The UK government has decided against restricting VPN access as part of its under-16 social media ban. Online Safety minister Kanishka Narayan told BBC Breakfast on July 15 that “we decided not to limit VPNs,” a clear answer after months of pressure to do the opposite. It’s roughly the outcome our July 12 piece on the promised statement flagged as most likely, and it’s the sensible one.
What was actually on the table
This didn’t come out of nowhere. England’s Children’s Commissioner, Dame Rachel de Souza, had spent months arguing that VPNs were “absolutely a loophole that needs closing,” pushing for age verification on VPN apps themselves after minors started using them to sidestep age checks on adult sites and, increasingly, on mainstream platforms too.
The pressure built after the Online Safety Act’s age-verification rules kicked in and sites like Pornhub, Reddit, and X started asking UK users to prove their age. VPN apps promptly became the most-downloaded apps on the UK App Store, which is exactly the kind of headline that gets ministers asked hard questions on morning television. We covered that surge, and how slowly Ofcom actually moved on it, in a separate piece on VPN downloads and enforcement.
Add to that a House of Lords vote back in January that backed banning VPNs for under-18s outright (a proposal we covered at the time), and by early summer it looked like some form of VPN restriction was a real possibility, not just a talking point.
What the government actually decided
On July 15, speaking on BBC Breakfast, Narayan put it plainly: “We decided not to limit VPNs.” Technology Secretary Liz Kendall backed that up in a written statement to Parliament, saying the government will not age-gate or ban VPN services because “VPNs have legitimate privacy and security uses.”
No age verification requirement for VPN apps. No provider-level obligation to block under-16s. No ban. After a year of consultations, Lords votes, and a Children’s Commissioner openly campaigning for the opposite, the government landed on the least disruptive option, the same one we said was the most likely bet in our July 12 article.
Why the government backed off
A few reasons line up here, and none of them are shocking once you look at the numbers.
First, the government’s own research undercuts the case for targeting VPNs. A Department for Science, Innovation and Technology report found that 26 percent of 11- to 17-year-olds use a VPN, but the large majority do it for privacy and general security, not to dodge age checks. Only 7 to 10 percent said they use one specifically to bypass age verification. Compare that to the 45 percent who simply type in a false date of birth, which is a far bigger hole in the system than VPN use, and costs nothing to exploit.
Second, VPNs are genuinely useful, boring, everyday tools for millions of adults and businesses: securing public Wi-Fi, remote work, banking on the go, journalists and abuse survivors protecting their location. Age-gating VPN sign-ups would have meant building age verification into a product whose entire job is making traffic harder to inspect and attribute. Cybersecurity experts and even Firefox’s creator warned that restricting VPN access this way would create new security risks for everyone, not just teenagers, and an industry open letter made the same case to lawmakers directly.
Third, and this is the part that should embarrass nobody in government but probably does, enforcement of the age checks that already exist is still lagging. We laid out the numbers in our June 26 piece on Ofcom’s enforcement record: the regulator holds fines of up to 18 million pounds against non-compliant platforms and has barely used them. Adding a second, harder-to-enforce layer of VPN restrictions on top of a first layer that isn’t being enforced well was never going to be an efficient use of anyone’s time.
What happens instead
The obligation moves to platforms, not VPN providers. Kendall’s statement says social media companies will be expected “to take robust steps to detect and prevent attempts by underage users to circumvent age assurance measures.” In practice, that means Ofcom and the Information Commissioner’s Office have been tasked with reporting back by October on how platforms can better detect and block VPN-based circumvention on their own systems, and the government says it will also engage directly with VPN providers about voluntary measures.
That’s a meaningfully different approach from what de Souza was pushing for. It puts the technical burden on platforms that already have some visibility into account behavior, rather than asking VPN companies to build age checks into a privacy tool. Whether Ofcom and the ICO come back in October with anything workable is a separate question, and one worth watching given how slow enforcement has been so far.
This all lands alongside the rest of the under-16 social media package: default midnight-to-6am social media curfews for 16- and 17-year-olds, autoplay and infinite-scroll features switched off by default, and mandatory break prompts for under-18s using AI chatbots. Those rules start rolling out from early 2027. The VPN question was the one piece of this package that could have reshaped how an entire category of software works in the UK, and it’s the one piece that didn’t happen.
This probably isn’t the last word
De Souza’s position hasn’t disappeared, and the government has been careful to say VPN use is something it will “continue to review.” That’s not a closed door. If the October Ofcom and ICO report concludes that platform-side detection isn’t working, or if VPN downloads keep climbing the way they have since age checks began, expect this conversation to resurface, probably framed the same way: child safety first, privacy tools second.
For now, though, this is a genuine win for anyone who uses a VPN for reasons that have nothing to do with getting around a website’s age gate, which is to say, almost everyone who uses one.
What it means for UK VPN users right now
Nothing changes. VPNs remain fully legal in the UK for adults and minors alike, with no age-verification requirement attached to downloading or using one. If you’re running a VPN for streaming, public Wi-Fi security, or general privacy, that stays exactly as it was yesterday.
If you’re shopping for a VPN and want one that’s weathered comparable political pressure elsewhere without changing how it operates, NordVPN is a solid starting point, it’s based outside UK jurisdiction and has a track record of holding its ground under regulatory scrutiny in other markets. For anyone specifically prioritizing privacy over everything else, Proton VPN is worth a look too, given its Swiss jurisdiction and audited no-logs policy.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
This is the right call, and not a close one. The government's own data shows VPN use among minors is overwhelmingly about privacy, not age-check evasion, and building age verification into VPN software would have made everyone less secure to catch a problem that a fake birthdate solves more easily anyway. Shifting the burden to platform-side detection is more sensible, even if Ofcom's track record on enforcement gives us reason to be skeptical it'll be handled well. Nothing changes for UK VPN users today, but keep an eye on the October Ofcom and ICO report, that's where this could start moving again.