UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is the most sweeping piece of internet regulation Britain has passed in a generation. It reshapes how platforms handle content, verify users, and cooperate with regulators — and inevitably, it reshapes your privacy too. Whether you run a small blog, moderate a Discord server, or simply browse social media, the Act touches your online life in ways that are worth understanding properly.
This guide breaks down what the Act actually does, where the genuine privacy risks lie, what protections remain, and the practical steps UK users can take to keep their personal data safer in a post-OSA internet.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that places legal duties on online services — including social networks, search engines, messaging apps, forums, and adult content sites — to protect users, especially children, from illegal and harmful content. Ofcom is the appointed regulator, with powers to fine companies up to £18 million or 10% of global turnover, whichever is higher.
The Act came into force in stages through 2024 and 2025, with the most significant duties — including age assurance for adult sites and illegal content codes — now fully active in 2026. It applies to any service with a "significant number of UK users" or that targets the UK market, meaning it reaches well beyond British-owned platforms.
Who the Act Applies To
- User-to-user services: Social media, forums, dating apps, gaming platforms with chat.
- Search services: General and vertical search engines.
- Pornography providers: Any commercial adult content site accessible from the UK.
- Category 1, 2A, and 2B services: The largest platforms face the strictest duties, including transparency reporting and user empowerment tools.
Why the Act Raises Privacy Concerns
The Online Safety Act was written primarily as a child protection and content moderation law, not a privacy law. Its duties frequently pull in the opposite direction from data minimisation, which is why privacy campaigners, cryptographers, and civil liberties groups have raised repeated alarms.
Three areas cause the most concern: mandatory age assurance, potential scanning of private messages, and the sheer volume of new data platforms must collect and retain to demonstrate compliance.
1. Age Assurance and Identity Data
Any site hosting adult content, and many mainstream platforms with adult sections, must now use "highly effective" age assurance. In practice this means one of several methods:
- Photo ID upload (passport, driving licence).
- Facial age estimation using a live selfie.
- Credit card checks.
- Mobile network operator age checks.
- Digital identity wallets from third-party providers.
Each method creates a new data trail. Even when platforms use "double-blind" third-party verifiers that promise not to store data, users are still handing biometric or identity information to companies whose security posture varies widely. A breach at a single age-verification vendor could expose millions of UK adults' viewing habits alongside government-issued ID.
2. Pressure on End-to-End Encryption
Section 121 of the Act allows Ofcom to require services to use "accredited technology" to identify child sexual abuse material, including in private messages. In theory this could compel messaging providers to scan content on-device before it is encrypted — a technique known as client-side scanning.
The government has said the power will only be used when "technically feasible," and no such notice has been issued at the time of writing. But the legal power exists, and its very presence has caused Signal, WhatsApp, and other privacy-focused services to warn they may withdraw from the UK market if compelled to weaken encryption.
3. More Data, Retained for Longer
To prove compliance, platforms must keep detailed records: risk assessments, moderation logs, complaint outcomes, age-check results, and evidence of user reports. That is a lot of information about you, sitting on more servers, for longer than before. Data minimisation — a core UK GDPR principle — is quietly being eroded by safety duties that reward extensive record-keeping.
What Privacy Protections Still Apply
The Online Safety Act does not override UK GDPR or the Data Protection Act 2018. Platforms handling your personal data still owe you the full suite of data protection rights, and the Information Commissioner's Office (ICO) has issued joint guidance with Ofcom to try to keep the two regimes aligned.
Your Core Rights Remain Intact
- Right of access: You can still request a copy of the personal data a platform holds on you.
- Right to erasure: You can ask for data to be deleted, subject to legal retention duties.
- Right to object: You can object to profiling and certain automated decisions.
- Lawful basis requirement: Platforms must still identify a valid lawful basis for processing, even when acting under the OSA.
- Data protection by design: Age assurance systems must be built with privacy in mind, using data minimisation and, where possible, zero-knowledge approaches.
Online Safety Act vs UK GDPR: A Quick Comparison
| Aspect | Online Safety Act | UK GDPR |
|---|---|---|
| Primary goal | Protect users from harmful content | Protect personal data and privacy |
| Regulator | Ofcom | ICO |
| Maximum fine | £18m or 10% global turnover | £17.5m or 4% global turnover |
| Data collection stance | Encourages record-keeping and verification | Requires data minimisation |
| Applies to | User-to-user, search, adult content services | Any organisation processing UK personal data |
| Individual rights | Complaint routes, appeals | Access, erasure, portability, objection |
Practical Steps to Protect Your Privacy Under the Act
You cannot opt out of the Online Safety Act, but you can reduce how much of your personal information ends up in verification systems and moderation databases. The following steps are all legal, straightforward, and appropriate for everyday UK users.
1. Prefer Privacy-Preserving Age Assurance Methods
When a site offers a choice, favour methods that share the least data. Facial age estimation that runs on-device and returns only a yes/no answer is typically better than uploading a passport scan. Digital identity wallets that use zero-knowledge proofs to confirm "over 18" without revealing your name or date of birth are the gold standard where available.
2. Use Encrypted DNS and Private Browsers
Turn on encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) in your browser and operating system. This prevents your internet provider and anyone on your local network from easily logging every domain you visit. Browsers such as Firefox, Brave, and Safari all offer strong tracking protection by default.
3. Compartmentalise Your Accounts
Use different email addresses for different services. A dedicated address for adult platforms, another for social media, another for banking. If one age-verification vendor is breached, the fallout stays contained.
4. Shorten and Cloak Links You Share
Every long URL you paste into a public forum leaks information — UTM parameters, session identifiers, sometimes even usernames. Using a privacy-respecting URL shortener like Lunyb replaces messy tracking-laden URLs with clean short links, giving you control over analytics and reducing what others can infer from your posts. For a full comparison of options see our Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide.
5. Audit Which Platforms Hold Your ID
Every three months, list the services where you have completed age verification or identity checks. If you no longer use a site, submit a data subject access request or deletion request. UK GDPR gives you 30 days for a response.
6. Turn Off Unnecessary Data Sharing
Dig into your account settings on major platforms. Disable ad personalisation, off-platform activity sharing, and any "help us improve" telemetry you do not need. These settings existed before the Act but matter more now that platforms have new reasons to profile users.
What the Act Means for Small Publishers and Businesses
If you run a website with user comments, a Discord server, a Mastodon instance, or a small forum, you may fall within the Act's scope. Ofcom has taken a proportionate approach for smaller services, but you still need to conduct and document a risk assessment.
Minimum Steps for Small UK Sites
- Complete an illegal content risk assessment using Ofcom's published template.
- Publish clear terms of service explaining what content is prohibited.
- Provide an easy reporting mechanism for users.
- Keep records of reports and moderation decisions.
- Review your risk assessment annually or when your service changes significantly.
For businesses that share branded links with customers, using a professional short-link service also helps demonstrate control over outbound content. Our Rebrandly Review 2026 and honest review of Lunyb both cover features relevant to UK compliance-conscious teams.
The Bigger Picture: Balancing Safety and Privacy
The Online Safety Act reflects a genuine and understandable public concern about harm on the internet — particularly to children. Nobody sensible argues that platforms should be free to ignore grooming, terrorist content, or non-consensual imagery. The debate is about how far the state can push private companies to surveil their users in the name of safety, and where the trade-offs become disproportionate.
In practice, 2026 is turning into a stress test. Age assurance vendors are proliferating, some more trustworthy than others. Ofcom is issuing codes of practice at a steady pace. Legal challenges are already underway. And users — you — are making daily decisions about which sites to verify against, which apps to keep, and how much identity data to hand over just to read a webpage.
The healthiest response is neither panic nor complacency. Understand what the law actually requires, favour services that treat your data with respect, and use the privacy tools that are still very much available to UK residents. The Act changes the landscape; it does not abolish your right to a private digital life.
Frequently Asked Questions
Does the UK Online Safety Act apply to foreign websites?
Yes. The Act applies to any service with a significant number of UK users or that targets the UK market, regardless of where the company is based. Ofcom can pursue enforcement against overseas providers, and in extreme cases can seek business disruption measures such as payment provider or ISP blocking.
Will my passport data be stored when I verify my age?
It depends on the provider. Reputable age-assurance vendors use "data minimisation by design" — they check your ID, return a yes/no result to the site, and delete the underlying document within minutes. Less scrupulous providers may retain data longer. Always read the privacy notice before uploading identity documents, and prefer providers certified against schemes such as the Age Check Certification Scheme.
Can Ofcom read my private messages?
Not directly, and not routinely. Ofcom does not have a general power to read individual messages. It does have a power under Section 121 to require services to use accredited technology to detect child sexual abuse material, which could in theory apply to encrypted messaging. No such notice has been issued so far, and the government has committed to using the power only when technically feasible without breaking encryption for everyone.
What happens if a platform I use ignores the Act?
Ofcom can issue fines of up to £18 million or 10% of global turnover, require remedial action, and in serious cases seek court orders forcing UK-based intermediaries — payment processors, advertising networks, or ISPs — to withdraw services from the non-compliant platform. Senior managers can also face criminal liability for certain failures relating to child safety.
Do I have to give up on encrypted messaging in the UK?
No. End-to-end encrypted services such as Signal, WhatsApp, and iMessage continue to operate normally in the UK in 2026. The government has not compelled any of them to weaken encryption. Keep an eye on official announcements from your messaging provider, and consider using multiple communication tools so you are not dependent on a single service.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.