UK Online Safety Act: What It Means for Your Privacy in 2026
The UK Online Safety Act is now fully operational, and its impact on everyday internet users is bigger than most people realise. Introduced with the goal of protecting children and cracking down on illegal content, the Act has quietly rewritten the rules for how platforms handle your data, verify your identity, and monitor private communications. For millions of Britons, that raises a difficult question: does making the internet safer also make it less private?
This guide breaks down what the UK Online Safety Act actually does, how it affects your personal privacy, what platforms are now legally required to do with your information, and the practical steps you can take to protect yourself while staying on the right side of the law.
What Is the UK Online Safety Act?
The UK Online Safety Act is a piece of legislation that received Royal Assent in October 2023 and is being enforced in phases by Ofcom, the UK communications regulator. It imposes a legal duty of care on online platforms — social networks, search engines, messaging apps, adult sites, and even smaller forums — to protect users, particularly children, from illegal and harmful content.
The Act applies to any service accessible from the UK, regardless of where the company is headquartered. That means US-based platforms like Meta, X, Reddit and Discord fall under its scope just as much as domestic services.
The Three Core Duties
- Illegal content duty: Platforms must proactively detect and remove illegal material, including terrorism content, child sexual abuse material (CSAM), fraud, and content that incites violence.
- Child safety duty: Services likely to be accessed by children must use age verification or age estimation to prevent minors from seeing pornography, self-harm content, and other harmful material.
- Transparency and reporting duty: Larger platforms must publish risk assessments, transparency reports, and provide clear user reporting mechanisms.
Non-compliance carries fines of up to £18 million or 10% of global annual turnover — whichever is higher. In serious cases, senior managers can face criminal liability.
Why Privacy Advocates Are Concerned
On paper, the Act sounds sensible. In practice, several provisions require platforms to collect more personal data, scan more private communications, and verify identities in ways that create new privacy risks for ordinary users.
1. Mandatory Age Verification
Since July 2025, any site hosting adult content — and many social platforms — must implement "highly effective" age assurance. In practice this means one of the following:
- Uploading a photo of your passport, driving licence or other ID
- Submitting a selfie to a facial age-estimation service
- Linking a credit card or bank account
- Using a mobile network age check
- Verifying through a third-party digital identity provider
Ofcom insists these systems are privacy-preserving, but every method creates a data trail. A leak at an age-verification vendor could expose which adult sites, forums, or political communities a user accessed — information that most people would consider deeply sensitive.
2. The Encryption Question
The most controversial section of the Act gives Ofcom the power to issue a "technology notice" requiring services to use "accredited technology" to scan private messages for illegal content — even in end-to-end encrypted services like WhatsApp, Signal, and iMessage.
The government has said it will not exercise this power until it is "technically feasible" to do so without breaking encryption, but the power exists in law. Signal has publicly stated it would withdraw from the UK rather than compromise its encryption. WhatsApp has made similar comments. The chilling effect on secure communication is significant, even if the power is never used.
3. Expanded Data Retention
To comply with the Act's reporting and content-moderation duties, platforms are keeping more logs for longer — including message metadata, IP addresses, upload histories, and moderation decisions. This creates larger data honeypots that are attractive targets for hackers and lawful access requests alike.
How the Act Affects Everyday Users
Let's translate the legal language into what actually changes for you as a UK internet user.
Table: Before vs After the Online Safety Act
| Activity | Before the Act | After the Act (2025–2026) |
|---|---|---|
| Accessing adult sites | Age self-declaration | ID or biometric age check required |
| Signing up for social media | Date of birth field | Age estimation for suspected minors |
| Private messaging | End-to-end encrypted, unscanned | Subject to potential scanning powers |
| Posting on forums | Light moderation | Proactive detection, more removals |
| Anonymous accounts | Widely permitted | Large platforms must offer verification and filtering tools |
| Reporting harmful content | Varied by platform | Standardised, legally required processes |
The Chilling Effect on Legal Speech
One of the quieter consequences of the Act is over-removal. Faced with enormous fines, platforms are incentivised to remove borderline content rather than risk regulatory action. Journalists, activists, satire accounts, and adult educators have all reported increased takedowns of legal material since enforcement began.
Practical Steps to Protect Your Privacy
You don't have to accept every privacy trade-off the Act introduces. Here are practical, lawful steps you can take to reduce your data exposure.
1. Choose Privacy-Respecting Age Verification
Where you must verify your age, prefer services that use "double-blind" or "zero-knowledge" methods, where the verification provider doesn't know which site you're accessing, and the site doesn't see your ID. Ofcom maintains a list of accredited providers — check which method each site uses before uploading anything.
2. Use Encrypted DNS and Private Browsers
Enable encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) in your browser or operating system. This prevents your internet provider from logging every domain you visit. Pair this with a hardened browser like Firefox with strict tracking protection, Brave, or the Mullvad Browser for stronger fingerprinting defences.
3. Minimise Data at the Source
The best defence against data breaches is not creating the data in the first place. Use separate email aliases (via services like SimpleLogin or Apple's Hide My Email) for different accounts, avoid linking phone numbers where possible, and regularly review and delete old accounts.
4. Be Careful With Links You Share
Every link you post publicly can be scraped, logged, and tied to your identity. When sharing sensitive links — a research document, a political petition, a support resource — use a privacy-focused link shortener that doesn't harvest visitor data or track clicks against your identity. Lunyb is one option built with minimal-logging principles; you can read our honest review of Lunyb for details on how it compares to alternatives.
5. Understand Your Rights Under UK GDPR
The Online Safety Act does not override UK GDPR. You still have the right to:
- Request a copy of your personal data (subject access request)
- Have inaccurate data corrected
- Request erasure in many circumstances
- Object to certain kinds of processing
- Complain to the ICO if a platform misuses your data
What Businesses and Website Owners Should Know
If you run a UK-facing website, forum, community, or app with user-generated content, the Act likely applies to you — even if you're small.
Compliance Checklist for Small Platforms
- Complete a risk assessment covering illegal content and, if children may access your service, child safety risks.
- Publish clear terms of service explaining what content is prohibited and how you enforce this.
- Implement a reporting mechanism that is easy to find and use.
- Keep records of moderation decisions and risk assessments for Ofcom inspection.
- Appoint a responsible person for online safety compliance.
- Review third-party tools (analytics, comment plugins, link shorteners) for data-handling practices.
For businesses managing customer-facing links and marketing campaigns, choosing tools carefully matters. Our 2026 buyer's guide to URL shorteners compares the leading options on privacy, features, and pricing — a useful starting point when auditing your marketing stack.
The Bigger Picture: Where Is This Heading?
The UK Online Safety Act is part of a global trend. The EU Digital Services Act, Australia's eSafety framework, and various US state-level bills all point in the same direction: platforms are becoming legally responsible for content, and users are being asked to prove who they are more often.
The next few years will decide whether these regimes evolve toward genuinely privacy-preserving verification (using cryptographic proofs, decentralised identity, or trusted hardware) or toward centralised identity databases that create massive new privacy risks.
For individuals, the practical advice is unchanged: use strong, unique passwords, enable two-factor authentication, minimise the data you share, prefer privacy-respecting services, and stay informed about your rights. The internet is not becoming less private by accident — it is being reshaped by deliberate policy choices, and how you configure your own tools and habits is one of the few areas where you retain meaningful control.
Frequently Asked Questions
Does the UK Online Safety Act require me to give my ID to every website?
No. Age verification is only required for services that host pornography, and for larger platforms that determine children are likely to access harmful content. Most everyday websites, news sites, and utility services are not affected. When ID is required, prefer providers that use double-blind verification so no single party sees both your identity and your browsing.
Is end-to-end encryption illegal in the UK now?
No. End-to-end encryption remains legal, and services like Signal and WhatsApp continue to operate in the UK. The Act contains a power for Ofcom to require scanning of encrypted messages, but the government has said this will not be used until it is "technically feasible" — a threshold that experts widely agree is not currently met without breaking encryption.
Can I be prosecuted for what I post under the Online Safety Act?
The Act primarily regulates platforms, not individual users. However, it did create new criminal offences — including "false communications" and "threatening communications" — that can be prosecuted. Existing laws on harassment, incitement, and illegal content already applied to individuals before the Act.
Does the Act apply to small forums, Discord servers, or personal websites?
Potentially yes, if UK users can access them and they allow user-to-user interaction. Ofcom has taken a proportionate approach for small services, but small forum operators should still complete a basic risk assessment and have clear terms of service and a reporting mechanism.
How can I complain if a platform over-removes my content?
Larger platforms are legally required to offer an internal appeals process — use it first. If that fails, you can raise concerns with Ofcom about systemic over-removal, and complain to the ICO if the removal involved misuse of your personal data. For content removal that affects legal speech, organisations like the Open Rights Group also track and campaign on these issues.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.