Artifact GuideUKComplaint and Appeal Handling Workflow
UK Online Safety Act Complaint and Appeal Handling Workflow
Classify the complaint by service, complainant, duty, and decision; route it to the right procedure; then give an appropriate response and retain the decision evidence.
The Act requires complaints procedures for specified matters. It does not create a universal internal appeal for every platform decision, so any appeal step must be tied to the applicable duty, code measure, or published terms.
A regulated user-to-user or search service must operate an easy-to-access, easy-to-use and transparent complaints procedure for the matters listed in section 21 or 32 of the Online Safety Act. The procedure must provide for in response. Start by identifying who is complaining and which statutory matter is raised. A user complaint, a complaint from an , an internal review, an Ofcom complaint, and a by an eligible organisation are different routes and should not be merged into one queue.
1
Section 1
How should the complaint workflow run?
Step 1 - log and classify. Capture the service, account or search result, content or conduct, date, complainant status, safety issue, decision being challenged, and any immediate threat. Preserve the relevant content, notices, policy version, moderation signals, and system logs before they expire.
Step 2 - route by statutory matter. For a user-to-user service, section 21 covers complaints by users and affected persons about specified illegal-content and child-safety duties, content reporting, and certain provider actions; Category 1 services have additional complaint subjects. Section 32 sets the corresponding complaints duty for search services. Check the statutory provision because the eligible complainant and subject differ by route.
Step 3 - contain urgent harm, then decide. Emergency, safeguarding, or law-enforcement escalation can run in parallel with the merits review. The reviewer should apply the Act, the service's terms, the current risk assessment, and the code measure or documented alternative actually adopted. Take , explain the outcome in usable language, and complete or assign any correction.
Step 4 - review a challenged decision when the service's applicable procedure provides for it. The baseline sections 21 and 32 duties require a complaints procedure and , but they do not create a universal statutory second-tier appeal for every decision. Use a reviewer who was not responsible for the original decision where independence matters, and record the final outcome and correction. Ofcom does not act as a general appeal body for individual cases; eligible entities may bring a statutory about features or conduct that present a material risk of significant harm or significantly adversely affect freedom of expression.
Decision outcome: upheld, partly upheld, not upheld, unable to decide pending information, or outside the procedure, with a reason and the action taken.
Evidence: original submission, preserved content, policy and terms version, relevant risk-assessment entry, reviewer notes, user notice, correction, and closure date.
Quality controls: accessibility, age-appropriate language where children use the route, protection against retaliation or discrimination for using the procedure, and monitoring for repeated systemic failures.
What fields should the Complaint and Appeal Handling Workflow template capture?
The case record should show whether the complainant and subject fall within the applicable statutory procedure. Capture contact preferences, accessibility needs, safeguarding flags, exact allegation, content identifier, original decision, applicable duty and policy, evidence reviewed, outcome, remedy, notice sent, review route, retention rule, and owner.
Do not require a complainant to identify the correct statutory section; intake staff should classify the issue from the facts.
Keep content-reporting and complaints routes connected but distinct: a report flags content or conduct, while a complaint challenges compliance or the provider's handling.
Record response times by risk and case type. Sections 21 and 32 do not set one universal response deadline, so do not invent one; apply any timing requirement that does arise from the relevant code, terms, notice, or safeguarding process.
Use complaint trends to test whether a risk assessment or safety measure is no longer accurate or effective.
How should teams review and improve the Complaint and Appeal Handling Workflow?
Review the procedure after a material service or terms change, an Ofcom code update, repeated overturned decisions, missed safeguarding cases, accessibility failures, or evidence that users cannot find or use the route. Sample both upheld and rejected cases and check the result against the evidence available at the time.
Measure abandonment, time to first safety action, time to final response, reversal rate, repeated complaints, and unresolved corrective actions.
Check whether children and affected non-users can use the route where the applicable provision requires it.
Feed systemic findings into risk assessments, terms enforcement, moderator guidance, product controls, and governance reporting.
Document why an internal appeal is or is not available; do not describe Ofcom as a general appeal body for individual cases.
Turn UK Online Safety Act Complaint and Appeal Handling Workflow into assigned work
This UK Online Safety Act guide helps turn Complaint and Appeal Handling Workflow into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Current regulator explanation of the difference between individual complaints and the systemic super-complaints route, including Ofcom's role and the 1 January 2026 commencement date.
Binding source for the complainants, complaint subjects, accessibility, transparency, terms, and response requirements that the user-to-user workflow record must distinguish.