facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··9 min read

The UK Online Safety Act is one of the most sweeping pieces of internet regulation Britain has ever passed. Introduced to protect children and tackle illegal content online, it also introduces significant new duties on tech platforms — duties that touch directly on how your personal data, messages, and browsing habits are handled. This guide explains what the Act actually says, what it means for your privacy in practice, and the sensible steps you can take today to stay in control of your information.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a UK law that imposes a legal "duty of care" on online services — from social media platforms and search engines to messaging apps and adult websites — to protect users, especially children, from illegal and harmful content. Ofcom is the appointed regulator and can issue fines of up to £18 million or 10% of global annual turnover, whichever is higher.

The Act received Royal Assent in October 2023, and its provisions are being phased in through 2024 and 2025 as Ofcom publishes codes of practice. By mid-2025, key duties around illegal content, child safety, and age assurance for pornography sites had come into force.

Who Does the Act Apply To?

The law applies to any service accessible in the UK, regardless of where the company is based. That includes:

  • User-to-user services (social networks, forums, comment sections)
  • Search engines
  • Messaging platforms (including end-to-end encrypted ones)
  • Pornography providers
  • File-sharing and cloud storage services with public sharing features

Even small platforms based abroad must comply if they have "significant" UK users or target the UK market.

The Privacy Concerns at the Heart of the Act

While the Act's aims — reducing child sexual abuse material, terrorism content, fraud, and cyberbullying — are widely supported, privacy advocates have raised serious concerns. The core tension is simple: to detect harmful content at scale, platforms may need to inspect what users are doing, including in private conversations.

1. The Encryption Debate

Section 121 of the Act gives Ofcom the power to require platforms to use "accredited technology" to identify child sexual abuse material — even in end-to-end encrypted services. Critics, including Signal, WhatsApp, and Apple, argue this effectively mandates client-side scanning: software on your device that scans messages before they are encrypted.

The UK government has said the power will only be used when "technically feasible," and has acknowledged that no such technology currently exists that preserves encryption. In practice, this means the clause is dormant — but it remains on the statute book and could be activated later.

2. Mandatory Age Verification

From July 2025, sites hosting pornography or content harmful to children must use "highly effective" age assurance. Acceptable methods include:

  1. Photo-ID matching (uploading a passport or driving licence)
  2. Facial age estimation via selfie
  3. Credit card checks
  4. Mobile network operator age checks
  5. Digital identity wallets

This creates new databases of highly sensitive information linking real identities to browsing habits. Even when third-party providers claim not to store data, the very act of verification creates new attack surfaces.

3. Content Moderation at Scale

Platforms must proactively detect and remove illegal content. In practice, this pushes services toward automated scanning, AI moderation, and metadata analysis of what users post, link to, and share — including private groups and DMs on some services.

How the Act Affects Everyday Users

You don't need to run a platform to feel the effects. Here's what typical UK internet users are already experiencing.

More Identity Checks

Expect to be asked to prove your age or identity more often — not just on adult sites, but potentially on dating apps, gambling sites, alcohol retailers, and any social platform that hosts content deemed harmful to minors. Each check is a data-sharing event.

Some Services Withdrawing From the UK

Smaller platforms, particularly niche forums and independent adult sites, have chosen to geo-block UK visitors rather than comply. Wikipedia has publicly warned it may be forced to restrict UK access if categorised as a Category 1 service requiring identity checks on editors.

Changes to Anonymous Posting

Category 1 services must offer users tools to verify their identity and to filter out unverified accounts. This isn't mandatory verification for everyone, but it creates a two-tier internet where anonymous voices are systematically deprioritised.

Link Sharing and Public Content

Because platforms are liable for illegal content shared through their services, expect more aggressive scanning of URLs, previews, and shared files. If you share a lot of links — for marketing, journalism, or community management — it's worth using tools that give you visibility into how those links perform and where they are being clicked. Privacy-respecting shorteners like Lunyb let you track clicks without harvesting personal data from your audience, which matters when the regulatory environment increasingly treats any shared link as a potential compliance event.

The Act vs. UK GDPR: A Quick Comparison

The Online Safety Act sits alongside the UK GDPR and Data Protection Act 2018 — sometimes reinforcing them, sometimes creating friction. Here's how they compare on key privacy questions.

AreaUK GDPROnline Safety Act
Primary aimProtect personal dataReduce online harm
RegulatorICOOfcom
Data minimisationCore principleEncourages more data collection (age, ID)
AnonymitySupported where possibleReduced via verification duties
Maximum fine£17.5m or 4% turnover£18m or 10% turnover
Applies to encrypted contentYes, but protects itReserves power to scan it

Practical Steps to Protect Your Privacy

The Act is now law, but you still have meaningful choices about how much of your digital life is exposed. Here are practical measures that don't require deep technical knowledge.

1. Choose Privacy-Respecting Age Verification

Where age checks are unavoidable, prefer providers that use "double-blind" or "zero-knowledge" methods — where the site you're visiting learns only that you passed the check, not who you are. Look for providers certified under the Age Check Certification Scheme (ACCS) and read their retention policies before uploading ID.

2. Use Encrypted Messaging With Care

End-to-end encryption remains legal and widely available. Signal and WhatsApp have both said they will leave the UK before compromising encryption. For now, encrypted messaging is one of the strongest tools you have for private communication — use it as your default for personal conversations.

3. Minimise Your Digital Footprint

  1. Audit which apps have your real name, phone number, and date of birth
  2. Use separate email addresses for high-risk sign-ups
  3. Turn off cross-app tracking on iOS and Android
  4. Regularly clear cookies and site data
  5. Use browsers with strong tracker blocking such as Firefox or Brave

4. Protect Your DNS and Browsing Metadata

Encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) prevents your internet provider from easily logging which websites you visit. Most modern browsers support it — enabling it takes two clicks in settings and dramatically reduces network-level tracking.

5. Be Deliberate About What You Share

Under the Act, platforms have stronger incentives to retain and analyse user content. Assume anything you post — even in "private" groups — could be scanned, flagged, or handed over on request. Adjust what you share accordingly.

6. Use Privacy-Friendly Tools for Public Sharing

If you publish links, run a newsletter, or manage a community, choose tools that collect the minimum data needed. A privacy-focused link shortener, for example, gives you analytics without turning every click into a profile-building event. Our own honest review of Lunyb covers what to look for, and our 2026 buyer's guide to URL shorteners compares the main options on privacy grounds.

What Businesses and Creators Need to Know

If you run a website, community, or online service accessible in the UK, the Act likely applies to you — even as a sole trader. Ofcom has published a risk-assessment framework and expects services to document their approach.

Key Obligations for Small Services

  • Complete an illegal content risk assessment
  • Publish clear terms of service explaining what content is banned
  • Provide a reporting and complaints mechanism
  • Keep records of decisions and moderation actions
  • Nominate a senior person accountable for compliance

Balancing Compliance With Data Protection

You still must comply with UK GDPR when collecting any additional data for safety purposes. That means collecting only what you need, storing it securely, and being transparent with users. Don't let the Online Safety Act become an excuse to over-collect — the ICO can still fine you if you do.

The Bigger Picture: Where This Is Heading

The Online Safety Act is not the end of the story. Ofcom continues to publish new codes throughout 2025 and 2026, and further legislation — including on AI-generated content, misinformation, and fraud — is on the horizon. The EU's Digital Services Act, Australia's Online Safety Act, and similar laws worldwide are creating a fragmented but broadly aligned regulatory landscape.

The direction of travel is clear: platforms will be held responsible for what happens on them, and identity will become more central to how the internet works. Whether this delivers safer online spaces without hollowing out privacy will depend on how Ofcom uses its powers — and how loudly users and providers push back against overreach.

Frequently Asked Questions

Does the UK Online Safety Act ban end-to-end encryption?

No, it does not ban encryption outright. However, Section 121 gives Ofcom the power to require accredited technology to detect child sexual abuse material, which could in future apply to encrypted services. The government has stated this power will only be used when technically feasible, and no such technology currently exists that preserves encryption.

Will I have to upload my passport to use social media?

Not for general social media use. Mandatory age assurance applies to sites hosting pornography and to content classed as harmful to children. Category 1 platforms must offer optional identity verification, but users can still choose to remain unverified — they may just have less access to certain features or filters.

Can I be prosecuted for sharing a link under the Act?

The Act primarily targets platforms, not individual users. However, existing UK laws already criminalise sharing illegal content such as CSAM, terrorist material, or content encouraging suicide. The Act introduces new offences around cyberflashing, threatening communications, and false information intended to cause harm.

How is the Online Safety Act enforced?

Ofcom is the regulator. It can require information from platforms, audit their systems, and issue fines of up to £18 million or 10% of global annual turnover. In serious cases, senior managers can face criminal liability, and Ofcom can seek court orders to block non-compliant services in the UK.

What can I do if a platform removes my content unfairly?

The Act requires large platforms to provide clear complaints and appeals processes. If you believe content has been removed unfairly, use the platform's appeal mechanism first. If unresolved, you can complain to Ofcom, though Ofcom generally deals with systemic issues rather than individual disputes. You may also have rights under UK GDPR to challenge automated decisions.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles