The position appears in Mozilla's response to a consultation by the Department for Science, Innovation and Technology on measures intended to prepare children for life in a digital environment. The consultation considers age-gating VPNs amid concerns that some users employ them to get around age-assurance systems required under the UK's Online Safety Act.
Mozilla accepts that protecting young people online is a serious policy challenge. It disputes, however, that mandatory age assurance or restrictions on privacy technology are effective answers. The organization says such measures could weaken fundamental rights for all users without tackling the sources of online harm.
A VPN routes internet traffic through an intermediary and conceals the user's public IP address from the services they visit. Mozilla says this can reduce location exposure, tracking and profiling based on an IP address. VPN connections are also routinely used to reach school or workplace networks, protect traffic on untrusted connections and access information where censorship blocks it.
Those functions can be particularly important to journalists, activists and dissidents, but Mozilla's submission argues that they form part of ordinary baseline protection. The organization also says children face substantial exposure to tracking, targeted advertising and commercial collection of personal data, sometimes without meaningful consent or transparency. Preventing them from learning to use privacy tools would therefore conflict with the goal of building safe and capable digital habits.
Mozilla's argument does not deny that VPNs can be used to bypass geographic or age-based controls. Instead, it focuses on proportionality: whether limiting a broadly useful security technology is justified by one form of circumvention. Its answer is no. The supplied submission does not include government data on the prevalence of VPN-based evasion or an assessment from child-safety groups, so the effectiveness debate cannot be settled from Mozilla's evidence alone.
As alternatives, Mozilla calls for policy aimed at the underlying causes of harm. It recommends stronger accountability for online platforms, responsible use of parental controls, investment in digital skills and a society-wide approach to digital wellbeing. That package would place more responsibility on services and education rather than making access to a network-security tool conditional on age verification.
The intervention reflects a recurring difficulty in online-safety regulation. Controls designed to limit children's access to harmful material can create new collection requirements or restrict technologies that protect privacy. Age assurance itself may require users to disclose information, while VPN limits could reduce their ability to obscure location and browsing metadata.
Mozilla's submission is an advocacy position, not the UK government's final policy. The consultation process will have to weigh that privacy case against evidence from regulators and child-protection stakeholders. Mozilla's central warning is that weakening VPN access would impose broad security costs while offering an uncertain benefit for young people's safety.



