facebook-pixel

UK Online Safety Act: What It Means for Your Privacy in 2026

L
Lunyb Security Team
··11 min read

The UK Online Safety Act is the most significant piece of internet regulation Britain has passed in a generation. It became law in October 2023, but the bulk of its enforcement powers, backed by Ofcom, only started biting in 2025 and 2026. If you live in the UK, or run a website that British users visit, the Act changes what you can post, what platforms must monitor, and how much personal information you may have to hand over just to read a page or send a message.

This guide explains, in plain English, what the Online Safety Act actually does, where it collides with your privacy, and the practical steps you can take to protect yourself without breaking any rules.

What is the UK Online Safety Act?

The Online Safety Act 2023 is a UK law that places legal duties on online platforms to protect users, particularly children, from illegal and harmful content. It applies to search engines, social networks, messaging apps, forums, dating services, pornography sites and many smaller user-to-user services, whether they are based in Britain or abroad, as long as they have a significant number of UK users.

Ofcom, the UK communications regulator, is the enforcer. It can issue fines of up to £18 million or 10% of a company's global annual turnover, whichever is higher, and in the most serious cases seek court orders to block services from operating in the UK.

Who the Act covers

  • User-to-user services: platforms where people share content with each other, from Facebook and TikTok down to hobbyist forums.
  • Search services: general and specialist search engines.
  • Pornography providers: any commercial site publishing adult content to UK users.
  • Certain file-sharing, live-streaming and messaging services, including some end-to-end encrypted apps.

Private email, internal business systems and one-to-one voice calls over traditional telephony are largely outside the Act's scope, but almost everything else in your daily online life is covered somewhere.

The Main Duties Platforms Now Have

The Act imposes a layered set of duties. The largest platforms, called Category 1 services, carry the heaviest obligations, but every in-scope service has to do something.

Illegal content duties

Platforms must proactively identify and remove content relating to a list of priority offences, including terrorism, child sexual abuse material, fraud, hate crimes, harassment, encouraging suicide and intimate image abuse. They cannot wait for a complaint; they are expected to design their systems to catch this material.

Child safety duties

Any service likely to be accessed by children must carry out a children's access assessment and, if children are likely to be present, additional risk assessments covering content such as pornography, self-harm promotion, eating disorder content, cyberbullying and violent material. Where risks are found, platforms must use "highly effective age assurance" to keep under-18s away from the worst content.

Transparency and reporting

Large platforms must publish annual transparency reports, offer easy-to-use reporting tools and complaint mechanisms, and give users the ability to appeal moderation decisions.

User empowerment tools

Category 1 services must let adult users filter out certain legal-but-harmful content, verify other users' identities if they choose, and control who can contact them.

Where the Online Safety Act Collides With Your Privacy

On paper, most of the Act's goals are uncontroversial: fewer scams, less child abuse material, safer teenagers. In practice, several provisions create real tension with individual privacy. Understanding these pressure points is the key to protecting yourself.

1. Age verification and identity checks

The most visible change for ordinary users in 2025 and 2026 has been the rollout of age assurance. To view adult content, and increasingly to use some social platforms or specific features, UK users may be asked to prove they are over 18 by:

  • Uploading a photo of a passport, driving licence or other ID document.
  • Submitting a live selfie for facial age estimation.
  • Linking a bank account, mobile contract or credit card as a proxy for adulthood.
  • Using a third-party "digital identity" wallet.

Each of these methods creates a data trail. Even when providers promise not to store your document, they process highly sensitive biometric or financial data on your behalf, and that data can be leaked, subpoenaed or misused. The bigger the age-check ecosystem gets, the larger the honeypot for attackers.

2. Pressure on end-to-end encryption

Section 121 of the Act allows Ofcom to require a service to use "accredited technology" to detect child sexual abuse material or terrorism content, including in private messages. On end-to-end encrypted platforms, the only way to do that at scale is client-side scanning: software on your phone that inspects messages before they are encrypted and sent.

The UK government has said the power will only be used when "technically feasible", and no notice has been served at the time of writing. But the legal mechanism exists, and privacy campaigners argue it undermines the meaning of end-to-end encryption itself. Signal, WhatsApp and others have publicly said they would rather leave the UK market than break their encryption.

3. More logging and moderation, more data retention

To satisfy illegal content duties and defend themselves to Ofcom, platforms must log more of what users do: who reported what, what was removed, who was warned, what content was scanned. That means more personal data is collected, more of it is retained, and more of it is potentially available to law enforcement, civil litigants and hackers.

4. Chilling effects on anonymous speech

The Act does not ban anonymity, but user-verification tools, age checks and stricter moderation combine to make it harder to participate anonymously in mainstream British online life. Whistleblowers, abuse survivors, LGBTQ+ people in hostile family environments and political dissidents all have legitimate reasons to speak without linking speech to a real-world identity.

What the Act Does Not Do

It is just as important to be clear about what the Online Safety Act is not.

  • It is not a general ban on encryption. Everyday HTTPS, encrypted DNS, secure email and encrypted messaging remain lawful.
  • It does not criminalise browsing. The Act targets platforms, not individual readers of legal content.
  • It does not require you to use your real name across the internet. Pseudonymous accounts are still allowed on most services.
  • It does not replace UK GDPR. Your existing data protection rights, including subject access requests and the right to erasure, still apply and sit alongside the Act.

Online Safety Act vs UK GDPR: How They Interact

Many people confuse the two regimes. They are separate but overlapping.

FeatureUK GDPR / Data Protection Act 2018Online Safety Act 2023
Main goalProtect personal data and privacy rightsReduce illegal and harmful online content
RegulatorInformation Commissioner's Office (ICO)Ofcom
Applies toAnyone processing personal data of UK residentsIn-scope online services with UK users
Key user rightAccess, correction, deletion, portabilityReporting, appeal, some content filtering
Maximum fine£17.5m or 4% of global turnover£18m or 10% of global turnover
Encryption stanceEncourages strong security by designAllows Ofcom to mandate scanning tech

In practice, platforms have to satisfy both. Ofcom and the ICO have published joint guidance on how to run age assurance and content moderation without breaching data protection rules, and the ICO has been clear that collecting more personal data than necessary, even in the name of online safety, is unlawful.

Practical Steps to Protect Your Privacy Under the Act

You cannot opt out of UK law, but you can make sensible choices that limit how much of your personal life is exposed to platforms, age-check providers and data brokers.

1. Minimise the identity data you submit

When a platform offers several age-check options, choose the one that shares the least. Facial age estimation that discards the image immediately is generally less risky than uploading a full passport scan. Prefer providers that publish independent audits, use "double-blind" architectures and delete data within a defined window.

2. Separate your identities

Use different email addresses for banking, shopping, social media and forums. If one platform is breached, or forced to disclose data under the Act, the damage stays contained. Password managers make this trivial.

3. Harden your browser and network

Use a privacy-respecting browser such as Firefox or Brave, block third-party trackers, and turn on encrypted DNS (DNS over HTTPS or DNS over TLS) so your internet provider cannot easily log every domain you visit. These are all still fully legal in the UK.

4. Prefer end-to-end encrypted messengers, but stay informed

Signal, WhatsApp and iMessage remain end-to-end encrypted in the UK today. Follow the providers' own statements: if any of them ever ships client-side scanning in response to an Ofcom notice, you will want to know before you send sensitive messages.

5. Think before you shorten and share

Links are data too. A long URL can reveal search terms, campaign IDs, session tokens and even location details. If you share a lot of links, use a shortener that treats privacy as a first-class feature rather than as an afterthought. Lunyb, for example, focuses on clean, tracker-light short links and minimal data collection, which matters more than ever now that platforms are logging more user behaviour to comply with the Act. For a broader look at options, see our 2026 shortener buyer's guide.

6. Exercise your data rights

You still have the full suite of UK GDPR rights. If a platform or age-check provider processes your data, you can:

  1. Submit a subject access request to see what they hold.
  2. Ask for inaccurate data to be corrected.
  3. Request erasure where the lawful basis has ended.
  4. Complain to the ICO for free if they refuse.

What the Act Means for Small Site Owners and Creators

If you run a UK-facing blog with comments, a Discord server, a niche forum or a Substack with a chat feature, you may be an in-scope "user-to-user service". You do not need a legal department, but you should:

  • Publish clear terms of service and a content policy.
  • Offer an obvious way to report illegal content and respond to reports promptly.
  • Keep a light-touch record of moderation decisions.
  • Carry out a proportionate risk assessment, especially if children are likely to visit.
  • Avoid collecting more personal data than you genuinely need.

Ofcom has repeatedly said its enforcement will be risk-based and proportionate: a small hobby forum will not be treated like Meta. But ignoring the Act entirely is not an option.

The Bigger Picture: A New Model for the Internet

The Online Safety Act is part of a global trend. The EU has the Digital Services Act, Australia has its Online Safety Act, and similar laws are being drafted in Canada, India and several US states. The direction of travel is clear: platforms are being made responsible for what happens on them, and users are being asked to prove more about themselves to access more of the web.

Whether that trade-off is worth it depends on your values, your threat model and how carefully the rules are enforced. What is certain is that individual privacy hygiene now matters more, not less. The people who come through this era best will be those who understand the rules, use the tools that respect them, and stay in the habit of sharing only what they must.

Frequently Asked Questions

Does the UK Online Safety Act require me to give my ID to use social media?

Not in general. The Act requires "highly effective age assurance" only for services that host content harmful to children, most obviously pornography and some parts of large social platforms. You can also usually choose between ID upload, facial age estimation, or account-based signals. Verified identity on mainstream social media is offered as an option, not a blanket requirement.

Is end-to-end encryption illegal in the UK now?

No. End-to-end encryption remains lawful and widely used. The Act gives Ofcom a power to require certain services to deploy accredited scanning technology in specific circumstances, but this power has not been exercised, and the government has said it will only apply when technically feasible. Everyday encrypted messaging, banking and browsing are unaffected.

Can I be prosecuted for what I read online under the Act?

The Online Safety Act primarily regulates platforms, not readers. Existing UK criminal law already covers things like accessing child sexual abuse material or terrorist content, and those laws are unchanged. Simply visiting a website that later turns out to breach the Act does not, on its own, make you a criminal.

How does the Act affect me if I run a small website or newsletter?

If your site allows user-to-user interaction, such as comments, forums or chat, and has UK users, you likely have some duties under the Act. In most cases these are proportionate: clear terms, a reporting route, prompt action on illegal content and a basic risk assessment. Purely one-way blogs and newsletters without user interaction are largely out of scope.

What is the safest way to share links now that platforms log more data?

Use links that carry as little personal information as possible. Strip tracking parameters before sharing, avoid pasting URLs that contain session tokens, and use a shortener that does not build advertising profiles on the people who click. A privacy-first tool like Lunyb keeps links tidy and reduces the metadata you spill into every platform that logs them.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles