UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most significant pieces of internet regulation in a generation. Passed in October 2023 and now being enforced in stages through 2025 and 2026, it changes how platforms handle harmful content, verify user ages, and moderate private messages. For everyday users in the UK, it also raises important questions about privacy, anonymity, and the future of encrypted communication.
This guide breaks down what the Act actually requires, how it affects your day-to-day online life, and the practical steps you can take to keep your personal data protected while staying compliant with UK law.
What Is the UK Online Safety Act?
The UK Online Safety Act is a law that imposes a legal duty of care on online platforms — from social networks and search engines to messaging apps and adult sites — to protect users, particularly children, from illegal and harmful content. Enforcement is handled by Ofcom, which can issue fines of up to £18 million or 10% of global annual turnover, whichever is higher.
The Act covers three broad categories of duties:
- Illegal content duties — platforms must proactively detect and remove illegal material such as terrorism content, child sexual abuse material (CSAM), fraud, and incitement to violence.
- Child safety duties — services likely to be accessed by children must assess risks and use age assurance to prevent minors from seeing harmful content, including pornography, self-harm material, and eating-disorder content.
- User empowerment duties — the largest platforms (Category 1 services) must offer tools that let adult users filter certain legal-but-harmful content and verify other users' identities.
Why the Online Safety Act Matters for Privacy
On the surface, the Act is about safety. But many of its requirements have direct consequences for user privacy, because enforcing safety rules at scale usually requires collecting more information about who users are and what they are doing. Three areas are especially important: age verification, message scanning, and identity checks.
1. Age Verification and Personal Data
From July 2025, sites hosting adult content and platforms judged likely to be accessed by children must use "highly effective" age assurance. In practice this can mean:
- Uploading a photo of a passport, driving licence, or other government ID
- Facial age estimation using a live selfie
- Credit card checks
- Mobile network operator age checks
- Digital identity wallets from certified providers
Each of these methods involves handing sensitive biometric or identity data to a third party. Even when providers promise "data minimisation" and immediate deletion, the sheer volume of new age checks creates fresh targets for data breaches and phishing attacks.
2. Pressure on End-to-End Encryption
Section 121 of the Act gives Ofcom the power to require services to use "accredited technology" to detect CSAM and terrorism content — including in private messages. This provision has been the most controversial part of the law. Encrypted messaging services argue that scanning private messages, even client-side, fundamentally breaks end-to-end encryption.
The UK government has said the power will only be used when "technically feasible." No such technology currently exists that can scan encrypted messages without weakening encryption for everyone. For now this creates a legal grey zone rather than immediate scanning, but the power remains on the statute book.
3. Identity Verification for Social Media
Category 1 services must offer adult users the option to verify their identity and to filter out interactions with unverified accounts. Verification itself is optional, but the design creates strong social pressure to hand over ID to remain fully visible on major platforms. Over time, this could erode the practical anonymity that has long been a feature of the open web.
Timeline: When Each Duty Comes Into Force
The Act is being rolled out in phases by Ofcom. Understanding the timeline helps you anticipate changes on the platforms you use.
| Phase | Date | What Changes |
|---|---|---|
| Phase 1: Illegal harms | March 2025 | Platforms must complete illegal content risk assessments and apply Ofcom's codes. |
| Phase 2: Child safety and porn | July 2025 | Age assurance required on adult sites and services likely to be accessed by children. |
| Phase 3: Transparency and Category 1 duties | Rolling through 2026 | Largest platforms must offer user empowerment tools, verification, and publish transparency reports. |
| Ongoing | 2026 onwards | Ofcom enforcement actions, fines, and possible service restrictions for non-compliant platforms. |
How the Act Affects Everyday UK Users
Browsing Adult and Age-Restricted Content
Adult websites accessible from the UK must now verify visitors are over 18. Some large platforms have complied with facial age estimation or ID checks; others have chosen to block UK traffic entirely rather than comply. Either way, the days of anonymous access to age-restricted content from a UK IP address are effectively over.
Using Social Media and Forums
Expect more prompts to verify your age or identity, stricter moderation of borderline content, and a smaller pool of small forums — some hobbyist communities have shut down rather than absorb compliance costs. Larger platforms will offer new filtering tools that let you hide posts from unverified accounts.
Messaging and Private Communications
For now, encrypted messaging apps like Signal and WhatsApp continue to operate as before. However, the legal power to demand scanning technology remains, and platforms have publicly said they would consider withdrawing from the UK market rather than break encryption. Watch this space carefully in 2026.
Sharing Links and Content Online
Platforms are more sensitive than ever about what gets posted or linked. Automated filters may flag or block links they don't recognise, especially shortened URLs from services with poor reputations. Using a trusted, transparent link shortener — for example Lunyb, which we cover in our honest review of Lunyb — helps ensure your links aren't misclassified as spam or malicious. For a broader look at the market, see our 2026 buyer's guide to URL shorteners.
Privacy Risks Created by the Act
Well-intentioned safety measures can produce unintended privacy costs. The main risks to be aware of are:
- Data breach exposure — every ID upload or facial scan is a new record that could leak. AgeID-style databases become high-value targets for attackers.
- Function creep — data collected for age assurance could later be used for advertising, law enforcement requests, or cross-site tracking if governance is weak.
- Chilling effects — people may self-censor on sensitive topics (mental health, sexuality, political dissent) if they believe posts are tied to a verified real-world identity.
- Reduced anonymity — whistleblowers, abuse survivors, and members of marginalised groups often rely on pseudonymity for safety. Verification requirements can put them at risk.
- Weakened encryption threats — even the possibility of mandated scanning discourages investment in stronger privacy technologies in the UK.
Practical Steps to Protect Your Privacy Under the Act
You cannot opt out of the Act, but you can be thoughtful about how much personal data you expose. Here is a practical checklist.
1. Choose Age Assurance Methods Carefully
Where you have a choice, prefer methods that share the least data. Facial age estimation from a certified provider that deletes the image immediately is usually less risky than uploading a full copy of your passport. Digital identity wallets that share only a "yes/no over-18" token are the gold standard when available.
2. Separate Identities Where Sensible
Use different email addresses (and, where permitted, different accounts) for sensitive activities versus general browsing. This limits the damage if one provider is breached.
3. Harden Your Browser and Device
- Use a privacy-respecting browser such as Firefox or Brave.
- Enable encrypted DNS (DNS over HTTPS) to prevent your ISP from logging every domain you visit.
- Keep your operating system and browser fully patched.
- Use a reputable password manager and enable two-factor authentication everywhere.
4. Be Cautious With Verification Providers
Before uploading ID, check whether the provider is certified under a recognised UK scheme (such as those accredited to the UK Digital Identity and Attributes Trust Framework). Look for a clear retention policy — ideally minutes or seconds, not months.
5. Rethink What You Share Publicly
With more content tied to verified identities, assume anything posted publicly could eventually be linked back to you. Move sensitive conversations to private, end-to-end encrypted channels.
6. Use Trustworthy Tools for Links and Sharing
When sharing links — especially in professional or community contexts — pick a shortener that publishes a clear privacy policy and doesn't monetise clickstream data. This reduces the personal information leaked every time someone clicks a link you share.
What the Act Does Not Do
It's easy to overstate the impact of the Online Safety Act. To be clear:
- It does not ban encrypted messaging apps.
- It does not require every website to verify your age — only those hosting adult content or judged likely to be accessed by children.
- It does not mandate real-name policies across the internet. Pseudonymity is still legal.
- It does not apply to purely private communications between individuals outside of regulated services.
- It does not give Ofcom the power to demand your personal browsing history from platforms without a lawful basis.
Understanding these limits is important because misinformation about the Act has driven some users to abandon useful safety features (like two-factor authentication) out of misplaced fear.
How Businesses and Publishers Should Respond
If you run a website, newsletter, or community forum accessible from the UK, you may be in scope even if you're based elsewhere. Small businesses should:
- Complete a risk assessment against Ofcom's illegal harms codes.
- Publish clear terms of service and a reporting mechanism for illegal content.
- Document your moderation processes and how you handle takedown requests.
- Minimise the personal data you collect from users to reduce breach risk.
- Choose vendors — including analytics, comment systems, and link tools — with strong privacy practices. Our reviews of tools like Rebrandly and other shorteners can help you compare privacy postures.
The Bigger Picture: Safety and Privacy Are Not Opposites
The debate around the Online Safety Act often frames safety and privacy as a trade-off. In reality, strong privacy protections — encryption, data minimisation, transparent moderation — usually make people safer, especially children, journalists, and abuse survivors. The most effective response to the Act is not to give up on privacy, but to demand that safety measures are implemented in privacy-respecting ways: certified age assurance providers, minimal data retention, independent audits of Ofcom's technology directions, and continued protection of end-to-end encryption.
As a user, the best thing you can do is stay informed, choose services that take privacy seriously, and use the tools available to limit unnecessary data exposure.
Frequently Asked Questions
Does the UK Online Safety Act mean I have to verify my identity to use the internet?
No. Identity verification is optional on Category 1 platforms, and general-purpose websites do not require it. Age assurance is required on adult sites and some services likely to be accessed by children, but that is age verification, not full identity verification.
Will the Act break end-to-end encryption on WhatsApp or Signal?
Not currently. The Act gives Ofcom the power to require content-scanning technology, but only when it is "technically feasible." No such technology exists today that preserves end-to-end encryption. Major encrypted messengers have said they would leave the UK market rather than weaken their encryption.
Are age verification services safe to use?
The risk varies by provider. Certified providers operating under recognised UK trust frameworks typically follow strict data-minimisation rules and delete biometric data within seconds. Unregulated providers are riskier. Prefer methods that share only a yes/no over-18 token rather than uploading a full ID document where possible.
Does the Online Safety Act apply to overseas websites?
Yes, if the service has "links with the United Kingdom" — for example, a significant number of UK users or content targeted at the UK. Ofcom can act against non-UK companies, and in serious cases can seek court orders to restrict access to non-compliant services from the UK.
What can I do if a platform removes my content unfairly under the Act?
Regulated platforms must offer an accessible complaints procedure. If your appeal is refused, you can complain to Ofcom about systemic failures, though Ofcom does not resolve individual content disputes. For legal-but-controversial content that has been removed, the platform's own transparency reports (required from 2026) may help you understand the moderation rules.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.