facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act is one of the most sweeping pieces of internet regulation ever passed in Britain. Marketed as a landmark law to protect children and tackle illegal content, it also introduces obligations that touch nearly every aspect of how you browse, message and share online. For anyone who values digital privacy, understanding what the Act actually requires — and where it stops — is essential.

This guide breaks down the Online Safety Act in plain English, explains the privacy trade-offs, and offers practical steps British users can take to stay in control of their personal data.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that places new legal duties on online platforms — from social networks and search engines to messaging apps and pornography sites — to reduce the risk of illegal and harmful content reaching users, particularly children. Ofcom is the appointed regulator, with powers to issue codes of practice, demand information and impose fines of up to £18 million or 10% of global turnover, whichever is greater.

The Act received Royal Assent in October 2023 and is being rolled out in phases throughout 2024 to 2026. By the time it is fully in force, it will affect an estimated 100,000+ online services worldwide, as long as they have a meaningful link to UK users.

Which Services Are Covered?

The scope is deliberately broad. Regulated services generally fall into three buckets:

  • User-to-user services: Platforms where users share content with each other — social media, forums, comment sections, dating apps, gaming chat.
  • Search services: General-purpose search engines that index third-party content.
  • Pornography services: Any commercial site publishing adult content, subject to strict age-verification requirements.

Even small platforms and community forums can be caught, though the heaviest duties fall on "Category 1" services — the largest, highest-risk platforms.

The Core Duties: What Platforms Must Now Do

At the heart of the Act sit several "duties of care" that platforms must fulfil. These duties are what create most of the privacy implications for ordinary users.

  1. Illegal content duties: Platforms must proactively identify and remove content relating to a defined list of offences — terrorism, child sexual abuse, fraud, harassment, controlling behaviour and more.
  2. Children's safety duties: Services likely to be accessed by children must protect them from "priority" content such as pornography, self-harm material, violent content and cyberbullying.
  3. Age assurance: Sites hosting adult content must implement "highly effective" age checks. Other services may need age assurance to keep certain content away from minors.
  4. Transparency reporting: Larger platforms must publish annual reports about their moderation and safety systems.
  5. User empowerment tools: Category 1 services must offer adults tools to filter out certain legal-but-harmful content and to control who can interact with them.

Age Verification: The Biggest Privacy Flashpoint

The most visible change for UK users is age verification. Since mid-2025, adult sites accessible from the UK have been required to implement "highly effective" age assurance. In practice, that means one or more of the following:

  • Uploading a photo of a passport or driving licence
  • Facial age estimation via webcam
  • Credit card checks
  • Mobile network operator age verification
  • Digital identity wallets from certified providers

Ofcom does not require sites to store the underlying documents, and most rely on third-party verification providers. But the sheer volume of sensitive data being processed — sometimes linking a real-world identity to viewing habits — creates a substantial new attack surface. High-profile breaches of age-verification providers in other jurisdictions have already exposed millions of records.

What This Means for You

Even if you trust the platform you are visiting, your identity data now often passes through a chain of processors. If any link is breached or misused, information about which sites you accessed could become linkable to your legal name. The Information Commissioner's Office (ICO) has issued guidance requiring data minimisation, but enforcement will be uneven, especially with smaller overseas providers.

Encrypted Messaging and the "Spy Clause" Debate

Section 121 of the Act gives Ofcom power to require regulated services to use "accredited technology" to identify child sexual abuse material or terrorism content — including on private messaging services. Critics, including WhatsApp, Signal and academic cryptographers, argued this could effectively force client-side scanning on end-to-end encrypted platforms.

During the passage of the Bill, the government stated the power would only be used when "technically feasible", and Ofcom has since indicated that no such technology currently meets the required standard for encrypted services. However, the legal power remains on the books. Signal and WhatsApp both publicly warned they would withdraw from the UK market rather than weaken their encryption — a stand-off that has been paused rather than resolved.

For privacy-conscious users, the practical takeaway is simple: end-to-end encryption in mainstream apps remains intact for now, but the legal architecture that could compel scanning still exists.

Data Collection: How the Act Changes What Platforms Know About You

To comply with the Act, platforms are collecting more data about their users than ever before. Below is a simplified comparison of what typical services processed before and after the Act.

Data Category Before Online Safety Act After Online Safety Act
Age data Self-declared date of birth Verified ID, facial estimation or credit checks
Content scanning Voluntary hash-matching for known CSAM Mandatory proactive detection for a wide range of illegal content
Behavioural signals Mainly for advertising and recommendations Also used to infer whether a user is a child
Risk assessments Not required Mandatory, documented and available to Ofcom
User reports Handled internally Must be logged, actioned and auditable

The direction of travel is clear: platforms know more about you, retain that information longer, and share more of it with regulators and third-party verifiers.

Free Speech and Legal-But-Harmful Content

An earlier draft of the Bill would have required Category 1 services to tackle "legal but harmful" content for adults. That provision was dropped after criticism from free-speech campaigners. Instead, platforms must give adult users tools to filter such content themselves and must enforce their own terms of service consistently.

In theory, this is a compromise that preserves adult autonomy. In practice, platforms facing enormous fines tend to over-moderate. Expect more aggressive automated takedowns, more shadow-banning of borderline content, and less tolerance for satire, dark humour or robust political debate — all with limited transparency about why a post was removed.

Practical Steps to Protect Your Privacy

You cannot opt out of the Online Safety Act, but you can make thoughtful choices that reduce your exposure. Here are pragmatic steps for UK users.

1. Choose Privacy-Respecting Age Verification Methods

Where an adult site offers multiple age-check options, prefer providers that use "double-blind" architectures — where the site never sees your ID and the verifier never sees the site. Look for certification under the UK digital identity trust framework. Avoid uploading raw passport scans to unfamiliar operators.

2. Harden Your Browser and DNS

Use a privacy-focused browser such as Firefox, Brave or LibreWolf. Enable encrypted DNS (DNS over HTTPS or DNS over TLS) through a reputable resolver — this prevents your internet provider and network operators from easily building a profile of every domain you visit.

3. Separate Identities Where It Matters

Use distinct email addresses (or email aliases) for accounts that require identity verification versus accounts you want to keep pseudonymous. This limits the damage if any single provider is breached.

4. Be Deliberate About Links You Share

Shared links can leak more than you expect — tracking parameters, referrer data and long, identifying URLs. A privacy-focused link shortener such as Lunyb strips tracking cruft and gives you a clean, neutral link to share. If you are curious about how it stacks up, our honest Lunyb review and the 2026 buyer's guide to URL shorteners compare the main options.

5. Review App Permissions Regularly

Platforms complying with children's safety duties may request more device signals — location, contacts, camera access for age estimation. Audit these permissions monthly and revoke anything that is not strictly necessary.

6. Use End-to-End Encrypted Messaging

Signal, WhatsApp and iMessage all remain end-to-end encrypted in the UK. If encryption is important to you, keep your sensitive conversations on these platforms rather than on SMS or unencrypted DMs.

7. Exercise Your UK GDPR Rights

The Online Safety Act does not override UK GDPR. You still have the right to access, correct and delete personal data held about you. If a platform has collected age-verification data, ask how long it is retained and request deletion once the check is complete.

What About Small Publishers and Businesses?

If you run a UK website with any user-generated content — a forum, a blog comments section, a Discord server that is publicly listed — you may have duties under the Act. Ofcom has published a proportionate regime for small services, but the basics still apply: complete an illegal-content risk assessment, publish clear terms, offer a reporting mechanism and act on complaints.

For creators sharing branded links, tools that keep your infrastructure lean matter. A hosted short-link service handles redirects, analytics and abuse reporting without you having to build compliance workflows from scratch. Comparisons like our Rebrandly review can help you weigh commercial options against privacy-first alternatives.

The Bigger Picture: Regulation Is Only Going to Grow

The UK Online Safety Act sits alongside the EU's Digital Services Act, Australia's eSafety regime and a growing patchwork of state-level laws in the US. Platforms serving global audiences increasingly design for the strictest common denominator — which usually means more identity collection and more content moderation, everywhere.

The best long-term defence is not any single tool but a habit of thoughtful digital hygiene: minimise the data you hand over, prefer services that publish clear privacy practices, and stay informed about how the rules are changing. Ofcom's codes of practice will continue evolving through 2026, and further legislation on AI-generated content and online fraud is already on the horizon.

Frequently Asked Questions

Does the Online Safety Act ban end-to-end encryption?

No. The Act does not ban end-to-end encryption, and mainstream encrypted messengers such as Signal and WhatsApp continue to operate in the UK. However, Section 121 gives Ofcom a legal power to require content-scanning technology on regulated services if it becomes "technically feasible". No such requirement has been imposed, but the power remains available.

Do I have to upload my passport to watch adult content in the UK?

Not necessarily. Sites must use "highly effective" age assurance, but this can include facial age estimation, credit card checks, mobile operator verification or digital identity wallets. You can usually choose the method you are most comfortable with. Look for providers certified under the UK digital identity trust framework, which are audited for data-minimisation and security.

Can I be fined under the Online Safety Act as a regular user?

The Act's fines target service providers, not ordinary users. However, it also created new communications offences — including sending threatening messages, cyberflashing and false communications intended to cause harm — which apply to individuals and carry criminal penalties. Standard laws against harassment, fraud and illegal content still apply as before.

Does the Act apply to overseas websites?

Yes, if they have a significant number of UK users or are targeted at the UK market. Ofcom can take action against non-UK providers, and in serious cases it can seek business disruption measures — including asking payment providers or app stores to cut off access to non-compliant services in the UK.

How can I keep browsing privately without breaking any laws?

Nothing in the Online Safety Act prohibits using privacy tools. You can lawfully use encrypted DNS, privacy-focused browsers, ad and tracker blockers, encrypted messengers, private email providers and link shorteners that strip tracking parameters. The Act regulates platforms and content, not your right to browse or communicate privately.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles