UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most sweeping pieces of internet legislation Britain has ever passed. Signed into law in October 2023 and now being enforced in phases by Ofcom through 2025 and 2026, it changes how platforms handle harmful content, verify users' ages, and moderate private messages. For everyday users, that raises an unavoidable question: what does the UK Online Safety Act mean for your privacy?
This guide breaks down the Act in plain English, explains the privacy trade-offs baked into it, and shows practical steps you can take to keep your personal data and browsing habits under your own control.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that requires online platforms — social networks, search engines, messaging apps, video-sharing sites, and even some smaller forums — to protect users, especially children, from illegal and harmful content. It is enforced by Ofcom, which can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.
The Act covers three broad categories of duty:
- Illegal content duties — platforms must proactively detect and remove content such as child sexual abuse material, terrorism content, fraud and revenge pornography.
- Child safety duties — services likely to be accessed by under-18s must use age assurance and shield minors from pornography, self-harm promotion, and other legal-but-harmful material.
- Category 1 duties — the largest platforms face additional transparency, user-empowerment and content-moderation obligations.
Why It Was Introduced
Parliament framed the Act as a response to years of criticism that self-regulation had failed. High-profile cases, such as the death of teenager Molly Russell, pushed lawmakers to make platforms legally accountable for the design choices that expose users to harm. The intent is protective — but the mechanisms it enables have significant knock-on effects for privacy.
How the Act Affects Your Online Privacy
The privacy impact of the UK Online Safety Act comes from four mechanisms: mandatory age assurance, potential scanning of private messages, expanded data retention, and Ofcom's information-gathering powers. Together, these change what platforms know about you and what they must share with regulators.
1. Age Assurance and Identity Verification
Any service that hosts pornography or content deemed harmful to children must implement "highly effective" age assurance. In practice, this can mean:
- Uploading a photo of a government ID
- Facial age estimation via webcam
- Credit card or bank verification
- Mobile network operator age checks
- Digital identity wallet integration
Even if the Act says providers should use privacy-preserving third parties, the reality is that millions of adults are now handing biometric data or ID scans to companies they had no relationship with before. Each verification creates a data point linking a real-world identity to a browsing activity — precisely the link most privacy-conscious users try to avoid.
2. Encrypted Messaging Under Pressure
Section 121 of the Act gives Ofcom the power to require messaging services to use "accredited technology" to identify illegal content, including in end-to-end encrypted chats. The government has said the power will only be used when "technically feasible", and the technology to scan encrypted messages without breaking encryption does not really exist. But the legal power remains on the books.
For users of apps like Signal, WhatsApp and iMessage, this creates ongoing uncertainty. Signal has publicly said it would withdraw from the UK rather than compromise its encryption. If client-side scanning is ever mandated, the confidentiality of private conversations changes fundamentally.
3. More Data Held for Longer
To demonstrate compliance, platforms must keep detailed records: risk assessments, moderation logs, evidence of takedowns, and audit trails of user reports. That means more of your interactions — reports you file, content you post, appeals you make — are logged and retained for regulator inspection.
4. Ofcom's Information Notices
Ofcom can issue formal information notices demanding user-level data to investigate compliance failures. While the regulator is bound by the UK GDPR, the range of data it can request is broad, and refusal is a criminal offence for named senior managers.
Who Is Affected: A Quick Comparison
Not every website faces the same obligations. The Act uses a tiered approach based on size, functionality and risk.
| Service Type | Key Duties | Privacy Impact on Users |
|---|---|---|
| Large social networks (Category 1) | All illegal-content, child-safety, transparency and user-empowerment duties | High — identity checks, content scanning, extensive logging |
| Pornography providers | Highly effective age assurance | High — ID or biometric checks required |
| Search engines | Reduce visibility of illegal content and CSAM | Moderate — more query logging and filtering |
| Private messaging apps | Illegal-content duties; possible scanning powers | Potentially very high if scanning is enforced |
| Small forums & blogs | Basic illegal-content duties | Low to moderate — depends on functionality |
| File-sharing & link services | Illegal-content duties, abuse reporting | Low — mainly operator-side compliance |
Pros and Cons for UK Users
The Act is genuinely trying to solve real harms, but the trade-offs are significant. Here is an honest look at both sides.
Pros
- Stronger child protection — clearer legal duties around grooming, self-harm and pornography access.
- Faster takedown of illegal content — fraud, revenge porn and terrorism content must be actioned quickly.
- Formal complaints routes — Ofcom oversight gives users a regulator to escalate to.
- Transparency reports — the largest platforms must publish moderation data.
Cons
- Identity data proliferation — more services collecting ID and biometric information.
- Chilling effect on encryption — the legal threat to end-to-end encryption remains.
- Over-blocking risk — automated moderation will inevitably remove legitimate content.
- Smaller sites disadvantaged — compliance costs push smaller UK forums to close or geo-block.
- Age gates as friction — everyday browsing now involves more identity checkpoints.
Practical Steps to Protect Your Privacy
You cannot opt out of the law, but you can reduce the amount of personal data attached to your online activity. Here is a practical checklist.
- Use a privacy-first browser. Browsers like Firefox, Brave and LibreWolf block trackers by default and expose fewer fingerprinting surfaces than default installations of Chrome or Edge.
- Turn on encrypted DNS. Configure DNS over HTTPS (DoH) using providers such as Cloudflare 1.1.1.1, Quad9 or NextDNS. This stops your internet provider from seeing every domain you visit.
- Prefer age-assurance methods that reveal the least. Where a service offers a choice, an anonymous age-estimation token from an independent provider leaks less data than uploading your passport.
- Use email aliases. Services like SimpleLogin, Fastmail Masked Email or Apple's Hide My Email let you sign up without exposing your primary address.
- Separate identities. Keep one browser profile for logged-in accounts and another for anonymous browsing so cookies and history do not cross-contaminate.
- Audit app permissions. On iOS and Android, review which apps have location, contacts and microphone access every few months.
- Shorten and monitor links you share. When sharing content publicly, a privacy-respecting link shortener like Lunyb lets you control click data yourself rather than handing it to a third party that resells it.
Protecting Links You Share on Regulated Platforms
Under the Act, large platforms scrutinise outbound links more aggressively. Using a reputable shortener helps in two ways: it gives you analytics on how a link is performing without needing to embed third-party trackers, and it lets you disable a link quickly if it is misused. Read our honest review of Lunyb or compare providers in our 2026 buyer's guide to URL shorteners to see what to look for.
What Ofcom Enforcement Looks Like in 2025-2026
Ofcom is rolling out the Act in phases. Illegal-content codes came into force in March 2025, child-safety codes followed in July 2025, and Category 1 duties for the largest platforms are being finalised through 2026. Expect three visible trends over the next 18 months:
More Age Gates
You will see age-verification walls on pornography sites, some social media features, and increasingly on gambling, alcohol retail and gaming platforms with UK visitors.
More Content Removal Notices
Expect visible increases in "this content is not available in the UK" messages, particularly on smaller international forums that decide compliance costs outweigh UK traffic.
Sharper Terms of Service
Platforms are rewriting terms to reflect their new duties. Read the update notifications you receive — they now materially change what data can be collected and shared.
How the UK Approach Compares Internationally
The UK is not alone. The EU's Digital Services Act, Australia's Online Safety Act and various US state laws all pull in similar directions, but the UK regime is notable for the breadth of powers Ofcom holds and the explicit inclusion of private messaging.
| Jurisdiction | Main Law | Age Checks | Message Scanning Powers |
|---|---|---|---|
| UK | Online Safety Act 2023 | Mandatory for high-risk content | Yes, under Section 121 (subject to feasibility) |
| EU | Digital Services Act | Encouraged, not mandated broadly | Separate CSAM regulation still under debate |
| Australia | Online Safety Act 2021 | Being expanded via industry codes | Limited |
| USA | State-level (e.g. Texas HB 1181) | Varies by state | No federal equivalent |
Frequently Asked Questions
Does the UK Online Safety Act mean my WhatsApp messages will be read?
Not today. The Act gives Ofcom the legal power to require scanning of encrypted messages, but the government has publicly acknowledged that no technology currently allows this without breaking encryption. Providers like WhatsApp and Signal have said they would rather leave the UK market than compromise end-to-end encryption. The situation should be monitored, but private messages are still encrypted as of now.
Will I have to upload my passport to use social media?
For general social media use, no. Age assurance is required where a service hosts pornography or content that is harmful to children. However, some platforms may introduce age checks for specific features — such as adult content settings, live streaming or direct messaging with strangers — even if the main service does not require ID.
Does the Act apply to small blogs and forums based outside the UK?
Yes, if the service has "links with the UK" — meaning UK users, UK-targeted content, or a significant UK user base. Small forums with limited UK reach face lower risk-assessment burdens, but they are still technically in scope. Many small operators have chosen to geo-block UK visitors rather than take on the compliance workload.
How is the UK Online Safety Act different from UK GDPR?
UK GDPR is about how personal data is collected, stored and used — it protects your data rights. The Online Safety Act is about content and user safety on online services. The two regimes overlap: age assurance and content moderation both involve processing personal data, so platforms must comply with both simultaneously. The Information Commissioner's Office and Ofcom are working together to align enforcement.
What should I do if I think a platform has mishandled my data under the Act?
You have two routes. For data protection concerns — for example, if you think your ID scan was retained too long — complain to the Information Commissioner's Office (ICO). For safety-duty failures, such as a platform ignoring reports of illegal content, complain via the platform's internal process first and then escalate to Ofcom. Keep records of everything you submit.
Final Thoughts
The UK Online Safety Act is a serious attempt to make the internet less harmful, particularly for children. But every safety mechanism it introduces — age checks, content scanning, expanded logging — carries a privacy cost that falls disproportionately on ordinary adult users. The best response is not to panic, but to be deliberate: choose services that minimise the data they collect, use encryption where you can, and take advantage of the tools available to keep your identity and browsing habits separate from the content you consume and share.
Privacy in 2026 is a practice, not a product. Small habits — a privacy-first browser, encrypted DNS, an email alias, a link shortener you actually trust — add up to a much larger buffer between you and the growing web of mandatory disclosures.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.