UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most far-reaching pieces of internet legislation in British history. Passed in 2023 and now being enforced in phases by Ofcom through 2025 and 2026, it changes how platforms handle harmful content, verify users' ages, and manage encrypted communications. For everyday users, it also raises serious questions about personal privacy, data collection, and the future of anonymous browsing in the UK.
This guide breaks down what the Online Safety Act actually says, how it affects your day-to-day online life, and what practical steps you can take to keep your personal data private under the new rules.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that requires online platforms to protect users — especially children — from illegal and harmful content. It applies to search engines, social networks, messaging apps, adult sites, and any service with UK users, regardless of where the company is based.
The Act is enforced by Ofcom, the UK's communications regulator. Platforms that fail to comply can be fined up to £18 million or 10% of global annual turnover, whichever is higher. Senior managers can also face criminal liability for repeated failures.
Key Duties Imposed on Platforms
- Illegal content duties — proactively detect and remove content relating to terrorism, child sexual abuse, fraud, and other priority offences.
- Child safety duties — assess risks to under-18s and implement age assurance where content is harmful to children.
- Adult content restrictions — pornographic sites must use "highly effective" age verification.
- Transparency reporting — regular public reports on moderation practices.
- Risk assessments — documented analysis of how services may be misused.
Why the Online Safety Act Matters for Privacy
While the Act's stated goal is user safety, many of its provisions directly touch on personal privacy. To enforce its rules, platforms must collect more data about who you are, what you do, and sometimes what you say — even in private messages.
Three areas cause the most concern among privacy advocates:
- Age verification — proving your age often means sharing an ID document, a face scan, or credit card details with a third-party verifier.
- Encrypted messaging — a controversial "spy clause" allows Ofcom to require scanning of private messages for illegal content.
- Anonymity trade-offs — pseudonymous accounts may become harder to maintain as identity checks spread.
Age Verification: The Biggest Privacy Change
From July 2025, adult content sites accessible in the UK must use "highly effective age assurance" — a standard much stricter than a simple date-of-birth checkbox. This has quickly expanded to include social media platforms, dating apps, and even some forums that host mature discussions.
How Age Assurance Actually Works
Platforms typically outsource verification to specialist providers such as Yoti, Persona, or VerifyMy. Common methods include:
- Photo ID upload — passport, driving licence, or national ID scanned via webcam or phone.
- Facial age estimation — an AI model estimates your age from a selfie.
- Credit card checks — a small verification charge confirms you hold an adult account.
- Bank or mobile network verification — your bank or mobile provider confirms your age without revealing details.
- Digital ID wallets — reusable credentials that verify age across multiple sites.
The Privacy Risks
Even when providers claim to delete data "immediately," you are still trusting a chain of companies with sensitive identity information. Data breaches at age-verification providers have already occurred elsewhere in Europe, exposing selfies and ID scans of adult site visitors. The mere link between a real identity and browsing habits creates a permanent risk profile.
Encrypted Messaging and the "Spy Clause"
Section 121 of the Act gives Ofcom the power to require messaging platforms to use "accredited technology" to identify illegal content, including in end-to-end encrypted services. This is widely known as the spy clause.
Signal, WhatsApp, and other providers have publicly stated they would rather leave the UK market than break their encryption. In practice, the government has said the powers will only be used when "technically feasible" — a phrase that currently kicks the problem down the road, since no known technology can scan encrypted content without weakening encryption for everyone.
What This Means for You Right Now
- End-to-end encrypted messaging in the UK still works as before in 2026.
- Client-side scanning (checking messages on your device before they are encrypted) remains the most likely future implementation.
- If scanning is introduced, metadata about flagged messages could be shared with authorities.
Data Collection and Retention Under the Act
To meet their duties, platforms need to log more information about user behaviour than ever before. Risk assessments require evidence, and enforcement actions require records.
What Platforms Are Collecting More Of
| Data Type | Before the Act | Under the Act |
|---|---|---|
| Age verification data | Rarely required | Required for many services |
| Content moderation logs | Basic | Detailed, auditable trails |
| User reports and appeals | Optional workflows | Mandatory record-keeping |
| Behavioural risk signals | Ad-focused | Safety-focused too |
| Location / jurisdiction data | Rough IP-level | More granular UK detection |
Under UK GDPR, this data must still be minimised, secured, and deleted when no longer needed — but the practical reality is that more data exists in more places for longer periods.
Who Is Affected — And Who Isn't
The Act applies to any service with a "significant number of UK users" or that targets the UK market. It does not only cover Big Tech.
Services in Scope
- Social networks (Facebook, X, TikTok, Instagram, Reddit)
- Search engines (Google, Bing, DuckDuckGo)
- Messaging apps (WhatsApp, Signal, Telegram, Discord)
- Adult content platforms
- Video-sharing services and live-streaming
- Dating apps and forums
- Gaming platforms with chat features
- Cloud file-sharing and link-sharing services
Services Largely Out of Scope
- Email providers (as one-to-one email)
- SMS and MMS via mobile carriers
- Internal business tools not open to the public
- News publishers' own comment sections (limited exemptions)
Practical Steps to Protect Your Privacy
You cannot opt out of the law, but you can reduce how much personal information ends up in third-party hands. Here is a practical checklist.
1. Choose Age-Verification Methods Wisely
When forced to verify, prefer methods that share the least data. Facial age estimation (without ID) or a bank check usually reveals less than uploading a passport scan. Look for providers that use "double-blind" architectures where the verifier does not know which site you are accessing.
2. Separate Identities
Use different email addresses for sensitive services (adult platforms, dating apps, mental-health forums) and your main identity. Email aliasing services like SimpleLogin or Apple's Hide My Email are effective, free, and legal.
3. Harden Your Browser
Switch to a privacy-respecting browser such as Firefox or Brave. Enable encrypted DNS (DNS over HTTPS) to stop your internet provider from logging every domain you visit. Use tracker-blocking extensions like uBlock Origin.
4. Watch What You Share in Links
Long URLs frequently leak tracking parameters, personal identifiers, or session tokens. When sharing links publicly or in group chats, use a reputable link shortener that strips tracking data and offers analytics you control. Services like Lunyb let you shorten and share links without handing personal data to advertising networks — useful when you want to distribute content without exposing your real referral chain. Our own honest review of Lunyb covers exactly what data is and isn't collected.
5. Review App Permissions Regularly
Every few months, audit which apps have access to your camera, microphone, contacts, and location. Revoke anything you don't actively use. On iOS and Android, both platforms now surface this in privacy dashboards.
6. Use Strong, Unique Passwords and Passkeys
Because more of your identity is now tied to online accounts, a single breach carries more weight. A password manager plus passkeys wherever supported dramatically reduces your exposure.
What Businesses and Creators Need to Do
If you run a website, community, newsletter, or online store with UK users, the Act may apply to you even if you are based elsewhere. Small services are not exempt — they simply have proportionate duties.
Compliance Checklist for Small Publishers
- Document a risk assessment covering illegal content and (if relevant) content harmful to children.
- Publish clear terms of service and complaint procedures.
- Provide accessible reporting tools for users.
- Keep audit logs of moderation decisions for at least 12 months.
- Review third-party embeds, comment systems, and shared links for compliance impact.
- If you brand short links for marketing, check that your provider handles UK data properly — our 2026 URL shortener buyer's guide compares the main options.
The Broader Privacy Debate
Civil liberties groups such as the Open Rights Group and Big Brother Watch have argued that the Act creates a compliance-driven surveillance architecture, even where individual companies act in good faith. Supporters, including many child-safety charities, argue that the pre-Act status quo left vulnerable users with no meaningful protection at all.
The truth in 2026 sits somewhere in between: illegal content takedowns have accelerated, but so has the volume of identity data floating between verification providers, platforms, and regulators. The next few years of Ofcom guidance will decide whether the balance shifts further toward safety, privacy, or a workable middle path.
Looking Ahead: 2026 and Beyond
Several developments are worth watching:
- Digital identity wallets — the UK government is progressing a trust framework that could make age checks less invasive by 2027.
- Categorisation rules — the largest "Category 1" services face additional duties around user empowerment tools and verified users.
- Legal challenges — expect judicial reviews on encryption and free-speech provisions.
- International alignment — the EU Digital Services Act and similar laws in Australia and Canada mean UK approaches may become global norms.
FAQ
Does the Online Safety Act require me to give my real name online?
Not directly. The Act does not mandate real-name identification for all users. However, on the largest platforms (Category 1 services), users have the right to verify themselves and to filter out interactions with unverified accounts. Adult sites and services with content harmful to children must confirm age, which often — but not always — involves ID.
Will end-to-end encryption be banned in the UK?
No. Encryption is not banned. The Act contains powers that could theoretically require scanning technology within encrypted services, but the government has stated these powers will only be used when technically feasible. As of 2026, Signal, WhatsApp, and iMessage continue to operate normally in the UK with full end-to-end encryption.
Can I be tracked or identified by age-verification providers?
Reputable providers use privacy-preserving designs where they do not know which site you are visiting, and the site does not see your ID. However, data breaches are always possible, and metadata (timestamps, IP addresses) can still exist. Choose the least invasive verification method available and prefer providers audited to the ICO's age assurance standards.
What happens if a small website doesn't comply?
Ofcom has said it will take a proportionate, risk-based approach and focus enforcement on the highest-risk services first. Small sites are unlikely to face immediate action if they have a documented risk assessment and reasonable moderation processes. Ignoring the Act entirely, however, is not a safe long-term strategy.
How can I share links privately without being tracked?
Use a link shortener that does not attach third-party ad trackers, avoid sharing URLs with embedded tracking parameters (strip "utm_" and "fbclid" tags), and prefer platforms that let you control or disable analytics. Combining a privacy-focused browser, encrypted DNS, and a trustworthy shortener like Lunyb covers most everyday sharing scenarios.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
A clear, practical guide to your GDPR rights in Ireland—covering the eight core rights, how to exercise them, how to complain to the Data Protection Commission, and what businesses must do to comply.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
A complete 2026 guide to privacy rights in Canada, covering PIPEDA, the CPPA, Quebec's Law 25, and provincial protections. Learn how to exercise your rights, what businesses must do, and how to safeguard your personal data online.
GDPR After Brexit: What Changed for UK Businesses
GDPR after Brexit created two parallel regimes: the EU GDPR and the UK GDPR. This guide breaks down the key differences, new transfer rules like the IDTA, ICO enforcement trends, and what UK businesses must do in 2026 to stay compliant and protect adequacy status.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data — from access and correction to consent withdrawal and breach notifications. This comprehensive guide explains each right, how to exercise it, and how the PDPA compares with global frameworks like GDPR.