facebook-pixel

UK Online Safety Act: What It Means for Your Privacy

L
Lunyb Security Team
··9 min read

The UK Online Safety Act is one of the most sweeping pieces of internet regulation Britain has ever introduced. Passed in October 2023 and now being enforced in phases by Ofcom, it promises to make the UK "the safest place in the world to be online" — but it also raises serious questions about privacy, encryption, and how much the government can see of what you say and do on the internet.

If you use WhatsApp, Signal, social media, dating apps, or even visit adult websites from a UK IP address, this law affects you. This guide explains exactly what the Online Safety Act does, what it means for your personal privacy, and the practical steps you can take to protect your data in 2026.

What Is the UK Online Safety Act?

The UK Online Safety Act 2023 is a law that imposes new duties of care on online platforms to protect users — particularly children — from illegal and harmful content. Ofcom, the UK's communications regulator, is responsible for enforcement and can fine companies up to £18 million or 10% of global annual turnover, whichever is higher.

The Act applies to any service accessible in the UK, regardless of where the company is based. That means American tech giants, European start-ups, and Asian platforms all have to comply if they have British users.

Who Does the Act Apply To?

  • User-to-user services: Social networks, messaging apps, forums, dating apps.
  • Search services: Google, Bing, DuckDuckGo and similar.
  • Pornography providers: Any site publishing adult content.
  • Category 1 services: The largest, highest-risk platforms with additional duties.

Key Dates and Enforcement Timeline

  1. October 2023 — Act receives Royal Assent.
  2. Late 2024 — Illegal content codes published by Ofcom.
  3. March 2025 — Platforms must complete illegal harms risk assessments.
  4. July 2025 — Age assurance requirements come into force for adult sites.
  5. 2026 onwards — Full enforcement, including Category 1 duties and transparency reporting.

How the Online Safety Act Affects Your Privacy

While the law is framed around safety, many of its mechanisms require platforms to collect more data about users, scan more content, and verify more identities. Each of these creates privacy trade-offs.

1. Mandatory Age Verification

Any website hosting pornography, and many platforms allowing user-generated adult content, must now use "highly effective age assurance." Acceptable methods include:

  • Credit card checks
  • Photo-ID matching (uploading a passport or driving licence)
  • Facial age estimation using selfies
  • Mobile network operator age checks
  • Open banking verification

Each method hands sensitive data — often a government-issued ID or biometric scan — to a third-party verification provider. Even when platforms use "double-blind" tokens, the verification companies themselves become attractive targets for hackers. The 2024 breaches of several ID-check vendors have already demonstrated the risk.

2. Pressure on End-to-End Encryption

Section 121 of the Act gives Ofcom the power to require services to use "accredited technology" to scan private messages for child sexual abuse material (CSAM) and terrorism content. In practice, this would mean client-side scanning — software on your phone that inspects messages before they are encrypted.

Signal, WhatsApp, and iMessage have all publicly stated they would withdraw from the UK rather than weaken encryption. The government responded by saying the power would only be used when "technically feasible," which currently it is not. But the legal power remains on the books, and that uncertainty itself is a privacy concern.

3. More Content Moderation Means More Monitoring

To meet their duties, platforms must proactively detect illegal content. That requires more automated scanning of posts, images, and even links you share. Many services are expanding their behavioural analytics, keyword monitoring, and image hashing — all of which involve processing user data at a larger scale than before.

4. Identity and Account Verification for Adults

Category 1 services (the biggest platforms) must offer users the option to verify their identity and to filter out non-verified accounts. In theory, verification is optional. In practice, if everyone else is verifying, unverified users become second-class citizens — pressured to hand over ID to participate fully.

Comparing Pre- and Post-Act Privacy Expectations

AreaBefore the ActUnder the Online Safety Act
Access to adult sitesSelf-declared ageID or biometric age check required
Private messagingEnd-to-end encrypted, no scanningLegal power exists to require scanning
Social media accountsPseudonymous allowed freelyPressure to verify identity on Category 1 sites
Content moderationReactive, user reportsProactive detection and risk assessments
Data shared with third partiesAdvertising and analyticsAdd age-check vendors, moderation AI providers
Regulator oversightLimited to ICO (data) and ASA (ads)Ofcom with enforcement powers up to 10% of turnover

The Pros and Cons for UK Users

Pros

  • Clearer legal obligations on platforms to remove illegal content quickly.
  • Stronger protections for children against grooming, self-harm content, and inappropriate material.
  • Transparency reports that let researchers and journalists examine platform behaviour.
  • A UK regulator (Ofcom) that British users can complain to directly.
  • Potentially fewer scam ads and fraudulent accounts on major platforms.

Cons

  • Age verification creates new honeypots of sensitive personal data.
  • Legal powers to undermine end-to-end encryption remain in reserve.
  • Smaller platforms and open-source projects may exit the UK due to compliance costs.
  • Pseudonymity — important for whistleblowers, abuse survivors, LGBTQ+ users — is weakened.
  • Overblocking: platforms may remove lawful content to stay safe from fines.

Practical Steps to Protect Your Privacy Under the Act

You can comply with the law and still take sensible steps to minimise your digital footprint. Here is a practical checklist for UK users in 2026.

  1. Choose age-verification methods that share the least data. Open banking checks and mobile operator verification generally share less than uploading your passport. Prefer providers certified under the Age Check Certification Scheme (ACCS).
  2. Use encrypted messaging apps that have publicly committed to resisting scanning. Signal remains the gold standard; WhatsApp also uses the Signal protocol.
  3. Switch to encrypted DNS. Services like Cloudflare 1.1.1.1 or NextDNS encrypt your DNS queries so your ISP cannot see which domains you visit.
  4. Use a privacy-respecting browser. Firefox with strict tracking protection, Brave, or Mullvad Browser block many of the trackers used in moderation and advertising pipelines.
  5. Separate your identities. Keep your verified, real-name account for banking and official services, and use a pseudonymous email alias (SimpleLogin, AnonAddy, Apple Hide My Email) for forums and social media.
  6. Shorten and track links carefully. When sharing links publicly, use a URL shortener you trust not to leak your IP or sell click data. Lunyb is a privacy-focused option built specifically for users who want analytics without surveillance-grade tracking.
  7. Review app permissions quarterly. Revoke access from apps you no longer use, especially those with camera, microphone, or contacts permissions.
  8. Exercise your GDPR rights. The Act does not replace the UK GDPR. You still have the right to access, delete, and port your personal data from any platform.

What the Act Does Not Do

It is easy to misread the headlines. For clarity, the Online Safety Act does not:

  • Give the police direct access to your messages.
  • Ban end-to-end encryption outright.
  • Require you to verify your identity on every website.
  • Replace the Investigatory Powers Act or UK GDPR — those still apply separately.
  • Criminalise ordinary users for lawful speech (though some speech-related offences from the Act do apply, like sending threatening communications).

How Businesses and Content Creators Should Respond

If you run a website, newsletter, Discord server, or small platform with UK users, you may fall within scope. The threshold is low: a forum with user-to-user messaging qualifies.

Minimum Compliance Checklist

  1. Complete an illegal harms risk assessment and document it.
  2. Publish clear terms of service explaining how you handle illegal content.
  3. Provide an easy reporting mechanism for users.
  4. Keep records of moderation decisions for Ofcom audits.
  5. If you host adult content, implement highly effective age assurance.
  6. Update your privacy policy to reflect any new data shared with age or moderation vendors.

Marketers and creators who rely on short links for campaigns should also ensure their link infrastructure is compliant and transparent. A privacy-first shortener gives you click analytics without the regulatory baggage of overcollecting personal data. If you are evaluating options, our 2026 URL shortener buyer's guide compares the leading tools on privacy, pricing, and features, and our Rebrandly review looks at one of the most popular enterprise options.

The Bigger Picture: Safety vs Privacy

The Online Safety Act reflects a genuine policy dilemma. Child protection groups, bereaved families, and law enforcement argue that platforms have failed to self-regulate and that stronger duties are overdue. Privacy advocates, security researchers, and encrypted-messaging providers argue that weakening encryption or forcing mass ID checks creates risks that outweigh the benefits.

Both camps are partially right. What matters now is how Ofcom uses its discretion. Codes of practice, enforcement priorities, and the willingness to accept privacy-preserving technologies will determine whether the Act becomes a model for the world or a cautionary tale. Users should pay attention to Ofcom consultations and respond — the regulator genuinely does read submissions from individuals.

Frequently Asked Questions

Does the UK Online Safety Act apply to foreign websites?

Yes. The Act applies to any service with a significant number of UK users or that targets the UK market, regardless of where the company is based. Non-compliant foreign platforms can be fined, have payment services withdrawn, or ultimately be blocked by UK internet providers.

Will I have to upload my passport to use social media?

Not in most cases. General social media use does not require identity verification. However, if you want to access adult content, use certain age-restricted features, or opt into "verified only" filters on Category 1 platforms, you will need to complete an age or identity check through an approved provider.

Is end-to-end encryption now illegal in the UK?

No. End-to-end encryption remains legal and widely used. The Act contains a reserve power to require scanning technology, but the government has said it will not use that power until it is "technically feasible" to do so without compromising encryption — which experts generally agree is not currently possible.

Can I be fined personally for breaking the Online Safety Act?

The Act's fines target platforms, not individual users. However, it did introduce new criminal offences — such as sending threatening communications, cyberflashing, and encouraging self-harm — that can lead to prosecution of individuals under existing criminal law.

How can I minimise the personal data I share when verifying my age?

Prefer verification methods that use tokenised, double-blind systems where the website never sees your ID and the verifier never sees which site you visited. Open banking and mobile network operator checks typically share less data than uploading a photo of your passport. Always check whether the provider is certified under the Age Check Certification Scheme (ACCS) and read its data retention policy before proceeding.

Final Thoughts

The UK Online Safety Act is here to stay, and in 2026 its practical effects on everyday browsing are becoming impossible to ignore. The best response is informed participation: understand what the law actually requires, pick tools and platforms that respect your data, and use your GDPR rights when things go wrong. Safety and privacy are not opposites — but defending both takes active choices from users, platforms, and regulators alike.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles