UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act (OSA) is one of the most sweeping pieces of internet regulation ever passed in Britain. Marketed as a law to protect children and reduce illegal content online, it also introduces sweeping new duties on platforms — from social networks and search engines to messaging apps and small community forums. For everyday users, the practical question is simple: what does the UK Online Safety Act mean for your privacy?
This guide breaks down the Act in plain English, explains where it strengthens user protection, where it creates genuine privacy risks, and what you can do to keep your data under control in 2026.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that places legal duties on online services accessible from the UK to reduce illegal content, protect children from harmful material, and give users more control over what they see. It is enforced by Ofcom, the UK's communications regulator, which can issue fines of up to £18 million or 10% of global annual turnover — whichever is greater.
The Act came into force in stages from 2024 through 2026, with the most visible measures — mandatory age assurance and content moderation duties — rolling out to platforms across 2025 and 2026.
Who Does the Act Apply To?
The Act covers a much broader range of services than many users realise:
- Category 1 services: Large social media and user-to-user platforms (Facebook, Instagram, TikTok, X, YouTube).
- Category 2A services: Major search engines (Google, Bing).
- Category 2B services: Smaller user-to-user platforms with significant risk factors.
- Pornography providers: Any adult content site accessible in the UK.
- Messaging services: Including end-to-end encrypted apps like WhatsApp, Signal and iMessage.
- Small forums and community sites: Even hobbyist forums may fall in scope if they host user-generated content.
The Core Privacy Concerns
While the Act's goals are widely supported, several provisions raise legitimate privacy concerns for adults, journalists, activists and ordinary users. Here are the main areas to understand.
1. Age Assurance and Identity Verification
Perhaps the most visible change for UK users is mandatory age assurance. Platforms hosting adult content, and any service likely to be accessed by children, must now confirm users are over 18 (or over 13 in some contexts) using "highly effective" methods.
Accepted methods include:
- Photo ID upload (passport, driving licence).
- Facial age estimation using a live selfie.
- Credit card verification.
- Mobile network operator age checks.
- Digital identity wallets.
- Bank-based age verification.
The privacy concern is straightforward: browsing habits — including sensitive categories like adult content, dating, gambling or mental health forums — can now be linked, however indirectly, to verified identity. Even when third-party verifiers promise a "double-blind" system, the data trail exists, and any breach could be devastating.
2. The Encryption Question
Section 122 of the Act allows Ofcom to require messaging services to use "accredited technology" to scan for child sexual abuse material (CSAM) and terrorism content. In practice, this could mean client-side scanning: software installed on your device that checks messages before they are encrypted and sent.
Critics — including Signal, WhatsApp, Apple and dozens of security researchers — argue this fundamentally breaks end-to-end encryption. Once a scanning mechanism exists on your device, the technical infrastructure for wider surveillance is already in place, even if it is only "turned on" for narrow purposes today.
The UK government has stated the powers will only be used when "technically feasible", but the legal power remains on the books, and platforms must comply if invoked.
3. Data Retention and Traceability
Platforms must now keep detailed records to demonstrate compliance with Ofcom, including:
- Content moderation decisions.
- Reports of harmful content and how they were handled.
- Age verification outcomes.
- Risk assessments that may reference user behaviour patterns.
This increases the amount of personal data platforms hold about you — and creates larger, more attractive targets for hackers.
What the Act Does Well
The Online Safety Act is not purely a privacy negative. Several provisions genuinely benefit users.
Stronger Rights Against Harmful Content
Platforms must now offer clear reporting tools, respond to complaints, and act quickly on illegal content — including intimate image abuse ("revenge porn"), cyberstalking, and threats. Victims have far stronger legal footing than under previous regimes.
Transparency Requirements
Large platforms must publish regular transparency reports covering moderation, algorithmic amplification and complaint handling. This gives researchers and journalists more insight into how platforms treat UK users.
Adult User Empowerment Tools
Category 1 services must give adult users tools to filter out legal-but-harmful content (such as content glorifying eating disorders or self-harm) and to reduce exposure to unverified accounts. These are opt-in features, so users remain in control.
Online Safety Act vs GDPR: How Do They Interact?
Many people ask whether the Online Safety Act overrides the UK GDPR. It does not — but the two laws sit in tension in several places.
| Issue | UK GDPR | Online Safety Act |
|---|---|---|
| Data minimisation | Collect only what is necessary | May require additional data for age checks and moderation |
| Purpose limitation | Use data only for stated purposes | Requires retention for regulatory oversight |
| End-to-end encryption | Encouraged as a security measure | May be weakened via scanning powers |
| Children's data | Extra protections under Age Appropriate Design | Requires age assurance that may collect more child data |
| Enforcement body | ICO | Ofcom |
In practice, the ICO and Ofcom have published joint guidance stating that age assurance should be designed to be privacy-preserving, using techniques like tokenisation and zero-knowledge proofs where possible. Whether every provider implements those best practices is another matter.
Practical Steps to Protect Your Privacy Under the OSA
You cannot opt out of the Act, but you can significantly reduce how much of your identity is tied to your online activity.
1. Choose Privacy-Preserving Age Verification
Where you have a choice, prefer age verification providers that use:
- Zero-knowledge tokens (a signed "over 18" flag with no identity attached).
- On-device facial age estimation that does not store the image.
- Reusable digital identity wallets you control.
Avoid uploading passport scans to unknown third parties whenever possible.
2. Segment Your Online Identities
Use separate email addresses (or email aliases) for different categories of service. This prevents a single breach from linking your gaming account, health forum activity and shopping history.
3. Use a Privacy-Focused Browser
Browsers like Firefox, Brave and DuckDuckGo block trackers by default. Combined with encrypted DNS (DNS-over-HTTPS), they significantly limit how much your ISP or network operator can observe about your browsing.
4. Be Careful With Link Shorteners
Under the Act, some link shorteners have become targets for regulatory scrutiny because they can be used to disguise harmful destinations. Choose a shortener that logs minimally, does not sell click data, and offers HTTPS and abuse controls. Services like Lunyb focus on lightweight, privacy-respecting URL shortening — you can read our honest Lunyb review or compare options in our 2026 buyer's guide to URL shorteners to see how different providers handle data.
5. Review Platform Privacy Settings
Category 1 platforms must now surface adult user empowerment tools clearly. Take ten minutes to review:
- Who can message or tag you.
- Whether unverified accounts can interact with you.
- Content filters and sensitivity controls.
- Ad personalisation and data sharing options.
6. Support Encrypted Messaging
Continue using end-to-end encrypted messengers like Signal. If scanning provisions are invoked in future, providers that refuse to comply may withdraw from the UK — supporting privacy-first alternatives keeps market pressure alive.
What the Act Means for Small Websites and Creators
If you run a UK-facing website with any user-generated content — comments, forums, reviews, community posts — you may have OSA duties even as a small operator. Key obligations include:
- Carrying out an illegal content risk assessment.
- Having clear terms of service explaining moderation.
- Providing accessible complaints and takedown mechanisms.
- For services likely to be accessed by children: a separate children's risk assessment.
Ofcom has published proportionate guidance for smaller services, but ignoring the Act is not an option. Creators using branded links for marketing should also make sure their link management provider offers abuse reporting and clear terms — something covered in more detail in our Rebrandly review.
The Bigger Picture: Where UK Regulation Is Heading
The Online Safety Act is not the end of the story. Related developments to watch in 2026 and beyond include:
- Data (Use and Access) Act 2025: reshaping UK GDPR and digital identity frameworks.
- Ofcom codes of practice: new guidance is published continuously and shapes real-world compliance.
- AI regulation: generative AI content is increasingly caught by OSA duties around deepfakes and synthetic CSAM.
- Cross-border interaction: how the OSA interacts with the EU Digital Services Act for platforms operating in both markets.
For UK users, the direction of travel is clear: more duties on platforms, more identity signals attached to online activity, and more incentive to be deliberate about which services get your real data.
Frequently Asked Questions
Does the UK Online Safety Act require ID to use social media?
Not universally. It requires "highly effective" age assurance for services likely to be accessed by children or hosting adult content. Many platforms will use age estimation rather than full ID checks, but some services — particularly adult content sites — do require formal verification.
Will the Online Safety Act break end-to-end encryption?
The Act contains powers that could require scanning of encrypted messages, but the government has said these will only be used when "technically feasible". As of 2026, no such notice has been issued, and major encrypted messengers continue to operate in the UK. The legal risk, however, remains.
Can I be fined personally under the Online Safety Act?
Fines target service providers, not individual users. However, senior managers of in-scope services can face personal liability, including criminal penalties in some cases, for repeated failures to comply.
How does the Act affect small UK forums and blogs?
Any UK service with user-generated content is technically in scope, but Ofcom applies proportionate duties. Small operators should complete a basic risk assessment, publish clear terms, and provide a way to report harmful content. Ignoring the Act is not safe even for small sites.
What is the best way to protect my privacy under the OSA?
Combine several measures: use privacy-preserving age verification methods, segment your online identities with email aliases, use a privacy-focused browser with encrypted DNS, support end-to-end encrypted messaging, and choose data-minimising tools — including for everyday utilities like link shorteners and password managers.
Final Thoughts
The UK Online Safety Act is a significant piece of legislation with genuine benefits — particularly for victims of online harm and for children. But it also normalises identity checks on everyday internet use and creates legal tools that could weaken encryption in future. For UK users, the sensible response is neither panic nor complacency. Understand what the Act requires, choose services that minimise the data they collect, and stay informed as Ofcom's codes of practice evolve.
Privacy in 2026 is less about avoiding the internet and more about being deliberate: knowing who holds your data, why, and for how long. The Online Safety Act makes that habit more important than ever.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.