting-children/age-checks-to-protect-children-online?language=en; Ofcom vendor due diligence resource: https://www.ofcom.org.uk/online-safety/protecting-children/vet-your-vendor.

Related reading

Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.