UK Online Safety Act: What It Means for Your Privacy in 2026
The UK Online Safety Act is one of the most far-reaching pieces of internet legislation ever passed in Britain. Marketed as a shield for children and vulnerable users, it also introduces sweeping new duties for platforms that will directly shape how you browse, message and share content online. If you live in the UK—or run a site that serves UK users—your day-to-day privacy is already being affected.
This guide breaks down what the Act actually says, what it means for your personal data, and the practical steps you can take to protect your privacy without breaking the law.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that places legal duties of care on online platforms to protect users—especially children—from illegal and harmful content. It gives the regulator Ofcom powers to enforce those duties with fines of up to £18 million or 10% of global annual turnover, whichever is greater.
The Act applies to search engines and any "user-to-user service" that allows people to encounter content generated by others. That includes social networks, forums, messaging apps, dating sites, cloud storage with sharing features, and even some gaming platforms. Crucially, it applies to services anywhere in the world if they have a significant number of UK users or target the UK market.
Key dates and rollout
- October 2023: The Act received Royal Assent.
- 2024: Ofcom published codes of practice on illegal harms.
- March 2025: Illegal content duties came into force.
- July 2025: Age assurance and children's safety duties began.
- 2026 onwards: Full enforcement, category classifications, and further codes.
The Core Duties That Affect Your Privacy
Most media coverage focuses on takedowns of illegal content, but several duties have direct privacy consequences for ordinary users.
1. Age verification and age assurance
Any service that hosts pornography or is likely to be accessed by children must implement "highly effective" age assurance. In practice this can mean uploading photo ID, submitting a selfie for facial age estimation, using open banking checks, or providing a credit card. Each of these creates a fresh data trail linking your legal identity to sites you previously visited anonymously.
2. Illegal content scanning
Platforms must proactively identify and remove terrorism content and child sexual abuse material (CSAM). For messaging services, the Act includes a controversial "technology notice" power (Section 121) that allows Ofcom to require the use of "accredited technology" to scan private messages—including in end-to-end encrypted services—when "technically feasible".
3. User verification options
The largest platforms (Category 1 services) must offer adult users a way to verify their identity and a tool to filter out content from unverified accounts. Verification itself is optional, but the infrastructure needed to support it means more identity data flowing through platforms.
4. Content reporting and complaints
Services must provide easy-to-use complaint systems. That is welcome, but it also means more moderation infrastructure, more logging, and more retention of who reported what.
How the Act Changes the Privacy Landscape
The Online Safety Act does not replace the UK GDPR or the Data Protection Act 2018—those still apply. Instead, it sits on top, sometimes creating tension between competing legal obligations. Here is what changes in practice.
More identity checks, more data trails
Before 2025, most UK users could browse adult content, sign up to forums, or create social media accounts with little more than an email address. From 2025 onward, an increasing number of services need to know—or at least strongly estimate—your age. Even where age-estimation tech is used instead of ID, biometric data is being processed on a scale never seen before in the UK.
Pressure on end-to-end encryption
Signal, WhatsApp and other encrypted messengers publicly opposed the Act during its passage. The government said it would not use Section 121 powers until scanning could be done without breaking encryption—but the powers remain on the statute book. The mere existence of these powers has already prompted some services to review their UK availability.
Chilling effects on smaller sites
Compliance is expensive. Small forums, hobby communities and independent platforms have shut their UK doors rather than face the risk of Ofcom fines. Fewer independent platforms means more concentration on a handful of large services—each of which holds even more of your data.
Comparison: Before vs After the Online Safety Act
| Area | Before the Act | After the Act |
|---|---|---|
| Age checks for adult sites | Self-declaration ("I am 18") | Highly effective age assurance (ID, biometrics, banking) |
| Message scanning | Not legally mandated | Possible under Ofcom Section 121 notices |
| Platform liability | Limited (hosting defences) | Statutory duty of care with heavy fines |
| Anonymous accounts | Standard on most platforms | Still allowed, but Category 1 users can filter them out |
| Small forums | Lightly regulated | In scope; many have withdrawn from the UK |
| Regulator | ICO for data; no single content regulator | Ofcom with major enforcement powers |
Pros and Cons for User Privacy
Pros
- Stronger protections for children—less exposure to grooming, self-harm content and extreme material.
- Clearer complaint routes when your own content is misused or you are targeted with illegal material.
- Legal duty on platforms to act, backed by an independent regulator with real teeth.
- Optional verification tools that can help reduce abuse from anonymous accounts if you choose to use them.
Cons
- New identity data pools held by age-check providers become attractive targets for hackers.
- Legal pressure on end-to-end encryption undermines a key privacy technology.
- Reduced anonymity in practice, even if not in law.
- Concentration of power among the very large platforms that can afford compliance.
- Ambiguity around "legal but harmful" content moderation for adults.
Practical Steps to Protect Your Privacy Under the Act
You cannot opt out of the law, but you can be strategic about how much personal data you expose while complying with it.
1. Choose privacy-respecting age assurance methods
When a site asks you to verify your age, look at the options. Standards like the UK's forthcoming digital identity trust framework and "double-blind" age tokens allow a provider to confirm you are over 18 without telling the destination site who you are. Prefer these over uploading a passport scan directly to an unfamiliar platform.
2. Use encrypted DNS and a privacy-focused browser
Encrypted DNS (DoH or DoT) prevents your internet provider from easily logging every domain you visit. Combined with a browser like Firefox or Brave with tracking protection enabled, you significantly reduce passive data collection—without needing any tool that would fall foul of UK law.
3. Separate identities for different activities
Use distinct email addresses (or email aliases) for shopping, social media, forums and adult services. If one provider suffers a breach, the fallout is contained. Password managers make this trivial to maintain.
4. Be careful what you shorten and share
Links you share on social media, in forums, or in messages are content the Act cares about. Use a reputable link shortener that does not resell your click data, gives you analytics you control, and lets you disable or update destinations if needed. Lunyb is one option built with UK privacy expectations in mind, and you can compare it against alternatives in our 2026 buyer's guide or read our detailed Rebrandly review for a competitor perspective.
5. Read the platform's transparency reports
Category 1 services must publish transparency reports covering content removals, complaints and government requests. Reading these tells you how a platform actually behaves—not just what its marketing claims.
6. Exercise your UK GDPR rights
Nothing in the Online Safety Act removes your right to access, correct or delete your personal data. If an age-check provider or platform is holding information you did not know about, submit a subject access request. Providers must respond within one month.
What the Act Means for Website Owners and Creators
If you run a blog with comments, a Discord server, a Substack with community features, or any UK-facing site with user-generated content, you probably fall within scope. That does not automatically mean heavy obligations—many small services face only minimal duties—but you should:
- Complete a risk assessment for illegal content and (if applicable) children's access.
- Publish clear terms and a reporting mechanism.
- Keep records of moderation decisions.
- Review Ofcom's codes of practice for small services, which are proportionate to size.
- Consider limiting features (e.g. anonymous file uploads) that create disproportionate risk.
Ignoring the Act is not an option: Ofcom can act against overseas services and can require UK payment processors and ad networks to stop working with non-compliant sites.
The Bigger Picture: A New Model of Internet Governance
The Online Safety Act reflects a global shift. The EU Digital Services Act, Australia's Online Safety Act, and various US state laws all push in the same direction: platforms are accountable for what happens on them, and regulators want auditable systems—not just goodwill. For users, the trade-off is real. Safer environments often mean more identification, more moderation, and more logging. The privacy-conscious path is not to withdraw from the internet, but to be deliberate about which services you trust with which pieces of your identity.
Frequently Asked Questions
Does the UK Online Safety Act ban end-to-end encryption?
No, it does not ban encryption outright. However, Section 121 gives Ofcom the power to require platforms to use "accredited technology" to detect CSAM and terrorism content, which many experts argue is incompatible with strong end-to-end encryption. The government has said it will only use this power when the technology exists to do so without breaking encryption—but the power remains on the books.
Do I have to hand over my ID to visit adult websites in the UK?
You need to pass "highly effective" age assurance, but that does not always mean uploading ID directly to the site. Approved methods include facial age estimation, mobile network operator checks, open banking, credit card checks and privacy-preserving age tokens. Choose the option that shares the least information with the destination site.
Does the Act apply to overseas websites?
Yes. Any service with a significant number of UK users, or that targets the UK, is in scope regardless of where it is based. Ofcom can fine overseas operators and, in serious cases, seek business disruption measures such as blocking payment services in the UK.
Can I still be anonymous online in the UK?
Yes. The Act does not require you to use your real name on social media or forums. Category 1 platforms must offer optional verification and tools to filter unverified users, but verifying yourself is a choice. Age assurance, however, is increasingly unavoidable on services likely to be accessed by children or hosting adult content.
What happens if a platform ignores the Online Safety Act?
Ofcom can issue enforcement notices, impose fines of up to £18 million or 10% of global turnover, and in extreme cases seek court orders to disrupt the service's ability to operate in the UK (for example, by requiring ad networks or payment providers to withdraw). Senior managers can also face criminal liability for specific failures, such as ignoring information requests.
Final Thoughts
The UK Online Safety Act is here to stay, and its full impact will unfold over the next few years as Ofcom finalises codes and starts enforcing them. For most users, the practical effect is more identity checks and more moderated environments—not a dramatic loss of freedom, but a steady erosion of the casual anonymity the early internet took for granted. By choosing privacy-respecting tools, separating identities, and using your existing UK GDPR rights, you can stay compliant with the law while keeping meaningful control over your personal data.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
A comprehensive guide to Singapore's Online Safety Act 2026, covering scope, obligations, penalties, and practical compliance steps for platforms, marketers, and users navigating the country's tightened online safety regime.
ePrivacy Regulations Ireland: Latest Updates for 2026
Ireland's ePrivacy rules govern cookies, tracking, and electronic marketing alongside GDPR. This 2026 guide covers the latest DPC guidance, enforcement trends, penalties, and practical compliance steps for Irish businesses.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a complex privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the incoming CPPA. This guide walks through practical compliance steps — consent, breach reporting, vendor management, and safeguards — so your organization can protect personal information and avoid costly penalties.
GDPR in Ireland: Your Privacy Rights Explained
A comprehensive guide to GDPR in Ireland, explaining your eight core privacy rights, how to make Subject Access Requests, and how to complain to the Data Protection Commission. Learn practical steps to protect your personal data online.