Where do the regimes overlap?
, content moderation, recommender controls, profiling, identity signals, user reports, and child-safety analytics can process personal data while also serving an Online Safety Act duty. The service must meet the applicable safety outcome and comply with principles, lawful-basis rules, transparency, rights, security, accountability, and retention requirements.
The applies to relevant information-society services likely to be accessed by children and explains how UK data-protection law applies in that context. Its scope test and the Online Safety Act children's access assessment come from different legislation. Record both conclusions rather than treating one as a substitute for the other.
- Name an online-safety owner and a privacy owner for each control, with one shared product and data-flow description.
- Identify the Online Safety Act duty, the data-protection purpose and lawful basis, affected people, data categories, recipients, retention, and rights route.
- Complete a where processing is likely to result in high risk, and connect mitigations to the safety assessment.
Current joint explanation of how Online Safety Act and UK data-protection duties apply together to age assurance.
Explains the Children's Code scope and its relationship to UK data-protection law.