Artifact GuideUKEnforcement and Penalties

UK Online Safety Act Enforcement and Penalties

Ofcom can investigate suspected non-compliance, require corrective steps, and impose a single penalty, a daily penalty, or both. For a regulated service provider, the statutory maximum is the greater of GBP18 million and 10% of qualifying worldwide revenue.

A fine is not automatic and service blocking is not an Ofcom order. The Act provides a notice and representations process, while business disruption measures require a court.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Online Safety Act enforcement usually moves from Ofcom's initial assessment to a formal investigation, a provisional notice of contravention, an opportunity to make representations, and a final . The outcome can include required remedial steps and financial penalties. In serious cases of continuing non-compliance, Ofcom may ask a court for affecting access to the service in the UK.

Section 1

How does an Online Safety Act enforcement case progress?

Not every concern becomes a formal investigation. Ofcom may first assess the issue, gather information, seek voluntary compliance, or use compliance remediation. If it opens an investigation and considers there are reasonable grounds to believe an enforceable requirement has been breached, it may issue a provisional notice of contravention.

The provisional notice identifies the suspected failure, Ofcom's reasons, any proposed penalty, and any steps Ofcom considers necessary. The recipient may make written representations and, where applicable, oral representations. A separate final decision maker then decides whether to close the case, issue another provisional notice, settle the matter, or issue a .

A records Ofcom's final breach finding and may require specified steps, set a deadline, and impose a financial penalty. Teams should treat each stage as a distinct legal event and preserve the evidence, submissions, and decisions for that stage.

  • Identify the exact enforceable requirement, affected service, relevant period, and facts under review.
  • Preserve the notice, underlying records, source data, decision logs, and communications as soon as a concern arises.
  • Calendar the response deadline stated by Ofcom; do not assume a standard period applies to every notice.
  • Separate remediation of the underlying issue from preparation of representations about the alleged breach.
Section 2

What can Ofcom require or impose after finding a breach?

A can require the recipient to take specified steps to comply with an obligation or remedy the failure, either immediately or by a stated deadline. Depending on the contravention and statutory limits, Ofcom can also impose a single financial penalty, a daily penalty for a continuing failure, or both.

For a regulated service provider, Schedule 13 sets the maximum at the greater of GBP18 million and 10% of the provider's for its most recent complete accounting period. That figure is a ceiling, not a standard tariff. Ofcom must consider the case in the round and set an amount it considers appropriate and proportionate.

Ofcom may pursue qualifying related companies or controlling individuals jointly with the service provider in circumstances set out in Schedule 15. That does not make every director, shareholder, parent, or affiliate automatically liable.

  • Assign a legal response lead and an operational owner who can make the required product, policy, moderation, age-assurance, or reporting change.
  • Record the proposed and final penalty separately; the final amount generally cannot exceed the amount proposed for the same breach, subject to the Act's rules on joint liability.
  • Where a daily penalty is proposed, track the required action, start date, daily rate, maximum period, and evidence that the failure ended.
  • Map the provider and group structure before making conclusions about or joint liability.
Section 3

When can a service be restricted or blocked in the UK?

Ofcom cannot itself order a global shutdown. In serious cases of continuing non-compliance, the Act allows Ofcom to apply to a court for . A court may make a service restriction order affecting ancillary services or an access restriction order requiring an access facility, such as an internet access service, to impede access in the UK. The Act also provides interim orders where the court is satisfied about likely non-compliance and the risk, nature, and severity of harm make it inappropriate to wait for a final failure finding.

Failure to pay a fine alone does not give Ofcom power to seek an order blocking the service. Ofcom has stated that continuing non-compliance with Online Safety Act duties is required. Unpaid penalties can instead be pursued as a debt, with the recovery route depending on the provider's assets, location, and applicable court process.

Some failures involving information notices, interviews, inspections, or confirmation decisions may also constitute criminal offences under the Act. Do not describe ordinary non-compliance with every safety duty as personal criminal liability.

  • Distinguish a financial penalty, debt recovery, a remedial requirement, and a court-ordered business disruption measure.
  • Check whether the alleged failure is continuing; that fact affects daily penalties and the business disruption analysis.
  • Identify whether the recipient is the provider, another person subject to an information requirement, a related company, or a controlling individual.
  • Obtain case-specific advice before assessing criminal exposure or responding to an application for a court order.
Section 4

What should a provider do when Ofcom raises a compliance concern?

Create one response record for the matter, led by legal or regulatory affairs and supported by the product or operations owner who can fix the issue. Record the exact obligation, service, period, Ofcom stage, response deadline, preservation scope, factual position, remediation decision, and approval route.

Respond to information requirements completely, accurately, and on time. If the request is unclear or the deadline cannot be met, escalate promptly and use the route stated by Ofcom rather than omitting information or assuming an extension. Remediation can affect Ofcom's next step and penalty assessment, but it does not erase a past breach.

  • Open a legal hold or equivalent preservation process for relevant records and communications.
  • Verify every factual statement against source data and identify limitations before submission.
  • Track remedial actions with owners, completion evidence, user-impact checks, and the deadline in any Ofcom decision.
  • Keep the board or accountable governance body informed where the seriousness, potential harm, group exposure, or business disruption risk warrants escalation.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Lists factors Ofcom may consider when setting an appropriate and proportionate penalty, including seriousness, duration, harm, gain, prevention, knowledge, remediation, history, and cooperation.
legislation.gov.uk
Referenced sections
  • Binding source for offences, penalty recovery, service restriction orders, access restriction orders, and interim measures.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.