facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act (OSA) is one of the most sweeping pieces of internet legislation ever passed in Britain. It reshapes how platforms moderate content, verify users' ages, and cooperate with regulators — and it has real consequences for your privacy. If you use social media, messaging apps, dating sites, or even niche forums from a UK address, this law affects you.

This guide breaks down what the Online Safety Act actually does, where it clashes with personal privacy, and what practical steps you can take to keep control of your data.

What is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that places a legal duty of care on online platforms to protect users — particularly children — from illegal and harmful content. It is enforced by Ofcom, the UK's communications regulator, which can fine non-compliant companies up to £18 million or 10% of global annual turnover, whichever is higher.

The Act came into force in stages, with the most significant duties — including age assurance for pornography and protections around illegal content — becoming enforceable from 2024 and 2025. It applies to any service with a "significant number of UK users" or that targets the UK market, regardless of where the company is based.

Which services are covered?

  • User-to-user services: Social networks, forums, messaging apps, dating apps.
  • Search services: Google, Bing, DuckDuckGo and other search engines.
  • Pornography publishers: Any commercial site publishing adult content accessible from the UK.
  • File-sharing and cloud services where users can share content with others.

The Core Duties Platforms Must Follow

Under the Act, in-scope platforms must carry out risk assessments, publish transparency reports, and take proportionate steps to reduce exposure to harmful material. The duties fall into three main buckets.

1. Illegal content duties

Every platform must prevent users from encountering priority illegal content — including terrorism, child sexual abuse material (CSAM), fraud, and content encouraging suicide. This requires proactive detection, not just reactive takedowns.

2. Child safety duties

Services likely to be accessed by children must protect them from "legal but harmful" content such as pornography, self-harm content, cyberbullying, and eating disorder material. This is where age verification enters the picture.

3. Adult user empowerment

The largest "Category 1" platforms must give adult users tools to filter certain content and to verify other users' identities if they wish.

Where the Online Safety Act Collides With Privacy

The privacy debate around the OSA centres on three flashpoints: mandatory age checks, potential scanning of encrypted messages, and the amount of data platforms now collect to prove compliance.

Age verification and identity data

To access adult content or, in some cases, mainstream social media, UK users may now be asked to verify their age. Approved methods include:

  1. Uploading a photo of a passport, driving licence, or other government ID.
  2. Facial age estimation via a live selfie processed by AI.
  3. Credit card checks (which imply adulthood in the UK).
  4. Mobile network operator age checks.
  5. Digital identity wallets from certified providers.

Each of these creates a new data trail. Even if the platform itself never sees your ID (because a third-party "age assurance provider" handles it), that provider now knows you tried to access a specific service on a specific date. That link between your real identity and your browsing habits didn't exist before.

The encryption question

Section 121 of the Act allows Ofcom to require platforms to use "accredited technology" to detect CSAM — even in end-to-end encrypted services. Providers like Signal and WhatsApp publicly warned they would leave the UK rather than break encryption. The government has since said the powers will only be used when "technically feasible," but the clause remains on the books, creating ongoing uncertainty about the future of private messaging in the UK.

Data retention and transparency

To prove they are meeting their duties, platforms must log more moderation decisions, retain evidence of enforcement actions, and share aggregate data with Ofcom. That means more of your activity is being categorised, scored, and stored — even if you never break a rule.

How the Act Compares to Other Privacy-Impacting Laws

The OSA doesn't exist in isolation. Here's how it stacks up against related legislation that touches British internet users.

LawMain FocusPrivacy ImpactRegulator
UK Online Safety Act 2023Harmful content, child safetyHigh — age checks, potential message scanningOfcom
UK GDPR / Data Protection Act 2018Personal data processingProtective — gives users rights over dataICO
Investigatory Powers Act 2016State surveillance and interceptionHigh — bulk data collection powersIPCO
Age-Appropriate Design CodeChildren's data by defaultProtective for under-18sICO

What This Means for Everyday Users

You don't need to be a lawyer to feel the effects of the Act. Here are the most likely changes to your daily internet experience in the UK.

More friction on adult and gambling sites

Expect ID checks, selfie scans, or credit card verification before you can access adult material, gambling services, or some dating features. Some smaller sites have geoblocked the UK entirely rather than comply.

Stricter moderation on social media

Content that is legal but flagged as harmful to children may be down-ranked or hidden from UK feeds. Some communities — particularly around harm reduction, sex education, or LGBTQ+ topics — have reported over-cautious moderation as platforms err on the safe side.

Reduced anonymity in some spaces

While the Act doesn't ban pseudonymity outright, large platforms must offer identity-verified accounts and let users filter out non-verified users. Over time, this creates pressure to link real identities to online personas.

Smaller sites may close or block the UK

Compliance is expensive. Small forums, independent adult creators, and hobbyist communities have already withdrawn from the UK market because they cannot afford the legal risk. The unintended consequence is a less diverse internet for British users.

Practical Steps to Protect Your Privacy Under the OSA

You can't opt out of the law, but you can be smarter about how much data you hand over. Here are eight concrete steps.

  1. Use age assurance providers that support "double-blind" checks. Providers certified under the ICO's Age Assurance framework can confirm you are over 18 without telling the receiving site who you are. Look for the certified badge.
  2. Prefer facial age estimation over ID uploads. A one-off selfie that is deleted immediately after processing leaves a smaller footprint than a copy of your passport sitting in a database.
  3. Switch to encrypted DNS. Services like Cloudflare's 1.1.1.1, Quad9, or NextDNS encrypt your DNS lookups so your ISP cannot easily log which sites you visit.
  4. Use a privacy-focused browser. Firefox, Brave, and Mullvad Browser strip tracking scripts and reduce fingerprinting.
  5. Compartmentalise accounts. Use different email addresses for social media, shopping, and services requiring ID. Email aliasing tools like SimpleLogin or Apple's Hide My Email make this trivial.
  6. Audit permissions quarterly. Revoke old app access from your Google, Apple, and Microsoft accounts. Every stale token is a potential leak.
  7. Shorten and mask links you share. When posting or messaging URLs, using a privacy-respecting shortener like Lunyb hides referrer data and prevents recipients from seeing tracking parameters. See our honest Lunyb review for how it handles user data.
  8. Read the age-check provider's privacy notice. Under UK GDPR you have the right to know what they collect and for how long. Reputable providers delete verification data within minutes.

What Businesses and Content Creators Should Do

If you run a website, newsletter, or community that UK users can access, you may have obligations under the Act even if you're based abroad.

Assess whether you're in scope

Ofcom's guidance sets out that services with links to the UK — a significant UK user base or UK-targeted marketing — are covered. Even a small forum can qualify.

Complete an illegal content risk assessment

This is a mandatory document that identifies how your service could be misused and what mitigations you have in place. Ofcom can request it at any time.

Publish clear terms and reporting tools

Users must be able to flag content easily, and you must respond within a reasonable time frame. Your terms of service must be understandable, not buried legalese.

Keep audit trails — but minimise data

You need enough evidence to prove compliance, but collecting more personal data than necessary breaches UK GDPR. The sweet spot is aggregated, pseudonymised logs. For businesses sharing links at scale, our 2026 URL shortener buyer's guide covers which services offer compliant analytics without hoarding user data.

The Road Ahead: What to Watch in 2025 and Beyond

The Online Safety Act is still bedding in. Several developments could reshape its privacy footprint in the coming years.

  • Category 1 designations: Ofcom is finalising which platforms count as "Category 1" and face the toughest duties, including verified-user features.
  • Encryption enforcement: Whether Ofcom will actually invoke Section 121 remains the biggest open question. Any move to require client-side scanning would trigger legal challenges and potentially the exit of major messaging apps.
  • Age assurance standards: The ICO and Ofcom are jointly developing stricter certification for age-check providers, which should improve — but not eliminate — privacy risks.
  • Judicial review: Civil liberties groups including the Open Rights Group and Big Brother Watch are pursuing legal challenges to specific provisions.
  • Interaction with the EU Digital Services Act: Cross-border platforms must reconcile two overlapping regimes, which may push them toward the stricter standard globally.

Final Thoughts

The UK Online Safety Act was written with legitimate goals — protecting children, tackling illegal content, holding platforms accountable. But the mechanisms it introduces (mandatory age checks, potential scanning of encrypted messages, and expanded data logging) shift the balance of privacy in ways that will affect every British internet user for years to come.

You can't opt out, but you can be deliberate. Choose privacy-respecting tools, minimise the personal data you hand to age-check providers, use encrypted DNS and privacy browsers, and hold the platforms you rely on to a higher standard by exercising your UK GDPR rights. Awareness is the first line of defence.

Frequently Asked Questions

Does the Online Safety Act mean I have to upload my passport to use social media?

Not for most mainstream social media — yet. Age verification is mandatory for pornography sites and services likely to be accessed by children where adult content appears. Large social platforms must offer identity verification as an option, not a requirement, though this could change as Ofcom refines its codes of practice.

Will WhatsApp and Signal be banned in the UK?

They have not been banned, and the government has clarified that Section 121 powers to scan encrypted messages will only be used when "technically feasible" — a standard experts say cannot currently be met without breaking encryption. Both services remain available, but the legal risk persists.

Is my browsing history now shared with Ofcom?

No. Ofcom does not receive individual browsing data. It receives aggregate reports from platforms about their moderation and enforcement activity. However, the age-check providers and platforms you interact with directly may retain more data about you than before.

What are my rights if an age-verification provider mishandles my data?

Under UK GDPR you can request access to your data, ask for it to be deleted, and complain to the Information Commissioner's Office (ICO) if the provider breaches the law. Certified age assurance providers must publish clear retention periods, typically ranging from immediate deletion to a maximum of 30 days.

Does the Act apply to overseas websites?

Yes, if they have a significant UK user base or target UK users. This is why some small international sites have geoblocked the UK entirely — the cost of compliance outweighs the value of British traffic. Larger global platforms have generally chosen to comply.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles