facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act is the most sweeping piece of internet regulation Britain has passed in a generation. It reshapes how platforms handle content, verify users, and cooperate with regulators — and inevitably, it reshapes your privacy too. Whether you run a small blog, moderate a Discord server, or simply browse social media, the Act touches your online life in ways that are worth understanding properly.

This guide breaks down what the Act actually does, where the genuine privacy risks lie, what protections remain, and the practical steps UK users can take to keep their personal data safer in a post-OSA internet.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that places legal duties on online services — including social networks, search engines, messaging apps, forums, and adult content sites — to protect users, especially children, from illegal and harmful content. Ofcom is the appointed regulator, with powers to fine companies up to £18 million or 10% of global turnover, whichever is higher.

The Act came into force in stages through 2024 and 2025, with the most significant duties — including age assurance for adult sites and illegal content codes — now fully active in 2026. It applies to any service with a "significant number of UK users" or that targets the UK market, meaning it reaches well beyond British-owned platforms.

Who the Act Applies To

  • User-to-user services: Social media, forums, dating apps, gaming platforms with chat.
  • Search services: General and vertical search engines.
  • Pornography providers: Any commercial adult content site accessible from the UK.
  • Category 1, 2A, and 2B services: The largest platforms face the strictest duties, including transparency reporting and user empowerment tools.

Why the Act Raises Privacy Concerns

The Online Safety Act was written primarily as a child protection and content moderation law, not a privacy law. Its duties frequently pull in the opposite direction from data minimisation, which is why privacy campaigners, cryptographers, and civil liberties groups have raised repeated alarms.

Three areas cause the most concern: mandatory age assurance, potential scanning of private messages, and the sheer volume of new data platforms must collect and retain to demonstrate compliance.

1. Age Assurance and Identity Data

Any site hosting adult content, and many mainstream platforms with adult sections, must now use "highly effective" age assurance. In practice this means one of several methods:

  1. Photo ID upload (passport, driving licence).
  2. Facial age estimation using a live selfie.
  3. Credit card checks.
  4. Mobile network operator age checks.
  5. Digital identity wallets from third-party providers.

Each method creates a new data trail. Even when platforms use "double-blind" third-party verifiers that promise not to store data, users are still handing biometric or identity information to companies whose security posture varies widely. A breach at a single age-verification vendor could expose millions of UK adults' viewing habits alongside government-issued ID.

2. Pressure on End-to-End Encryption

Section 121 of the Act allows Ofcom to require services to use "accredited technology" to identify child sexual abuse material, including in private messages. In theory this could compel messaging providers to scan content on-device before it is encrypted — a technique known as client-side scanning.

The government has said the power will only be used when "technically feasible," and no such notice has been issued at the time of writing. But the legal power exists, and its very presence has caused Signal, WhatsApp, and other privacy-focused services to warn they may withdraw from the UK market if compelled to weaken encryption.

3. More Data, Retained for Longer

To prove compliance, platforms must keep detailed records: risk assessments, moderation logs, complaint outcomes, age-check results, and evidence of user reports. That is a lot of information about you, sitting on more servers, for longer than before. Data minimisation — a core UK GDPR principle — is quietly being eroded by safety duties that reward extensive record-keeping.

What Privacy Protections Still Apply

The Online Safety Act does not override UK GDPR or the Data Protection Act 2018. Platforms handling your personal data still owe you the full suite of data protection rights, and the Information Commissioner's Office (ICO) has issued joint guidance with Ofcom to try to keep the two regimes aligned.

Your Core Rights Remain Intact

  • Right of access: You can still request a copy of the personal data a platform holds on you.
  • Right to erasure: You can ask for data to be deleted, subject to legal retention duties.
  • Right to object: You can object to profiling and certain automated decisions.
  • Lawful basis requirement: Platforms must still identify a valid lawful basis for processing, even when acting under the OSA.
  • Data protection by design: Age assurance systems must be built with privacy in mind, using data minimisation and, where possible, zero-knowledge approaches.

Online Safety Act vs UK GDPR: A Quick Comparison

AspectOnline Safety ActUK GDPR
Primary goalProtect users from harmful contentProtect personal data and privacy
RegulatorOfcomICO
Maximum fine£18m or 10% global turnover£17.5m or 4% global turnover
Data collection stanceEncourages record-keeping and verificationRequires data minimisation
Applies toUser-to-user, search, adult content servicesAny organisation processing UK personal data
Individual rightsComplaint routes, appealsAccess, erasure, portability, objection

Practical Steps to Protect Your Privacy Under the Act

You cannot opt out of the Online Safety Act, but you can reduce how much of your personal information ends up in verification systems and moderation databases. The following steps are all legal, straightforward, and appropriate for everyday UK users.

1. Prefer Privacy-Preserving Age Assurance Methods

When a site offers a choice, favour methods that share the least data. Facial age estimation that runs on-device and returns only a yes/no answer is typically better than uploading a passport scan. Digital identity wallets that use zero-knowledge proofs to confirm "over 18" without revealing your name or date of birth are the gold standard where available.

2. Use Encrypted DNS and Private Browsers

Turn on encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) in your browser and operating system. This prevents your internet provider and anyone on your local network from easily logging every domain you visit. Browsers such as Firefox, Brave, and Safari all offer strong tracking protection by default.

3. Compartmentalise Your Accounts

Use different email addresses for different services. A dedicated address for adult platforms, another for social media, another for banking. If one age-verification vendor is breached, the fallout stays contained.

4. Shorten and Cloak Links You Share

Every long URL you paste into a public forum leaks information — UTM parameters, session identifiers, sometimes even usernames. Using a privacy-respecting URL shortener like Lunyb replaces messy tracking-laden URLs with clean short links, giving you control over analytics and reducing what others can infer from your posts. For a full comparison of options see our Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide.

5. Audit Which Platforms Hold Your ID

Every three months, list the services where you have completed age verification or identity checks. If you no longer use a site, submit a data subject access request or deletion request. UK GDPR gives you 30 days for a response.

6. Turn Off Unnecessary Data Sharing

Dig into your account settings on major platforms. Disable ad personalisation, off-platform activity sharing, and any "help us improve" telemetry you do not need. These settings existed before the Act but matter more now that platforms have new reasons to profile users.

What the Act Means for Small Publishers and Businesses

If you run a website with user comments, a Discord server, a Mastodon instance, or a small forum, you may fall within the Act's scope. Ofcom has taken a proportionate approach for smaller services, but you still need to conduct and document a risk assessment.

Minimum Steps for Small UK Sites

  1. Complete an illegal content risk assessment using Ofcom's published template.
  2. Publish clear terms of service explaining what content is prohibited.
  3. Provide an easy reporting mechanism for users.
  4. Keep records of reports and moderation decisions.
  5. Review your risk assessment annually or when your service changes significantly.

For businesses that share branded links with customers, using a professional short-link service also helps demonstrate control over outbound content. Our Rebrandly Review 2026 and honest review of Lunyb both cover features relevant to UK compliance-conscious teams.

The Bigger Picture: Balancing Safety and Privacy

The Online Safety Act reflects a genuine and understandable public concern about harm on the internet — particularly to children. Nobody sensible argues that platforms should be free to ignore grooming, terrorist content, or non-consensual imagery. The debate is about how far the state can push private companies to surveil their users in the name of safety, and where the trade-offs become disproportionate.

In practice, 2026 is turning into a stress test. Age assurance vendors are proliferating, some more trustworthy than others. Ofcom is issuing codes of practice at a steady pace. Legal challenges are already underway. And users — you — are making daily decisions about which sites to verify against, which apps to keep, and how much identity data to hand over just to read a webpage.

The healthiest response is neither panic nor complacency. Understand what the law actually requires, favour services that treat your data with respect, and use the privacy tools that are still very much available to UK residents. The Act changes the landscape; it does not abolish your right to a private digital life.

Frequently Asked Questions

Does the UK Online Safety Act apply to foreign websites?

Yes. The Act applies to any service with a significant number of UK users or that targets the UK market, regardless of where the company is based. Ofcom can pursue enforcement against overseas providers, and in extreme cases can seek business disruption measures such as payment provider or ISP blocking.

Will my passport data be stored when I verify my age?

It depends on the provider. Reputable age-assurance vendors use "data minimisation by design" — they check your ID, return a yes/no result to the site, and delete the underlying document within minutes. Less scrupulous providers may retain data longer. Always read the privacy notice before uploading identity documents, and prefer providers certified against schemes such as the Age Check Certification Scheme.

Can Ofcom read my private messages?

Not directly, and not routinely. Ofcom does not have a general power to read individual messages. It does have a power under Section 121 to require services to use accredited technology to detect child sexual abuse material, which could in theory apply to encrypted messaging. No such notice has been issued so far, and the government has committed to using the power only when technically feasible without breaking encryption for everyone.

What happens if a platform I use ignores the Act?

Ofcom can issue fines of up to £18 million or 10% of global turnover, require remedial action, and in serious cases seek court orders forcing UK-based intermediaries — payment processors, advertising networks, or ISPs — to withdraw services from the non-compliant platform. Senior managers can also face criminal liability for certain failures relating to child safety.

Do I have to give up on encrypted messaging in the UK?

No. End-to-end encrypted services such as Signal, WhatsApp, and iMessage continue to operate normally in the UK in 2026. The government has not compelled any of them to weaken encryption. Keep an eye on official announcements from your messaging provider, and consider using multiple communication tools so you are not dependent on a single service.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles