Check into a Harrogate hotel now and you may never speak to anyone at the desk. The booking, the card and the ID were matched online hours before you arrived, and the room key sits on your phone. Ordering at the table runs on the same plumbing, and so does the loyalty scheme you joined on the way out.
Every one of those steps asks a venue to make the same trade. Push too much friction at the customer and they give up at the door. Push too little and the venue carries the risk when something goes wrong: an underage sale, a chargeback dispute, or a customer database nobody got round to locking down properly.
Yorkshire operators are still working out where that line sits. Mostly they are watching the sectors that were made to solve it first.
The Sector That Was Given A Deadline
Online gambling got there early, because a regulator made it. Until 2019 a UK operator could let a new customer deposit and play while age verification ran in the background, with 72 hours to finish the job. The Gambling Commission closed that window on 7 May 2019. Name, address and date of birth now have to be confirmed before anyone deposits a penny, and before they can touch even the free-to-play versions of the games.
Michael McKean, who tracks how the licensed operators handle that sequence, makes the same point from the customer’s side: the routine checks cannot be parked until someone asks to take their money out (source: next.io/online-casinos-uk/).
The requirements have kept tightening since. Light-touch financial vulnerability checks arrived on 30 August 2024, triggered at £500 of net deposits over a rolling 30 days, then dropped to £150 from 28 February 2025. In July the Commission confirmed that Financial Risk Assessments will be introduced in stages, beginning with the largest operators and with customers whose net deposits pass £5,000 inside 24 hours.
The thresholds matter less than the sequencing. Identity is settled first, the payment method second, spending patterns third, and all of it before the customer reaches the thing they came for. A contactless tab or a loyalty sign-up is a much smaller version of the same problem.
Where The Digital Layer Actually Earns Its Place
Not all of it is defensive. Some of it is simply better than what it replaced. QR check-in at an event beats a queue and a printed ticket on both speed and accuracy, and it makes forgeries and touted resale harder to pull off. Digital key collection lets a guest skip reception entirely once the booking and the ID have been matched online.
Loyalty schemes have moved the same way. A stamp on a paper card can be faked with any rubber stamp off eBay, tells the merchant nothing afterwards, and spends half its life in a wallet the customer left at home. On a phone it does none of those things.
Leeds got a working example of that in October 2024, when a digital loyalty app aimed at independent retail and hospitality launched in the UK, with city businesses among the first to sign up. Llama Points was built in Switzerland by BFM Solutions and ran there from 2023. Co-founder Fergus Rae said the point was to put a digital loyalty programme within reach of small businesses that could never commission one of their own. For an independent trying to match a chain on convenience, it closes a gap that was obvious to anyone still handing out dog-eared cards.
The Part Venues Still Have To Get Right
Collecting the data is the easy half. Holding it properly is where the regulator is now looking.
On 12 March the Information Commissioner’s Office published an open letter to social media and video-sharing platforms telling them to stop relying on users to declare their own ages. “There’s now modern technology at your fingertips, so there is no excuse not to have effective age assurance measures in place,” said Paul Arnold, the ICO’s chief executive. The letter landed a few weeks after the office fined Reddit £14.47 million and MediaLab, the owner of Imgur, £247,590, in both cases for processing children’s personal information without a robust age check behind it.
Those are platforms, not pubs. The principle travels anyway. A venue that scans an ID on the door, or stores a date of birth against a loyalty profile, is processing personal data and has to be able to say what it holds, why it holds it and when it deletes it. Having a check that works is not the whole job.
What It Looks Like From Behind The Bar
None of this arrives as a single deadline. It arrives as a run of small decisions. Which supplier. How long the record sits on the system. Whether the person on the door knows what happens to the scan after the light goes green.
The venues handling it well tend to treat friction and trust as one question rather than two. The rest tend to find out they got it wrong from a customer, or from a letter.

