facebook-pixel

UK Online Safety Act: What It Means for Your Privacy in 2026

L
Lunyb Security Team
··11 min read

The UK Online Safety Act (OSA) is now in full effect, and if you live in Britain you have almost certainly noticed the changes: age verification pop-ups on adult sites, new content warnings on social platforms, and headlines about Ofcom fining tech giants. But behind the child-safety framing sits a much larger question — what does the Online Safety Act mean for your privacy?

This guide breaks the law down in plain English. We'll cover what the Act actually requires, how it affects encrypted messaging, what data platforms now collect about you, and the practical steps you can take to protect your privacy while staying within the law.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a piece of legislation that places legal duties on online platforms — from Facebook and TikTok to small forums and search engines — to protect users, particularly children, from illegal and harmful content. Ofcom is the regulator responsible for enforcement, with powers to issue fines of up to £18 million or 10% of global annual turnover, whichever is higher.

The Act received Royal Assent in October 2023, but its duties are being phased in through 2025 and 2026. Key milestones include the illegal content codes (in force from March 2025) and the child safety duties, including age assurance requirements, which came into effect in July 2025.

Who Does It Apply To?

The Act applies to any service that has "links to the UK" — meaning it has UK users, targets the UK market, or could cause harm to people in the UK. This is deliberately broad and captures:

  • Social media platforms (Meta, X, TikTok, Snapchat, Reddit)
  • Search engines (Google, Bing, DuckDuckGo)
  • Messaging apps (WhatsApp, Signal, Telegram)
  • Video-sharing platforms (YouTube, Twitch)
  • Adult content sites
  • Online gaming services with communication features
  • File-sharing services and cloud storage
  • Even small forums, Discord servers and dating apps

The Core Duties Platforms Must Follow

Under the OSA, in-scope services must carry out risk assessments and put systems in place to reduce specific harms. These duties fall into three broad tiers:

  1. Illegal content duties — All services must proactively tackle content relating to terrorism, child sexual abuse material (CSAM), fraud, hate crimes, and other priority offences.
  2. Child safety duties — Services "likely to be accessed by children" must protect under-18s from legal but harmful content such as pornography, self-harm material, or content promoting eating disorders.
  3. Category 1 duties — The largest platforms (as designated by Ofcom) have extra obligations around transparency, user empowerment tools, and protection of journalistic and democratic content.

How the Online Safety Act Affects Your Privacy

The privacy implications are where the Act becomes controversial. Compliance with these duties often requires platforms to collect more data about you than before, verify your identity or age, and — in some interpretations — weaken end-to-end encryption. Here's how it plays out in practice.

1. Age Verification and "Highly Effective" Age Assurance

The most visible change for UK users is age verification. Sites hosting adult content, and any service where children may encounter harmful material, must now use "highly effective" age assurance methods. Ofcom has confirmed that self-declaration (ticking a box saying "I am over 18") is not sufficient.

Approved methods include:

  • Photo ID upload (passport, driving licence)
  • Facial age estimation via selfie
  • Credit card checks
  • Mobile network operator age checks
  • Open banking-based age verification
  • Digital identity wallets

Every one of these methods creates a new data trail linking your real identity to your online activity. Even if the age-check provider deletes the data immediately (as many claim), the fact that a verification event occurred is often logged, and breaches at these providers would be catastrophic for user privacy.

2. Increased Data Collection and Retention

To meet their illegal content duties, platforms are under pressure to detect prohibited material at scale. This has led to more aggressive content scanning, longer retention of user activity logs, and expanded use of automated moderation. In turn, this means more data about your posts, messages, uploads and metadata is being processed and stored — often for longer periods and by more third-party contractors than before.

3. The Encrypted Messaging Debate

Section 121 of the Act gives Ofcom the power to require platforms to use "accredited technology" to identify CSAM and terrorist content — even on end-to-end encrypted services. The government has repeatedly said this power will only be used when "technically feasible," and Ofcom has so far declined to invoke it, but the legal mechanism remains on the statute book.

Signal, WhatsApp and Apple all publicly warned during the Bill's passage that they would rather leave the UK market than break end-to-end encryption. For now, an uneasy truce holds: encrypted messages are not being scanned, but the possibility that they could be — via client-side scanning on your own device — has not gone away.

4. More Identifiable You, Less Anonymous Web

Category 1 platforms must offer adult users tools to verify their identity and to filter out unverified accounts. In principle you can still browse anonymously; in practice, an increasing share of the UK internet now requires you to prove who you are before you can post, comment, or view certain content.

What Data Are Platforms Now Collecting?

The exact answer varies by service, but the general trend is clear. Here is a simplified comparison of what typical data collection looked like before and after the OSA's implementation:

Data Category Before OSA (Pre-2025) After OSA (2025+)
Age confirmation Self-declared checkbox ID document, facial scan, or credit card check
Content moderation logs Retained days to weeks Retained months to years for audit trail
Reported content records Limited retention Extended retention to demonstrate compliance
Identity verification (optional) Rare Offered by all Category 1 platforms
Automated scanning of uploads Hash-matching for known CSAM Broader AI-based classification of new content
Metadata sharing with regulators Case-by-case Regular transparency reports to Ofcom

Pros and Cons of the Online Safety Act from a Privacy Perspective

Pros

  • Stronger child protection. Under-18s face genuinely reduced exposure to pornography, pro-suicide content and grooming attempts.
  • Faster removal of illegal content. Fraud, revenge porn and terror material must now be actively pursued rather than merely responded to.
  • Transparency reports. Large platforms must publish detailed data on how they moderate — giving researchers and users insight that was previously hidden.
  • User empowerment tools. You can now filter out unverified accounts, block certain content categories, and get clearer reporting mechanisms.
  • Redress against Big Tech. Ofcom finally has real fining power to enforce basic safety standards.

Cons

  • Mandatory identity/age checks create new databases of sensitive personal information that can be breached.
  • Chilling effect on anonymous speech — whistleblowers, abuse survivors and LGBTQ+ users in hostile households rely on anonymity.
  • Latent threat to encryption via Section 121 remains a source of ongoing concern.
  • Over-removal of lawful content as platforms err on the side of caution to avoid fines.
  • Small forums and hobby sites face disproportionate compliance costs, pushing some to shut down or geo-block UK users.
  • Concentration of power in the hands of a small number of age-check vendors.

Practical Steps to Protect Your Privacy Under the OSA

The Act is here to stay, but you still have meaningful choices about how much of your identity you hand over online. Here is a practical checklist.

  1. Choose privacy-respecting age check methods. When forced to verify age, prefer providers that use "double-blind" or zero-knowledge techniques — where the site never sees your ID and the verifier never sees the site you're accessing. Look for services accredited under the Age Check Certification Scheme (ACCS).
  2. Use a dedicated email for verified services. Keep age-verified accounts separate from your primary identity email to reduce cross-referencing.
  3. Enable end-to-end encrypted messaging in Signal, WhatsApp or iMessage. These remain unscanned for now, and using them normalises encryption for everyone.
  4. Switch to encrypted DNS (DNS over HTTPS or DNS over TLS) in your browser and on your router. This hides which domains you visit from your ISP, which is required to log some of that data.
  5. Use a privacy-focused browser such as Firefox with strict tracking protection, Brave, or Mullvad Browser. Disable third-party cookies and enable HTTPS-Only mode.
  6. Review your account settings on major platforms. Category 1 services must now offer stronger privacy and content controls — use them.
  7. Be careful with URL shorteners. Shortened links can be used to profile clickers. Use a shortener that doesn't sell click data or require accounts to view links — Lunyb is one option that keeps analytics minimal and doesn't require sign-in to resolve links.
  8. Minimise ID uploads. Where possible, choose facial age estimation (which doesn't require a name-linked document) over passport upload. Photos should be deleted after verification — read the provider's policy.
  9. Exercise your GDPR rights. The UK GDPR still applies alongside the OSA. You can request access to, correction of, and deletion of personal data held by any service.

What About Small Websites and Link Sharing?

A common misconception is that only tech giants are affected. In reality, any UK-facing service with user-to-user functionality — including comment sections, forums, and even some URL shorteners with public-facing pages — has duties under the Act. Smaller services are subject to proportionate rather than identical requirements, but they still need to complete risk assessments and publish terms of service that reflect the new duties.

If you run a website or share links professionally, this matters. Choose tools that already handle abuse reporting and content moderation properly. Our roundup of the best URL shorteners for 2026 highlights which services have clear policies on illegal content and cooperate appropriately with UK regulators without over-collecting user data. For a deeper look at one popular commercial option, see our Rebrandly review.

The Bigger Picture: Where UK Online Privacy Is Heading

The Online Safety Act sits alongside other UK developments — the Data (Use and Access) Bill, the government's push for a digital identity wallet, and evolving Ofcom codes of practice. Together, they represent a decisive shift away from anonymous, self-declared online life toward a more identity-linked internet.

Whether that's a good thing depends on your priorities. For parents of teenagers, the reduction in accessible harmful content is meaningful. For adults who value the ability to speak, browse and buy without leaving an identity trail, the trade-offs are real and worth taking seriously.

The best response is neither panic nor complacency. Understand what the law actually requires, pick tools and providers that minimise data collection while remaining compliant, and stay engaged with Ofcom's ongoing consultations — many of the most consequential decisions about how the Act works in practice are still being written.

Frequently Asked Questions

Does the UK Online Safety Act require me to upload my ID to use social media?

Not for general use. ID or age verification is required to access adult content and may be required to access certain age-restricted features. Ordinary social media browsing does not require ID upload, though Category 1 platforms must offer optional identity verification if you want a "verified" badge or wish to filter out unverified accounts.

Is end-to-end encrypted messaging still legal in the UK?

Yes. WhatsApp, Signal, iMessage and other encrypted services remain fully legal and unscanned. The Act contains a power for Ofcom to require scanning technology on encrypted services, but the government has stated this will only be used when "technically feasible" and it has not been invoked. Encrypted messaging is not going anywhere in the short term.

Can I be fined for accessing blocked content?

No. The Online Safety Act imposes duties on platforms, not on individual users. Fines apply to services that fail to protect their users, not to users themselves. Accessing content is not criminalised by the OSA (though other laws, such as those on CSAM or terror material, still apply as they always did).

What happens if a platform refuses to comply?

Ofcom can issue fines of up to £18 million or 10% of global annual turnover, whichever is greater. In extreme cases it can seek court orders to require payment providers and advertisers to stop working with the service, or to require ISPs to block access to it in the UK. Senior managers can also face criminal liability for specific failings, particularly around child safety.

How can I check what data an age-verification provider holds about me?

Under the UK GDPR you have the right to submit a Subject Access Request (SAR) to any age-check provider. They must respond within one month and disclose what personal data they hold, how it's used, and who it's shared with. Reputable ACCS-accredited providers publish clear retention policies — typically deleting biometric and ID data within seconds or minutes of verification, keeping only a hashed record that verification occurred.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles