Britain Will Accept Digital ID for Buying Alcohol

02.09.2026 6 min 6

Britain is about to let people prove their age at the bar and the supermarket till with a phone. The Home Office has laid an amendment to the mandatory licensing conditions that would allow a certified digital ID to be used for buying alcohol in England and Wales, and on 1 September the Office for Digital Identities and Attributes published guidance on how that check is supposed to work in practice. The rules still need to clear Parliament, but the shape of the scheme is now clear, and it says a lot about where age verification is heading.

What the amendment actually changes

The instrument being amended is the set of mandatory licensing conditions attached to the Licensing Act 2003. Today those conditions assume a physical document: a passport, a driving licence, a PASS card. The change adds a third option, a check performed by a registered digital verification service, for pubs, clubs, restaurants and shops. The government's own framing is that this is about choice: venues are not obliged to accept a digital ID, customers are not obliged to use one, and physical documents keep working exactly as before.

The check follows you to the self-checkout

The part with the most practical consequence is the self-service till. Under the guidance, a digital proof of age can be accepted at a self-checkout, provided a member of staff still supervises the wider environment, the usual concerns about proxy purchases and serving someone already drunk do not go away because a phone is involved. In other words, the machine can handle the age question by itself, and a person only watches the room. That is a meaningful shift for a check that until now always ended with a human looking at a card and at a face.

"Yes or no" is the promise, binding is the condition

The privacy pitch for digital ID is genuinely better than handing over a driving licence: the till gets a binary answer, old enough or not, and no name, address or document number travels with it. The guidance is explicit that nothing beyond age eligibility should be disclosed.

The condition attached to that promise is binding. The credential has to be tied to the person presenting it, which in practice means a biometric check somewhere in the flow. Tony Allen of the Age Check Certification Scheme put the reasoning bluntly: a genuine over-18 credential is not much of an age control if it can simply be handed to a 16-year-old sibling. So the reassuring part, no data leaves the phone, sits on top of a less discussed part: your face has to match the credential.

Who is allowed to issue one

  • Registered providers only: the app has to come from a digital verification service registered under the UK trust framework, not from any developer who fancies building an ID wallet.
  • Medium confidence minimum: the identity behind the credential must have been verified to at least a medium level of confidence as the framework defines it.
  • A short list in practice: certified apps such as Yoti and the Post Office EasyID are the names most often cited as candidates once the rules are in force.

That certification requirement is the quiet centre of the scheme. It keeps out fly-by-night apps, and it also means a handful of private companies end up sitting between British adults and a routine purchase.

Important: nothing here is in force yet. The amendment still has to complete its passage through Parliament, and the plan is for it to take effect in autumn 2026. Until then, a shop that refuses a digital ID is not doing anything wrong.

The age gate keeps moving outward

Read on its own, this is a sensible modernisation of a paper-era rule. Read next to everything else happening this year, it is another step in the same direction: proof of age is becoming a routine part of ordinary transactions, online and now offline. We have covered the same mechanism arriving in a game asking for a national ID, and the pattern is consistent: the check starts as an option and becomes the default.

The privacy risk is not really in the till. It is in the infrastructure behind it. Verification providers hold exactly the material that makes a breach expensive, and a recent tally counted 88 breaches at identity verification services, with document scans and selfies among the leaked data. A binary yes or no at the checkout is a good design. It still depends on a company somewhere holding the thing that produced the yes.

Will I have to use a digital ID to buy alcohol in the UK?
No. The change adds an option, it does not remove physical documents. Shops and pubs can decline to accept digital ID, and customers can keep showing a passport, driving licence or PASS card exactly as now.
Does the shop see my name and date of birth?
Not under the described model. The check returns whether you meet the age requirement and nothing else. What the shop does not see, the provider still processed at some point, which is why the certification requirement matters.
Why does a biometric check come into it?
Because a credential that can be lent to someone else is not an age control. The guidance requires the credential to be bound to the person presenting it, so somewhere in the flow the app has to confirm that the phone is in the hands of its owner.
Does a VPN have anything to do with this?
No, and it is worth being clear about that. This is a check at a physical till, tied to a document and a face. A VPN changes where your traffic appears to come from, which is irrelevant when a shop assistant is watching you scan a phone. It matters for online age gates, not for this one.

privacyage verificationdigital idunited kingdomukbiometricsdigital rightslegislationdata protectionyoti

Read also