Artifact GuideUKContent Moderation and Appeals

UK Online Safety Act Content Moderation and Appeals

Content moderation and appeals under the UK Online Safety Act means deciding how a regulated service will find, assess, remove, restrict, report, and review harmful content, and how users can challenge or complain about those decisions.

The Act does not impose one universal appeal model. It requires service-specific reporting and complaints procedures tied to the applicable duties, with clear terms and records.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This page explains the Online Safety Act duties that sit behind moderation and review: service scope, illegal content and child-safety duties, , complaints procedures, record-keeping, and the Ofcom code of practice path. The Act requires specified complaint routes rather than one universal appeal for every moderation decision.

Section 1

What should teams decide about Content Moderation and Appeals under the UK Online Safety Act?

Start with the service type and duty. A regulated user-to-user service must use proportionate systems and processes designed to minimize the time is present, swiftly take down illegal content when the provider becomes aware of it, and effectively mitigate and manage the risk that the service is used to commit or facilitate priority offences. A regulated search service has a different duty focused on minimizing the risk that users encounter priority illegal search content and other illegal search content the provider is aware of.

Where children are likely to access the service, moderation and ranking controls must also support the children's safety duties. The provider should distinguish illegal content, primary priority content harmful to children, other content harmful to children, and content that only violates the service's terms; the decision ground changes the required action and complaint route.

Sections 20 and 31 require an easy-to-use content-reporting process. Sections 21 and 32 require an easy-to-use, transparent for specified complaints, including relevant complaints about content, failure to comply with duties, and certain actions taken against users or their content. The exact entitlement differs by service type, duty, complainant, and category.

A content report asks the provider to assess content or search content. A complaint can concern the provider's handling of that report, a failure to comply with a relevant duty, or an action taken against a user or content where the applicable section covers it. Route each intake by its statutory ground and service type; do not make a user guess between internal teams.

A complaint review should not assume the original moderation decision was correct. Give the reviewer the content, context, applicable law or policy ground, user submission, automated signals, prior action, and any child-safety or privacy issue needed to reach and explain the outcome. Record whether the service upheld, varied, or reversed the action and whether the case exposed a wider control failure.

  • Classify the decision ground and service part before choosing remove, de-index, restrict, demote, label, age-gate, preserve, or restore.
  • Route reports from users and other affected people to a team that can act within the risk-based response time.
  • Tell complainants which decisions or failures can be challenged, what information to provide, how the service reviews the matter, and how it communicates an outcome.
  • Record automated and human inputs, the policy version, decision, reviewer, timing, reasons, notice, and any reversal or remediation.
  • Escalate uncertain illegality, imminent harm, conflicting rights, law-enforcement requests, and systematic control failures.
Section 2

Who should own Content Moderation and Appeals, and what evidence should prove the decision?

Trust and safety should own day-to-day decisions, product and engineering should own systems and process changes, and legal or specialist reviewers should handle uncertain illegality and rights conflicts. Privacy and child-safety owners should review workflows that use personal data or affect children.

Evidence should connect service risk assessments to moderation coverage, staffing, automated tools, response targets, quality checks, notices, complaints, reversals, recurring error analysis, terms enforcement, and code-of-practice mapping.

  • Set decision authority and escalation rules for illegal content, child harm, emergency risk, and policy-only violations.
  • Use samples and outcome data to test accuracy, timeliness, consistency, and whether users can find and use the reporting and complaints paths.
  • Record why the provider follows each relevant Ofcom code measure or how an alternative measure meets the underlying duty.
  • Feed complaint reversals, repeat reports, missed harms, and false positives back into risk assessments and control reviews.
Section 3

Which edge cases should teams check before relying on a Content Moderation and Appeals decision?

The Act does not require every disputed decision to use the same review route. A report about illegal content, a complaint that the provider failed a safety duty, a challenge to removal under the terms, and a Category 1 complaint can have different statutory bases.

Removal is not the only relevant control, and removal alone may not satisfy a systems-and-processes duty. Risk can also arise from recommendation, search ranking, virality, default settings, user contact, or repeat offending.

  • Do not equate content that violates terms with illegal content; record the actual decision ground.
  • Do not promise a statutory appeal right broader than the applicable complaints duty, but give users an accessible route for every complaint the Act requires.
  • Check whether a search result should be de-indexed or ranked differently rather than applying a user-to-user takedown model.
  • Protect freedom of expression and privacy when designing safety systems, especially where automated moderation or identity and age data affect lawful users.
Section 4

How should teams implement moderation and complaint reviews?

Build one decision record that follows a case from report or detection through classification, action, notice, complaint, independent review where assigned, outcome, and control feedback. Keep user-facing explanations consistent with the actual policy and service terms.

Measure both safety and error: harmful-content prevalence or reach, time to action, repeat exposure, reporting accessibility, complaint completion, reversals, inconsistent outcomes, and effects on privacy and lawful expression.

  • Publish clear terms and reporting and complaints routes for the regulated service.
  • Train reviewers on the Act's content categories, service policy, evidence standard, child-safety duties, and escalation rules.
  • Test automated tools and human decisions before and after material changes, and document known limitations.
  • Use recurring complaints and reversals to revise risk assessments, policy, tooling, staffing, and user notices.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Service-specific safety, reporting, complaints, freedom-of-expression, privacy, record, and review duties.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.