facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act is one of the most sweeping pieces of internet legislation Britain has ever passed. Championed as a landmark law to protect children and tackle illegal content, it also introduces powers that could reshape how private your online life really is. If you send messages, share links, run a small website, or simply browse the web from a home in Manchester or Manchester Road, this law now touches you in some way.

This guide breaks down what the Online Safety Act actually says, what it means for your privacy in practice, and the concrete steps you can take to protect your data without breaking any rules.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that places legal duties on online platforms — from social networks and search engines to messaging apps and adult content sites — to prevent users from encountering illegal content and to protect children from harmful material. It is regulated by Ofcom, which can issue fines of up to £18 million or 10% of global turnover for non-compliance.

The Act came into force in stages between late 2023 and 2025, with the most consequential duties — including age assurance for pornography sites and illegal-content risk assessments — active from 2025 onwards. It applies to any service with a significant number of UK users, regardless of where the company is based.

Who the Act Applies To

  • User-to-user services: Social media, forums, comment sections, dating apps.
  • Search services: Google, Bing, DuckDuckGo and similar.
  • Pornography providers: Any commercial site serving UK users.
  • Messaging platforms: Including end-to-end encrypted services like WhatsApp and Signal.
  • Small platforms: Even blogs with comments can technically fall in scope, though enforcement priorities focus on larger services.

The Privacy Concerns at the Heart of the Act

While the Act's child-safety goals attract broad support, several provisions have alarmed privacy advocates, cryptographers and human-rights groups. The concerns break down into three main areas: age verification, encryption, and content scanning.

1. Age Verification and Identity Data

The Act requires "highly effective" age assurance for services likely to be accessed by children — especially adult content platforms. In practice, this can mean:

  1. Uploading a photo of your passport or driving licence.
  2. Submitting a live selfie for facial age estimation.
  3. Connecting a bank account or mobile operator for age confirmation.
  4. Using a third-party "digital identity wallet".

Each option creates a new data trail linking your real identity to sensitive browsing habits. Even if the platform doesn't store the ID directly, the age-check provider often does — and every additional database is a potential breach waiting to happen.

2. The Encryption Backdoor Debate

Section 121 of the Act gives Ofcom power to require platforms to use "accredited technology" to detect child sexual abuse material and terrorism content, including in private messages. Signal, WhatsApp and Apple have all publicly stated that scanning encrypted messages is technically incompatible with end-to-end encryption. The government has said it will not use these powers until scanning is "technically feasible" without breaking encryption — a position critics call impossible by design.

3. Content Moderation and Legal-but-Harmful Speech

Earlier drafts of the Act required platforms to police "legal but harmful" content for adults. That was dropped, but large platforms must still give users tools to filter such content and enforce their own terms of service consistently. In practice, this pushes platforms toward more aggressive automated moderation — which routinely misclassifies lawful speech, particularly around health, politics and LGBTQ+ topics.

How the Act Changes Your Everyday Online Experience

Most UK users have already noticed changes, whether they realise it or not. Here's what the Act looks like in daily life.

Age-Gated Content

Adult sites now demand verification before displaying anything. Some Reddit communities, Wikipedia articles about historical events, and even mainstream news sites have added age walls in the UK. Wikipedia's operator has publicly challenged aspects of the Act in court, arguing that categorisation as a Category 1 service would compromise volunteer editor privacy.

More Data Requests When Signing Up

Expect to be asked for date of birth, phone number, or ID more often. Services are erring on the side of caution and requesting identifying information from all users rather than risk missing a minor.

Restrictions on Anonymous Accounts

Category 1 services must offer users a way to verify their identity and to filter out unverified accounts. Anonymity is still legal, but it is being nudged to the margins.

Regional Content Blocks

Some overseas platforms — particularly smaller adult sites and niche forums — have chosen to geoblock the UK entirely rather than comply. Others show a stripped-down version of their service to UK IP addresses.

Online Safety Act vs Previous UK Privacy Rules

To understand what actually changed, it helps to compare the Act with the frameworks it sits alongside.

FeatureUK GDPR / Data Protection Act 2018Online Safety Act 2023
Primary goalProtect personal dataProtect users from harmful content
RegulatorICOOfcom
Max fine£17.5m or 4% turnover£18m or 10% turnover
Age checks requiredNo (parental consent for under-13 data only)Yes, for many services
Applies to encrypted messagingYes, for data protectionYes, including content scanning powers
Criminal liability for executivesLimitedYes, for repeated non-compliance

Practical Steps to Protect Your Privacy Under the Act

You cannot opt out of the law, but you can reduce how much personal information you expose to platforms complying with it. Here is a practical, prioritised checklist.

1. Minimise the Identity Data You Share

  • Where age checks are required, prefer providers that use zero-knowledge or "over-18 token" methods rather than uploading full ID.
  • Never reuse the same age-verification account across unrelated services.
  • Check whether the age-check provider is certified under the UK digital identity trust framework.

2. Use Privacy-Respecting Tools

  • Switch to a browser with strong tracker blocking — Firefox, Brave, or Safari with Advanced Tracking Protection.
  • Enable encrypted DNS (DNS-over-HTTPS) in your browser or router to stop your ISP logging every domain you visit.
  • Use a password manager so unique credentials protect each new account you're forced to create.
  • Prefer end-to-end encrypted messengers for personal conversations, and keep them updated.

3. Be Careful With Links You Share and Click

Links are metadata goldmines. A single shared URL can leak referrer information, tracking parameters, and location clues. When sharing links publicly — on social media, in newsletters, or in Discord — use a link management service that lets you strip trackers and control click analytics rather than pasting raw URLs full of UTM tags. Services like Lunyb let you create clean, branded short links without embedding third-party trackers, which is useful both for privacy-conscious individuals and for UK small businesses trying to stay clear of unnecessary data-processing obligations. For a broader look at your options, see our 2026 buyer's guide to URL shorteners.

4. Separate Your Online Identities

  1. Use one email address for banking and government services only.
  2. Use a second for shopping and subscriptions.
  3. Use aliases (via services like SimpleLogin or Apple's Hide My Email) for casual sign-ups.
  4. Never link your verified "real name" account to pseudonymous accounts on the same platform.

5. Know Your Rights

  • Under UK GDPR you can still request a copy of all data a service holds on you, including age-verification records.
  • You can complain to the ICO about excessive data collection even when it is done in the name of Online Safety Act compliance.
  • You can complain to Ofcom if a platform's safety measures cause disproportionate harm, such as wrongly removing your lawful content.

What the Act Means for Small Website Owners

If you run a UK-facing blog, forum, Discord server or Substack with comments, the Act may apply to you. The good news is that Ofcom has repeatedly said enforcement will be risk-based and proportionate: a hobbyist WordPress site with a comment section is not the same as a global social network.

Basic Compliance Checklist for Small Sites

  1. Publish clear terms of service that prohibit illegal content.
  2. Provide an obvious way for users to report problems (a working contact form or email).
  3. Act promptly when illegal content is reported — remove it and keep a record.
  4. Complete Ofcom's illegal-content risk assessment (a template is on the Ofcom site).
  5. If children are likely to access your service, complete a separate children's access assessment.

If you're using shortened links to drive traffic to your site, choose a provider that logs the minimum necessary data. Our honest review of Lunyb and Rebrandly review for 2026 both cover how each service handles analytics and user data — a useful comparison if you're rebuilding your stack around stricter UK rules.

The Bigger Picture: Where UK Online Privacy Is Heading

The Online Safety Act is not the end of the story. Several parallel developments will shape UK online privacy over the next few years:

  • Data (Use and Access) Act: Reshaping UK data protection post-Brexit, potentially loosening some GDPR-style protections.
  • Digital identity framework: A government-backed trust scheme for ID providers used in age checks and beyond.
  • AI regulation: Ofcom is expected to take on additional responsibilities for AI-generated harmful content.
  • Investigatory Powers Act amendments: Expanding lawful access to communications data.

Taken together, these create a UK internet that is safer in some measurable ways — particularly for children — but also more identity-bound and more monitored than the one Britons grew up with. Understanding the trade-offs is the first step to protecting yourself intelligently within them.

Pros and Cons of the Online Safety Act

Pros

  • Stronger legal duties on platforms to remove child sexual abuse material and terrorist content.
  • Clearer rules for tackling online fraud, revenge porn and cyberflashing.
  • New criminal offences for sending threatening or false communications.
  • Better transparency reporting from large platforms.

Cons

  • Age-verification schemes create sensitive new databases vulnerable to breaches.
  • Potential future pressure on end-to-end encryption.
  • Compliance costs may push smaller platforms out of the UK market.
  • Over-cautious automated moderation risks silencing lawful speech.
  • Complex duties fall on hobbyist and community-run sites.

FAQ

Does the Online Safety Act ban end-to-end encryption?

No, the Act does not ban end-to-end encryption. However, it gives Ofcom the power to require platforms to deploy "accredited technology" to detect illegal content, which could in theory require client-side scanning. The government has said it will not exercise this power until it is technically possible without weakening encryption — a caveat that remains contested by cryptographers.

Do I have to upload my passport to use adult websites in the UK?

Not necessarily. Adult sites must use "highly effective" age assurance, but that can include facial age estimation, mobile-operator checks, credit-card verification or digital ID wallets. You should still prefer methods that don't retain your document, and check the provider's privacy policy before uploading anything.

Can I still use a pseudonym online?

Yes. The Act does not require real-name identification for general use of online services. Large "Category 1" platforms must offer users the option to verify their identity and to filter out non-verified accounts, but you are free to remain pseudonymous if you choose.

Does the Act apply to my small blog or Discord server?

Technically it can, if you have UK users and allow user-generated content. In practice, Ofcom has said enforcement will be proportionate to risk and size. Small operators should still publish clear rules, provide a reporting mechanism, and complete a basic illegal-content risk assessment.

What is the safest way to share links in a post-Online-Safety-Act UK?

Use a link management service that lets you strip tracking parameters, uses HTTPS by default, and offers transparent analytics without selling data. Avoid pasting raw URLs stuffed with UTM tags into public posts, and consider branded short links from privacy-focused providers so recipients can see where a link leads before clicking.

Final Thoughts

The UK Online Safety Act is neither the internet apocalypse some feared nor the child-safety panacea its supporters promised. It is a serious, complex law that shifts the balance between safety and privacy — often in favour of safety. That makes it more important than ever for UK users to take practical control of their own data: minimise what you share, choose tools that respect your privacy by design, and stay aware of your rights under both the Online Safety Act and UK GDPR. The law has changed. Your privacy habits should too.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles