A close-up captures Discord's application icon on a cell phone screen

Discord’s new age checks spark fresh privacy fears after ID breach

Discord says it wants to make its platform safer for young people. But many users are asking a different question: can it be trusted with even more sensitive data?

The chat platform has announced a global rollout of stricter age checks. To access adult content or unblur sensitive media, users may soon need to verify their age using a video selfie or by uploading a government ID.

But the move comes just months after a breach at Discord exposed highly sensitive user data — including scanned ID documents in some cases.

Here’s what’s happening, and why it matters. 

What is Discord changing?

Under the new policy, Discord will begin a phased global rollout of age verification from early March. All users will initially be defaulted to “teen-appropriate” experiences. 

To access age-restricted channels or content, some users will be asked to: 

  • Complete a facial age estimation process using a video selfie, or
  • Upload a government-issued ID for verification. 

Discord has been working with age-assurance provider k-ID, which uses on-device facial age estimation technology from Swiss firm Privately. Discord says:  

  • Selfie-based age estimation runs on the user’s device
  • The video selfie used for facial age estimation never leaves the device 
  • Government IDs are checked off-device but deleted once age is confirmed 
  • Only a “pass/fail” age result is shared with Discord. 

The company has also said it may use behavioural signals — such as activity patterns and metadata — to infer whether someone is likely to be an adult.

Users considered “high confidence” adults may not need to complete the selfie or ID process.

However, recent reporting suggests that the picture may now be more complex for UK users.  

UK users told they “May be part of an experiment”

According to media reports, UK users have now been told that they “may be part of an experiment” involving a different age-assurance provider. Instead of all selfie-based age estimation data staying on the device, the notice states that information submitted by some UK users will be processed by vendor Persona.

 

The notice reportedly reads: 
“Important: If you’re located in the UK, you may be part of an experiment where your information will be processed by an age-assurance vendor, Persona. The information you submit will be temporarily stored for up to 7 days, then deleted. For ID document verification, all details are blurred except your photo and date of birth, so only what’s truly needed for age verification is used.” 

 

This appears to mark a shift from earlier assurances that video selfies used for facial age estimation would never leave a user’s device. At the time of writing, Discord has not publicly clarified why some UK users are being routed through a different vendor model. 

Why are users worried?

Age verification is a necessary and important step in protecting young people online. But any system that collects sensitive identity data must also meet the highest standards of security and transparency.  

It is therefore understandable that concerns are being raised, particularly after the platform recently experienced a security incident involving identity documents.

In October 2025, Discord confirmed a data breach affecting users who had contacted its support teams.

The incident involved a third-party customer service provider. 

According to Discord, exposed data may have included: 

  • Usernames and email addresses
  • Billing details and IP addresses
  • Messages exchanged with support
  • The last four digits of credit card numbers
  • In some cases, scanned ID documents submitted during age verification appeals. 

Discord said no full credit card numbers, passwords or CVV codes were taken.

The inclusion of scanned ID documents raised serious concerns. ID images are particularly sensitive. They can be used in identity theft, impersonation scams and social engineering attacks.  

Now, with age checks expanding globally — and some UK users potentially having their data temporarily stored off-device for up to seven days — concerns about data security have intensified. 

The bigger picture: digital identity and AI systems

Across social media, gaming, banking and public services, organisations are collecting more digital identity data than ever. Facial scans, behavioural analysis, AI profiling and document uploads are becoming routine. But repeated breaches show that compliance on paper does not always mean protection in practice.

The Discord situation highlights a broader issue: as verification systems evolve, the supply chain often becomes more complex. Multiple vendors, experiments and regional variations can make it harder for users to understand exactly where their data is going and how long it is kept.

At Join the Claim, we believe digital identity data deserves stronger safeguards, not just reassurances after something goes wrong. 

That’s why we’re calling on organisations to back our five-point Digital ID pledge: 

  • Full transparency over where data is stored
  • Immediate and full disclosure of any breach attempts
  • Independent annual security audits
  • Strict limits on data sharing, including a ban on commercial profiling
  • Clear accountability for every organisation handling Digital ID data. 

If you believe digital identity protections need to be taken more seriously, share your support using #ProtectOurDigitalID.

Stay informed with Join the Claim

Tech platforms are evolving fast. So are the risks. We’ll continue to examine what’s changing, why it matters, and what stronger protections should look like in practice.

Because when it comes to your digital identity, convenience should never come at the cost of control.

If you are concerned that your data may have been involved in last year’s Discord data breach, we have a full breakdown of what happened, what information may have been exposed, and practical steps you can take. 

Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.  

This information is for general guidance only and does not constitute legal or financial advice.

You may also like:

BMW faces legal action over emissions-cheating software. Learn what the scandal involves, who is affected, and what it means for UK diesel car owners.
Capita’s data breach exposed pension holders’ personal data. Stay updated on the latest legal action, investigations, and regulatory responses.
Confused about Jaguar Land Rover DPF claims vs. Dieselgate? Learn the key differences, legal actions, and how to check if you qualify for compensation.

Latest news & insights

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.