Artifact GuideUKComplaint and Appeal Handling Workflow

UK Online Safety Act Complaint and Appeal Handling Workflow

Classify the complaint by service, complainant, duty, and decision; route it to the right procedure; then give an appropriate response and retain the decision evidence.

The Act requires complaints procedures for specified matters. It does not create a universal internal appeal for every platform decision, so any appeal step must be tied to the applicable duty, code measure, or published terms.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A regulated user-to-user or search service must operate an easy-to-access, easy-to-use and transparent complaints procedure for the matters listed in section 21 or 32 of the Online Safety Act. The procedure must provide for in response. Start by identifying who is complaining and which statutory matter is raised. A user complaint, a complaint from an , an internal review, an Ofcom complaint, and a by an eligible organisation are different routes and should not be merged into one queue.

Section 1

How should the complaint workflow run?

Step 1 - log and classify. Capture the service, account or search result, content or conduct, date, complainant status, safety issue, decision being challenged, and any immediate threat. Preserve the relevant content, notices, policy version, moderation signals, and system logs before they expire.

Step 2 - route by statutory matter. For a user-to-user service, section 21 covers complaints by users and affected persons about specified illegal-content and child-safety duties, content reporting, and certain provider actions; Category 1 services have additional complaint subjects. Section 32 sets the corresponding complaints duty for search services. Check the statutory provision because the eligible complainant and subject differ by route.

Step 3 - contain urgent harm, then decide. Emergency, safeguarding, or law-enforcement escalation can run in parallel with the merits review. The reviewer should apply the Act, the service's terms, the current risk assessment, and the code measure or documented alternative actually adopted. Take , explain the outcome in usable language, and complete or assign any correction.

Step 4 - review a challenged decision when the service's applicable procedure provides for it. The baseline sections 21 and 32 duties require a complaints procedure and , but they do not create a universal statutory second-tier appeal for every decision. Use a reviewer who was not responsible for the original decision where independence matters, and record the final outcome and correction. Ofcom does not act as a general appeal body for individual cases; eligible entities may bring a statutory about features or conduct that present a material risk of significant harm or significantly adversely affect freedom of expression.

  • Triage outcome: emergency action, ordinary statutory complaint, non-statutory customer complaint, privacy complaint, law-enforcement request, or specialist legal review.
  • Decision outcome: upheld, partly upheld, not upheld, unable to decide pending information, or outside the procedure, with a reason and the action taken.
  • Evidence: original submission, preserved content, policy and terms version, relevant risk-assessment entry, reviewer notes, user notice, correction, and closure date.
  • Quality controls: accessibility, age-appropriate language where children use the route, protection against retaliation or discrimination for using the procedure, and monitoring for repeated systemic failures.
Section 2

What fields should the Complaint and Appeal Handling Workflow template capture?

The case record should show whether the complainant and subject fall within the applicable statutory procedure. Capture contact preferences, accessibility needs, safeguarding flags, exact allegation, content identifier, original decision, applicable duty and policy, evidence reviewed, outcome, remedy, notice sent, review route, retention rule, and owner.

  • Do not require a complainant to identify the correct statutory section; intake staff should classify the issue from the facts.
  • Keep content-reporting and complaints routes connected but distinct: a report flags content or conduct, while a complaint challenges compliance or the provider's handling.
  • Record response times by risk and case type. Sections 21 and 32 do not set one universal response deadline, so do not invent one; apply any timing requirement that does arise from the relevant code, terms, notice, or safeguarding process.
  • Use complaint trends to test whether a risk assessment or safety measure is no longer accurate or effective.
Section 3

How should teams review and improve the Complaint and Appeal Handling Workflow?

Review the procedure after a material service or terms change, an Ofcom code update, repeated overturned decisions, missed safeguarding cases, accessibility failures, or evidence that users cannot find or use the route. Sample both upheld and rejected cases and check the result against the evidence available at the time.

  • Measure abandonment, time to first safety action, time to final response, reversal rate, repeated complaints, and unresolved corrective actions.
  • Check whether children and affected non-users can use the route where the applicable provision requires it.
  • Feed systemic findings into risk assessments, terms enforcement, moderator guidance, product controls, and governance reporting.
  • Document why an internal appeal is or is not available; do not describe Ofcom as a general appeal body for individual cases.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Current regulator explanation of the difference between individual complaints and the systemic super-complaints route, including Ofcom's role and the 1 January 2026 commencement date.
gov.uk
Referenced sections
  • Review support for Complaint and Appeal Handling Workflow.
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.