UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most sweeping pieces of internet legislation the country has ever passed. It reshapes how platforms handle harmful content, how they verify users' ages, and how they respond to regulators. But behind the headlines about child safety and illegal content lies a quieter, more personal question: what does this law actually mean for your privacy?
This guide breaks down the Act in plain English, explains where privacy tensions arise, and offers practical steps British users can take to stay in control of their personal data.
What Is the UK Online Safety Act?
The UK Online Safety Act is a 2023 law that places a legal duty of care on online platforms — from social networks and search engines to messaging apps and adult sites — to protect users, especially children, from illegal and harmful content. It is enforced by Ofcom, which can fine non-compliant companies up to £18 million or 10% of global annual turnover, whichever is higher.
The Act came into full force in phases through 2024 and 2025, with age verification and illegal content duties among the most visible for everyday users. It applies to any service accessible from the UK, meaning even foreign platforms must comply if they have British users.
Who Does the Act Cover?
- User-to-user services: social media, forums, dating apps, gaming platforms.
- Search services: Google, Bing, and specialised search engines.
- Pornography providers: both user-generated and commercial adult sites.
- Messaging services: including those offering end-to-end encryption.
The Core Privacy Concerns
While the Act's stated goals are protective, several of its mechanisms directly touch on personal data, identity, and private communications. Understanding these is the first step to protecting yourself.
1. Mandatory Age Verification
Adult content sites and platforms hosting content deemed harmful to children must now use "highly effective" age assurance. Ofcom's guidance lists acceptable methods including credit card checks, photo ID uploads, facial age estimation, and mobile network operator checks.
The privacy issue is straightforward: to prove you are an adult, you may need to hand over government ID, biometric data, or financial information to third-party verification providers. Even when platforms use intermediaries that promise not to store data, you are creating new attack surfaces for identity theft and data breaches.
2. Pressure on Encrypted Messaging
Section 121 of the Act allows Ofcom to require platforms to use "accredited technology" to scan for child sexual abuse material and terrorism content — including in private messages. Critics, including Signal and WhatsApp, argue this could force client-side scanning, which would break the guarantees of end-to-end encryption.
The government has said the power will only be used when "technically feasible," but the legal mechanism remains on the books. For anyone who relies on encrypted messaging for journalism, activism, medical conversations, or simple personal privacy, this is a live concern.
3. Expanded Content Monitoring
Platforms must proactively identify and remove illegal content and, for larger services, content that is "legal but harmful" to children. In practice, this pushes companies toward more aggressive automated scanning of what users post, share, and even privately message — which means more of your online behaviour is analysed by algorithms.
4. Data Retention for Enforcement
To demonstrate compliance, platforms need audit trails. That often translates into keeping more logs, more metadata, and more records of user behaviour than they otherwise would — data that can later be requested by regulators or law enforcement.
How the Act Compares to Other Frameworks
The UK's approach sits between the EU's Digital Services Act and more restrictive regimes elsewhere. Here is a quick comparison:
| Feature | UK Online Safety Act | EU Digital Services Act | US Section 230 |
|---|---|---|---|
| Age verification mandate | Yes, strict | Limited | No federal mandate |
| Encrypted messaging scanning powers | Yes (Section 121) | Under debate (CSAM regulation) | No |
| Regulator | Ofcom | European Commission + national regulators | None dedicated |
| Maximum fine | 10% global turnover or £18m | 6% global turnover | N/A |
| Applies to foreign platforms | Yes, if UK-accessible | Yes, if EU-accessible | US-focused |
What Changes for You as a UK Internet User
The Act's impact varies depending on how you use the internet. Here are the most noticeable shifts for everyday users.
Age Checks on More Sites
You will encounter age verification not only on adult sites but potentially on social platforms, gaming services, and any site where children might access age-restricted content. Expect prompts to upload ID, submit a selfie for age estimation, or link a payment card.
More Content Removals and Appeals
Platforms are erring on the side of removal to avoid fines. This means more of your posts, comments, or uploads may be flagged, hidden, or deleted — sometimes incorrectly. The Act does require appeals processes, so you can contest wrongful takedowns.
Some Services May Exit the UK
Smaller platforms and privacy-focused services have already withdrawn from the UK market rather than comply with expensive obligations. Wikipedia, Signal, and various niche forums have all publicly raised concerns. You may see fewer alternative services available.
Changes to How Links and Shared Content Are Handled
Platforms are scrutinising outbound links and shared media more aggressively. If you share URLs — for marketing, journalism, or personal reasons — you may find some shorteners or link services face additional friction. Using a reputable, transparent service like Lunyb, which is compliant and privacy-respecting, can reduce the risk of your links being blocked or flagged.
Practical Steps to Protect Your Privacy
You cannot opt out of the Act, but you can make deliberate choices that reduce how much personal data you expose.
1. Be Selective About Age Verification Providers
When a site asks you to verify your age, check who is performing the check. Look for providers certified under the Age Check Certification Scheme (ACCS) and prefer methods that use zero-knowledge tokens or facial age estimation without ID retention. Avoid uploading a full passport scan when a mobile-network check would suffice.
2. Use Privacy-Respecting Browsers and DNS
Browsers like Firefox, Brave, and Safari offer stronger default privacy protections than Chrome. Pair them with encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) through providers such as Cloudflare 1.1.1.1 or Quad9. This prevents your internet provider from logging every domain you visit — an increasingly relevant protection as monitoring obligations expand.
3. Compartmentalise Your Accounts
Use separate email addresses for different purposes: one for banking and government, one for social media, one for shopping. Services like Apple's Hide My Email or Fastmail's masked addresses make this easy. If one platform is forced to disclose data, the damage is contained.
4. Review Your Messaging Choices
End-to-end encrypted messengers remain the strongest protection for private conversations. Signal, in particular, minimises metadata. Keep your operating system updated, since client-side vulnerabilities are the most likely way encrypted messages could be exposed.
5. Shorten and Share Links Carefully
If you run a business, newsletter, or public profile, use a link management tool that gives you control over analytics and does not sell your click data. Our 2026 buyer's guide to URL shorteners compares the main options for UK users balancing compliance with privacy.
6. Exercise Your Data Rights
The UK GDPR still applies alongside the Online Safety Act. You have the right to access, correct, and delete data platforms hold about you. Use subject access requests annually to see what is being retained — you may be surprised by how much verification and moderation data is kept.
Implications for Businesses and Publishers
If you run any kind of UK-facing platform, community, or content business, the Act creates new operational requirements.
Risk Assessments Are Mandatory
User-to-user services must complete illegal content risk assessments and, where relevant, children's risk assessments. Even small forums and community sites need documented policies.
Transparency Reporting
Larger platforms must publish transparency reports covering takedowns, complaints, and enforcement actions. This is public data — you can use competitors' reports to benchmark your own moderation.
Marketing and Link Sharing
Marketers should audit their outbound link infrastructure. Platforms flagging suspicious shorteners can hurt campaign performance overnight. Reliable, transparent providers matter more than ever — see our Rebrandly review for 2026 for a look at one enterprise option and how it stacks up on compliance features.
The Bigger Picture: Safety Versus Privacy
The Online Safety Act reflects a genuine policy dilemma. Governments face real pressure to reduce online harms, particularly to children. But every mechanism used to detect harm — whether it is scanning messages, verifying ages, or logging behaviour — creates new privacy costs. There is no version of the Act that eliminates both harm and surveillance simultaneously.
What British users can do is stay informed, choose services thoughtfully, and use the rights they already have under UK GDPR to push back against unnecessary data collection. Regulators, platforms, and users are still calibrating how the law works in practice, and public feedback shapes Ofcom's codes of practice.
Frequently Asked Questions
Does the Online Safety Act require me to give my ID to use the internet?
Not to use the internet generally, but yes for specific services — particularly adult sites and platforms hosting content deemed harmful to children. You can often choose between methods such as facial age estimation, mobile network checks, or ID upload. Choose the least data-intensive option that the site accepts.
Will the Act break end-to-end encryption in the UK?
Not directly. Section 121 gives Ofcom the power to require scanning technology, but the government has stated it will only be exercised when "technically feasible" — which most experts agree is not currently the case without weakening encryption. The legal risk remains, and services like Signal have said they would leave the UK rather than comply.
Can I be fined or prosecuted under the Online Safety Act as an individual user?
The Act primarily targets platforms, not ordinary users. However, it created new individual offences including "false communications" and "threatening communications," so sending seriously harmful or knowingly false messages could lead to prosecution under those specific provisions.
Does the Act apply if I use a foreign platform?
Yes. Any service accessible from the UK with a significant UK user base must comply, regardless of where it is based. This is why some smaller international platforms have blocked UK access rather than take on the compliance burden.
How can I check what data a platform holds about me under the Act?
Submit a subject access request under UK GDPR. Platforms must respond within one month and provide the personal data they hold, including age verification records, moderation decisions, and behavioural logs kept for compliance. If they refuse or delay, you can complain to the Information Commissioner's Office (ICO).
Final Thoughts
The UK Online Safety Act is here to stay, and its full effects will unfold over the next several years as Ofcom issues more detailed codes and platforms adjust their systems. Your best defence is informed, deliberate choices: knowing what data you are being asked to share, why, and whether a less invasive alternative exists. Privacy in 2026 Britain is not automatic — but it is still very much achievable with the right habits and tools.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How Canadian Businesses Should Handle Data Privacy in 2026
A complete 2026 guide to how Canadian businesses should handle data privacy — covering PIPEDA, Quebec Law 25, Bill C-27, breach response, cross-border transfers, and building customer trust.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step guide to lodging a privacy complaint with the OAIC in Australia — from your first contact with the organisation, through conciliation, to formal determinations and compensation. Includes timelines, evidence tips, and common pitfalls.
Data Protection Act 2018 Ireland: Complete Guide for Businesses
A complete guide to Ireland's Data Protection Act 2018, covering scope, individual rights, DPC enforcement powers, penalties, and practical compliance steps for Irish businesses. Learn how the Act works with GDPR and what your organisation needs to do.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces powerful new rights for Australians, including erasure, de-indexing, and the ability to sue for serious privacy breaches. This plain-English guide explains what's changed, what businesses must do, and how to exercise your rights.