UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most sweeping pieces of internet regulation Britain has ever passed. Introduced to protect children and tackle illegal content online, it also introduces significant new duties on tech platforms — duties that touch directly on how your personal data, messages, and browsing habits are handled. This guide explains what the Act actually says, what it means for your privacy in practice, and the sensible steps you can take today to stay in control of your information.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a UK law that imposes a legal "duty of care" on online services — from social media platforms and search engines to messaging apps and adult websites — to protect users, especially children, from illegal and harmful content. Ofcom is the appointed regulator and can issue fines of up to £18 million or 10% of global annual turnover, whichever is higher.
The Act received Royal Assent in October 2023, and its provisions are being phased in through 2024 and 2025 as Ofcom publishes codes of practice. By mid-2025, key duties around illegal content, child safety, and age assurance for pornography sites had come into force.
Who Does the Act Apply To?
The law applies to any service accessible in the UK, regardless of where the company is based. That includes:
- User-to-user services (social networks, forums, comment sections)
- Search engines
- Messaging platforms (including end-to-end encrypted ones)
- Pornography providers
- File-sharing and cloud storage services with public sharing features
Even small platforms based abroad must comply if they have "significant" UK users or target the UK market.
The Privacy Concerns at the Heart of the Act
While the Act's aims — reducing child sexual abuse material, terrorism content, fraud, and cyberbullying — are widely supported, privacy advocates have raised serious concerns. The core tension is simple: to detect harmful content at scale, platforms may need to inspect what users are doing, including in private conversations.
1. The Encryption Debate
Section 121 of the Act gives Ofcom the power to require platforms to use "accredited technology" to identify child sexual abuse material — even in end-to-end encrypted services. Critics, including Signal, WhatsApp, and Apple, argue this effectively mandates client-side scanning: software on your device that scans messages before they are encrypted.
The UK government has said the power will only be used when "technically feasible," and has acknowledged that no such technology currently exists that preserves encryption. In practice, this means the clause is dormant — but it remains on the statute book and could be activated later.
2. Mandatory Age Verification
From July 2025, sites hosting pornography or content harmful to children must use "highly effective" age assurance. Acceptable methods include:
- Photo-ID matching (uploading a passport or driving licence)
- Facial age estimation via selfie
- Credit card checks
- Mobile network operator age checks
- Digital identity wallets
This creates new databases of highly sensitive information linking real identities to browsing habits. Even when third-party providers claim not to store data, the very act of verification creates new attack surfaces.
3. Content Moderation at Scale
Platforms must proactively detect and remove illegal content. In practice, this pushes services toward automated scanning, AI moderation, and metadata analysis of what users post, link to, and share — including private groups and DMs on some services.
How the Act Affects Everyday Users
You don't need to run a platform to feel the effects. Here's what typical UK internet users are already experiencing.
More Identity Checks
Expect to be asked to prove your age or identity more often — not just on adult sites, but potentially on dating apps, gambling sites, alcohol retailers, and any social platform that hosts content deemed harmful to minors. Each check is a data-sharing event.
Some Services Withdrawing From the UK
Smaller platforms, particularly niche forums and independent adult sites, have chosen to geo-block UK visitors rather than comply. Wikipedia has publicly warned it may be forced to restrict UK access if categorised as a Category 1 service requiring identity checks on editors.
Changes to Anonymous Posting
Category 1 services must offer users tools to verify their identity and to filter out unverified accounts. This isn't mandatory verification for everyone, but it creates a two-tier internet where anonymous voices are systematically deprioritised.
Link Sharing and Public Content
Because platforms are liable for illegal content shared through their services, expect more aggressive scanning of URLs, previews, and shared files. If you share a lot of links — for marketing, journalism, or community management — it's worth using tools that give you visibility into how those links perform and where they are being clicked. Privacy-respecting shorteners like Lunyb let you track clicks without harvesting personal data from your audience, which matters when the regulatory environment increasingly treats any shared link as a potential compliance event.
The Act vs. UK GDPR: A Quick Comparison
The Online Safety Act sits alongside the UK GDPR and Data Protection Act 2018 — sometimes reinforcing them, sometimes creating friction. Here's how they compare on key privacy questions.
| Area | UK GDPR | Online Safety Act |
|---|---|---|
| Primary aim | Protect personal data | Reduce online harm |
| Regulator | ICO | Ofcom |
| Data minimisation | Core principle | Encourages more data collection (age, ID) |
| Anonymity | Supported where possible | Reduced via verification duties |
| Maximum fine | £17.5m or 4% turnover | £18m or 10% turnover |
| Applies to encrypted content | Yes, but protects it | Reserves power to scan it |
Practical Steps to Protect Your Privacy
The Act is now law, but you still have meaningful choices about how much of your digital life is exposed. Here are practical measures that don't require deep technical knowledge.
1. Choose Privacy-Respecting Age Verification
Where age checks are unavoidable, prefer providers that use "double-blind" or "zero-knowledge" methods — where the site you're visiting learns only that you passed the check, not who you are. Look for providers certified under the Age Check Certification Scheme (ACCS) and read their retention policies before uploading ID.
2. Use Encrypted Messaging With Care
End-to-end encryption remains legal and widely available. Signal and WhatsApp have both said they will leave the UK before compromising encryption. For now, encrypted messaging is one of the strongest tools you have for private communication — use it as your default for personal conversations.
3. Minimise Your Digital Footprint
- Audit which apps have your real name, phone number, and date of birth
- Use separate email addresses for high-risk sign-ups
- Turn off cross-app tracking on iOS and Android
- Regularly clear cookies and site data
- Use browsers with strong tracker blocking such as Firefox or Brave
4. Protect Your DNS and Browsing Metadata
Encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) prevents your internet provider from easily logging which websites you visit. Most modern browsers support it — enabling it takes two clicks in settings and dramatically reduces network-level tracking.
5. Be Deliberate About What You Share
Under the Act, platforms have stronger incentives to retain and analyse user content. Assume anything you post — even in "private" groups — could be scanned, flagged, or handed over on request. Adjust what you share accordingly.
6. Use Privacy-Friendly Tools for Public Sharing
If you publish links, run a newsletter, or manage a community, choose tools that collect the minimum data needed. A privacy-focused link shortener, for example, gives you analytics without turning every click into a profile-building event. Our own honest review of Lunyb covers what to look for, and our 2026 buyer's guide to URL shorteners compares the main options on privacy grounds.
What Businesses and Creators Need to Know
If you run a website, community, or online service accessible in the UK, the Act likely applies to you — even as a sole trader. Ofcom has published a risk-assessment framework and expects services to document their approach.
Key Obligations for Small Services
- Complete an illegal content risk assessment
- Publish clear terms of service explaining what content is banned
- Provide a reporting and complaints mechanism
- Keep records of decisions and moderation actions
- Nominate a senior person accountable for compliance
Balancing Compliance With Data Protection
You still must comply with UK GDPR when collecting any additional data for safety purposes. That means collecting only what you need, storing it securely, and being transparent with users. Don't let the Online Safety Act become an excuse to over-collect — the ICO can still fine you if you do.
The Bigger Picture: Where This Is Heading
The Online Safety Act is not the end of the story. Ofcom continues to publish new codes throughout 2025 and 2026, and further legislation — including on AI-generated content, misinformation, and fraud — is on the horizon. The EU's Digital Services Act, Australia's Online Safety Act, and similar laws worldwide are creating a fragmented but broadly aligned regulatory landscape.
The direction of travel is clear: platforms will be held responsible for what happens on them, and identity will become more central to how the internet works. Whether this delivers safer online spaces without hollowing out privacy will depend on how Ofcom uses its powers — and how loudly users and providers push back against overreach.
Frequently Asked Questions
Does the UK Online Safety Act ban end-to-end encryption?
No, it does not ban encryption outright. However, Section 121 gives Ofcom the power to require accredited technology to detect child sexual abuse material, which could in future apply to encrypted services. The government has stated this power will only be used when technically feasible, and no such technology currently exists that preserves encryption.
Will I have to upload my passport to use social media?
Not for general social media use. Mandatory age assurance applies to sites hosting pornography and to content classed as harmful to children. Category 1 platforms must offer optional identity verification, but users can still choose to remain unverified — they may just have less access to certain features or filters.
Can I be prosecuted for sharing a link under the Act?
The Act primarily targets platforms, not individual users. However, existing UK laws already criminalise sharing illegal content such as CSAM, terrorist material, or content encouraging suicide. The Act introduces new offences around cyberflashing, threatening communications, and false information intended to cause harm.
How is the Online Safety Act enforced?
Ofcom is the regulator. It can require information from platforms, audit their systems, and issue fines of up to £18 million or 10% of global annual turnover. In serious cases, senior managers can face criminal liability, and Ofcom can seek court orders to block non-compliant services in the UK.
What can I do if a platform removes my content unfairly?
The Act requires large platforms to provide clear complaints and appeals processes. If you believe content has been removed unfairly, use the platform's appeal mechanism first. If unresolved, you can complain to Ofcom, though Ofcom generally deals with systemic issues rather than individual disputes. You may also have rights under UK GDPR to challenge automated decisions.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 delivers the most significant privacy overhaul since 1988, introducing new individual rights, tougher penalties, and broader coverage. This guide explains exactly what has changed and how you can exercise your new rights.
UK Data Protection Act vs GDPR Explained: Key Differences in 2026
The UK Data Protection Act 2018 and UK GDPR work together to form Britain's post-Brexit data protection regime — closely aligned with the EU GDPR but with important differences. This guide explains the key distinctions, compliance obligations, and what UK businesses need to know in 2026.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR share the same privacy goals but differ sharply on consent, DPO appointment, breach timelines, and penalties. This guide breaks down the key differences and gives Singapore businesses a practical compliance checklist for 2026.
PIPEDA vs GDPR: Canadian Privacy Law Explained for 2026
PIPEDA and GDPR share the same goal of protecting personal information, but they differ dramatically in consent rules, breach deadlines, and penalties. This guide compares both laws and explains what Canadian businesses need to do to stay compliant with either—or both.