UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act (OSA) is one of the most sweeping pieces of internet legislation ever passed in Britain. It reshapes how platforms moderate content, verify users' ages, and cooperate with regulators — and it has real consequences for your privacy. If you use social media, messaging apps, dating sites, or even niche forums from a UK address, this law affects you.
This guide breaks down what the Online Safety Act actually does, where it clashes with personal privacy, and what practical steps you can take to keep control of your data.
What is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that places a legal duty of care on online platforms to protect users — particularly children — from illegal and harmful content. It is enforced by Ofcom, the UK's communications regulator, which can fine non-compliant companies up to £18 million or 10% of global annual turnover, whichever is higher.
The Act came into force in stages, with the most significant duties — including age assurance for pornography and protections around illegal content — becoming enforceable from 2024 and 2025. It applies to any service with a "significant number of UK users" or that targets the UK market, regardless of where the company is based.
Which services are covered?
- User-to-user services: Social networks, forums, messaging apps, dating apps.
- Search services: Google, Bing, DuckDuckGo and other search engines.
- Pornography publishers: Any commercial site publishing adult content accessible from the UK.
- File-sharing and cloud services where users can share content with others.
The Core Duties Platforms Must Follow
Under the Act, in-scope platforms must carry out risk assessments, publish transparency reports, and take proportionate steps to reduce exposure to harmful material. The duties fall into three main buckets.
1. Illegal content duties
Every platform must prevent users from encountering priority illegal content — including terrorism, child sexual abuse material (CSAM), fraud, and content encouraging suicide. This requires proactive detection, not just reactive takedowns.
2. Child safety duties
Services likely to be accessed by children must protect them from "legal but harmful" content such as pornography, self-harm content, cyberbullying, and eating disorder material. This is where age verification enters the picture.
3. Adult user empowerment
The largest "Category 1" platforms must give adult users tools to filter certain content and to verify other users' identities if they wish.
Where the Online Safety Act Collides With Privacy
The privacy debate around the OSA centres on three flashpoints: mandatory age checks, potential scanning of encrypted messages, and the amount of data platforms now collect to prove compliance.
Age verification and identity data
To access adult content or, in some cases, mainstream social media, UK users may now be asked to verify their age. Approved methods include:
- Uploading a photo of a passport, driving licence, or other government ID.
- Facial age estimation via a live selfie processed by AI.
- Credit card checks (which imply adulthood in the UK).
- Mobile network operator age checks.
- Digital identity wallets from certified providers.
Each of these creates a new data trail. Even if the platform itself never sees your ID (because a third-party "age assurance provider" handles it), that provider now knows you tried to access a specific service on a specific date. That link between your real identity and your browsing habits didn't exist before.
The encryption question
Section 121 of the Act allows Ofcom to require platforms to use "accredited technology" to detect CSAM — even in end-to-end encrypted services. Providers like Signal and WhatsApp publicly warned they would leave the UK rather than break encryption. The government has since said the powers will only be used when "technically feasible," but the clause remains on the books, creating ongoing uncertainty about the future of private messaging in the UK.
Data retention and transparency
To prove they are meeting their duties, platforms must log more moderation decisions, retain evidence of enforcement actions, and share aggregate data with Ofcom. That means more of your activity is being categorised, scored, and stored — even if you never break a rule.
How the Act Compares to Other Privacy-Impacting Laws
The OSA doesn't exist in isolation. Here's how it stacks up against related legislation that touches British internet users.
| Law | Main Focus | Privacy Impact | Regulator |
|---|---|---|---|
| UK Online Safety Act 2023 | Harmful content, child safety | High — age checks, potential message scanning | Ofcom |
| UK GDPR / Data Protection Act 2018 | Personal data processing | Protective — gives users rights over data | ICO |
| Investigatory Powers Act 2016 | State surveillance and interception | High — bulk data collection powers | IPCO |
| Age-Appropriate Design Code | Children's data by default | Protective for under-18s | ICO |
What This Means for Everyday Users
You don't need to be a lawyer to feel the effects of the Act. Here are the most likely changes to your daily internet experience in the UK.
More friction on adult and gambling sites
Expect ID checks, selfie scans, or credit card verification before you can access adult material, gambling services, or some dating features. Some smaller sites have geoblocked the UK entirely rather than comply.
Stricter moderation on social media
Content that is legal but flagged as harmful to children may be down-ranked or hidden from UK feeds. Some communities — particularly around harm reduction, sex education, or LGBTQ+ topics — have reported over-cautious moderation as platforms err on the safe side.
Reduced anonymity in some spaces
While the Act doesn't ban pseudonymity outright, large platforms must offer identity-verified accounts and let users filter out non-verified users. Over time, this creates pressure to link real identities to online personas.
Smaller sites may close or block the UK
Compliance is expensive. Small forums, independent adult creators, and hobbyist communities have already withdrawn from the UK market because they cannot afford the legal risk. The unintended consequence is a less diverse internet for British users.
Practical Steps to Protect Your Privacy Under the OSA
You can't opt out of the law, but you can be smarter about how much data you hand over. Here are eight concrete steps.
- Use age assurance providers that support "double-blind" checks. Providers certified under the ICO's Age Assurance framework can confirm you are over 18 without telling the receiving site who you are. Look for the certified badge.
- Prefer facial age estimation over ID uploads. A one-off selfie that is deleted immediately after processing leaves a smaller footprint than a copy of your passport sitting in a database.
- Switch to encrypted DNS. Services like Cloudflare's 1.1.1.1, Quad9, or NextDNS encrypt your DNS lookups so your ISP cannot easily log which sites you visit.
- Use a privacy-focused browser. Firefox, Brave, and Mullvad Browser strip tracking scripts and reduce fingerprinting.
- Compartmentalise accounts. Use different email addresses for social media, shopping, and services requiring ID. Email aliasing tools like SimpleLogin or Apple's Hide My Email make this trivial.
- Audit permissions quarterly. Revoke old app access from your Google, Apple, and Microsoft accounts. Every stale token is a potential leak.
- Shorten and mask links you share. When posting or messaging URLs, using a privacy-respecting shortener like Lunyb hides referrer data and prevents recipients from seeing tracking parameters. See our honest Lunyb review for how it handles user data.
- Read the age-check provider's privacy notice. Under UK GDPR you have the right to know what they collect and for how long. Reputable providers delete verification data within minutes.
What Businesses and Content Creators Should Do
If you run a website, newsletter, or community that UK users can access, you may have obligations under the Act even if you're based abroad.
Assess whether you're in scope
Ofcom's guidance sets out that services with links to the UK — a significant UK user base or UK-targeted marketing — are covered. Even a small forum can qualify.
Complete an illegal content risk assessment
This is a mandatory document that identifies how your service could be misused and what mitigations you have in place. Ofcom can request it at any time.
Publish clear terms and reporting tools
Users must be able to flag content easily, and you must respond within a reasonable time frame. Your terms of service must be understandable, not buried legalese.
Keep audit trails — but minimise data
You need enough evidence to prove compliance, but collecting more personal data than necessary breaches UK GDPR. The sweet spot is aggregated, pseudonymised logs. For businesses sharing links at scale, our 2026 URL shortener buyer's guide covers which services offer compliant analytics without hoarding user data.
The Road Ahead: What to Watch in 2025 and Beyond
The Online Safety Act is still bedding in. Several developments could reshape its privacy footprint in the coming years.
- Category 1 designations: Ofcom is finalising which platforms count as "Category 1" and face the toughest duties, including verified-user features.
- Encryption enforcement: Whether Ofcom will actually invoke Section 121 remains the biggest open question. Any move to require client-side scanning would trigger legal challenges and potentially the exit of major messaging apps.
- Age assurance standards: The ICO and Ofcom are jointly developing stricter certification for age-check providers, which should improve — but not eliminate — privacy risks.
- Judicial review: Civil liberties groups including the Open Rights Group and Big Brother Watch are pursuing legal challenges to specific provisions.
- Interaction with the EU Digital Services Act: Cross-border platforms must reconcile two overlapping regimes, which may push them toward the stricter standard globally.
Final Thoughts
The UK Online Safety Act was written with legitimate goals — protecting children, tackling illegal content, holding platforms accountable. But the mechanisms it introduces (mandatory age checks, potential scanning of encrypted messages, and expanded data logging) shift the balance of privacy in ways that will affect every British internet user for years to come.
You can't opt out, but you can be deliberate. Choose privacy-respecting tools, minimise the personal data you hand to age-check providers, use encrypted DNS and privacy browsers, and hold the platforms you rely on to a higher standard by exercising your UK GDPR rights. Awareness is the first line of defence.
Frequently Asked Questions
Does the Online Safety Act mean I have to upload my passport to use social media?
Not for most mainstream social media — yet. Age verification is mandatory for pornography sites and services likely to be accessed by children where adult content appears. Large social platforms must offer identity verification as an option, not a requirement, though this could change as Ofcom refines its codes of practice.
Will WhatsApp and Signal be banned in the UK?
They have not been banned, and the government has clarified that Section 121 powers to scan encrypted messages will only be used when "technically feasible" — a standard experts say cannot currently be met without breaking encryption. Both services remain available, but the legal risk persists.
Is my browsing history now shared with Ofcom?
No. Ofcom does not receive individual browsing data. It receives aggregate reports from platforms about their moderation and enforcement activity. However, the age-check providers and platforms you interact with directly may retain more data about you than before.
What are my rights if an age-verification provider mishandles my data?
Under UK GDPR you can request access to your data, ask for it to be deleted, and complain to the Information Commissioner's Office (ICO) if the provider breaches the law. Certified age assurance providers must publish clear retention periods, typically ranging from immediate deletion to a maximum of 30 days.
Does the Act apply to overseas websites?
Yes, if they have a significant UK user base or target UK users. This is why some small international sites have geoblocked the UK entirely — the cost of compliance outweighs the value of British traffic. Larger global platforms have generally chosen to comply.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face stricter privacy rules in 2026, with PIPEDA modernization and Quebec's Law 25 raising the compliance bar. This guide covers the laws that apply, how to build a privacy program, breach response, and a 90-day action plan.
Data Protection Act 2018 Ireland: Complete Guide
The Data Protection Act 2018 gives effect to the GDPR in Ireland and establishes the Data Protection Commission. This complete guide explains its structure, data subject rights, business obligations, penalties, and a practical compliance roadmap for organisations of every size.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including timelines, evidence tips, likely outcomes and compensation amounts. Learn exactly how to hold organisations accountable when your personal information has been mishandled.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 delivers the biggest overhaul of Australian privacy law in decades. This guide explains your new rights — including erasure, direct action and protection from automated decisions — plus what businesses must now do to comply.