facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··10 min read

The UK Online Safety Act (OSA) is one of the most sweeping pieces of internet legislation ever passed in Britain. Marketed as a law to protect children and remove harmful content, it also introduces powers that could reshape how private your online life really is. If you use social media, messaging apps, search engines or even niche forums, this legislation touches you.

This guide breaks down what the Online Safety Act actually says, what it means for your personal privacy, and the practical steps UK users can take to stay in control of their data.

What Is the UK Online Safety Act?

The Online Safety Act 2023 is a UK law that places legal duties on online platforms to protect users, especially children, from illegal and harmful content. It is enforced by Ofcom, which can issue fines of up to £18 million or 10% of global annual turnover, whichever is greater.

The Act covers a huge range of services: social networks, video-sharing platforms, search engines, dating apps, cloud storage, messaging services, gaming platforms and pornography sites. Even smaller UK forums and community sites fall within scope if they host user-generated content.

Key Duties Introduced by the Act

  1. Illegal content duties: Platforms must proactively prevent users from encountering illegal material such as terrorism content, child sexual abuse material (CSAM), fraud and revenge porn.
  2. Child safety duties: Services likely to be accessed by children must protect them from pornography, self-harm content, bullying and other legally defined harms.
  3. Age assurance: Sites hosting adult content must implement "highly effective" age verification.
  4. Transparency reporting: Large platforms must publish annual reports on their moderation practices.
  5. User empowerment tools: Category 1 services must give adults tools to filter content and verify other users.

Why Privacy Advocates Are Worried

On the surface, protecting children and removing illegal content is uncontroversial. The concerns come from how the Act requires platforms to meet those duties. Several provisions create tension between safety goals and the privacy of ordinary users.

1. The Encryption Question

Section 121 of the Act allows Ofcom to require providers to use "accredited technology" to identify CSAM or terrorism content in private communications. In practice, that could mean scanning messages before they are encrypted, a technique known as client-side scanning.

End-to-end encryption is the reason services like Signal, WhatsApp and iMessage can promise that no one, not even the provider, can read your messages. Client-side scanning would place monitoring software directly on your device, effectively breaking that promise even if the encryption itself remains technically intact.

The government has said the power will not be used until the technology is "technically feasible" without compromising privacy. Critics, including Signal and Apple, argue such technology cannot exist safely, because any scanning system creates a backdoor that could be exploited by criminals or foreign governments.

2. Age Verification and Identity Data

Adult sites and any platform likely to be accessed by children now need robust age checks. This is not a simple tick-box; Ofcom expects methods such as:

  • Photo ID matching (uploading a passport or driving licence)
  • Facial age estimation using selfie video
  • Credit card or bank-based verification
  • Mobile network operator age checks
  • Digital identity wallets

Every one of these methods means sharing sensitive personal data, often with third-party verification vendors. The more sites that require age assurance, the more copies of your ID exist across the internet, each one a potential breach waiting to happen.

3. Expanded Data Retention

To demonstrate compliance, platforms must keep more logs: who saw what, when moderation decisions were made, how age checks were performed, and how complaints were handled. More retained data means a larger attack surface if a company is hacked, and more information available to authorities via legal requests.

4. Chilling Effects on Anonymous Speech

Although the Act does not ban anonymity, the "user verification" duty on Category 1 platforms pushes services to offer verified badges and allow users to filter out unverified accounts. Over time, this could marginalise pseudonymous users, including whistleblowers, abuse survivors, LGBTQ+ people in unsafe circumstances and political activists.

How the Act Affects Everyday UK Users

Most people will notice the Online Safety Act through small but significant changes to how they use the internet.

More Age Gates

Expect to be asked to prove your age on more sites than ever before, not just adult content but also alcohol retailers, gambling services, some social platforms and dating apps. Some overseas services have chosen to block UK visitors entirely rather than comply, reducing the range of sites available to British users.

More Content Removals

Platforms face heavy penalties for missing illegal content, so many err on the side of over-removal. Legal but controversial posts, satire, journalism and educational content about sensitive topics can be caught by automated moderation. Appeals processes exist but are often slow.

Fewer Small Communities

Compliance is expensive. Small UK forums, hobbyist communities and independent platforms have already shut down rather than face the cost and legal risk of complying. This concentrates online life around a few large platforms, which itself is a privacy concern.

Changes to Messaging Apps

If Ofcom eventually invokes its scanning powers, some encrypted messengers have said they will withdraw from the UK market rather than weaken their product. That would leave UK users on less secure alternatives.

Ofcom's Role and Enforcement Powers

Ofcom is the regulator responsible for enforcing the Act. Its powers are substantial and worth understanding.

PowerWhat It Means
FinesUp to £18m or 10% of global turnover
Business disruption measuresCourt orders requiring ISPs and payment providers to cut off non-compliant services
Information noticesLegal demands for internal data, algorithms and moderation records
Senior manager liabilityNamed executives can face criminal charges for failing to comply with information requests
Technology noticesPower to require use of accredited scanning technology

Ofcom's Codes of Practice

Ofcom has published detailed codes of practice explaining how platforms can meet their duties. Following the codes gives a "safe harbour" from enforcement. This effectively makes Ofcom the arbiter of acceptable moderation practices across the UK internet.

Practical Steps to Protect Your Privacy

You cannot opt out of the Online Safety Act, but you can reduce how much personal data you expose in the new compliance-heavy internet.

1. Minimise Age Verification Exposure

  • Where possible, choose age assurance methods that do not require uploading government ID. Facial age estimation from reputable providers typically deletes the image after processing.
  • Look for services that use a digital identity wallet, so the actual document is only shared once with a trusted issuer.
  • Check whether the site uses a certified third-party verifier rather than storing your ID themselves.

2. Use Privacy-Respecting Browsers and DNS

Independent of the Act, using a privacy-focused browser like Firefox or Brave, enabling encrypted DNS (DNS over HTTPS) and blocking third-party trackers reduces the amount of behavioural data collected about you as you comply with new age gates and content controls.

3. Separate Your Identities

Use different email addresses for different purposes: one for verified accounts that require ID, one for shopping, one for newsletters. Email aliasing services make this easy and prevent data brokers from correlating your activity across sites.

4. Be Careful What You Share on Public Platforms

With more moderation logs and retained data, assume that anything you post to a large platform may be reviewed, stored and disclosed under legal process. Sensitive conversations belong in end-to-end encrypted apps, at least until that protection is compromised.

5. Use Trusted Link Shorteners for Sharing

When sharing links, especially in professional or public contexts, use a shortener that respects privacy and offers analytics you control. Lunyb is a privacy-conscious URL shortener that does not sell click data to advertisers, which is a meaningful difference given how much data-brokering exists around link tracking. You can read an independent take in our honest Lunyb review or compare options in the 2026 URL shortener buyer's guide.

6. Support Encrypted Services

Continue using and paying for end-to-end encrypted messaging and email. Public and commercial support for these services strengthens the case against mandatory scanning powers being activated.

What Businesses and Site Owners Should Do

If you run a UK-facing website, blog or forum that allows any user-generated content, the Act likely applies to you. Even comment sections count. Practical priorities:

  1. Assess your risk: Complete Ofcom's illegal content and children's risk assessments. Templates are available on Ofcom's website.
  2. Update terms and moderation policies: Make rules clear, publish how users can report content, and document your response times.
  3. Implement reporting tools: Provide an obvious way for users to flag illegal content.
  4. Keep records: Log moderation decisions and risk assessment reviews. Ofcom can ask to see them.
  5. Review data minimisation: Ironically, holding less user data helps you comply with UK GDPR while still meeting OSA logging duties. Only retain what is necessary.

The Bigger Picture: Safety vs Privacy

The Online Safety Act reflects a genuine dilemma. Illegal content, especially CSAM and terrorist material, causes real harm and platforms have historically been too slow to act. At the same time, the tools proposed to fight that content, mass scanning, mandatory age verification and expanded surveillance, weaken the privacy protections that keep every other user safe.

History suggests that once surveillance infrastructure exists, its scope tends to grow. Powers introduced for one purpose are frequently extended to others. That is why civil liberties groups such as Open Rights Group, Big Brother Watch and the Electronic Frontier Foundation have been so vocal, even while acknowledging the harms the Act aims to address.

What to Watch in 2026 and Beyond

  • Ofcom's technology notices: If and when Section 121 powers are used against encrypted services, expect legal challenges.
  • Age assurance rollout: Watch which methods become dominant and how well they protect the data they collect.
  • Judicial review outcomes: Several aspects of the Act are likely to face court challenges under the Human Rights Act.
  • EU alignment: The EU's Digital Services Act takes a different, more transparency-focused approach; comparisons will influence future UK reforms.

FAQ

Does the UK Online Safety Act ban end-to-end encryption?

No, it does not ban encryption directly. However, Section 121 gives Ofcom the power to require platforms to use "accredited technology" to detect illegal content, which in practice could mean client-side scanning that undermines end-to-end encryption. The government has said the power will not be used until it is technically possible without compromising privacy, but that condition is contested by security experts.

Will I have to upload my passport to use social media?

Not for general social media use, but you may need to verify your age for adult content, gambling, alcohol sales and some features on larger platforms. Verification does not always require uploading ID; facial age estimation, mobile operator checks and digital identity wallets are alternatives that share less data.

Does the Online Safety Act apply to overseas websites?

Yes, if a service has a significant number of UK users or targets the UK market, it falls within scope regardless of where it is based. Ofcom can seek business disruption measures against non-compliant overseas services, including blocking payments and requiring ISPs to restrict access.

Can Ofcom read my private messages?

Not directly. Ofcom is a regulator, not a law enforcement agency. However, its powers to compel platforms to deploy scanning technology could indirectly result in message content being analysed on your device. Existing law enforcement access via warrants and interception powers is separate from the OSA.

What happens to small UK forums under the Act?What happens to small UK forums under the Act?

Small forums with user-generated content are in scope but face lighter duties than large platforms. They still need to complete risk assessments, offer reporting tools and act on illegal content. Some have chosen to close or move overseas due to compliance costs. Ofcom has published simplified guidance for small services to help them comply proportionately.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles