Artifact GuideUKApplicability Test

UK Online Safety Act Applicability Test

A service is in Part 3 scope only if it is a user-to-user service or search service, has links with the United Kingdom, falls outside the applicable Schedule 1 exemptions, and is not described in Schedule 2.

Run the test feature by feature. A product may contain regulated, exempt, and out-of-scope functions, and provider pornographic content is covered separately under Part 5.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use four checks to decide whether a function is part of a : identify the internet-service functionality, decide whether it is user-to-user or search, apply the UK-link test, and then apply the and Schedule 2 exclusion. If Part 3 applies, the provider has illegal-content, assessment, reporting, complaints, record-keeping, and other duties according to the service type and facts. Categorisation and likely child access are later tests; they do not decide basic Part 3 scope.

Section 1

What should the UK Online Safety Act Applicability Test decide?

A is an internet service through which content generated, uploaded, or shared by one user may be encountered by another user. A is an internet service that is, or includes, a search engine. Apply these definitions to actual functions such as posts, comments, reviews, file sharing, group spaces, marketplaces, messaging, and public search rather than relying on the product label.

The service must also have links with the United Kingdom. Section 4 provides three routes: a significant number of UK users; the United Kingdom as a target market; or UK access combined with reasonable grounds to believe that user-generated or search content presents a material risk of significant harm to individuals in the United Kingdom. A provider can be in scope even when it is established outside the United Kingdom.

Finally, apply the , the Schedule 2 exclusion for specified user-to-user or search services that include regulated , and any function-specific disapplication. Schedule 1 descriptions include certain email, SMS or MMS, one-to-one live aural communication, limited-functionality, internal business, public-body, and education or childcare services, but each exemption has conditions and some have exceptions. Record the exact paragraph and facts instead of treating a product name or sector as automatically exempt.

Part 5 uses a separate test for a service that publishes or displays and has . Do not force that service into the Part 3 user-to-user or search analysis when the relevant content is published by the provider.

  • Map each content flow: who creates or uploads the content, who can encounter it, and whether a search engine produces results from more than one website or database.
  • Record the UK-link route and evidence, including UK user data, UK-facing marketing or commercial design, and any material-risk analysis.
  • Test every claimed Schedule 1 exemption and any Schedule 2 exclusion against its full conditions and exceptions; an exempt or excluded function does not necessarily remove the rest of a from scope.
  • State the result separately for the user-to-user part, public search engine, and any provider-pornography part.
Section 2

What outcomes can the applicability test produce?

Record one of four outcomes for each assessed function: Part 3 regulated , Part 3 regulated , exempt, excluded or disapplied Part 3 functionality, or outside Part 3 because a required element is absent. Assess separately under Part 5. A single product can produce more than one outcome.

For example, a marketplace may have regulated user reviews and messages, an exempt internal staff area, and a provider-operated product search that does not meet the public search-service definition. A foreign discussion forum can still be in scope through UK users or a UK target market. These are examples only; the service facts and statutory conditions control.

  • If Part 3 applies, open the illegal-content risk assessment and children's access assessment immediately and assign owners for reporting, complaints, terms, and records.
  • If Part 5 applies, document the provider-content boundary and highly effective age-assurance work separately.
  • If an exemption or exclusion applies, cite the exact Schedule 1 or Schedule 2 provision, preserve evidence for every condition, and identify any function left in scope.
  • If the function is outside scope, record which required element is absent and the product change that would require a new test.
Section 3

Who should own the UK Online Safety Act applicability test, and what evidence should prove the decision?

A product owner should supply the functional facts; legal or regulatory counsel should review the statutory classification; data and commercial owners should support the UK-link analysis. The provider remains responsible for the service-level conclusion.

The scope record should identify the service, provider entity, functions assessed, users who can create and encounter content, search sources, , each Schedule 1 exemption and Schedule 2 exclusion considered, the conclusion for each service part, and the facts that would trigger reassessment.

  • Name the provider entity and one accountable scope owner; a vendor or moderator does not replace the provider's statutory role.
  • Keep current user journeys, permissions, screenshots, architecture notes, user metrics, target-market evidence, and the exemption analysis with the decision.
  • List assumptions that could change the outcome, such as whether a message can be forwarded, whether comments are limited to provider content, or whether search spans multiple sites.
  • Repeat the test when functionality, audience, UK availability, ownership, or content flows materially change.
Section 4

Which edge cases should teams check before relying on a UK Online Safety Act applicability test decision?

Scope can attach to only part of a product. Internal search over one provider's own content is not automatically a regulated public search engine, while user comments or reviews may create user-to-user functionality even when the main product is publishing or commerce.

Do not use company size, revenue, or formal categorisation as the basic applicability test. Small services can be in Part 3 scope, and the core illegal-content and children-access assessment duties apply before the Category 1, 2A, or 2B analysis.

  • Check mixed products separately: a can contain both a regulated user-to-user part and a regulated public search engine.
  • Treat comments, reactions, reviews, and direct messages as fact-sensitive; Schedule 1's limited-functionality rules are narrower than a general low-risk exemption.
  • Do not count provider-generated content as user-generated merely because a user prompted or selected it without checking the Act's detailed rules.
  • Escalate borderline facts and preserve the alternative analysis; this page cannot determine scope without the service's actual content and access design.
Section 5

How should teams implement the applicability decision?

Write the result as a service-scope memo, not a single yes-or-no field. It should show the analysis for each service part and explain why each Schedule 1 exemption and Schedule 2 exclusion does or does not apply.

If Part 3 applies, the immediate next steps are an illegal-content risk assessment and record, the related safety and reporting controls, and a children's access assessment. If Part 5 applies, run the provider-pornography age-assurance analysis separately.

  • Approve the scope memo with dated evidence and an owner for every follow-on duty.
  • Record a review trigger for new content-sharing, messaging, search, recommender, age-gating, or UK-launch functionality.
  • Use the regulated-service-scope guide for the detailed exemption analysis and the categorisation guide only after Part 3 scope is established.
  • Keep unresolved legal interpretations visible; an operational checklist must not turn an uncertain service fact into a definitive legal conclusion.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Primary source for the applicability decision and the duties that follow once a Part 3 service is regulated.
legislation.gov.uk
Referenced sections
  • Separate legal regime for provider pornographic content, including its own scope and age-verification duties.
legislation.gov.uk
Referenced sections
  • Binding descriptions and conditions for exempt user-to-user and search services and disapplied functionality.
legislation.gov.uk
Referenced sections
  • Binding regulated-service, UK-link, Schedule 1, Schedule 2, and combined-service rules used in the recorded conclusion.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.