FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
35of35items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Is This a User-to-user or Search Service Under the UK Online Safety Act?

How do you classify the service functionality?

A user-to-user classification turns on functionality, not branding. Ask whether content generated, uploaded, or shared by one user may be encountered by another. Public or group posts, user profiles, uploaded media, marketplace listings, in-game chat, collaborative spaces, and messaging can meet the test. The amount of user-generated content does not matter, and a Schedule 1 exemption must be tested separately.

For search, ask whether a person can search more than one website or database. General search and vertical search for products, jobs, travel, academic material, or another topic can qualify. A tool restricted to one website or one database does not meet the section 229 search-engine definition merely because it uses filters, recommendations, or sophisticated ranking.

If one product has both functions, apply the section 3 tie-breaker. Unless its only user-generated content falls within the specified exempt types, it is treated as user-to-user. If the same provider also operates a public search engine, it is a combined service and the search duties apply to that engine.

  • Inventory every function through which a user creates, uploads, shares, searches, comments on, or encounters content.
  • Record whether communications are public, group, one-to-one, live, aural, asynchronous, internal, or attached to provider content.
  • For each search function, record the websites and databases searched and the entity that controls indexing, ranking, requests, and results.
  • Classify distinct functions and service parts before deciding whether an exemption covers the whole product or only a defined part.
Citations
Is This a User-to-user or Search Service Under the UK Online Safety Act?

Who is the provider, and does the service have UK links?

Identify the responsible provider by control, rather than assuming it is the brand owner, parent company, app-store operator, or company named in a customer contract. Section 226 generally identifies the user-to-user provider by control over who can use the relevant user-to-user elements. For search, it identifies the entity with control over the operations that accept search requests and generate responses.

UK establishment is not required. A significant UK user base or UK target market establishes links with the United Kingdom. A service accessible to individuals in the UK can also qualify where there are reasonable grounds to believe that its content or functionality creates a material risk of significant harm to individuals in the UK.

There is no general minimum revenue, employee, or user threshold for baseline Part 3 scope. Category thresholds determine additional duties for some services; they do not decide whether an otherwise regulated service has baseline duties.

  • Draw the entity and control chain for account access, posting, sharing, moderation, indexing, ranking, and search-result generation.
  • Keep dated evidence for UK users, UK marketing and localisation, commercial targeting, accessibility from the UK, and UK-specific harm signals.
  • Do not treat low UK traffic as conclusive if the service targets the UK or presents a material risk of significant harm in the UK.
  • Revisit the provider and UK-links analysis after acquisitions, outsourcing, market launches, platform migrations, or changes in operational control.
Citations
Is This a User-to-user or Search Service Under the UK Online Safety Act?

Which exemptions and service boundaries must be checked?

Schedule 1 exemptions use specific statutory conditions. They include services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications; defined limited-functionality services; qualifying internal business services; specified public-body services; and qualifying education or childcare services. A broad product or sector label does not establish an exemption, and some exemptions operate at service-part level.

The limited-functionality exemption generally concerns comments or reviews on provider content, reactions to that content, and sharing those comments or reviews elsewhere. It does not exempt a service that also enables wider user interaction. The education and childcare exemption applies only to the providers and purposes described in Schedule 1, not every product sold to a school or used by a child.

Schedule 2 addresses certain services combining otherwise exempt user-to-user or search functions with provider pornographic content. Such a service may remain regulated under Part 5 even when the Part 3 user-to-user or search duties do not apply. Section 5 can also disapply the Act to a qualifying internal-business part of a Part 3 service or a specified part of a regulated search service without removing the whole service from scope.

  • Test the exact content, functionality, provider, user, and purpose conditions for an exemption.
  • Check the exception in Schedule 1 paragraph 6 to the email, messaging, aural, limited-functionality, and combination exemptions.
  • For internal tools, document the corporate relationship, permitted users, purpose, and any public or customer-facing part.
  • For pornography, education, childcare, and public-body cases, record the separate conditions and any duty that remains under another Part.
Citations
Is This a User-to-user or Search Service Under the UK Online Safety Act?

What follows after classification?

Every regulated Part 3 service must complete an illegal-content risk assessment and maintain the applicable safety, reporting, complaints, freedom-of-expression, privacy, record-keeping, and review controls. The safety duties differ by service type: user-to-user services address user-generated content and use of the service to commit or facilitate priority offences, while search services address risks arising through search content and results.

The provider must also complete a children's access assessment. If the service or a relevant part is likely to be accessed by children, the children's risk-assessment and safety duties apply. Category status can add transparency, user-empowerment, fraudulent-advertising, and other duties, but it does not replace the baseline scope decision.

  • Approve a scope memo with the feature inventory, provider entity, UK-links evidence, exemption analysis, service-part boundaries, and unresolved questions.
  • Open separate duty maps for the user-to-user and search components of a combined service.
  • Reassess before adding public comments, messaging, uploads, group interaction, multi-database search, or a UK market.
  • Keep child-access and category decisions as later branches; do not use them to erase baseline Part 3 duties.

Is a service outside the Act because it has few UK users?

Not necessarily. A significant number of UK users is one route to links with the United Kingdom. A UK target market is another. A service accessible in the UK can also qualify where there are reasonable grounds to believe its content or functionality creates a material risk of significant harm to individuals in the UK.

Is an internal search box a search service?

Not if it searches only one website or one database. Section 229 excludes a service or functionality limited to one website or database. A vertical search engine covering multiple websites or databases can qualify even if it covers only one topic.

Are email and private messages always exempt?

No. Schedule 1 exempts services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications, subject to the schedule's conditions and exceptions. A wider service with posts, group communications, profiles, uploads, comments, or other interaction needs a function-by-function analysis.

Does a service need to meet a category threshold before baseline duties apply?

No. Category thresholds determine additional duties for Category 1, 2A, or 2B services. They are not a minimum threshold for baseline Part 3 scope. A service that meets the functionality, UK-links, and non-exemption tests can have baseline duties without being categorised.

Citations
Ofcom Transparency Reporting

Who must report and when?

Section 77 requires Ofcom, once a year, to give every provider of a relevant service a transparency notice. A relevant service is a Category 1, Category 2A, or Category 2B service. The provider must produce and publish the report by the date and in the manner specified in the notice.

Ofcom published final transparency guidance in July 2025 and its categorised-services register in June 2026, updated in July. Ofcom's implementation roadmap says categorised services will publish their first transparency reports in 2027 and that a further timeline update will follow the register. Providers should use the actual notice as the controlling deadline rather than infer a date from an older roadmap.

  • Confirm that the named service and provider match the current Ofcom register and the notice.
  • Extract every request, definition, reporting period, unit, disaggregation, format, publication method, and deadline into a controlled requirements table.
  • Escalate ambiguity during Ofcom's draft-notice process and preserve correspondence and the final position.
Citations
Online Safety Act 2023

Creates the annual notice, report, publication, and timing framework for relevant categorised services.

Ofcom - Roadmap to regulation

Current implementation roadmap stating that first categorised-service transparency reports are due in 2027 and that timing will be updated.

Ofcom Transparency Reporting

What can the notice require?

Schedule 8 lists possible subjects. They include the incidence and dissemination of illegal content and content harmful to children; systems for risk assessment, reporting, complaints, moderation, user support, age assurance, and compliance; the use and effect of algorithms; cooperation with public authorities; staff and resourcing; and other listed safety and governance matters.

The notice determines which permitted matters apply to the service. Do not assume that every Schedule 8 item will be required, or substitute a voluntary environmental, social, and governance report. Where a requested figure cannot be measured directly, document the method, limitations, estimation, and quality checks rather than presenting an unsupported number as exact.

  • Assign each requested item to a data owner and an accountable approver.
  • Define the numerator, denominator, event, service part, geography, age group, content taxonomy, and treatment of duplicates before querying data.
  • Retain reproducible queries, source-system versions, exclusions, manual adjustments, samples, reconciliations, and explanations of uncertainty.
Citations
Ofcom Transparency Reporting

How should publication and corrections be controlled?

Treat the public report as a regulated output. Review it for consistency with risk assessments, terms, complaints data, published policies, prior submissions, and the actual service. Preserve approvals, the publication URL and time, the exact published file, accessibility checks, and evidence that it remained available as required.

If an error is found, assess materiality, notify the responsible legal and reporting owners, preserve the original, and follow the notice and Ofcom guidance for correction or communication. Do not overwrite the record without a dated explanation. A transparency report does not replace records that Ofcom may request under other powers.

  • Run privacy, security, legal, and statistical-disclosure review without suppressing information the notice requires.
  • Use stable metric definitions across reporting cycles and explain genuine methodology changes.
  • Keep an issue log for late source data, weak controls, disagreements, corrections, and remediation.
Citations
Online Safety Act moderation, reporting, and complaints

What moderation outcomes does the Act require?

For illegal content, user-to-user services need proportionate systems and processes designed to prevent users encountering priority illegal content, mitigate identified risks, minimise how long priority illegal content remains, and swiftly take down illegal content when the provider becomes aware of it. Search services must minimise the risk of users encountering priority illegal content and known illegal content in or via search results.

Services likely to be accessed by children have additional duties for content harmful to children. The exact moderation design depends on the service, assessed risks, applicable duties, and Ofcom codes. Measures can include detection, triage, human review, removal, visibility reduction, recommendation controls, account action, user support, and escalation, but each measure must be justified and tested in context.

  • Map each content class and risk to a detection route, decision rule, response target, reviewer, escalation path, and user-facing outcome.
  • Test automated systems for accuracy and bias, and give reviewers enough context and authority to correct errors.
  • Keep urgent routes for child sexual abuse material, terrorism content, imminent danger, and other cases requiring specialist handling or reporting.
Citations
Online Safety Act moderation, reporting, and complaints

How do content reports and complaints differ?

A content-reporting mechanism lets users and other eligible people notify the provider about content of a kind covered by the Act. A complaints procedure covers specified complaints about content, the provider's compliance, and certain provider decisions. For user-to-user services, sections 20 and 21 govern these duties; sections 31 and 32 cover search services.

The complaints procedure must allow relevant complaints, provide for appropriate action when a complaint is upheld, be easy to access and use, including by children, and be transparent. Appropriate action depends on the case. It may include removing illegal content, correcting a restriction, reinstating content removed in error, or changing an account decision. The Act does not require every complaint to produce the user's preferred result.

  • Keep reporting and complaints entry points clear, even if one intake form routes users behind the scenes.
  • Tell users what they can complain about, what information is needed, how the service will communicate, and what outcomes are possible.
  • Record the original decision, evidence, rule applied, reviewer, outcome, action taken, and any policy or model feedback.
Citations
Online Safety Act 2023

Sets user-to-user complaints duties, relevant complaint types, accessibility, transparency, and appropriate action.

Online Safety Act moderation, reporting, and complaints

What should terms, metrics, and governance show?

User-to-user terms must explain how users are protected from illegal content and set out the complaints policies and procedures required by the Act. Search services must make the corresponding illegal-content statement and complaints information public. Providers must apply stated provisions consistently.

Useful evidence includes moderation guidance, training, quality sampling, model and rule versions, error analysis, response times, reversals, repeat reports, systemic issues, staffing and language coverage, vendor oversight, child accessibility, and remediation. Metrics need stable definitions and should distinguish reports, pieces of content, decisions, accounts, complaints, and successful complaints.

  • Reconcile written terms, moderator guidance, product labels, enforcement reasons, and complaint outcomes after every policy change.
  • Track error and reversal rates by content class, language, age group where lawful and appropriate, and decision method.
  • Escalate repeated reversals or reporting failures into the risk assessment and control-review process.
Citations
UK Online Safety Act categories: thresholds and duties

What are the Category 1, 2A, and 2B thresholds?

Category 1 applies where a regulated user-to-user service exceeds 34 million average monthly active UK users and uses a content recommender system, or exceeds 7 million average monthly active UK users and has both a content recommender system and functionality for users to forward or share regulated user-generated content with other users.

Category 2A applies where a regulated search service, or the search engine of a combined service, exceeds 7 million average monthly active UK users and is not the specified type of vertical search engine limited to selected sites or databases under a relevant arrangement.

Category 2B applies where a regulated user-to-user service exceeds 3 million average monthly active UK users and provides qualifying direct messaging designed so messages cannot be encountered by other users unless the sender or recipient takes further action.

  • Apply each threshold to the relevant user-to-user part or search engine, not automatically to every function of a combined service.
  • Use the Regulations' monthly-active-UK-user calculation and prescribed assessment period rather than a global account count or headline reach figure.
  • Document the recommender, forwarding or sharing, search, and direct-messaging functionality with product evidence.
Citations
UK Online Safety Act categories: thresholds and duties

How does a service become formally categorised?

An internal threshold calculation is a monitoring decision, not the formal categorisation result. Ofcom assesses services, gives affected providers an opportunity to make representations, and publishes the register required by section 95. The register was published on 10 July 2026.

A service can appear in more than one category, and only the relevant part may be categorised. Ofcom's register, for example, explains that category treatment of a search function within a combined service does not automatically extend to non-search chatbot or feed functionality.

  • Check the current Ofcom register and retain the entry, provider entity, service description, category, and effective review date.
  • Notify the responsible legal and product teams of a provisional assessment or information request and preserve the underlying metrics.
  • Monitor material changes in UK users and qualifying functionality even when the service is not currently on the register.
Citations
UK Online Safety Act categories: thresholds and duties

What changes after categorisation?

All three categories are subject to transparency reporting after an Ofcom notice. Category 1 services also face additional user-empowerment, content, terms, and fraudulent-advertising duties; Category 2A services have additional search and fraudulent-advertising duties; Category 2B services have additional transparency obligations. The exact commencement and applicable notice must be checked for each duty.

Category 1 and Category 2A providers must also publish specified risk-assessment findings and provide Ofcom with assessment records as required. Categorisation does not replace the baseline illegal-content, children's access, child-safety, complaints, record-keeping, or enforcement duties.

  • Build a duty map by category, service part, commencement status, and regulator notice.
  • Keep risk-assessment publication text consistent with the full internal record while protecting information the law does not require to be disclosed.
  • Do not delay baseline duties while waiting for categorisation.
Citations
Online Safety Act 2023

Creates the annual transparency-notice framework for providers of relevant, categorised services.

When Are Senior Managers Liable Under the UK Online Safety Act?

When can section 110 apply?

Ofcom may include a requirement in an information notice for an entity to name one individual who meets the section 103 senior-manager test and can reasonably be expected to ensure compliance. The notice must also require the entity to inform the individual and explain the consequences of non-compliance. Naming happens in the entity's response; assigning an executive internally before a notice arrives is useful preparation but is not the statutory trigger.

Section 110 covers failure to prevent specified entity offences under section 109. These include failing to comply with the notice; knowingly or recklessly providing information that is false in a material particular; intentionally supplying encrypted information in a form that prevents Ofcom from understanding it; intentionally suppressing, destroying, or altering required information or documents; and intentional deletion or alteration of information that a data-preservation notice requires the entity to retain for an official investigation into a child's death. The precise intent and other elements in section 109 must be proved for the relevant route.

The entity must commit the underlying offence and the named individual must have failed to take all reasonable steps to prevent it. Section 110 therefore addresses information governance and evidence handling. A failure to meet an unrelated safety duty does not by itself establish the offence.

  • Authenticate the notice, recipient entity, legal power, covered service, questions, deadline, response format, preservation scope, and naming requirement.
  • Name an individual who meets section 103 and has enough authority, access, time, and organisational support to direct the response.
  • Issue written collection and preservation instructions, identify systems and data owners, and suspend routine deletion where retention is required.
  • Verify completeness, material accuracy, calculations, explanations, encryption usability, approvals, and delivery before the deadline.
Citations
Online Safety Act 2023 section 109

Binding elements of the entity and individual offences connected with information notices, including non-compliance, false information, encryption, destruction, alteration, and data preservation.

When Are Senior Managers Liable Under the UK Online Safety Act?

Which defences and separate liability routes matter?

Section 110 contains specific defences. For the failure-to-comply route, it is a defence that the person held the relevant senior-manager role for such a short time after the notice was given that they could not reasonably have been expected to prevent the entity's offence. For the false-information, encryption, destruction, alteration, and data-preservation routes, it is a defence that the person was not a section 103 senior manager when the relevant act occurred. For every section 110 route, lack of knowledge that the person had been named is a defence.

Section 201 addresses the burden once sufficient evidence raises one of these statutory defences: the court must assume the defence is satisfied unless the prosecution proves otherwise beyond reasonable doubt. Whether a defence succeeds depends on the evidence and should be assessed by qualified counsel.

Section 202 is separate. If an entity commits an offence and it was committed with a corporate officer's consent or connivance, or was attributable to the officer's neglect, the officer also commits the offence. This route does not depend on an Ofcom requirement to name a senior manager.

  • Analyse section 110 and section 202 separately because they cover different people, triggers, and legal tests.
  • Record when the individual learned of the naming, when they met the role test, and what authority and time they had.
  • Preserve contemporaneous instructions, decisions, challenges, corrections, escalations, and unresolved limitations.
  • Do not rewrite records after the event or treat a policy, board minute, or attestation as proof that every reasonable step was taken.
Citations
Page 2 of 3