FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
35of35items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Does the UK Online Safety Act apply to this service?

Which services are in scope?

A Part 3 user-to-user service is an internet service through which content generated, uploaded, or shared by one user may be encountered by another user. A Part 3 search service is an internet service that is, or includes, a search engine. A combined service can contain both parts, and each part may have different duties.

Part 5 separately covers an internet service on which the provider publishes or displays regulated provider pornographic content. A service may therefore be outside the Part 3 user-to-user and search definitions but still have Part 5 duties.

The provider's location is not decisive. A service has UK links if it has a significant number of UK users, targets the UK market, or is capable of UK use and there are reasonable grounds to believe that UK users face a material risk of significant harm from content on or accessible through it.

  • Map each product function and identify who creates content, who can encounter it, and whether a search engine presents results.
  • Apply the UK-links test to the service facts, including UK users, marketing, language, commercial targeting, and the identified harm route.
  • Record separate conclusions for user-to-user, search, combined-service, and provider-pornography parts.
Citations
Does the UK Online Safety Act apply to this service?

Which exclusions and edge cases need a closer check?

Schedule 1 exempts specified services or parts of services, including email, SMS and MMS, one-to-one live aural communications, limited functionality, certain internal business services, and services provided by public bodies or qualifying education and childcare providers. Each exemption has conditions. An exempt function does not automatically exempt the rest of a combined product.

Comments and reviews on provider content can fall within the limited-functionality exemption only if the statutory conditions are met. File storage, group messaging, forums, dating, gaming, social media, and content-sharing features can be user-to-user services even when interaction is not the product's main purpose. Apply the definitions to the actual journey rather than the marketing label.

  • Test every relied-on exemption against its full statutory conditions and document which service part it covers.
  • Reassess scope before launching messaging, sharing, comments, public profiles, feeds, search, or UK targeting.
  • Escalate borderline classifications where users, providers, and third parties contribute content in different parts of the same service.
Citations
Does the UK Online Safety Act apply to this service?

What should the scope record contain?

The scope record should be short enough to review but detailed enough to reproduce the decision. Include a service map, the relevant statutory definition, UK-links evidence, every exemption considered, the provider entity, and the product owner. State any assumptions and the event that will trigger reassessment.

Scope is only the gateway. If a Part 3 service is regulated, the provider must address illegal-content duties and complete a children's access assessment. Categorisation, transparency reporting, and some additional duties are later questions; a service can be regulated without appearing on Ofcom's categorised-services register.

  • Keep dated screenshots, feature descriptions, user-flow evidence, UK audience data, and the approved scope rationale.
  • Assign review triggers for product changes, acquisitions, new UK launches, user growth, and new evidence about harm.
  • Link the result to the illegal content risk assessment and children's access assessment rather than treating the scope memo as the compliance outcome.
Citations
Online Safety Act 2023

Establishes Ofcom's register of categorised services, which is separate from the baseline regulated-service test.

How Ofcom and ICO duties overlap for online services

Where do the regimes overlap?

Age assurance, content moderation, recommender controls, profiling, identity signals, user reports, and child-safety analytics can process personal data while also serving an Online Safety Act duty. The service must meet the applicable safety outcome and comply with UK GDPR principles, lawful-basis rules, transparency, rights, security, accountability, and retention requirements.

The Children's Code applies to relevant information-society services likely to be accessed by children and explains how UK data-protection law applies in that context. Its scope test and the Online Safety Act children's access assessment come from different legislation. Record both conclusions rather than treating one as a substitute for the other.

  • Name an online-safety owner and a privacy owner for each control, with one shared product and data-flow description.
  • Identify the Online Safety Act duty, the data-protection purpose and lawful basis, affected people, data categories, recipients, retention, and rights route.
  • Complete a data protection impact assessment where processing is likely to result in high risk, and connect mitigations to the safety assessment.
Citations
How Ofcom and ICO duties overlap for online services

How should teams resolve an apparent privacy-safety tension?

Start with the exact legal outcomes rather than assuming one regulator requires maximum data collection. Define the safety risk, the required effectiveness level, and the minimum personal data needed to achieve it. Compare feasible methods, including their accuracy, bias, circumvention, security, retention, and effects on rights.

For age assurance, Ofcom and the ICO say all methods process personal data, self-declaration alone is ineffective, and data may be processed where the method is necessary, proportionate to the risk, and compliant with data-protection law. The joint statement does not create an exemption from either regime.

  • Document why the selected method meets the safety need and why less intrusive alternatives do not.
  • Limit collection and disclosure to the decision needed; an age result or token may be enough where identity is not required.
  • Provide transparent explanations, accessible alternatives, correction or appeal routes, deletion rules, and supplier controls.
Citations
How Ofcom and ICO duties overlap for online services

What evidence should be kept?

Keep separate but linked records: the service-scope decision, risk assessments, code or guidance mapping, data protection impact assessment, lawful-basis analysis, privacy notices, legitimate-interests assessment where relevant, vendor terms, security review, retention schedule, test results, complaints, and change approvals.

Record how errors affect people. False adult classifications can expose children to harm; false child classifications can deny adults access or subject them to different processing. Test affected groups, monitor outcomes, and review both the safety and privacy records after material changes or incidents.

  • Use one change trigger for product, model, vendor, data, threshold, or legal changes, then route it to both owners.
  • Keep evidence of actual deployment and performance, not only policy wording or supplier assurances.
  • Preserve the reason for rejected options and the controls used to reduce remaining risks.
Citations
How Ofcom enforces the UK Online Safety Act

How does an Ofcom investigation usually proceed?

Ofcom can use statutory information notices to obtain information needed for its online-safety functions. It can open an investigation where it suspects non-compliance. Its enforcement guidance describes a process that may lead to a provisional notice of contravention, an opportunity for written and oral representations, and then a confirmation decision, a further provisional notice, settlement, or closure.

A confirmation decision can record a contravention, require steps to remedy it or comply with the obligation, and impose a financial penalty. Ofcom may also impose daily penalties in circumstances allowed by the Act. The specific process and available outcome depend on the requirement being enforced.

  • Log every notice, statutory basis, question, definition, deadline, submission channel, owner, reviewer, and dependency.
  • Preserve responsive documents and data, control queries and calculations, and retain the final response with approvals and delivery proof.
  • Correct identified errors promptly through the appropriate channel; do not silently change an earlier submission.
Citations
How Ofcom enforces the UK Online Safety Act

What penalties and court orders are available?

For many enforceable requirements, the maximum financial penalty is the greater of GBP18 million or 10% of qualifying worldwide revenue. Schedule 13 contains the penalty framework, including how qualifying worldwide revenue is determined. The actual amount depends on the legal power, facts, seriousness, and Ofcom's penalty guidance.

In serious cases and subject to the statutory conditions, Ofcom can apply to the court for service-restriction or access-restriction orders directed at ancillary services or access facilities. These are court orders, not an automatic result of an investigation. Criminal offences also exist for specified information failures and related conduct; individual and senior-manager exposure depends on the exact offence and facts.

  • Do not describe the maximum as the expected fine or apply the 10% figure without the statutory revenue definition.
  • Escalate any suspected false statement, destruction or alteration of information, obstruction, or missed statutory deadline immediately.
  • Separate Ofcom's administrative decisions from orders that require a court application and judicial decision.
Citations
How Ofcom enforces the UK Online Safety Act

What does enforcement readiness require?

Enforcement readiness is the ability to reproduce a compliance decision and answer a regulator accurately. Keep current scope analyses, risk assessments, code mappings or alternative-measure rationales, child-access and age-assurance records, terms, complaints evidence, transparency data definitions, governance approvals, incidents, tests, and change logs.

Ofcom does not resolve individual users' complaints or direct a service to remove or reinstate specific content. It can use complaints and other intelligence to identify systemic compliance issues. A provider therefore needs an internal complaints process that works and an evidence trail showing whether recurring failures were fed back into risk assessments and controls.

  • Run a notice-response tabletop using existing records without creating new facts after the event.
  • Name legal, trust and safety, engineering, analytics, privacy, finance, and executive contacts before a notice arrives.
  • Track remediation to verified completion and keep evidence that the deployed service changed.
Citations
How to complete a children's access assessment

How does the two-stage test work?

Stage one asks whether children can normally access the service or a particular part of it. A provider can conclude they cannot only where highly effective age assurance and access controls prevent users who have not been identified as adults from entering. Self-declared age, an age statement in terms, or a weak gate does not support that conclusion.

If children can access the service, stage two asks whether the child user condition is met: there is a significant number of child users, or the service is of a kind likely to attract a significant number of children. Assess actual and foreseeable use, not only the intended audience. A conclusion can differ between distinct parts of one service.

  • Define the service or part being assessed and treat a child as a person under 18.
  • Use user data, research, complaints, content, design, marketing, competitors, and foreseeable circumvention to assess actual use and likely attraction.
  • Record the steps and detailed evidence supporting the result, especially any conclusion that the service is not likely to be accessed by children.
Citations
How to complete a children's access assessment

When is the assessment due and when must it be repeated?

The initial deadline for services already in scope was 16 April 2025. A user-to-user or search service that later comes into scope must complete the assessment within three months of the first day it becomes available to UK users.

If the provider concludes that the service is not likely to be accessed by children, it must repeat the assessment within 12 months, and sooner where the Act or Ofcom guidance requires. Reassess before or after relevant changes as required, including changes to design, operation, target market, age controls, or evidence of child use.

  • Set a dated annual reassessment trigger for every negative conclusion.
  • Start an earlier review when a product change could alter child access or attraction, or when new evidence contradicts the existing conclusion.
  • Keep prior versions and change logs so reviewers can see why the outcome changed or remained the same.
Citations
How to complete a children's access assessment

What happens if children are likely to access the service?

The provider must complete a suitable and sufficient children's risk assessment for the affected service or part and comply with the applicable child-safety, record-keeping, and review duties. For existing services, the first children's risk assessment deadline was 24 July 2025 and child-protection measures applied from 25 July 2025.

A negative access conclusion does not remove the baseline illegal-content duties. It also does not settle whether the Children's Code applies, because the data-protection and Online Safety Act tests have different legal sources and should be assessed separately.

  • Open the children's risk assessment with the access-assessment scope, evidence, affected age groups, and service parts.
  • Map the risk findings to proportionate systems and processes, Ofcom code measures or documented alternatives, owners, and test evidence.
  • Keep the privacy and Online Safety Act analyses connected but record their separate legal conclusions.
Citations
How to complete an illegal content risk assessment

What must the assessment cover?

User-to-user providers assess the risk of users encountering each kind of priority illegal content and other illegal content, and the risk of the service being used to commit or facilitate a priority offence. Search providers assess the risk of users encountering priority illegal content and other illegal content in or via search results. Sections 9 and 26 set the detailed elements for each service type.

The assessment must consider the service's user base, functionalities, algorithmic systems, business model, governance, proactive technology, user tools, intended and unintended uses, and how easily, quickly, and widely content may spread. It must also consider Ofcom's current risk profiles. Rate likelihood and impact using evidence that reflects the actual service.

  • Define each assessed service and part, provider entity, user groups, languages, geography, features, algorithms, and revenue model.
  • Assess every statutory kind of priority illegal content; do not limit the work to content already found on the service.
  • Record evidence, assumptions, risk level, existing controls, gaps, owner, and the proportionate measure chosen for each material risk.
Citations
Online Safety Act 2023

Sets the illegal content risk assessment duties and required elements for regulated user-to-user services.

How to complete an illegal content risk assessment

When is it due and when must it be reviewed?

Services already in scope had to complete the first assessment by 16 March 2025. A new user-to-user or search service, or an existing service that newly comes into scope, must complete it within three months of starting or changing the service.

The provider must take appropriate steps to keep the assessment up to date. Complete a new assessment before a significant change to the service's design or operation. Review sooner when Ofcom significantly changes a relevant risk profile or when incidents, complaints, enforcement, research, or performance data show that the current risk picture may be wrong. Ofcom recommends review at least every 12 months.

  • Put the annual review and every known product-change gate into the release calendar.
  • Version the assessment and preserve the evidence and approval behind each changed risk rating.
  • Treat new priority offences and changes to Ofcom risk profiles as legal-review triggers, not background reading.
Citations
How to complete an illegal content risk assessment

What must happen after the assessment?

The assessment is an input to the illegal-content safety duties. User-to-user providers need proportionate systems and processes designed to prevent users encountering priority illegal content, mitigate identified harm and offence risks, minimise how long priority illegal content remains, swiftly take down illegal content when aware of it, and effectively mitigate and manage the risk that the service is used to commit or facilitate priority offences. Search providers must use proportionate systems and processes to minimise encounter risk in or via search results and manage assessed risks.

Providers may follow applicable measures in Ofcom's codes of practice or use alternative measures that meet the legal duties. Keep the assessment record, the code mapping or alternative-measure rationale, implementation evidence, tests, terms or public statement, content-reporting route, complaints procedure, and review record. Ofcom can request these records.

  • Assign every mitigation to a product, moderation, engineering, policy, or governance owner with a due date and acceptance test.
  • Make terms and public statements match the systems actually deployed and apply the stated rules consistently.
  • Test reporting and complaints journeys, including access by children and people who need assistance where the Act requires it.
Citations
Page 1 of 3
Previous123Next