facebook-pixel

UK Online Safety Act: What It Means for Your Privacy in 2026

L
Lunyb Security Team
··11 min read

The UK Online Safety Act (OSA) is now in full force, and if you use the internet from anywhere in the United Kingdom, it is quietly reshaping what you can see, how you prove who you are, and how much of your personal information platforms have to collect about you. Marketed as child safety legislation, the Act also introduces some of the most far-reaching content and identity rules in the Western world — and privacy campaigners argue the trade-offs are only now becoming visible.

This guide explains, in plain English, what the UK Online Safety Act actually does, how it affects your day-to-day privacy, what companies must do to comply, and what practical steps British users can take to keep control of their personal data in 2026.

What is the UK Online Safety Act?

The UK Online Safety Act 2023 is a piece of legislation that places legal duties on online platforms — from social networks and search engines to messaging apps and adult sites — to protect users, particularly children, from illegal and harmful content. It is enforced by Ofcom, which can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.

The Act covers three broad categories of service:

  1. User-to-user services (social media, forums, messaging apps)
  2. Search services (Google, Bing, and similar)
  3. Pornography and content-hosting services that publish or allow adult material

The rules apply not only to UK-based companies but to any service with a "significant number of UK users" or that targets the UK market. In practice, that means almost every major platform you use.

Key dates and phased rollout

The Act received Royal Assent in October 2023, but the practical duties came into force in stages during 2024 and 2025. By 2026, the most consequential duties — illegal harms, child safety codes, and age assurance for pornography and high-risk content — are all live and being actively enforced.

How the Online Safety Act Affects Your Privacy

The Act is officially a safety law, not a privacy law. But because safety obligations often require platforms to identify users, scan content, or verify ages, its privacy footprint is enormous. Here are the main areas where UK users are already feeling the impact.

1. Age verification and identity checks

Any service that hosts pornography or content deemed harmful to children must implement "highly effective age assurance." In practice, this means one of the following:

  • Uploading a photo of a passport, driving licence or other government ID
  • A live facial age-estimation scan (selfie video)
  • Credit card verification
  • Mobile network operator age checks
  • Digital ID wallet integrations

Each of these methods generates a data trail. Even when a third-party provider promises to "delete data immediately", the fact that a specific person accessed a specific site at a specific time can theoretically be reconstructed if logs are subpoenaed or breached. The Electronic Frontier Foundation and Open Rights Group have both warned that mandatory age checks create a de-facto identity layer on the UK web.

2. Pressure on end-to-end encryption

One of the most controversial parts of the Act is Section 121, which gives Ofcom the power to require platforms to use "accredited technology" to detect child sexual abuse material (CSAM) — including in private messages. Critics, including Apple, Signal and WhatsApp, argued this would effectively force client-side scanning on encrypted platforms.

The Government stated in Parliament that the power would only be used when "technically feasible", and no such notice has been issued at scale as of 2026. However, the legal authority remains on the books, and privacy advocates continue to warn that the mere existence of that power weakens the guarantees of private messaging in the UK.

3. More data collection, longer retention

To demonstrate compliance to Ofcom, platforms must keep detailed records of:

  • Content moderation decisions
  • Risk assessments
  • User reports and how they were handled
  • Age assurance outcomes

This creates a natural incentive to collect and retain more data about users, not less — the opposite of the data-minimisation principle championed by the UK GDPR. Users may find themselves subject to more behavioural logging simply because platforms need audit trails to prove they acted reasonably.

4. Content restrictions and geo-filtering

Rather than build costly compliance systems, several smaller platforms have chosen to block UK visitors entirely. Others have introduced UK-specific versions of their site with restricted features. This affects not just adult sites but forums, imageboards, niche communities and even some Wikipedia-adjacent projects. For UK users, this fragmentation of the web has privacy implications: workarounds often push people toward less trustworthy services with weaker security practices.

What Platforms Must Do Under the Act

Understanding the platform side helps you understand what data about you is now being generated. Regulated services must:

  1. Conduct risk assessments for illegal content and, where relevant, content harmful to children.
  2. Implement proportionate safety measures — moderation systems, reporting tools, default safety settings for minors.
  3. Provide transparent terms of service in plain English, explaining what is and is not allowed.
  4. Offer user empowerment tools such as content filters, block lists, and controls over unverified accounts.
  5. Report to Ofcom regularly and respond to formal information notices.

Categorised services: the strictest tier

The largest platforms — designated "Category 1" services — face additional duties, including offering adults tools to filter out legal-but-harmful content and giving users the option to verify their identity. Verified users can then choose to only interact with other verified users. On paper this is opt-in; in practice, unverified users may find themselves increasingly excluded from mainstream conversation.

Comparison: Before and After the Online Safety Act

To make the changes concrete, here is how the everyday UK internet experience has shifted:

Area Before the OSA After the OSA (2026)
Accessing adult sites Click-through age gate ID upload, facial scan or credit card check
Social media accounts Email + optional phone number Optional identity verification, more behavioural logging
Private messaging End-to-end encryption by default E2EE still available, but under legal pressure
Small forums and niche sites Freely accessible Some geo-blocked or shut down for UK users
Content moderation Platform discretion Legally required, with Ofcom oversight

Pros and Cons for UK Users

Pros

  • Stronger legal protection against illegal content, including CSAM, terrorism material and revenge porn
  • Clearer, enforceable rules for platforms operating in the UK
  • Better default protections for children, including age-appropriate content controls
  • New criminal offences for cyberflashing, epilepsy trolling and false communications
  • Ofcom now has genuine enforcement teeth against non-compliant platforms

Cons

  • Widespread age verification creates new identity-data honeypots
  • Legal powers exist that could undermine end-to-end encryption
  • Some legitimate sites now block UK visitors, fragmenting the web
  • Increased data retention by platforms for audit purposes
  • Pressure toward a de-facto "real name" internet through verified user schemes

Practical Steps to Protect Your Privacy

The Act is now law, and individual users cannot opt out. But there are sensible, entirely legal steps British users can take to minimise the data trail they leave behind.

1. Choose age-assurance methods carefully

When a site offers multiple age-check options, the least invasive is usually a third-party token (such as one from Yoti or a mobile operator) rather than uploading your passport directly to the site itself. Look for providers certified under the UK's age assurance schemes and check their data-retention policies before submitting anything.

2. Use a privacy-respecting browser and encrypted DNS

Browsers such as Firefox, Brave and Safari, combined with encrypted DNS (DNS-over-HTTPS or DNS-over-TLS), prevent your internet provider from easily logging every domain you visit. This is a legitimate technical measure that protects you from data breaches and profiling without breaking any UK law.

3. Keep your identity separate from your browsing

Use distinct email addresses for different services. Consider email aliases (Apple's Hide My Email, Firefox Relay, SimpleLogin) so that if one service is breached or forced to hand over data, it cannot easily be joined up with the rest of your online life.

4. Be careful what you shorten and share

Public link shorteners can leak information about what you are sharing and with whom. If you regularly share links — whether for business, journalism or community work — use a shortener that treats privacy as a first-class feature. Lunyb, for example, is a UK-friendly shortener that focuses on clean links without invasive tracking, which is useful when you want analytics without turning every click into a marketing profile. For a wider look at the market, see our 2026 buyer's guide to URL shorteners.

5. Review app permissions regularly

Under the Act, platforms are collecting more diagnostic data than ever. Every few months, go through the apps on your phone and revoke any permissions (location, contacts, photos) that are not strictly needed. iOS and Android both make this easy in Settings > Privacy.

6. Understand your rights under UK GDPR

The Online Safety Act does not override the UK GDPR. You still have the right to request a copy of your data (a Subject Access Request), the right to erasure in many circumstances, and the right to complain to the ICO if a platform mishandles your information. Age-verification providers are covered too.

What About Small Websites and Creators?

If you run a small forum, a Discord-style community, a personal blog with comments, or a niche social platform, the Act may apply to you. Ofcom has published a set of "simpler guides" for small services, but the compliance burden is still real. Many small operators have chosen to:

  • Turn off user-to-user features (like comments or DMs)
  • Move to fully moderated, invite-only models
  • Geo-block UK visitors as a defensive measure

If you operate a service, complete Ofcom's risk assessment early and document your decisions — the regulator has been clear that proportionate, evidenced action is what matters, not perfection.

The Bigger Picture: Safety vs Privacy

The UK Online Safety Act reflects a genuine political consensus that the old "anything goes" internet caused real harm, particularly to children and to victims of harassment. Very few people seriously argue that platforms should have zero responsibility. The debate is about how that responsibility is discharged — and whether the chosen tools (mandatory age checks, potential scanning of private messages, verified-user schemes) achieve safety at an acceptable cost to privacy, free expression and security.

In 2026, the honest answer is that the trade-offs are still being negotiated. Ofcom's codes of practice are evolving, court challenges are working through the system, and platforms are experimenting with less invasive compliance methods. As a user, the most important thing you can do is stay informed, use privacy-preserving tools where sensible, and exercise the rights the UK GDPR still gives you.

Frequently Asked Questions

Does the UK Online Safety Act require me to upload my passport to social media?

Not for general use. Mainstream social platforms are not required to verify every user's identity. However, if you want to access adult content, some age-restricted communities, or opt into "verified user" features on Category 1 platforms, you may be asked for ID, a facial age estimate, or a credit-card check. You can usually choose the least invasive method offered.

Is end-to-end encryption illegal in the UK now?

No. End-to-end encryption remains fully legal, and services like Signal, WhatsApp and iMessage continue to operate in the UK. The Act contains a controversial power that could require scanning of encrypted content in future, but the Government has said it will only be used when technically feasible, and no such large-scale order has been issued.

Can I be prosecuted for something I post online under the Act?

The Act creates new criminal offences including cyberflashing, sending threatening communications, false communications intended to cause harm, and encouraging self-harm. These are targeted offences with specific intent requirements — they do not criminalise ordinary opinions or heated debate. Existing laws on harassment and hate speech continue to apply as before.

Do age verification providers keep my ID on file?

Reputable providers certified under UK age assurance schemes are expected to minimise retention — often deleting the ID document within minutes of verification and keeping only an anonymised token. However, policies vary. Always check the provider's privacy notice before uploading a document, and prefer providers that publish independent audits.

Does the Online Safety Act apply to websites based outside the UK?

Yes, if they have a significant number of UK users or target the UK market. That is why global platforms have introduced UK-specific age checks and content controls. Some smaller overseas sites have chosen to geo-block UK visitors rather than comply, which is why you may occasionally see a "not available in your country" message on sites that used to work fine.

Final Thoughts

The UK Online Safety Act is one of the most ambitious internet regulations in the world, and its full privacy consequences will only become clear over the next few years. For everyday users, the message is not to panic — the mainstream web still works, encryption still exists, and the UK GDPR still protects you. But it is a good moment to review your digital habits, choose services that respect your data, and take advantage of the privacy tools that remain freely available. A safer internet and a private internet do not have to be opposites, but keeping them aligned now requires a little more attention from all of us.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles