UK Online Safety Act: What It Means for Your Privacy in 2026
The UK Online Safety Act (OSA) is now in full force, and if you use the internet from anywhere in the United Kingdom, it is quietly reshaping what you can see, how you prove who you are, and how much of your personal information platforms have to collect about you. Marketed as child safety legislation, the Act also introduces some of the most far-reaching content and identity rules in the Western world — and privacy campaigners argue the trade-offs are only now becoming visible.
This guide explains, in plain English, what the UK Online Safety Act actually does, how it affects your day-to-day privacy, what companies must do to comply, and what practical steps British users can take to keep control of their personal data in 2026.
What is the UK Online Safety Act?
The UK Online Safety Act 2023 is a piece of legislation that places legal duties on online platforms — from social networks and search engines to messaging apps and adult sites — to protect users, particularly children, from illegal and harmful content. It is enforced by Ofcom, which can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.
The Act covers three broad categories of service:
- User-to-user services (social media, forums, messaging apps)
- Search services (Google, Bing, and similar)
- Pornography and content-hosting services that publish or allow adult material
The rules apply not only to UK-based companies but to any service with a "significant number of UK users" or that targets the UK market. In practice, that means almost every major platform you use.
Key dates and phased rollout
The Act received Royal Assent in October 2023, but the practical duties came into force in stages during 2024 and 2025. By 2026, the most consequential duties — illegal harms, child safety codes, and age assurance for pornography and high-risk content — are all live and being actively enforced.
How the Online Safety Act Affects Your Privacy
The Act is officially a safety law, not a privacy law. But because safety obligations often require platforms to identify users, scan content, or verify ages, its privacy footprint is enormous. Here are the main areas where UK users are already feeling the impact.
1. Age verification and identity checks
Any service that hosts pornography or content deemed harmful to children must implement "highly effective age assurance." In practice, this means one of the following:
- Uploading a photo of a passport, driving licence or other government ID
- A live facial age-estimation scan (selfie video)
- Credit card verification
- Mobile network operator age checks
- Digital ID wallet integrations
Each of these methods generates a data trail. Even when a third-party provider promises to "delete data immediately", the fact that a specific person accessed a specific site at a specific time can theoretically be reconstructed if logs are subpoenaed or breached. The Electronic Frontier Foundation and Open Rights Group have both warned that mandatory age checks create a de-facto identity layer on the UK web.
2. Pressure on end-to-end encryption
One of the most controversial parts of the Act is Section 121, which gives Ofcom the power to require platforms to use "accredited technology" to detect child sexual abuse material (CSAM) — including in private messages. Critics, including Apple, Signal and WhatsApp, argued this would effectively force client-side scanning on encrypted platforms.
The Government stated in Parliament that the power would only be used when "technically feasible", and no such notice has been issued at scale as of 2026. However, the legal authority remains on the books, and privacy advocates continue to warn that the mere existence of that power weakens the guarantees of private messaging in the UK.
3. More data collection, longer retention
To demonstrate compliance to Ofcom, platforms must keep detailed records of:
- Content moderation decisions
- Risk assessments
- User reports and how they were handled
- Age assurance outcomes
This creates a natural incentive to collect and retain more data about users, not less — the opposite of the data-minimisation principle championed by the UK GDPR. Users may find themselves subject to more behavioural logging simply because platforms need audit trails to prove they acted reasonably.
4. Content restrictions and geo-filtering
Rather than build costly compliance systems, several smaller platforms have chosen to block UK visitors entirely. Others have introduced UK-specific versions of their site with restricted features. This affects not just adult sites but forums, imageboards, niche communities and even some Wikipedia-adjacent projects. For UK users, this fragmentation of the web has privacy implications: workarounds often push people toward less trustworthy services with weaker security practices.
What Platforms Must Do Under the Act
Understanding the platform side helps you understand what data about you is now being generated. Regulated services must:
- Conduct risk assessments for illegal content and, where relevant, content harmful to children.
- Implement proportionate safety measures — moderation systems, reporting tools, default safety settings for minors.
- Provide transparent terms of service in plain English, explaining what is and is not allowed.
- Offer user empowerment tools such as content filters, block lists, and controls over unverified accounts.
- Report to Ofcom regularly and respond to formal information notices.
Categorised services: the strictest tier
The largest platforms — designated "Category 1" services — face additional duties, including offering adults tools to filter out legal-but-harmful content and giving users the option to verify their identity. Verified users can then choose to only interact with other verified users. On paper this is opt-in; in practice, unverified users may find themselves increasingly excluded from mainstream conversation.
Comparison: Before and After the Online Safety Act
To make the changes concrete, here is how the everyday UK internet experience has shifted:
| Area | Before the OSA | After the OSA (2026) |
|---|---|---|
| Accessing adult sites | Click-through age gate | ID upload, facial scan or credit card check |
| Social media accounts | Email + optional phone number | Optional identity verification, more behavioural logging |
| Private messaging | End-to-end encryption by default | E2EE still available, but under legal pressure |
| Small forums and niche sites | Freely accessible | Some geo-blocked or shut down for UK users |
| Content moderation | Platform discretion | Legally required, with Ofcom oversight |
Pros and Cons for UK Users
Pros
- Stronger legal protection against illegal content, including CSAM, terrorism material and revenge porn
- Clearer, enforceable rules for platforms operating in the UK
- Better default protections for children, including age-appropriate content controls
- New criminal offences for cyberflashing, epilepsy trolling and false communications
- Ofcom now has genuine enforcement teeth against non-compliant platforms
Cons
- Widespread age verification creates new identity-data honeypots
- Legal powers exist that could undermine end-to-end encryption
- Some legitimate sites now block UK visitors, fragmenting the web
- Increased data retention by platforms for audit purposes
- Pressure toward a de-facto "real name" internet through verified user schemes
Practical Steps to Protect Your Privacy
The Act is now law, and individual users cannot opt out. But there are sensible, entirely legal steps British users can take to minimise the data trail they leave behind.
1. Choose age-assurance methods carefully
When a site offers multiple age-check options, the least invasive is usually a third-party token (such as one from Yoti or a mobile operator) rather than uploading your passport directly to the site itself. Look for providers certified under the UK's age assurance schemes and check their data-retention policies before submitting anything.
2. Use a privacy-respecting browser and encrypted DNS
Browsers such as Firefox, Brave and Safari, combined with encrypted DNS (DNS-over-HTTPS or DNS-over-TLS), prevent your internet provider from easily logging every domain you visit. This is a legitimate technical measure that protects you from data breaches and profiling without breaking any UK law.
3. Keep your identity separate from your browsing
Use distinct email addresses for different services. Consider email aliases (Apple's Hide My Email, Firefox Relay, SimpleLogin) so that if one service is breached or forced to hand over data, it cannot easily be joined up with the rest of your online life.
4. Be careful what you shorten and share
Public link shorteners can leak information about what you are sharing and with whom. If you regularly share links — whether for business, journalism or community work — use a shortener that treats privacy as a first-class feature. Lunyb, for example, is a UK-friendly shortener that focuses on clean links without invasive tracking, which is useful when you want analytics without turning every click into a marketing profile. For a wider look at the market, see our 2026 buyer's guide to URL shorteners.
5. Review app permissions regularly
Under the Act, platforms are collecting more diagnostic data than ever. Every few months, go through the apps on your phone and revoke any permissions (location, contacts, photos) that are not strictly needed. iOS and Android both make this easy in Settings > Privacy.
6. Understand your rights under UK GDPR
The Online Safety Act does not override the UK GDPR. You still have the right to request a copy of your data (a Subject Access Request), the right to erasure in many circumstances, and the right to complain to the ICO if a platform mishandles your information. Age-verification providers are covered too.
What About Small Websites and Creators?
If you run a small forum, a Discord-style community, a personal blog with comments, or a niche social platform, the Act may apply to you. Ofcom has published a set of "simpler guides" for small services, but the compliance burden is still real. Many small operators have chosen to:
- Turn off user-to-user features (like comments or DMs)
- Move to fully moderated, invite-only models
- Geo-block UK visitors as a defensive measure
If you operate a service, complete Ofcom's risk assessment early and document your decisions — the regulator has been clear that proportionate, evidenced action is what matters, not perfection.
The Bigger Picture: Safety vs Privacy
The UK Online Safety Act reflects a genuine political consensus that the old "anything goes" internet caused real harm, particularly to children and to victims of harassment. Very few people seriously argue that platforms should have zero responsibility. The debate is about how that responsibility is discharged — and whether the chosen tools (mandatory age checks, potential scanning of private messages, verified-user schemes) achieve safety at an acceptable cost to privacy, free expression and security.
In 2026, the honest answer is that the trade-offs are still being negotiated. Ofcom's codes of practice are evolving, court challenges are working through the system, and platforms are experimenting with less invasive compliance methods. As a user, the most important thing you can do is stay informed, use privacy-preserving tools where sensible, and exercise the rights the UK GDPR still gives you.
Frequently Asked Questions
Does the UK Online Safety Act require me to upload my passport to social media?
Not for general use. Mainstream social platforms are not required to verify every user's identity. However, if you want to access adult content, some age-restricted communities, or opt into "verified user" features on Category 1 platforms, you may be asked for ID, a facial age estimate, or a credit-card check. You can usually choose the least invasive method offered.
Is end-to-end encryption illegal in the UK now?
No. End-to-end encryption remains fully legal, and services like Signal, WhatsApp and iMessage continue to operate in the UK. The Act contains a controversial power that could require scanning of encrypted content in future, but the Government has said it will only be used when technically feasible, and no such large-scale order has been issued.
Can I be prosecuted for something I post online under the Act?
The Act creates new criminal offences including cyberflashing, sending threatening communications, false communications intended to cause harm, and encouraging self-harm. These are targeted offences with specific intent requirements — they do not criminalise ordinary opinions or heated debate. Existing laws on harassment and hate speech continue to apply as before.
Do age verification providers keep my ID on file?
Reputable providers certified under UK age assurance schemes are expected to minimise retention — often deleting the ID document within minutes of verification and keeping only an anonymised token. However, policies vary. Always check the provider's privacy notice before uploading a document, and prefer providers that publish independent audits.
Does the Online Safety Act apply to websites based outside the UK?
Yes, if they have a significant number of UK users or target the UK market. That is why global platforms have introduced UK-specific age checks and content controls. Some smaller overseas sites have chosen to geo-block UK visitors rather than comply, which is why you may occasionally see a "not available in your country" message on sites that used to work fine.
Final Thoughts
The UK Online Safety Act is one of the most ambitious internet regulations in the world, and its full privacy consequences will only become clear over the next few years. For everyday users, the message is not to panic — the mainstream web still works, encryption still exists, and the UK GDPR still protects you. But it is a good moment to review your digital habits, choose services that respect your data, and take advantage of the privacy tools that remain freely available. A safer internet and a private internet do not have to be opposites, but keeping them aligned now requires a little more attention from all of us.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.