UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most far-reaching pieces of internet legislation ever passed in Britain. Marketed as a landmark law to protect children and clamp down on illegal content, it also introduces sweeping new duties for platforms, sweeping new powers for Ofcom, and a set of privacy trade-offs that every UK internet user should understand.
This guide breaks down what the Act actually says, how it changes your day-to-day browsing, what it means for encrypted messaging, and the practical steps you can take to keep your personal data private in a post-Online-Safety-Act Britain.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that regulates online platforms, search engines and messaging services accessible to UK users, requiring them to reduce the risk of illegal and harmful content. It came into force in stages from 2024 onward, with the majority of duties enforced by the communications regulator, Ofcom.
The Act covers three broad categories of service:
- User-to-user services such as social networks, forums and messaging apps.
- Search services like Google, Bing and specialist search engines.
- Services publishing pornographic content, which face specific age-assurance duties.
Any service with a "significant number of UK users" or that targets the UK market falls within scope — regardless of where the company is based. That means US, EU and Asian platforms must comply if UK users can access them.
The Core Duties Imposed on Platforms
At the heart of the Act are three overlapping duties:
- Illegal content duty: Platforms must proactively identify and remove content related to terrorism, child sexual abuse material (CSAM), fraud, and a growing list of priority offences.
- Child safety duty: Services likely to be accessed by children must use age assurance and reduce exposure to harmful (though legal) content such as self-harm promotion, pornography, and eating-disorder content.
- Transparency and risk assessment duty: Platforms must publish risk assessments and cooperate with Ofcom audits.
Fines for non-compliance can reach £18 million or 10% of global annual turnover — whichever is higher — and senior managers can face criminal liability in serious cases.
How the Online Safety Act Impacts Your Privacy
While the Act's stated aims are safety-focused, several of its mechanisms have direct consequences for personal privacy. The most significant are age verification, content scanning, and expanded data retention.
1. Mandatory Age Verification
Any site hosting adult content, and many mainstream platforms accessible to children, must now implement "highly effective" age assurance. In practice, this often means:
- Uploading a photo of your passport, driving licence or national ID.
- Submitting a live selfie for facial age estimation.
- Linking a credit card, mobile operator record or open-banking check.
- Using a third-party "digital identity wallet" that vouches for your age.
Even when providers claim they don't store your ID document, the process itself creates new data flows, new databases, and new breach targets. History shows that identity-verification vendors are attractive to attackers, and a leak of "users of adult site X" is far more damaging than a leak of ordinary account credentials.
2. Pressure on End-to-End Encryption
Section 121 of the Act gives Ofcom the power to require messaging providers to use "accredited technology" to detect CSAM, even in private communications. Although the government has said the power will only be used when "technically feasible", major platforms including Signal and WhatsApp warned they would rather withdraw from the UK than weaken end-to-end encryption.
The practical concern is client-side scanning: software that inspects your messages, photos or files on your own device before they are encrypted and sent. Privacy advocates argue this effectively turns every phone into a surveillance endpoint, undermining the guarantees that make encrypted messaging useful in the first place.
3. Expanded Logging and Data Retention
To demonstrate compliance, platforms are keeping richer logs of user behaviour: what content you viewed, what you reported, how long you spent on certain pages, and the outcomes of age checks. These logs may be shared with Ofcom under formal information notices or in response to law-enforcement requests.
The result is a quiet expansion of the data trail every UK internet user leaves behind — even on services that previously prided themselves on being minimal-data.
Who Is Affected — And Who Isn't
The Act's scope is broad, but it isn't universal. Understanding who is covered helps you make informed choices about where you spend your time online.
| Service Type | In Scope? | Key Obligations |
|---|---|---|
| Large social networks (Meta, TikTok, X) | Yes — Category 1 | Full risk assessments, transparency reports, adult-user empowerment tools |
| Search engines | Yes — Category 2A | Illegal content duty, child safety duty |
| Messaging apps (WhatsApp, Signal, iMessage) | Yes | Illegal content duty; possible scanning notices |
| Adult content sites | Yes | Highly effective age assurance |
| Small forums, hobby communities | Often yes | Proportionate illegal content duties |
| Email providers, internal business tools, one-to-one voice/video calls | Largely exempt | Limited or no duties |
| News publishers with comment sections | Comments exempt; site partially exempt | Reduced obligations under "recognised news publisher" carve-out |
The Trade-offs: Safety vs. Privacy
The Online Safety Act sits at a genuinely difficult intersection. Reducing exposure to CSAM, fraud and terror content is a legitimate public interest, and some of the Act's provisions — like clearer complaint routes and mandatory transparency reporting — are unambiguously positive. The privacy concerns come from the mechanisms used to achieve those goals.
Pros of the Act
- Clearer legal duties on platforms to remove illegal content quickly.
- Stronger protection for children from grooming and harmful material.
- Meaningful fines that make compliance a boardroom issue, not just a policy issue.
- Requirement for platforms to publish transparency reports.
- User-empowerment tools (filters, blocklists) on the largest platforms.
Cons and Privacy Risks
- Age verification creates new honeypots of sensitive identity data.
- Encryption-scanning powers may weaken the security of private messaging.
- Smaller communities may shut down rather than absorb compliance costs, reducing internet diversity.
- Increased logging expands the surveillance surface for every user.
- Definitions of "harmful" content risk over-removal of legitimate speech.
Practical Steps to Protect Your Privacy Under the Act
You can't opt out of the Online Safety Act, but you can shape how much personal data you expose while complying with it. The following steps are legal, straightforward, and appropriate for ordinary users.
1. Choose Privacy-Respecting Age Verification Methods
Where a site offers multiple age-assurance options, prefer methods that share the least data. "Attribute-only" digital identity wallets that confirm "user is over 18" without revealing your name, date of birth or document number are the strongest option. Avoid uploading raw copies of passports or driving licences whenever an alternative exists.
2. Use Encrypted DNS and a Privacy-Focused Browser
Encrypted DNS (DNS over HTTPS or DNS over TLS) prevents your internet provider from easily building a browsing profile from your lookups. Combine this with a privacy-focused browser such as Firefox, Brave or LibreWolf, and enable tracker blocking. This reduces the amount of metadata generated by your everyday browsing, independent of any platform's own logging.
3. Minimise Account Linking
Avoid logging into unrelated services with a single social account. Every "Sign in with Google/Facebook" button ties another data source to your identity — data that may now be retained longer under compliance obligations. Use unique email aliases where possible, and consider a password manager to make separate accounts practical.
4. Be Careful With Link Sharing
Links you share on social media, in group chats and on forums may be logged, scanned and analysed by platforms responding to their duties under the Act. If you run a newsletter, community or small business and want to share links without exposing raw destination URLs — or without leaking analytics to third-party trackers — use a privacy-respecting link shortener. Tools like Lunyb let you create clean, branded short links with transparent analytics and no invasive tracking scripts. You can read our honest review of Lunyb or compare alternatives in our 2026 buyer's guide to URL shorteners.
5. Review App Permissions Regularly
On both iOS and Android, revisit which apps have access to your photos, contacts, microphone and location. Platforms subject to child-safety duties may request expanded permissions to power age-estimation or content-moderation features. Grant only what is essential.
6. Keep Up With Ofcom's Codes of Practice
Ofcom publishes and periodically updates codes of practice explaining how platforms should meet their duties. These documents also reveal what platforms are being asked to collect and retain — useful intelligence for anyone making informed choices about which services to use.
What the Act Means for Small Publishers, Creators and Businesses
If you run a website with user-generated content — comments, forums, reviews, community chat — you may fall within scope, even as a hobbyist. Ofcom has emphasised proportionality, but the baseline still requires:
- A written risk assessment covering illegal content risks.
- Clear terms of service explaining how you handle reports.
- Accessible reporting and complaint mechanisms.
- Records demonstrating you have acted on reports.
For creators sharing links across platforms, one small operational change makes a big difference: consolidate your outbound links behind a single, trustworthy short-link service. That gives you a clean audit trail, the ability to update destinations if content becomes non-compliant, and reduced exposure to third-party tracking scripts. Branded links from services like Lunyb or Rebrandly also help audiences trust what they're clicking — an underrated safety feature in itself.
The Future: Amendments, Court Challenges and International Ripples
The Online Safety Act is not a finished document. Several provisions are still being consulted on, and Ofcom is expected to publish further codes throughout 2026. Legal challenges — particularly around the encryption-scanning powers and freedom-of-expression concerns — are already being prepared by civil-liberties groups.
Internationally, the Act is influencing similar debates in Australia, Canada and the EU, where regulators are watching to see whether the UK's approach delivers meaningful safety gains without collapsing the security guarantees ordinary users rely on. Whichever way that debate goes, one thing is clear: the era of assuming your online activity is unlogged, unmoderated and unregulated is firmly over.
Frequently Asked Questions
Does the UK Online Safety Act apply to me if I only use foreign websites?
Yes. The Act applies to any service with a significant UK user base or that targets UK users, regardless of where the company is based. Foreign social networks, forums and adult sites accessible from the UK must comply or risk being blocked by Ofcom.
Will I have to show ID to use social media?
Not for every service, but many platforms likely to be accessed by children will need to use age assurance. This can range from facial age estimation (which doesn't require ID) to full document verification. You will usually have a choice of methods; pick the one that shares the least personal data.
Does the Act break end-to-end encryption?
Not directly. The Act allows Ofcom to require content-scanning technology in messaging apps, but only where "technically feasible". The government has stated the power will not be used until such technology exists without weakening encryption. Critics argue that condition may never truly be met, and the powers remain on the statute book.
Can I be prosecuted for what I post under the Act?
The Act creates new communications offences, including sending false information intended to cause non-trivial harm, threatening communications, and cyberflashing. Most everyday posting is unaffected, but sharing illegal content, harassment, or fraud material can now be prosecuted more easily.
What is the best way to stay private online in the UK today?
Combine several small habits: use encrypted DNS, choose a privacy-respecting browser, prefer attribute-only age verification, minimise account linking, and use tools that don't track you unnecessarily — including privacy-friendly link shorteners for anything you share publicly. No single tool solves the problem, but layered choices meaningfully reduce your exposure.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, introduces the CPPA, a new privacy tribunal, and AIDA to modernize privacy and regulate AI. Learn what it means for Canadian businesses and consumers, how it compares globally, and how to prepare.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.