FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
35of35items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
When Are Senior Managers Liable Under the UK Online Safety Act?

What evidence should the response process keep?

Treat the information notice as a controlled legal and evidence process. Maintain a live requirements matrix, give the named individual authority to direct business and technical teams, and escalate immediately when a requirement cannot be met as written or on time.

The response record should cover information held by vendors and overseas teams, data lineage, calculation methods, samples, source preservation, and whether Ofcom can understand any encrypted material. For a data-preservation notice, document how the hold prevents both deliberate alteration and routine irreversible deletion for the required period.

Evidence should show what the manager did, when, with what information, and how the team addressed problems. It cannot determine by itself whether all reasonable steps were taken; that conclusion depends on the full facts.

  • Requirements matrix: each question or retention requirement, owner, source system, response format, reviewer, status, and deadline.
  • Preservation record: systems, custodians, vendors, backups, automated deletion, hold start, verification, exceptions, and release authority.
  • Accuracy record: source-to-answer trace, calculation method, material assumptions, known gaps, technical validation, legal review, and approval.
  • Escalation record: blocker, impact, options, decision-maker, contact with Ofcom where appropriate, remediation, and closure evidence.
Citations
When Are Senior Managers Liable Under the UK Online Safety Act?

Common questions about Senior Manager Liability

The answers below separate the statutory trigger from useful governance. They explain the general law, not whether an offence or defence is proved in a particular case.

  • Escalate immediately if the entity, notice requirement, deadline, data source, preservation scope, accuracy, or authority to direct the response is unclear.
  • Obtain case-specific legal advice before making a personal-liability conclusion.

Can a senior manager be liable for any Online Safety Act breach?

No. Section 110 is limited to an individual named in response to an Ofcom information notice, an underlying entity offence listed in section 110, and failure by that individual to take all reasonable steps to prevent it. Section 202 is a separate route for an entity offence involving a corporate officer's consent, connivance, or neglect. Neither provision creates automatic personal liability for every breach of a safety duty.

Does Ofcom have to name the senior manager?

No. Ofcom can require the entity, through an information notice, to name an individual who meets the section 103 role test and can reasonably be expected to ensure compliance. The entity names the person in its response and must inform that person when the notice requires it.

Does a board title or compliance policy prove all reasonable steps?

No. The Act does not provide a closed checklist, and the answer depends on the notice, underlying offence, role, authority, time, systems, and actions taken. Keep contemporaneous evidence of instructions, preservation, verification, escalation, correction, and blockers. A title, policy, or attestation is only part of that factual record.

What should a named senior manager do first after receiving notice?

Confirm the recipient entity, legal power, full requirements, deadline, response format, preservation obligations, and responsible data owners. Establish a requirements matrix, issue collection and preservation instructions, assign legal and technical review, and escalate any inability to comply or any suspected inaccuracy immediately.

Citations
When is age assurance required under the UK Online Safety Act?

When is highly effective age assurance required?

Part 5 providers that publish or display regulated provider pornographic content must use age verification or age estimation that is highly effective at determining whether a user is a child, so children are not normally able to encounter that content. Those duties took effect on 17 January 2025.

For Part 3 user-to-user and search services, highly effective age assurance can support a conclusion at stage one of the children's access assessment that children cannot normally access the service or a particular part of it. Services likely to be accessed by children must also use highly effective age assurance where the child-safety duties or Ofcom's codes require it, including to protect children from pornography and other primary-priority content. The Part 3 child-protection measures applied from 25 July 2025.

  • Identify the exact statutory or code trigger and the service part, content class, and age boundary it controls.
  • Do not rely on a date-of-birth box or self-declaration alone where highly effective age assurance is required.
  • Keep an accessible fallback and complaints route for users who cannot complete or are wrongly classified by the primary method.
Citations
When is age assurance required under the UK Online Safety Act?

What makes an age-assurance process highly effective?

Ofcom assesses the whole process, not the vendor label. Its criteria are technical accuracy, robustness, reliability, and fairness. The provider should test the method in the real user journey, including circumvention, repeat attempts, false acceptance of children, false rejection of adults, bias across relevant groups, outages, and the effect of fallbacks.

Methods can include open banking, photo identification matching, facial age estimation, mobile-network checks, credit-card checks, digital identity services, and email-based age estimation where the method meets Ofcom's guidance. No method is automatically compliant in every deployment. Ofcom's July 2026 report says age inference is not accepted as highly effective for services that must prevent child access unless the provider can support a different conclusion with reliable and compelling evidence.

  • Set measurable acceptance criteria for accuracy, circumvention resistance, reliability, fairness, and completion rates before launch.
  • Document vendor due diligence, test populations, thresholds, model or rule versions, security controls, retention, deletion, and incident handling.
  • Monitor performance after launch and reassess after material product, vendor, threshold, or threat changes.
Citations
When is age assurance required under the UK Online Safety Act?

How do privacy duties apply?

Every age-assurance method processes personal data. UK GDPR and the Data Protection Act 2018 continue to apply alongside the Online Safety Act. The organisation must identify a lawful basis, use only data needed for the stated age decision, explain the processing, secure it, set retention limits, support rights, and assess processors and international transfers.

Complete a data protection impact assessment where the processing is likely to create a high risk to people. Connect it to the online-safety rationale so the record explains why the method and threshold are necessary and proportionate, what less intrusive options were considered, and how misclassification is corrected. The Children's Code may also apply to an online service likely to be accessed by children.

  • Keep the online-safety assessment, data protection impact assessment, privacy notice, vendor terms, and deletion evidence aligned.
  • Separate age tokens or results from identity data where the purpose does not require identity disclosure.
  • Give users a clear explanation and a practical route to challenge an incorrect result.
Citations
Page 3 of 3