UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act has been described as one of the most sweeping pieces of internet legislation in the world. Passed in October 2023 and now being enforced in phases by Ofcom, the Act aims to make the UK "the safest place in the world to be online". Whatever your view of that ambition, the law has real consequences for your privacy, the services you use, and the way you access content from a UK address.
This guide breaks down what the Online Safety Act actually does, where the privacy tensions lie, and what practical steps British users can take to protect themselves in 2026 and beyond.
What Is the UK Online Safety Act?
The Online Safety Act 2023 is a UK law that places legal duties on online platforms to protect users, particularly children, from illegal and harmful content. It is enforced by Ofcom, the UK's communications regulator, which can fine companies up to £18 million or 10% of global annual revenue for non-compliance.
The Act applies to a very broad range of services accessible in the UK, including:
- Social media platforms (Facebook, Instagram, TikTok, X)
- Search engines (Google, Bing, DuckDuckGoresults surfaced in the UK)
- Messaging apps (WhatsApp, Signal, Telegram)
- Video-sharing and livestreaming services
- Adult content sites
- Forums, discussion boards and even smaller community sites
- Cloud-based file sharing and, in some cases, link-based services
Crucially, it applies to services wherever they are based, as long as they have a significant number of UK users or target the UK market.
The Three Core Duties
- Illegal content duty: Platforms must proactively identify, remove and prevent the reappearance of illegal content, such as terrorism material, child sexual abuse material (CSAM), fraud and intimate image abuse.
- Child safety duty: Any service likely to be accessed by children must use "highly effective" age assurance and shield minors from pornography, self-harm, suicide, eating-disorder and violent content.
- User empowerment duty (Category 1 services): The largest platforms must give adult users tools to filter certain legal-but-harmful content and to verify other users' identities.
Why the Act Matters for Your Privacy
On paper, the Online Safety Act is about safety. In practice, several of its mechanisms directly touch personal data, identity and encrypted communications. The three biggest privacy flashpoints are age verification, message scanning, and increased data collection by platforms trying to prove compliance.
1. Mandatory Age Verification
Since July 2025, sites hosting pornography or other "primary priority content" harmful to children must use highly effective age assurance. That typically means one of the following:
- Uploading a photo of a government-issued ID
- Face-scan age estimation
- Credit card checks
- Mobile network operator age checks
- Open banking or digital identity wallet verification
Ofcom insists the process should be privacy-preserving, and many providers use third-party services that return a simple yes/no result. However, users now have to trust an extra company with sensitive documents, and data breaches at age-verification vendors would be catastrophic. There are also concerns about function creep — data collected to prove age could later be repurposed for advertising, fraud detection or law enforcement requests.
2. Pressure on End-to-End Encryption
Section 121 of the Act gives Ofcom the power to require services to use "accredited technology" to identify CSAM and terrorism content, including in private messages. For end-to-end encrypted platforms like WhatsApp, Signal and iMessage, that raises a serious technical problem: you cannot scan encrypted content without either breaking the encryption or scanning on the device before it is encrypted ("client-side scanning").
The UK government has said the power will only be used when "technically feasible", and Ofcom has indicated it will not currently require encrypted services to break encryption. But the legal power remains on the statute book, and any future policy shift could force major messaging apps to weaken their security for UK users — or leave the UK market entirely, as Signal has publicly threatened to do.
3. More Data Collection, More Attack Surface
To meet their duties, platforms are collecting more information than ever: age signals, behavioural data to spot suspicious accounts, more detailed reporting logs, and identity verification records for user-empowerment features. Every extra dataset is another target for hackers and another item that can be requested by governments.
How Ofcom Enforces the Act
Ofcom has published codes of practice and risk assessment guidance that platforms must follow. Enforcement is being rolled out in phases:
| Phase | Focus | Status in 2026 |
|---|---|---|
| Phase 1 | Illegal content duties | In force since March 2025 |
| Phase 2 | Child safety and age assurance | In force since July 2025 |
| Phase 3 | Categorised services (Category 1, 2A, 2B) additional duties | Rolling out through 2026 |
Non-compliant companies face fines, business disruption orders (which can force UK payment providers and ISPs to cut them off) and, in extreme cases, criminal liability for senior managers who ignore Ofcom's information notices.
What Has Actually Changed for UK Users?
Adult and Dating Sites
Most major adult sites now require robust age verification for UK visitors. Some smaller sites have geo-blocked the UK entirely rather than comply. Dating apps have tightened onboarding, adding selfie checks and, in some cases, ID uploads.
Social Media
Platforms have introduced or expanded UK-specific teen accounts with default privacy settings, restricted DMs and content filters. Age estimation via selfie or behavioural signals is now common when your declared age looks inconsistent with your activity.
Search Engines
Search results in the UK are more aggressively filtered for self-harm, suicide and pornographic content, particularly when signals suggest a younger user. Safe search is on by default for accounts believed to belong to under-18s.
Forums and Small Communities
This has been one of the most controversial areas. Small hobbyist forums, Mastodon instances and even personal wikis fall within scope if UK users can access them. Some volunteer-run communities have shut down rather than face the compliance burden.
Link Sharing and URL Shorteners
Link-based services have had to think carefully about how they moderate content behind shortened URLs. Reputable UK-facing providers now scan destinations for malware, phishing and illegal content and remove offending links quickly. Privacy-focused tools such as Lunyb take a minimal-data approach — shortening links without demanding accounts or building advertising profiles — which reduces the amount of personal information exposed if a platform is ever subject to a legal request. If you're comparing providers, our 2026 buyer's guide to URL shorteners covers what to look for.
The Privacy Trade-Offs: A Balanced View
What the Act Gets Right
- Clear legal duties around CSAM, terrorism and fraud that most people support
- Stronger default protections for children on mainstream platforms
- Transparency reports that force big tech to publish moderation data
- A single UK regulator (Ofcom) instead of fragmented enforcement
Where It Creates Privacy Risk
- ID and biometric data are now routinely collected by third-party age assurance vendors
- Legal powers exist that could, in theory, undermine end-to-end encryption
- Small communities lack resources to comply, reducing pluralism online
- Definitions of "harmful" content can shift with future secondary legislation
- Increased data retention creates larger breach targets
Practical Steps to Protect Your Privacy in 2026
1. Choose Age-Verification Methods Carefully
When a UK site asks you to verify your age, look for options that reveal the least data. Face-scan age estimation (which returns an approximate age without storing your image) is generally less invasive than uploading a passport. Digital ID wallets that share only a "yes, over 18" attestation are the gold standard.
2. Use Encrypted DNS and Private Browsers
Turn on encrypted DNS (DoH or DoT) in your browser or operating system, and consider browsers such as Brave, Firefox with strict tracking protection, or the Mullvad Browser. This limits how much your ISP and third parties can see, independent of any government mandate.
3. Minimise the Data You Give to Every Platform
- Use unique email aliases (Apple Hide My Email, DuckDuckGo Email Protection, SimpleLogin)
- Set social media accounts to private by default
- Turn off ad personalisation and location history
- Regularly delete old accounts you no longer use
4. Prefer Privacy-Respecting Tools
Where possible, choose services that don't require an account for basic functions, don't run advertising trackers, and publish clear data-retention policies. This applies to search engines, note apps, cloud storage and even URL shorteners — see our honest review of Lunyb for an example of what a minimal-data approach looks like in practice, and our Rebrandly review for 2026 for a look at a more feature-heavy commercial alternative.
5. Keep Encrypted Messaging as Your Default
Use Signal, WhatsApp or iMessage for anything sensitive. If any of these ever announce they are weakening encryption specifically for UK users, that is your cue to reassess and potentially move to a service that maintains full end-to-end encryption globally.
6. Exercise Your Data Rights
The UK GDPR still applies alongside the Online Safety Act. You have the right to request a copy of your data, correct it, and in many cases delete it. Use those rights regularly — especially with age-verification providers you interact with only once.
What Comes Next?
Expect the following developments through 2026 and 2027:
- More enforcement actions. Ofcom has begun opening formal investigations, and the first significant fines are expected in 2026.
- Expansion of digital identity. The UK's digital identity framework will make age and identity checks smoother — and more centralised.
- Ongoing debate about encryption. Expect legal challenges, parliamentary reviews and international coordination (or friction) with the EU's Digital Services Act.
- Further categorisation of services. Ofcom's Category 1, 2A and 2B lists will define which platforms carry the heaviest duties.
Frequently Asked Questions
Does the UK Online Safety Act ban end-to-end encryption?
No, it does not ban encryption outright. However, Section 121 gives Ofcom the power to require accredited scanning technology on messaging services, which could in principle conflict with end-to-end encryption. The government has said it will not use this power until it is technically feasible to do so without breaking encryption, but the legal power remains in place.
Do I have to upload my passport to use social media in the UK?
Not usually. Mainstream social media platforms mostly use age estimation, self-declaration and behavioural signals rather than ID uploads. ID or credit card checks are more common on adult content sites and some dating apps. Where ID is required, look for providers offering privacy-preserving methods that don't retain the document itself.
Does the Online Safety Act apply to small websites and forums?
Yes, in principle. Any user-to-user service accessible in the UK can fall within scope, regardless of size. Ofcom applies a proportionate approach — smaller, lower-risk services have lighter duties — but even hobby forums must complete a risk assessment and have basic reporting mechanisms in place.
Can I use a private browser or encrypted DNS to bypass age verification?
Privacy tools like encrypted DNS, private browsers and anti-tracking extensions are legal in the UK. They can reduce tracking and, in some cases, change how a site sees your location. However, deliberately circumventing age verification on sites subject to the Act may breach those sites' terms of service, and children using such methods is exactly the risk regulators are trying to close down.
How does the Online Safety Act interact with UK GDPR?
They run in parallel. The Online Safety Act creates safety duties enforced by Ofcom; UK GDPR governs how personal data is collected and processed, and is enforced by the ICO. Platforms must comply with both — meaning any age assurance or content-scanning system must also meet GDPR principles like data minimisation, purpose limitation and security.
Final Thoughts
The UK Online Safety Act is neither the internet apocalypse some critics feared nor the safety utopia the government promised. It is a serious, wide-ranging law that shifts real responsibility onto platforms — and, indirectly, more data collection onto users. For anyone in the UK, the sensible response is not panic but hygiene: understand what data you are handing over, prefer services that ask for less, and keep encrypted communications as your default. Privacy in 2026 is less about hiding and more about deliberately choosing who gets to see what.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to notify the OAIC and affected individuals when a breach is likely to cause serious harm. This guide covers obligations, timelines, penalties up to AUD $50 million, and how to build a compliant response plan.
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms moderate content, verify ages and handle private messages. Here's what it means for your privacy in 2026 — and the practical steps every UK user can take to protect their data.