If children are likely to access all or part of a regulated user-to-user or search service, the provider must assess the risks and protect children from content harmful to them.
The duties apply to the child-accessible part. They require service-specific evidence, written records, ongoing review, and controls matched to the risks and children's ages.
Every regulated Part 3 user-to-user and search service must complete a . If children are likely to access the whole service or a part of it, the provider must complete a , apply the safety duties for that service type, maintain reporting and complaints routes, and keep written records. A child is a person under 18.
1
Section 1
What should teams decide about Children's Safety Duties under the UK Online Safety Act?
These duties apply to the provider of a regulated Part 3 user-to-user or search service with links to the United Kingdom, even if the provider is established elsewhere. Confirm the service type, responsible provider, UK links, exemptions, and child-accessible parts first. Categorisation can add duties, but it is not a condition for the baseline children's safety duties.
Start with the . Stage one asks whether children can normally access the service or part. A provider may conclude that access is not possible only where and access controls prevent people not identified as adults from entering. Otherwise, assess whether a significant number of children use the service or the service is likely to attract a significant number of children.
For every child-accessible part, assess each kind of , , and relevant that may harm children. Use evidence about the user base, different age groups, design, algorithms, functionalities, business model, governance, incidents, complaints, and Ofcom's Children's Risk Profiles. Record likelihood and impact and assign the Ofcom risk level used in the assessment.
covers pornography and content that encourages, promotes, or instructs suicide, deliberate self-injury, or eating disorders. includes targeted abuse or incitement of hatred, bullying, serious violence, realistic serious violence or graphic injury, dangerous stunts and challenges, and self-administration of harmful substances. is other content presenting a material risk of significant harm to an appreciable number of UK children. Assess each relevant kind separately rather than treating these labels as one risk.
The user-to-user duties include proportionate systems and processes designed to prevent children encountering and to protect children in age-appropriate ways from other harmful content. Search-service duties focus on minimizing the risk that child users encounter harmful search content. The exact controls must follow the service type, risk assessment, and applicable legal duty.
For a user-to-user service, must be prevented from reaching children of any age. Other harmful content is controlled for the age groups judged to be at risk. Search services have minimisation duties rather than the user-to-user prevention formulation. Age assurance is not one universal control for every child-safety risk; use it where the Act or selected code measure requires it and design the processing to comply with data-protection law.
Scope the service first: record the provider, user-to-user or search functions, UK links, applicable exemptions, and every child-accessible part.
Record the access-assessment result for each part of the service and the evidence supporting any conclusion that children are unlikely to access it.
Assess every relevant kind of harmful content separately; an overall low-risk label does not replace harm-by-harm analysis.
Link each control to the risk it addresses, the child age group, the responsible owner, and the evidence used to test effectiveness.
Complete a new before a significant change and keep both access and risk assessments up to date.
Who should own Children's Safety Duties, and what evidence should prove the decision?
The provider should assign one accountable child-safety owner with authority across product, trust and safety, engineering, data, privacy, and legal teams. Control owners must be able to change recommender systems, moderation, search, access, reporting, or complaints where the assessment identifies risk.
Evidence should include the scope and access decisions, child-user and age-group data, risk profiles consulted, harm-by-harm analysis, control design, age-assurance evaluation, testing, incidents, complaints, terms, review approvals, and the written record required by sections 23 or 34.
The terms of service should explain the measures used to protect children in language users can understand, and the provider must apply those terms consistently. Reporting and complaints routes should let children and affected users report harmful content, challenge relevant decisions, and receive an appropriate response; retain evidence that the routes are accessible and work in practice.
Name an owner for each safety measure and a reviewer independent of day-to-day implementation.
Preserve the complete written assessment in an easily understandable form, including method, evidence, findings, assumptions, and control decisions.
Record why the provider follows each relevant Ofcom code measure or how an alternative measure satisfies the underlying duty.
Test whether controls work for different age groups and for logged-out, new, and returning users where those states affect access.
Which edge cases should teams check before relying on a Children's Safety Duties decision?
An age gate based only on a self-declared birth date does not support a conclusion that children cannot normally access the service. If only one part is effectively restricted to adults, the remaining child-accessible parts still require assessment and controls.
The is separate from the illegal-content risk assessment. The same content or feature can be relevant to both, but the provider must preserve the distinct statutory analysis.
Do not assume terms that prohibit under-18s prove that children cannot access the service; use actual access controls and user evidence.
Assess recommender systems, group messaging, search prompts, virality, live streaming, and other relevant features rather than only the moderation rulebook.
Distinguish content harmful to children from illegal content and from provider pornographic content, while coordinating controls that address more than one duty.
When age assurance processes personal data, document data minimization, accuracy, security, retention, fairness, and routes for users to challenge an age result.
How should teams implement and review children's safety controls?
Existing Part 3 services had to complete children's access assessments by 16 April 2025 and, where likely accessed by children, children's risk assessments by 24 July 2025; the child-safety duties became enforceable from 25 July 2025. Those dates are completed milestones, not deadlines for a new service.
A service that comes into scope later generally has three months from the relevant trigger to complete the required access or risk assessment under Ofcom's current guidance. Complete a before a significant change and repeat an access assessment within 12 months after a conclusion that the service is not likely to be accessed by children, or sooner when a specified trigger applies.
The Act sets the binding risk-assessment, safety, terms, reporting, complaints, record-keeping, and review duties. Ofcom's Protection of Children Codes describe measures providers can use as a route to compliance, while Ofcom guidance explains its assessment and enforcement approach. A provider using an alternative measure should document how it satisfies the underlying duty and why it addresses the assessed risk.
Approve the access assessment before relying on an adult-only design.
Complete and record the harm-by-harm before selecting final controls.
Implement, test, and monitor safety, moderation, search, recommender, age-assurance, reporting, and complaints measures assigned by the assessment.
Review after significant changes, new evidence, incidents, control failures, or updated Ofcom risk profiles, guidance, or codes.
Which sources control the duties, and what should happen next?
Sections 35 to 37 control the access gateway, sections 11 to 13 the user-to-user duties, sections 28 to 30 the search duties, sections 60 to 62 the harmful-content categories, and sections 23 and 34 the written-record duties. Ofcom's protection-of-children pages and regulatory-document library explain the current operating sequence, risk levels, codes, and review expectations.
This page is a general implementation guide, not a conclusion about a specific service or control. Confirm the provider, UK links, exemptions, service type, child-accessible parts, affected age groups, current Ofcom publications, and the evidence for every harm before acting. Data-protection law continues to apply to age assurance, profiling, moderation, and other processing used for child safety.
Binding law: the Online Safety Act defines the gateway, harmful-content categories, service-specific duties, records, and reviews.
Compliance route: Ofcom's in-force codes set measures providers can adopt; alternative measures need a documented case that the statutory duty is met.
Regulator guidance: Ofcom's guidance and risk profiles shape the assessment method and evidence but do not replace a service-specific assessment.
Next action: approve the access result, complete the harm-by-harm , assign controls and owners, and retain test evidence before launch or a significant change.
Turn UK Online Safety Act Children's Safety Duties into assigned work
This UK Online Safety Act guide helps turn Children's Safety Duties into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Current versions of the Children's Access Assessments Guidance, Children's Risk Assessment Guidance, risk profiles, codes, content guidance, and record-keeping guidance.