UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act is one of the most sweeping pieces of internet regulation Britain has ever introduced. Passed in October 2023 and now being enforced in phases by Ofcom, it promises to make the UK "the safest place in the world to be online" — but it also raises serious questions about privacy, encryption, and how much the government can see of what you say and do on the internet.
If you use WhatsApp, Signal, social media, dating apps, or even visit adult websites from a UK IP address, this law affects you. This guide explains exactly what the Online Safety Act does, what it means for your personal privacy, and the practical steps you can take to protect your data in 2026.
What Is the UK Online Safety Act?
The UK Online Safety Act 2023 is a law that imposes new duties of care on online platforms to protect users — particularly children — from illegal and harmful content. Ofcom, the UK's communications regulator, is responsible for enforcement and can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.
The Act applies to any service accessible in the UK, regardless of where the company is based. That means American tech giants, European start-ups, and Asian platforms all have to comply if they have British users.
Who Does the Act Apply To?
- User-to-user services: Social networks, messaging apps, forums, dating apps.
- Search services: Google, Bing, DuckDuckGo and similar.
- Pornography providers: Any site publishing adult content.
- Category 1 services: The largest, highest-risk platforms with additional duties.
Key Dates and Enforcement Timeline
- October 2023 — Act receives Royal Assent.
- Late 2024 — Illegal content codes published by Ofcom.
- March 2025 — Platforms must complete illegal harms risk assessments.
- July 2025 — Age assurance requirements come into force for adult sites.
- 2026 onwards — Full enforcement, including Category 1 duties and transparency reporting.
How the Online Safety Act Affects Your Privacy
While the law is framed around safety, many of its mechanisms require platforms to collect more data about users, scan more content, and verify more identities. Each of these creates privacy trade-offs.
1. Mandatory Age Verification
Any website hosting pornography, and many platforms allowing user-generated adult content, must now use "highly effective age assurance." Acceptable methods include:
- Credit card checks
- Photo-ID matching (uploading a passport or driving licence)
- Facial age estimation using selfies
- Mobile network operator age checks
- Open banking verification
Each method hands sensitive data — often a government-issued ID or biometric scan — to a third-party verification provider. Even when platforms use "double-blind" tokens, the verification companies themselves become attractive targets for hackers. The 2024 breaches of several ID-check vendors have already demonstrated the risk.
2. Pressure on End-to-End Encryption
Section 121 of the Act gives Ofcom the power to require services to use "accredited technology" to scan private messages for child sexual abuse material (CSAM) and terrorism content. In practice, this would mean client-side scanning — software on your phone that inspects messages before they are encrypted.
Signal, WhatsApp, and iMessage have all publicly stated they would withdraw from the UK rather than weaken encryption. The government responded by saying the power would only be used when "technically feasible," which currently it is not. But the legal power remains on the books, and that uncertainty itself is a privacy concern.
3. More Content Moderation Means More Monitoring
To meet their duties, platforms must proactively detect illegal content. That requires more automated scanning of posts, images, and even links you share. Many services are expanding their behavioural analytics, keyword monitoring, and image hashing — all of which involve processing user data at a larger scale than before.
4. Identity and Account Verification for Adults
Category 1 services (the biggest platforms) must offer users the option to verify their identity and to filter out non-verified accounts. In theory, verification is optional. In practice, if everyone else is verifying, unverified users become second-class citizens — pressured to hand over ID to participate fully.
Comparing Pre- and Post-Act Privacy Expectations
| Area | Before the Act | Under the Online Safety Act |
|---|---|---|
| Access to adult sites | Self-declared age | ID or biometric age check required |
| Private messaging | End-to-end encrypted, no scanning | Legal power exists to require scanning |
| Social media accounts | Pseudonymous allowed freely | Pressure to verify identity on Category 1 sites |
| Content moderation | Reactive, user reports | Proactive detection and risk assessments |
| Data shared with third parties | Advertising and analytics | Add age-check vendors, moderation AI providers |
| Regulator oversight | Limited to ICO (data) and ASA (ads) | Ofcom with enforcement powers up to 10% of turnover |
The Pros and Cons for UK Users
Pros
- Clearer legal obligations on platforms to remove illegal content quickly.
- Stronger protections for children against grooming, self-harm content, and inappropriate material.
- Transparency reports that let researchers and journalists examine platform behaviour.
- A UK regulator (Ofcom) that British users can complain to directly.
- Potentially fewer scam ads and fraudulent accounts on major platforms.
Cons
- Age verification creates new honeypots of sensitive personal data.
- Legal powers to undermine end-to-end encryption remain in reserve.
- Smaller platforms and open-source projects may exit the UK due to compliance costs.
- Pseudonymity — important for whistleblowers, abuse survivors, LGBTQ+ users — is weakened.
- Overblocking: platforms may remove lawful content to stay safe from fines.
Practical Steps to Protect Your Privacy Under the Act
You can comply with the law and still take sensible steps to minimise your digital footprint. Here is a practical checklist for UK users in 2026.
- Choose age-verification methods that share the least data. Open banking checks and mobile operator verification generally share less than uploading your passport. Prefer providers certified under the Age Check Certification Scheme (ACCS).
- Use encrypted messaging apps that have publicly committed to resisting scanning. Signal remains the gold standard; WhatsApp also uses the Signal protocol.
- Switch to encrypted DNS. Services like Cloudflare 1.1.1.1 or NextDNS encrypt your DNS queries so your ISP cannot see which domains you visit.
- Use a privacy-respecting browser. Firefox with strict tracking protection, Brave, or Mullvad Browser block many of the trackers used in moderation and advertising pipelines.
- Separate your identities. Keep your verified, real-name account for banking and official services, and use a pseudonymous email alias (SimpleLogin, AnonAddy, Apple Hide My Email) for forums and social media.
- Shorten and track links carefully. When sharing links publicly, use a URL shortener you trust not to leak your IP or sell click data. Lunyb is a privacy-focused option built specifically for users who want analytics without surveillance-grade tracking.
- Review app permissions quarterly. Revoke access from apps you no longer use, especially those with camera, microphone, or contacts permissions.
- Exercise your GDPR rights. The Act does not replace the UK GDPR. You still have the right to access, delete, and port your personal data from any platform.
What the Act Does Not Do
It is easy to misread the headlines. For clarity, the Online Safety Act does not:
- Give the police direct access to your messages.
- Ban end-to-end encryption outright.
- Require you to verify your identity on every website.
- Replace the Investigatory Powers Act or UK GDPR — those still apply separately.
- Criminalise ordinary users for lawful speech (though some speech-related offences from the Act do apply, like sending threatening communications).
How Businesses and Content Creators Should Respond
If you run a website, newsletter, Discord server, or small platform with UK users, you may fall within scope. The threshold is low: a forum with user-to-user messaging qualifies.
Minimum Compliance Checklist
- Complete an illegal harms risk assessment and document it.
- Publish clear terms of service explaining how you handle illegal content.
- Provide an easy reporting mechanism for users.
- Keep records of moderation decisions for Ofcom audits.
- If you host adult content, implement highly effective age assurance.
- Update your privacy policy to reflect any new data shared with age or moderation vendors.
Marketers and creators who rely on short links for campaigns should also ensure their link infrastructure is compliant and transparent. A privacy-first shortener gives you click analytics without the regulatory baggage of overcollecting personal data. If you are evaluating options, our 2026 URL shortener buyer's guide compares the leading tools on privacy, pricing, and features, and our Rebrandly review looks at one of the most popular enterprise options.
The Bigger Picture: Safety vs Privacy
The Online Safety Act reflects a genuine policy dilemma. Child protection groups, bereaved families, and law enforcement argue that platforms have failed to self-regulate and that stronger duties are overdue. Privacy advocates, security researchers, and encrypted-messaging providers argue that weakening encryption or forcing mass ID checks creates risks that outweigh the benefits.
Both camps are partially right. What matters now is how Ofcom uses its discretion. Codes of practice, enforcement priorities, and the willingness to accept privacy-preserving technologies will determine whether the Act becomes a model for the world or a cautionary tale. Users should pay attention to Ofcom consultations and respond — the regulator genuinely does read submissions from individuals.
Frequently Asked Questions
Does the UK Online Safety Act apply to foreign websites?
Yes. The Act applies to any service with a significant number of UK users or that targets the UK market, regardless of where the company is based. Non-compliant foreign platforms can be fined, have payment services withdrawn, or ultimately be blocked by UK internet providers.
Will I have to upload my passport to use social media?
Not in most cases. General social media use does not require identity verification. However, if you want to access adult content, use certain age-restricted features, or opt into "verified only" filters on Category 1 platforms, you will need to complete an age or identity check through an approved provider.
Is end-to-end encryption now illegal in the UK?
No. End-to-end encryption remains legal and widely used. The Act contains a reserve power to require scanning technology, but the government has said it will not use that power until it is "technically feasible" to do so without compromising encryption — which experts generally agree is not currently possible.
Can I be fined personally for breaking the Online Safety Act?
The Act's fines target platforms, not individual users. However, it did introduce new criminal offences — such as sending threatening communications, cyberflashing, and encouraging self-harm — that can lead to prosecution of individuals under existing criminal law.
How can I minimise the personal data I share when verifying my age?
Prefer verification methods that use tokenised, double-blind systems where the website never sees your ID and the verifier never sees which site you visited. Open banking and mobile network operator checks typically share less data than uploading a photo of your passport. Always check whether the provider is certified under the Age Check Certification Scheme (ACCS) and read its data retention policy before proceeding.
Final Thoughts
The UK Online Safety Act is here to stay, and in 2026 its practical effects on everyday browsing are becoming impossible to ignore. The best response is informed participation: understand what the law actually requires, pick tools and platforms that respect your data, and use your GDPR rights when things go wrong. Safety and privacy are not opposites — but defending both takes active choices from users, platforms, and regulators alike.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland powerful rights over their personal data, from access and erasure to portability and objection. This guide explains each right in plain English, how to enforce it through the Data Protection Commission, and practical steps to protect your privacy online.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.