UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most far-reaching pieces of internet legislation ever passed in Britain. Marketed as a law to protect children and tackle illegal content, it also introduces sweeping new duties for platforms — and raises serious questions about the future of online privacy for ordinary users. If you send messages, browse forums, run a website, or simply share links, this law affects you.
This guide breaks down what the Online Safety Act actually does, how Ofcom is enforcing it, where the privacy risks lie, and what practical steps UK users can take to keep their data under their own control.
What Is the UK Online Safety Act?
The Online Safety Act 2023 is a UK law that places legal duties on online services — including social networks, search engines, messaging apps and adult content sites — to protect users from illegal and harmful content. It is enforced by Ofcom, which can fine companies up to £18 million or 10% of global annual revenue, whichever is higher.
The Act came into force in stages during 2024 and 2025, with the illegal harms duties, child safety duties and age verification requirements all now active. In practical terms, it changes how platforms moderate content, how they identify users, and — most controversially — how they handle private communications.
Who the Act Applies To
- User-to-user services: social media, forums, dating apps, gaming chat, comment sections.
- Search services: Google, Bing, DuckDuckGo and specialist search engines.
- Pornography providers: both commercial adult sites and platforms that host user-generated adult content.
- Any service with UK users: the law has extraterritorial reach, meaning overseas platforms must comply if they have a significant UK audience.
The Core Duties Platforms Must Follow
The Act creates tiered duties depending on the size and risk profile of a service. Category 1 platforms — the largest, riskiest services — face the strictest obligations.
- Illegal content duty: platforms must proactively prevent users from encountering illegal content, including terrorism, child sexual abuse material (CSAM), fraud, and cyberflashing.
- Child safety duty: services likely to be accessed by children must shield minors from harmful (but legal) content such as self-harm material, pornography and abusive content.
- Age assurance duty: platforms hosting pornography, or content harmful to children, must use "highly effective" age verification.
- Transparency and reporting: Category 1 services must publish annual transparency reports and give users clear tools to report harm.
- Fraudulent advertising duty: large platforms must prevent paid-for scam ads reaching UK users.
Why the Online Safety Act Raises Privacy Concerns
Supporters of the Act argue it modernises outdated internet regulation. Critics — including the Open Rights Group, Big Brother Watch and encrypted messaging providers — argue that several provisions undermine the fundamental privacy of every UK internet user, not just bad actors.
1. The Encrypted Messaging Problem
Section 121 of the Act gives Ofcom the power to require platforms to use "accredited technology" to identify illegal content — including CSAM — in private messages. The problem: on end-to-end encrypted services like WhatsApp, Signal and iMessage, no one except the sender and recipient can read messages. Scanning them requires either breaking the encryption or installing client-side scanning software on your device.
Both approaches effectively create a backdoor. Signal's president Meredith Whittaker has said the company would leave the UK before compromising its encryption. Apple abandoned an earlier client-side scanning proposal after security researchers warned it could be repurposed for mass surveillance. The government has said it will not use the power "until it is technically feasible" — but the power itself remains on the statute book.
2. Mandatory Age Verification
To access adult content in the UK, users must now prove their age using methods such as photo ID upload, credit card checks, facial age estimation, or mobile network verification. Each of these requires handing sensitive personal data to a third-party age assurance provider.
The privacy risks are significant:
- Data breaches at age verification providers could expose exactly which adult sites a specific person visits.
- Facial age estimation involves biometric processing — a special category of personal data under UK GDPR.
- Historically, similar schemes (such as the abandoned 2019 porn block) collapsed partly over privacy fears.
3. Broader Data Collection by Default
To comply with the child safety duty, many platforms are now age-gating far more services than just adult content — including Reddit, X, Bluesky, and even Wikipedia has considered its position. This means millions of adults are being asked to verify their identity to access mainstream websites they previously used anonymously.
4. Chilling Effects on Free Expression
The Act does not directly criminalise speech, but it incentivises platforms to over-remove content to avoid Ofcom fines. Legal but controversial speech — political commentary, sex education, harm-reduction advice, journalism about difficult topics — can end up being removed as a precaution.
How the Act Compares to Other Regulations
The Online Safety Act sits alongside — and sometimes overlaps with — other major digital laws. Here is how it compares:
| Regulation | Region | Primary Focus | Privacy Impact |
|---|---|---|---|
| Online Safety Act 2023 | UK | Illegal + harmful content, child safety | High — affects encryption and anonymity |
| Digital Services Act (DSA) | EU | Platform accountability, transparency | Moderate — no encryption-scanning mandate |
| UK GDPR / Data Protection Act | UK | Personal data rights | Protective — grants user rights |
| Investigatory Powers Act | UK | State surveillance powers | High — bulk data collection |
| COPPA | US | Children's online privacy | Protective — for under-13s |
What the Act Means for Everyday UK Internet Users
Social Media Users
Expect more identity checks, more content moderation, and more removed posts. Some smaller platforms have simply blocked UK users rather than comply — the community forums LFGSS and microcosm shut down in late 2024 citing compliance costs. Others have added friction such as age gates or reduced anonymity.
Private Messengers
For now, WhatsApp, Signal and iMessage remain fully encrypted. But the legal power to compel scanning exists. Users concerned about long-term privacy should follow announcements from these providers carefully — if the government activates Section 121, some services may leave the UK market entirely.
Website Operators and Small Publishers
If you run a UK-facing website with user-generated content — even a small forum, blog comment section, or Discord server tied to your brand — you may fall within scope. Ofcom has published risk assessment templates, but many hobbyist operators have found compliance costs prohibitive.
Marketers and Link Sharers
The fraudulent advertising duty is pushing platforms to scrutinise links more heavily. Shortened URLs from low-reputation services are increasingly flagged or blocked. Using a reputable, transparent link shortener — one that publishes clear privacy policies and doesn't inject tracking — matters more than ever. Services like Lunyb focus on clean, privacy-respecting short links, which we've reviewed in more detail in our honest Lunyb review and compared against alternatives in our 2026 URL shortener buyer's guide.
Practical Steps to Protect Your Privacy Under the Act
You cannot opt out of the Online Safety Act, but you can reduce how much personal data is collected about you in the process of complying with it.
- Use encrypted messengers with disappearing messages. Signal, WhatsApp and iMessage remain end-to-end encrypted. Enable disappearing messages so past conversations aren't stored indefinitely.
- Switch to encrypted DNS. Services like Cloudflare 1.1.1.1, NextDNS or Quad9 stop your internet provider from logging every domain you visit. Configure DNS-over-HTTPS or DNS-over-TLS on your devices.
- Choose a privacy-focused browser. Firefox with strict tracking protection, Brave, or Mullvad Browser reduce fingerprinting and third-party tracking.
- Prefer age assurance methods that don't store ID. Where possible, choose age estimation providers that use "zero-knowledge" or ephemeral checks rather than uploading a passport or driving licence.
- Use unique email aliases. Services like SimpleLogin, Firefox Relay or Apple's Hide My Email let you register for age-gated services without exposing your real address.
- Review app permissions monthly. On iOS and Android, revoke camera, microphone, contacts and location access for apps that don't strictly need them.
- Exercise your UK GDPR rights. You have the right to access, correct and erase personal data held by UK-facing services. Age assurance providers must delete verification data promptly — ask them to confirm they have.
- Support digital rights organisations. Groups like the Open Rights Group and Big Brother Watch challenge disproportionate implementation of the Act.
The Ongoing Political Debate
The Online Safety Act was passed with cross-party support, but implementation has been contested. Ofcom has taken a relatively pragmatic approach, publishing codes of practice that give platforms some flexibility. However, campaigners argue that the underlying architecture — particularly the encryption-scanning power and the normalisation of ID checks — sets a dangerous precedent that other democracies may copy.
Future amendments are already being discussed, including proposals to raise the minimum age for social media to 16 (as Australia has legislated) and to add "legal but harmful" duties for adults, which were removed from the original Bill after free-speech concerns.
Will the Online Safety Act Actually Make the Internet Safer?
That depends on how you measure safety. There is genuine evidence that better content moderation reduces some harms — grooming, fraud, and coordinated abuse. There is also evidence that heavy-handed moderation drives harmful activity into less regulated spaces, and that age gates push teenagers toward services with weaker safeguards, not stronger ones.
The privacy trade-off is real. A safer internet built on the erosion of encryption and anonymous browsing is a fundamentally different internet — one where surveillance is the default, and trust in platforms depends on the goodwill of regulators and the security of third-party ID providers. That is a bargain UK users deserve to understand clearly.
Frequently Asked Questions
Does the Online Safety Act ban end-to-end encryption?
No, it does not ban encryption outright. However, Section 121 gives Ofcom the power to require platforms to scan messages for illegal content using "accredited technology." On encrypted services, this would effectively require breaking or bypassing encryption. The government has said the power will not be used until it is technically feasible to do so without weakening security — but the legal power exists.
Do I have to upload my passport to use social media in the UK?
Not usually. Age verification is mandatory for adult content sites and for services with a significant risk of children accessing harmful material. Many platforms offer alternative methods such as facial age estimation, mobile carrier checks, or credit card verification. Where possible, choose the method that stores the least data.
Can I be prosecuted for what I post under the Online Safety Act?
The Act primarily targets platforms, not individual users. However, it did introduce new user-facing criminal offences, including sending threatening or false communications, cyberflashing, and encouraging self-harm. Ordinary speech, opinion and criticism remain legal, though platforms may over-remove content to avoid regulatory risk.
Does the Act apply to small websites and personal blogs?
Potentially, if they allow user-generated content (comments, forums, uploads) and have UK users. Ofcom has scaled duties by size and risk, so a small personal blog with a comment section has far lighter obligations than a global social network. Still, all in-scope services must complete a risk assessment. Some small operators have chosen to close UK access rather than comply.
How can I share links privately without falling foul of new advertising rules?
Use reputable, transparent link shorteners with clear privacy policies, avoid embedding trackers, and be honest about where links lead. Platforms are increasingly filtering suspicious short URLs to comply with the fraudulent advertising duty, so choose a service that is well-known and trusted. Our 2026 comparison of link shorteners covers which providers score best on privacy and deliverability.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to notify the OAIC and affected individuals when a breach is likely to cause serious harm. This guide covers obligations, timelines, penalties up to AUD $50 million, and how to build a compliant response plan.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces enforceable individual rights, a fair and reasonable test, and tough new penalties. Learn how the reforms affect you, how to exercise your rights, and what organisations must do to comply.
ePrivacy Regulations Ireland: Latest Updates for 2026
Ireland's ePrivacy Regulations govern cookies, direct marketing, and electronic communications privacy. This 2026 guide covers the latest DPC enforcement trends, cookie consent rules, direct marketing obligations, and a practical compliance checklist for Irish businesses.