UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most sweeping pieces of internet legislation Britain has ever passed. Introduced to protect children and clamp down on illegal content, it also reshapes how platforms handle user data, verify ages, and moderate speech. For anyone who values online privacy, understanding what the Act actually requires — and what it doesn't — is essential.
This guide breaks down the Online Safety Act in plain English, explains its real impact on your personal privacy, and offers practical steps you can take to stay in control of your data.
What Is the UK Online Safety Act?
The Online Safety Act 2023 is a UK law that places legal duties on online platforms — from social networks and search engines to messaging apps and adult sites — to protect users, especially children, from illegal and harmful content. Ofcom is the regulator responsible for enforcement, with the power to fine companies up to £18 million or 10% of global annual turnover, whichever is higher.
The law came into force in stages, with the most consequential provisions — including mandatory age verification and illegal content duties — taking effect in 2025. By 2026, most in-scope services must comply fully or face significant penalties.
Who Does the Act Apply To?
The Act covers any service accessible from the UK that hosts user-generated content or facilitates online interaction. This includes:
- Social media platforms (Facebook, X, TikTok, Instagram)
- Search engines (Google, Bing)
- Messaging and communication apps (WhatsApp, Signal, Telegram)
- Video-sharing platforms (YouTube, Twitch)
- Adult content sites
- Online forums, community sites, and even smaller platforms if they meet certain risk thresholds
Crucially, the Act applies extraterritorially: a platform based in the US or elsewhere still has to comply if UK users can access it.
The Core Duties Platforms Must Now Follow
The Act imposes several categories of duty. Understanding these helps you see where your data may be collected, analysed, or shared.
1. Illegal Content Duty
Platforms must proactively identify and remove illegal material — including terrorism content, child sexual abuse material (CSAM), fraud, and content encouraging self-harm. To do this, many services now scan uploads, messages, and metadata using automated systems.
2. Child Safety Duty
Any service likely to be accessed by children must assess risks and implement "highly effective" age assurance. This is where the privacy implications begin to bite: platforms must know who is a child and who isn't, which means everyone effectively has to prove their age.
3. Transparency and Reporting
Platforms must publish transparency reports, provide user reporting tools, and maintain clear terms of service. Ofcom can demand internal data at any point.
4. Duty on Fraudulent Advertising
Larger platforms must prevent and remove fraudulent adverts, which often means more aggressive tracking of advertiser behaviour and ad content.
Age Verification: The Biggest Privacy Flashpoint
Age assurance is the most controversial element of the Online Safety Act from a privacy perspective. From July 2025, adult sites and any service hosting pornographic content have had to implement "highly effective" age checks. Many social platforms are following suit for sensitive content categories.
Accepted methods include:
- Photo ID upload — scanning a passport or driving licence
- Facial age estimation — a selfie analysed by AI to guess your age
- Credit card checks — verifying an adult-only payment method
- Mobile network verification — your operator confirms you passed their age filter
- Digital identity wallets — reusable credentials from certified providers
- Open banking checks — confirming account age via bank data
Each of these methods involves sharing sensitive personal information — biometrics, government IDs, or financial data — with either the platform itself or a third-party verification provider. Even when providers claim data is deleted after verification, users must trust that this actually happens.
Privacy Risks of Age Verification
- Data breaches: Verification databases become high-value targets for hackers.
- Linkage risk: Your ID could be linked to browsing behaviour on adult or sensitive sites.
- Chilling effect: Users may self-censor legitimate speech to avoid submitting ID.
- Third-party trust: Verification firms are lightly regulated compared to banks.
What the Act Means for Encrypted Messaging
One of the most heated debates during the Bill's passage was whether the government could compel platforms to scan end-to-end encrypted messages for illegal content. The final Act includes a power (Section 121) allowing Ofcom to require services to use "accredited technology" to detect CSAM.
In practice, ministers stated during debate that this power would only be used when "technically feasible" — an admission that scanning encrypted content without breaking encryption is currently impossible. As of 2026, no such notice has been issued, and companies like Signal and WhatsApp have said they would withdraw from the UK rather than weaken encryption.
The situation, however, remains legally live. If a scanning notice were ever served, it could fundamentally alter the privacy guarantees you rely on for personal messaging.
How Your Data Collection Is Changing
Even if you never upload an ID, the Online Safety Act indirectly increases the amount of data platforms hold about you. Here's how:
| Area | Before the Act | Under the Act |
|---|---|---|
| Age data | Self-declared or none | Verified via ID, biometrics, or third parties |
| Content scanning | Limited, mostly voluntary | Mandatory scanning for illegal content |
| Behavioural profiling | Primarily for ads | Also for risk assessments and safety flags |
| User reports | Ad hoc | Structured, retained, and auditable by Ofcom |
| Retention | Varied by platform | Longer, to demonstrate compliance |
The Interaction With UK GDPR
The Online Safety Act does not override UK GDPR. Platforms must still have a lawful basis for processing personal data, minimise what they collect, and honour subject access requests. The Information Commissioner's Office (ICO) and Ofcom have published joint guidance urging companies to build in "data protection by design" when implementing safety measures.
In principle, this means age assurance should use the least intrusive method available. In reality, cost and speed pressures often push platforms towards the easiest option — usually ID upload — rather than the most private.
Practical Steps to Protect Your Privacy
You can't opt out of the Online Safety Act, but you can make informed choices about how much data you share.
1. Choose Privacy-Preserving Age Assurance
Where a platform offers multiple age-check methods, pick the one that shares the least data. Digital identity wallets and "zero-knowledge" attestations (which confirm you're over 18 without revealing your identity) are usually preferable to uploading a passport scan.
2. Use Encrypted DNS and a Private Browser
Enable encrypted DNS (DNS-over-HTTPS) in your browser or at the network level. Combined with a privacy-focused browser like Firefox, Brave, or Safari with Private Relay, this reduces how much your internet provider and third parties can see about your browsing.
3. Compartmentalise Your Accounts
Use different email addresses for sensitive services and general browsing. Consider email aliases (from providers like Fastmail, Proton, or Apple's Hide My Email) so a data breach at one platform doesn't cascade across your life.
4. Review Platform Privacy Settings Quarterly
Platforms have updated their policies significantly to comply with the Act. Take 30 minutes every three months to review who can see your content, what data is used for personalisation, and which third parties have access.
5. Be Cautious With Link Sharing
Links you share on social media, in messages, or in forums are increasingly scanned and logged. If you share URLs professionally — for marketing, journalism, or research — use a shortener that respects privacy and gives you control over analytics. Lunyb is one option that lets you shorten links without handing over reams of personal data, and you can compare it against alternatives in our 2026 buyer's guide.
6. Exercise Your Data Rights
Under UK GDPR, you can request a copy of your data, ask for corrections, or demand deletion. If a platform's age verification stored more than it should, a subject access request will reveal it.
What About Free Speech and Legal-but-Harmful Content?
Earlier drafts of the Bill required platforms to remove "legal but harmful" content for adults. This was dropped after concerns about over-censorship. The final Act instead requires large platforms to give adult users tools to filter content they don't want to see — such as abuse, eating disorder content, or self-harm material — and to enforce their own terms of service consistently.
This is a positive outcome for expression, but it still nudges platforms towards heavier moderation and more detailed content classification, which itself relies on analysing what you post and read.
Enforcement Timeline and What's Next
Ofcom has been rolling out codes of practice in phases:
- 2024–2025: Illegal content codes and risk-assessment duties commenced.
- Mid-2025: Age assurance for pornographic services became enforceable.
- Late 2025 into 2026: Full child safety codes for social media and search took effect.
- 2026 and beyond: Ofcom's first major enforcement actions, plus expected reviews of encryption powers and transparency reporting.
Legal challenges are likely. Civil liberties groups, encryption advocates, and some overseas platforms have signalled they may test parts of the Act in court, particularly around proportionality and the encryption scanning power.
Pros and Cons of the Online Safety Act for UK Users
Pros
- Stronger protection for children against exploitation and harmful content
- Clearer legal duties for platforms, with real financial penalties
- Better user reporting tools and transparency
- Tougher action against fraud, scams, and illegal advertising
Cons
- Significant privacy trade-offs from mandatory age verification
- Potential future threat to end-to-end encryption
- Higher data collection and longer retention for compliance
- Risk of smaller platforms leaving the UK market entirely
- Chilling effect on anonymous participation in legitimate discussion
Frequently Asked Questions
Does the Online Safety Act require me to upload my passport to use social media?
Not necessarily. Age verification is mandatory for adult content and for platforms likely to be accessed by children, but platforms can offer several methods — including facial age estimation, mobile network checks, and digital identity wallets. You can usually avoid uploading a passport if you choose the least intrusive available option.
Can the government read my WhatsApp or Signal messages under the Act?
No, not currently. The Act contains a power (Section 121) allowing Ofcom to require scanning of encrypted content, but ministers have said this will only be used when technically feasible — which, without breaking encryption, it currently is not. No scanning notice has been issued as of 2026.
What happens if a platform ignores the Online Safety Act?
Ofcom can impose fines of up to £18 million or 10% of global annual turnover, whichever is higher. In serious cases, it can seek court orders to block access to the service from the UK or hold senior managers personally liable.
Does the Act apply to small websites and forums?
Yes, in principle, if they host user-generated content and are accessible in the UK. However, duties are proportionate to size and risk. Small, low-risk community sites face lighter obligations than mainstream platforms, but they still must have basic reporting mechanisms and act on illegal content.
How can I protect my privacy while still complying with age checks?
Where possible, use reusable digital identity wallets that confirm your age without revealing your identity to the platform. Use encrypted DNS, a privacy-respecting browser, and email aliases to reduce cross-site tracking. Review and delete data via subject access requests under UK GDPR whenever you no longer use a service.
Final Thoughts
The Online Safety Act is a well-intentioned law aimed at real harms, but it comes with genuine privacy costs. As a UK user, your best defence is awareness: understand what data platforms are collecting to comply with the Act, choose the most private tools where you have a choice, and exercise your rights under UK GDPR to keep those platforms honest.
Privacy and safety are not opposites — but achieving both requires vigilance. The next few years of enforcement will determine whether the Act's balance shifts too far in one direction, and users who stay informed will be best placed to push back if it does.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share the same goal but take very different paths to get there. This guide compares consent, breach notification, penalties, and cross-border rules — and shows how Singapore businesses can build one unified compliance program that satisfies both.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
A comprehensive 2026 guide to privacy rights in Canada, covering PIPEDA, Quebec's Law 25, provincial PIPAs, emerging AI and biometrics rules, and practical steps for individuals and businesses. Learn what protections you have, how enforcement is evolving, and how to exercise your rights.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn exactly how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This 2026 guide covers the step-by-step process, timelines, evidence tips, and what to expect from the investigation and appeal stages.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 introduces sharper duties for platforms and businesses, from rapid takedowns to child safety by design. This complete guide breaks down obligations, penalties, and a 90-day compliance plan for organisations operating in Singapore.