facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act is one of the most sweeping pieces of internet legislation Britain has ever passed. Signed into law in October 2023 and now being enforced in phases by Ofcom through 2025 and 2026, it changes how platforms handle harmful content, verify users' ages, and moderate private messages. For everyday users, that raises an unavoidable question: what does the UK Online Safety Act mean for your privacy?

This guide breaks down the Act in plain English, explains the privacy trade-offs baked into it, and shows practical steps you can take to keep your personal data and browsing habits under your own control.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that requires online platforms — social networks, search engines, messaging apps, video-sharing sites, and even some smaller forums — to protect users, especially children, from illegal and harmful content. It is enforced by Ofcom, which can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.

The Act covers three broad categories of duty:

  1. Illegal content duties — platforms must proactively detect and remove content such as child sexual abuse material, terrorism content, fraud and revenge pornography.
  2. Child safety duties — services likely to be accessed by under-18s must use age assurance and shield minors from pornography, self-harm promotion, and other legal-but-harmful material.
  3. Category 1 duties — the largest platforms face additional transparency, user-empowerment and content-moderation obligations.

Why It Was Introduced

Parliament framed the Act as a response to years of criticism that self-regulation had failed. High-profile cases, such as the death of teenager Molly Russell, pushed lawmakers to make platforms legally accountable for the design choices that expose users to harm. The intent is protective — but the mechanisms it enables have significant knock-on effects for privacy.

How the Act Affects Your Online Privacy

The privacy impact of the UK Online Safety Act comes from four mechanisms: mandatory age assurance, potential scanning of private messages, expanded data retention, and Ofcom's information-gathering powers. Together, these change what platforms know about you and what they must share with regulators.

1. Age Assurance and Identity Verification

Any service that hosts pornography or content deemed harmful to children must implement "highly effective" age assurance. In practice, this can mean:

  • Uploading a photo of a government ID
  • Facial age estimation via webcam
  • Credit card or bank verification
  • Mobile network operator age checks
  • Digital identity wallet integration

Even if the Act says providers should use privacy-preserving third parties, the reality is that millions of adults are now handing biometric data or ID scans to companies they had no relationship with before. Each verification creates a data point linking a real-world identity to a browsing activity — precisely the link most privacy-conscious users try to avoid.

2. Encrypted Messaging Under Pressure

Section 121 of the Act gives Ofcom the power to require messaging services to use "accredited technology" to identify illegal content, including in end-to-end encrypted chats. The government has said the power will only be used when "technically feasible", and the technology to scan encrypted messages without breaking encryption does not really exist. But the legal power remains on the books.

For users of apps like Signal, WhatsApp and iMessage, this creates ongoing uncertainty. Signal has publicly said it would withdraw from the UK rather than compromise its encryption. If client-side scanning is ever mandated, the confidentiality of private conversations changes fundamentally.

3. More Data Held for Longer

To demonstrate compliance, platforms must keep detailed records: risk assessments, moderation logs, evidence of takedowns, and audit trails of user reports. That means more of your interactions — reports you file, content you post, appeals you make — are logged and retained for regulator inspection.

4. Ofcom's Information Notices

Ofcom can issue formal information notices demanding user-level data to investigate compliance failures. While the regulator is bound by the UK GDPR, the range of data it can request is broad, and refusal is a criminal offence for named senior managers.

Who Is Affected: A Quick Comparison

Not every website faces the same obligations. The Act uses a tiered approach based on size, functionality and risk.

Service TypeKey DutiesPrivacy Impact on Users
Large social networks (Category 1)All illegal-content, child-safety, transparency and user-empowerment dutiesHigh — identity checks, content scanning, extensive logging
Pornography providersHighly effective age assuranceHigh — ID or biometric checks required
Search enginesReduce visibility of illegal content and CSAMModerate — more query logging and filtering
Private messaging appsIllegal-content duties; possible scanning powersPotentially very high if scanning is enforced
Small forums & blogsBasic illegal-content dutiesLow to moderate — depends on functionality
File-sharing & link servicesIllegal-content duties, abuse reportingLow — mainly operator-side compliance

Pros and Cons for UK Users

The Act is genuinely trying to solve real harms, but the trade-offs are significant. Here is an honest look at both sides.

Pros

  • Stronger child protection — clearer legal duties around grooming, self-harm and pornography access.
  • Faster takedown of illegal content — fraud, revenge porn and terrorism content must be actioned quickly.
  • Formal complaints routes — Ofcom oversight gives users a regulator to escalate to.
  • Transparency reports — the largest platforms must publish moderation data.

Cons

  • Identity data proliferation — more services collecting ID and biometric information.
  • Chilling effect on encryption — the legal threat to end-to-end encryption remains.
  • Over-blocking risk — automated moderation will inevitably remove legitimate content.
  • Smaller sites disadvantaged — compliance costs push smaller UK forums to close or geo-block.
  • Age gates as friction — everyday browsing now involves more identity checkpoints.

Practical Steps to Protect Your Privacy

You cannot opt out of the law, but you can reduce the amount of personal data attached to your online activity. Here is a practical checklist.

  1. Use a privacy-first browser. Browsers like Firefox, Brave and LibreWolf block trackers by default and expose fewer fingerprinting surfaces than default installations of Chrome or Edge.
  2. Turn on encrypted DNS. Configure DNS over HTTPS (DoH) using providers such as Cloudflare 1.1.1.1, Quad9 or NextDNS. This stops your internet provider from seeing every domain you visit.
  3. Prefer age-assurance methods that reveal the least. Where a service offers a choice, an anonymous age-estimation token from an independent provider leaks less data than uploading your passport.
  4. Use email aliases. Services like SimpleLogin, Fastmail Masked Email or Apple's Hide My Email let you sign up without exposing your primary address.
  5. Separate identities. Keep one browser profile for logged-in accounts and another for anonymous browsing so cookies and history do not cross-contaminate.
  6. Audit app permissions. On iOS and Android, review which apps have location, contacts and microphone access every few months.
  7. Shorten and monitor links you share. When sharing content publicly, a privacy-respecting link shortener like Lunyb lets you control click data yourself rather than handing it to a third party that resells it.

Protecting Links You Share on Regulated Platforms

Under the Act, large platforms scrutinise outbound links more aggressively. Using a reputable shortener helps in two ways: it gives you analytics on how a link is performing without needing to embed third-party trackers, and it lets you disable a link quickly if it is misused. Read our honest review of Lunyb or compare providers in our 2026 buyer's guide to URL shorteners to see what to look for.

What Ofcom Enforcement Looks Like in 2025-2026

Ofcom is rolling out the Act in phases. Illegal-content codes came into force in March 2025, child-safety codes followed in July 2025, and Category 1 duties for the largest platforms are being finalised through 2026. Expect three visible trends over the next 18 months:

More Age Gates

You will see age-verification walls on pornography sites, some social media features, and increasingly on gambling, alcohol retail and gaming platforms with UK visitors.

More Content Removal Notices

Expect visible increases in "this content is not available in the UK" messages, particularly on smaller international forums that decide compliance costs outweigh UK traffic.

Sharper Terms of Service

Platforms are rewriting terms to reflect their new duties. Read the update notifications you receive — they now materially change what data can be collected and shared.

How the UK Approach Compares Internationally

The UK is not alone. The EU's Digital Services Act, Australia's Online Safety Act and various US state laws all pull in similar directions, but the UK regime is notable for the breadth of powers Ofcom holds and the explicit inclusion of private messaging.

JurisdictionMain LawAge ChecksMessage Scanning Powers
UKOnline Safety Act 2023Mandatory for high-risk contentYes, under Section 121 (subject to feasibility)
EUDigital Services ActEncouraged, not mandated broadlySeparate CSAM regulation still under debate
AustraliaOnline Safety Act 2021Being expanded via industry codesLimited
USAState-level (e.g. Texas HB 1181)Varies by stateNo federal equivalent

Frequently Asked Questions

Does the UK Online Safety Act mean my WhatsApp messages will be read?

Not today. The Act gives Ofcom the legal power to require scanning of encrypted messages, but the government has publicly acknowledged that no technology currently allows this without breaking encryption. Providers like WhatsApp and Signal have said they would rather leave the UK market than compromise end-to-end encryption. The situation should be monitored, but private messages are still encrypted as of now.

Will I have to upload my passport to use social media?

For general social media use, no. Age assurance is required where a service hosts pornography or content that is harmful to children. However, some platforms may introduce age checks for specific features — such as adult content settings, live streaming or direct messaging with strangers — even if the main service does not require ID.

Does the Act apply to small blogs and forums based outside the UK?

Yes, if the service has "links with the UK" — meaning UK users, UK-targeted content, or a significant UK user base. Small forums with limited UK reach face lower risk-assessment burdens, but they are still technically in scope. Many small operators have chosen to geo-block UK visitors rather than take on the compliance workload.

How is the UK Online Safety Act different from UK GDPR?

UK GDPR is about how personal data is collected, stored and used — it protects your data rights. The Online Safety Act is about content and user safety on online services. The two regimes overlap: age assurance and content moderation both involve processing personal data, so platforms must comply with both simultaneously. The Information Commissioner's Office and Ofcom are working together to align enforcement.

What should I do if I think a platform has mishandled my data under the Act?

You have two routes. For data protection concerns — for example, if you think your ID scan was retained too long — complain to the Information Commissioner's Office (ICO). For safety-duty failures, such as a platform ignoring reports of illegal content, complain via the platform's internal process first and then escalate to Ofcom. Keep records of everything you submit.

Final Thoughts

The UK Online Safety Act is a serious attempt to make the internet less harmful, particularly for children. But every safety mechanism it introduces — age checks, content scanning, expanded logging — carries a privacy cost that falls disproportionately on ordinary adult users. The best response is not to panic, but to be deliberate: choose services that minimise the data they collect, use encryption where you can, and take advantage of the tools available to keep your identity and browsing habits separate from the content you consume and share.

Privacy in 2026 is a practice, not a product. Small habits — a privacy-first browser, encrypted DNS, an email alias, a link shortener you actually trust — add up to a much larger buffer between you and the growing web of mandatory disclosures.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles