Artifact GuideUKChildren's Safety Duties

UK Online Safety Act Children's Safety Duties

If children are likely to access all or part of a regulated user-to-user or search service, the provider must assess the risks and protect children from content harmful to them.

The duties apply to the child-accessible part. They require service-specific evidence, written records, ongoing review, and controls matched to the risks and children's ages.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Every regulated Part 3 user-to-user and search service must complete a . If children are likely to access the whole service or a part of it, the provider must complete a , apply the safety duties for that service type, maintain reporting and complaints routes, and keep written records. A child is a person under 18.

Section 1

What should teams decide about Children's Safety Duties under the UK Online Safety Act?

These duties apply to the provider of a regulated Part 3 user-to-user or search service with links to the United Kingdom, even if the provider is established elsewhere. Confirm the service type, responsible provider, UK links, exemptions, and child-accessible parts first. Categorisation can add duties, but it is not a condition for the baseline children's safety duties.

Start with the . Stage one asks whether children can normally access the service or part. A provider may conclude that access is not possible only where and access controls prevent people not identified as adults from entering. Otherwise, assess whether a significant number of children use the service or the service is likely to attract a significant number of children.

For every child-accessible part, assess each kind of , , and relevant that may harm children. Use evidence about the user base, different age groups, design, algorithms, functionalities, business model, governance, incidents, complaints, and Ofcom's Children's Risk Profiles. Record likelihood and impact and assign the Ofcom risk level used in the assessment.

covers pornography and content that encourages, promotes, or instructs suicide, deliberate self-injury, or eating disorders. includes targeted abuse or incitement of hatred, bullying, serious violence, realistic serious violence or graphic injury, dangerous stunts and challenges, and self-administration of harmful substances. is other content presenting a material risk of significant harm to an appreciable number of UK children. Assess each relevant kind separately rather than treating these labels as one risk.

The user-to-user duties include proportionate systems and processes designed to prevent children encountering and to protect children in age-appropriate ways from other harmful content. Search-service duties focus on minimizing the risk that child users encounter harmful search content. The exact controls must follow the service type, risk assessment, and applicable legal duty.

For a user-to-user service, must be prevented from reaching children of any age. Other harmful content is controlled for the age groups judged to be at risk. Search services have minimisation duties rather than the user-to-user prevention formulation. Age assurance is not one universal control for every child-safety risk; use it where the Act or selected code measure requires it and design the processing to comply with data-protection law.

  • Scope the service first: record the provider, user-to-user or search functions, UK links, applicable exemptions, and every child-accessible part.
  • Record the access-assessment result for each part of the service and the evidence supporting any conclusion that children are unlikely to access it.
  • Assess every relevant kind of harmful content separately; an overall low-risk label does not replace harm-by-harm analysis.
  • Link each control to the risk it addresses, the child age group, the responsible owner, and the evidence used to test effectiveness.
  • Complete a new before a significant change and keep both access and risk assessments up to date.
Section 2

Who should own Children's Safety Duties, and what evidence should prove the decision?

The provider should assign one accountable child-safety owner with authority across product, trust and safety, engineering, data, privacy, and legal teams. Control owners must be able to change recommender systems, moderation, search, access, reporting, or complaints where the assessment identifies risk.

Evidence should include the scope and access decisions, child-user and age-group data, risk profiles consulted, harm-by-harm analysis, control design, age-assurance evaluation, testing, incidents, complaints, terms, review approvals, and the written record required by sections 23 or 34.

The terms of service should explain the measures used to protect children in language users can understand, and the provider must apply those terms consistently. Reporting and complaints routes should let children and affected users report harmful content, challenge relevant decisions, and receive an appropriate response; retain evidence that the routes are accessible and work in practice.

  • Name an owner for each safety measure and a reviewer independent of day-to-day implementation.
  • Preserve the complete written assessment in an easily understandable form, including method, evidence, findings, assumptions, and control decisions.
  • Record why the provider follows each relevant Ofcom code measure or how an alternative measure satisfies the underlying duty.
  • Test whether controls work for different age groups and for logged-out, new, and returning users where those states affect access.
Section 3

Which edge cases should teams check before relying on a Children's Safety Duties decision?

An age gate based only on a self-declared birth date does not support a conclusion that children cannot normally access the service. If only one part is effectively restricted to adults, the remaining child-accessible parts still require assessment and controls.

The is separate from the illegal-content risk assessment. The same content or feature can be relevant to both, but the provider must preserve the distinct statutory analysis.

  • Do not assume terms that prohibit under-18s prove that children cannot access the service; use actual access controls and user evidence.
  • Assess recommender systems, group messaging, search prompts, virality, live streaming, and other relevant features rather than only the moderation rulebook.
  • Distinguish content harmful to children from illegal content and from provider pornographic content, while coordinating controls that address more than one duty.
  • When age assurance processes personal data, document data minimization, accuracy, security, retention, fairness, and routes for users to challenge an age result.
Section 4

How should teams implement and review children's safety controls?

Existing Part 3 services had to complete children's access assessments by 16 April 2025 and, where likely accessed by children, children's risk assessments by 24 July 2025; the child-safety duties became enforceable from 25 July 2025. Those dates are completed milestones, not deadlines for a new service.

A service that comes into scope later generally has three months from the relevant trigger to complete the required access or risk assessment under Ofcom's current guidance. Complete a before a significant change and repeat an access assessment within 12 months after a conclusion that the service is not likely to be accessed by children, or sooner when a specified trigger applies.

The Act sets the binding risk-assessment, safety, terms, reporting, complaints, record-keeping, and review duties. Ofcom's Protection of Children Codes describe measures providers can use as a route to compliance, while Ofcom guidance explains its assessment and enforcement approach. A provider using an alternative measure should document how it satisfies the underlying duty and why it addresses the assessed risk.

  • Approve the access assessment before relying on an adult-only design.
  • Complete and record the harm-by-harm before selecting final controls.
  • Implement, test, and monitor safety, moderation, search, recommender, age-assurance, reporting, and complaints measures assigned by the assessment.
  • Review after significant changes, new evidence, incidents, control failures, or updated Ofcom risk profiles, guidance, or codes.
Section 5

Which sources control the duties, and what should happen next?

Sections 35 to 37 control the access gateway, sections 11 to 13 the user-to-user duties, sections 28 to 30 the search duties, sections 60 to 62 the harmful-content categories, and sections 23 and 34 the written-record duties. Ofcom's protection-of-children pages and regulatory-document library explain the current operating sequence, risk levels, codes, and review expectations.

This page is a general implementation guide, not a conclusion about a specific service or control. Confirm the provider, UK links, exemptions, service type, child-accessible parts, affected age groups, current Ofcom publications, and the evidence for every harm before acting. Data-protection law continues to apply to age assurance, profiling, moderation, and other processing used for child safety.

  • Binding law: the Online Safety Act defines the gateway, harmful-content categories, service-specific duties, records, and reviews.
  • Compliance route: Ofcom's in-force codes set measures providers can adopt; alternative measures need a documented case that the statutory duty is met.
  • Regulator guidance: Ofcom's guidance and risk profiles shape the assessment method and evidence but do not replace a service-specific assessment.
  • Next action: approve the access result, complete the harm-by-harm , assign controls and owners, and retain test evidence before launch or a significant change.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Primary legislation for children's access assessments, risk assessments, safety duties, content reporting, complaints, and records.
legislation.gov.uk
Referenced sections
  • Binding source for children's access, risk-assessment, safety, terms, reporting, complaints, record-keeping, and review duties.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.