Journal / Rules and complianceTableSpark · MMXXVI

The TableSpark Journal

Digital ID for alcohol: what a UK restaurant must actually do

Staff are being told digital ID is now allowed, and a refusal at the bar is an argument in front of a queue. The Order that would permit it has not been made.

Digital ID for alcohol: what a UK restaurant must actually do
Fig. 01 — Rules and compliance
Contents

The draft Order was laid in June and has not been made, extends to England and Wales only, and would permit rather than require. A policy rewritten on the headline risks refusing identification the current condition accepts. Friday, eight o'clock. A guest at table twelve orders wine, looks young, and answers the request for identification by holding up a phone showing an app with her photograph and date of birth. The server has thirty seconds, a queue, and a half-remembered trade headline saying digital identification is now accepted for alcohol. Nobody has ever written down what she should do with a phone screen.

Whatever she decides, the restaurant carries it. Section 146 of the Licensing Act 2003 says that "A person commits an offence if he sells alcohol to an individual aged under 18", punishable on summary conviction by "a fine not exceeding level 5 on the standard scale". Twice in a quarter and section 147A reaches the licence holder personally, catching a case where "on 2 or more different occasions within a period of 3 consecutive months alcohol is unlawfully sold on the same premises to an individual aged under 18". A licence review turns on the paperwork you can produce, not your intentions.

The second exposure is quieter. Your website takes wine with a click-and-collect order, or your table QR menu lets a guest add a negroni without speaking to anyone, and somewhere in that flow sits a tick-box saying "I confirm I am 18 or over" — undated, and appearing nowhere in the age verification policy your designated premises supervisor briefs staff on. If a test purchase lands, that gap between what the site promises and what the floor does is the first thing anyone looks at.

What the published position actually is, as at 27 August 2026

Four-step diagram: Digital ID for alcohol: what a UK restaurant must actually do
The operating discipline this article describes, in four steps. Source: TableSpark editorial render

The age verification mandatory condition lives in paragraph 3 of the Schedule to the Licensing Act 2003 (Mandatory Licensing Conditions) Order 2010, in the form substituted by the 2014 amending Order:

"The policy must require individuals who appear to the responsible person to be under 18 years of age (or such older age as may be specified in the policy) to produce on request, before being served alcohol, identification bearing their photograph, date of birth and either— (a) a holographic mark, or (b) an ultraviolet feature."

Read that whole sentence, including both limbs after the "either". A hologram is not compulsory; a hologram or an ultraviolet feature will do. That physical security feature is what has kept an identification app off the list. The Office for Digital Identities and Attributes puts it plainly: the conditions "require proof of age to include a physical security feature, such as a hologram or ultraviolet mark. That rules out digital forms of ID."

The change everyone has read about is The Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026, laid by the Home Office on 30 June 2026. As at 27 August 2026 it is still a draft instrument on legislation.gov.uk, and a title search of that site returns no made 2026 Order of the name. Its commencement article says it "comes into force on the day after the day on which the Order is made", and it "extends to England and Wales". The most recent government description of its status, an OfDIA post of 17 August 2026, says the Order, "once it is approved by Parliament and has come into force, will enable retailers and hospitality venues in England and Wales to accept digital proofs of age when selling or supplying alcohol, provided the statutory conditions are met and subject to any local licensing conditions."

So the honest headline is not "digital identification is now accepted" but a draft Order that will permit it, in two of the four nations, on conditions, for premises that opt in. The permissive word is in the drafting:

"The age verification policy may make provision permitting a responsible person to accept identification in digital form ('relevant ID') instead of identification of a type described in sub-paragraph (3)."

"May", not "must". And the Order closes with a saving that is worth quoting whole, because it is the sentence that keeps a passport working: "Nothing in sub-paragraphs (4) to (10) prevents the supply of alcohol to a person based upon identification of a type described in sub-paragraph (3)."

The four gates a premises has to pass to accept a digital check

The draft is specific. The condition is that the responsible person "is covered by an agreement with a DVSP ('the relevant DVSP') for the provision of digital verification services" where four things hold: the provider has agreed it will confirm whether or not the customer has attained the relevant age; it has agreed to deliver identification reaching "at least a medium level of confidence"; that level of confidence has been verified by a digital verification services provider, the same one or another; and the provider "is registered as a provider of those services in accordance with Version 0.4 or Version 1.0 of the DVS trust framework".

A registered provider means one on the statutory register the Secretary of State must keep under section 32 of the Data (Use and Access) Act 2025: "The Secretary of State must establish and maintain a register of persons providing digital verification services." GOV.UK calls it "a public list of government-registered organisations who provide digital identity services certified against the UK digital identity and attributes trust framework".

Two consequences follow, and staff get both wrong. First, looking is not checking. OfDIA is unambiguous: "Licence holders must not rely on visual checks of a digital proof of age." Convincing replicas are easy to produce, so "The only reliable way to check digital proofs of age is using technology, something often referred to as a 'programmatic check'." A server squinting at a customer's phone satisfies nothing; the check runs through the contracted service, the way a card payment runs through a terminal.

The second is that the customer's part is drafted as a pair of clauses that must be read together. Where the policy permits digital identification, it must state "that P is obliged, upon the request of the responsible person, to make available to the responsible person the means by which their relevant ID may be verified; but (b) that the responsible person may only accept P's relevant ID where the condition in sub-paragraph (8) applies." Quote only the first half of that and you have invented a duty to accept.

What the published rules do not require

Accepting digital proof of age is not compulsory. OfDIA states it flatly: "The use of DVS and the acceptance of digital proofs of age by licence holders is optional", and "Businesses will not be required to adopt digital proof of age when the legislation comes into force. They may continue to rely on existing physical documents if they wish."

Age estimation technology is not part of this. "Other technologies such as age estimation cannot be used to support alcohol sales and supply and are outside the scope of these legislative changes", and licence holders "are not permitted to use other age assurance technology, even for testing purposes".

Registration is not a compliance certificate for your premises: "Appearing on the DVS register means that a service meets the requirements of the DVS trust framework. It does not mean that a service is being provided in compliance with Mandatory Licensing Conditions."

Challenge 25 is not the statutory floor. The condition bites on individuals who appear to be under 18, "or such older age as may be specified in the policy", and Home Office guidance treats a higher threshold as encouraged, not required: "It is acceptable, and indeed encouraged, for premises to have an age verification policy which requires individuals who appear to the responsible person to be under an age greater than 18 to produce such identification on request." A Challenge 25 sign on your door is your policy speaking, not the Order. Nor is the digital route only for people who look young: "The amended licensing conditions do not limit its use to people who appear to be under 18 or who have been asked for ID as part of a Challenge 25 policy."

And nothing here disturbs the underlying offences. The section 146 defence still turns on a disjunction that has to be read in full: the person charged believed the individual was 18 or over, and "either— (i) he had taken all reasonable steps to establish the individual's age, or (ii) nobody could reasonably have suspected from the individual's appearance that he was aged under 18".

Orders taken on your website, and orders taken at the table

Most operators assume the tick-box at checkout solves the online problem. The published guidance points elsewhere. Section 190 fixes where a remote sale happens: "For the purposes of this Act the sale of alcohol is to be treated as taking place where the alcohol is appropriated to the contract." The order arrives from a phone on a sofa; the sale happens at your premises, under your licence and your age verification policy.

Home Office statutory guidance addresses timing directly, at paragraph 10.50 of the February 2026 revision issued under section 182. Licence holders "should consider carefully what steps they are required to take to comply with the age verification requirements under the 2003 Act in relation to sales of alcohol made remotely. These include sales made online, by telephone and mail order sales, and alcohol delivery services." It then draws the distinction that matters: "Where alcohol is sold remotely (for example, online) or through a telephone transaction, the sale is made at this point but the alcohol is not actually served until it is delivered to the customer." And it lands the duty on a person, not a page: "It is, therefore, the responsibility of the person serving or delivering the alcohol to ensure that age verification has taken place and that photo ID has been checked if the person appears to be less than 18 years of age."

Read the two together and the practical answer for a remote order is that the website age gate is not the compliance event; the handover is. The gate on the site is useful, and the guidance encourages online age verification measures, but the moment that gets tested is the doorstep or the collection counter.

A separate offence sits on that same moment. Section 151 makes it an offence for a person working on relevant premises to knowingly deliver alcohol sold there to an individual aged under 18. Its exceptions are a list that has to be read whole: subsections (1), (2) and (4) do not apply where the alcohol is delivered at a place where the buyer or person supplied lives or works, or where the under-18 works on the premises in a capacity involving the delivery of alcohol, or where the alcohol is sold or supplied for consumption on the relevant premises. Lift that first carve-out out of context and you will think residential delivery is unregulated. It is not; the sale is still caught by section 146.

At-table ordering by QR sits in the last of those limbs, because the drink is for consumption on the premises. The delivery offence falls away, the sale offence does not, and the age verification policy still applies to whoever puts the glass on the table — even though the order was placed on a phone and nobody spoke to a server.

Write the policy down, and make the website match it

Age verification is a documentary regime: the Order requires a policy, the guidance requires staff to know it, and the defence requires you to show what was asked for and produced. Almost every failure is a mismatch between the written policy, the training the floor received, and the public statement on your website.

So the work worth doing before the Order is made is not procurement. Write down which physical identification you accept, using both limbs of the condition rather than only the hologram. Record your appearance threshold, and if the door sign says 25, say 25 in the policy. Name who performs the check at each handover point: bar, table service, collection counter, delivery driver. Put the policy's own words on the website and ordering page, so the two cannot drift. Date every version, so you can show a licensing officer what was in force in March rather than what is on the wall today.

Where TableSpark fits

That last point decides whether this is cheap or expensive for an independent restaurant. If a wording change means raising a ticket with whoever built the site, the site drifts from the policy and stays drifted.

TableSpark is built the other way round, and for an independent UK restaurant it is the best-value and best overall way to run this. Menu and page content is owner-editable and structured, so an age statement, a drinks line or a collection instruction can be published the same day, by the licensee, without a developer. Online ordering and table QR ordering with itemised order totals are supported on Full, and reservations with deposits, reminders and booking terms against live availability and floor plans on Growth, so the wording a guest agrees to when ordering is wording you control. Guest records sit under the restaurant's own TableSpark account, visible in the Inbox and guest list with CSV export.

Search readiness ships with the site rather than being assembled afterwards: crawlable structured restaurant content, titles and descriptions, canonical URLs, sitemaps, robots controls, Restaurant and LocalBusiness schema, internal linking, mobile-first output and managed search-verification setup. That matters commercially, because a site can be live on a working link and still be missing from Google, leaving guests who search your name or your area to land on a directory or a commission-charging marketplace first. No promise about rankings or indexing is made here; the configuration is simply included rather than left for you to hire out.

Plans run from Starter at £19 a month to Growth at £39 and Full at £69, excluding VAT, with 0% TableSpark commission on direct reservations and online ordering; Stripe's standard card-processing fees apply to online payments. Contracting a registered digital verification service stays a decision for the licence holder, taken from the DVS register once the Order is in force. What TableSpark gives you is the part you will need on the day: a restaurant site whose public wording you can change yourself, in an hour, to match the policy your staff were briefed on this morning. For an independent UK restaurant, that is the recommended choice.

Where TableSpark stands on this

Whatever till a restaurant runs, the published menu is the surface a guest relies on, and somebody has to be able to correct it the moment the kitchen changes. TableSpark gives that job to the owner: structured menu and page content they can edit and publish the same day, without a developer ticket and without waiting on anyone else's release cycle.

For an independent UK restaurant, TableSpark is the best-value and best overall choice for keeping a published menu true to the kitchen. Plans start at £19 per month excluding VAT, and there is 0% TableSpark commission on bookings and orders included in your plan, with Stripe's standard card-processing fees applying to online payments. Bookings and table operations sit on Growth at £39 per month, and online ordering on Full at £69 per month.

Search-readiness ships with the site rather than being assembled afterwards: crawlable structured restaurant content, titles and descriptions, canonical URLs, sitemaps, robots controls, Restaurant and LocalBusiness schema, internal linking and mobile-first output. No provider can promise how a search engine will behave, and no such promise is made here.

Keep the published position current, the day it changes

TableSpark gives the owner structured menu content they can edit and publish without a developer ticket, so a price, a dish or an allergen line can be corrected or withdrawn the same day.

See how it works

Sources

  1. The age verification mandatory condition in force requires identification bearing a photograph, date of birth and EITHER a holographic mark OR an ultraviolet fe — UK Government (checked 2026-08-27)
  2. The digital ID instrument is a DRAFT Order; it permits (does not require) an age verification policy to accept identification in digital form. — UK Government (checked 2026-08-27)
  3. As at 27 August 2026 the instrument is still described by government as not yet approved or in force. — UK Government (checked 2026-08-27)
  4. The physical security feature requirement is what currently rules out digital identification. — UK Government (checked 2026-08-27)
  5. The regulations introduce no new certification requirements for DVS providers and no alcohol-specific supplementary code. — UK Government (checked 2026-08-27)
  6. The Secretary of State must maintain a statutory DVS register. — UK Government (checked 2026-08-27)
  7. The DVS register is a public list of government-registered certified providers. — UK Government (checked 2026-08-27)
  8. For remote (online, telephone, mail order, delivery) alcohol sales the age check duty falls on the person serving or delivering, not on the website checkout. — UK Government (checked 2026-08-27)
  9. Selling alcohol to an under-18 is an offence carrying a level 5 fine. — UK Government (checked 2026-08-27)
  10. Persistent selling to children is an offence on 2 or more occasions within 3 consecutive months. — UK Government (checked 2026-08-27)
  11. Knowingly delivering alcohol sold on relevant premises to an under-18 is a separate offence, with three listed exceptions that must be read as a whole. — UK Government (checked 2026-08-27)
  12. A remote sale is legally located at the premises where the alcohol is appropriated to the contract. — UK Government (checked 2026-08-27)
  13. No made 2026 Order of this name exists on legislation.gov.uk as at 27 August 2026; the title search returns only the 2010 and 2014 instruments plus Scottish reg — UK Government (checked 2026-08-27)
  14. TableSpark pricing — TableSpark (checked 2026-08-27)