---
title: "UK Online Safety Act FAQ: scope, duties, and deadlines"
canonical_url: "https://www.sorena.io/artifacts/uk/online-safety-act/faq"
source_url: "https://www.sorena.io/artifacts/uk/online-safety-act/faq/items/page/3"
author: "Sorena AI"
description: "Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement."
published_at: "2026-05-09"
updated_at: "2026-07-24"
keywords:
  - "UK Online Safety Act"
  - "FAQ"
  - "UK Online Safety Act FAQ"
  - "compliance checklist"
  - "practical guidance"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK Online Safety Act FAQ: scope, duties, and deadlines

Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.

*Artifact Guide* *UK* *FAQ*

## UK Online Safety Act FAQ

Use this FAQ to identify the service, apply the right gateway tests, and move from legal scope to owned evidence and controls.

The answers distinguish baseline Part 3 and Part 5 duties from child-access, categorisation, transparency, privacy, and enforcement questions.

Start with the service, not the desired control. Decide whether it contains a regulated user-to-user part, search engine, combined-service part, or provider-pornography service and whether it has UK links. Then apply the illegal-content, children's access, age-assurance, complaints, categorisation, reporting, and enforcement rules that fit that result.

## Definitions

### Links with the United Kingdom

**Term:** UK links

A user-to-user or search service has UK links if it has a significant number of UK users, targets the UK market, or is accessible in the UK and there are reasonable grounds to believe its user-generated or search content presents a material risk of significant harm to people in the UK. A provider does not need to be established in the UK.

**Why it matters here:** UK links are a territorial gateway for Part 3 scope. The provider should record which route applies and preserve user, market, access, and risk evidence rather than relying only on a UK domain, office, or contract.

Sources:

- [Online Safety Act 2023, section 4](https://www.legislation.gov.uk/ukpga/2023/50/section/4?ref=sorena.io)

## Browse sub-FAQ modules

### [Does the UK Online Safety Act apply to this service?](/artifacts/uk/online-safety-act/faq/regulated-service-scope.md)

A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.

- 3 items

### [How Ofcom and ICO duties overlap for online services](/artifacts/uk/online-safety-act/faq/ico-overlap.md)

How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.

- 3 items

### [How Ofcom enforces the UK Online Safety Act](/artifacts/uk/online-safety-act/faq/ofcom-enforcement.md)

Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.

- 3 items

### [How to complete a children's access assessment](/artifacts/uk/online-safety-act/faq/children-s-access-assessment.md)

The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.

- 3 items

### [How to complete an illegal content risk assessment](/artifacts/uk/online-safety-act/faq/illegal-content-risk-assessment.md)

UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.

- 3 items

### [Is This a User-to-user or Search Service Under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/user-to-user-and-search-services.md)

Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.

- 4 items

### [Ofcom Transparency Reporting FAQ](/artifacts/uk/online-safety-act/faq/transparency-reporting.md)

Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.

- 3 items

### [Online Safety Act moderation, reporting, and complaints](/artifacts/uk/online-safety-act/faq/moderation-and-appeals.md)

How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.

- 3 items

### [UK Online Safety Act categories: thresholds and duties](/artifacts/uk/online-safety-act/faq/categorisation.md)

How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.

- 3 items

### [When Are Senior Managers Liable Under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/senior-manager-liability.md)

When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.

- 4 items

### [When is age assurance required under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/age-assurance.md)

When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.

- 3 items

Browse all indexed questions: [/artifacts/uk/online-safety-act/faq/items](/artifacts/uk/online-safety-act/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 5 of 35 items.*

### [What evidence should the response process keep?](/artifacts/uk/online-safety-act/faq/senior-manager-liability.md#what-evidence-should-the-response-process-keep)

*Module: [When Are Senior Managers Liable Under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/senior-manager-liability.md)*

Treat the information notice as a controlled legal and evidence process. Maintain a live requirements matrix, give the named individual authority to direct business and technical teams, and escalate immediately when a requirement cannot be met as written or on time.

- Requirements matrix: each question or retention requirement, owner, source system, response format, reviewer, status, and deadline.
- Preservation record: systems, custodians, vendors, backups, automated deletion, hold start, verification, exceptions, and release authority.
- Accuracy record: source-to-answer trace, calculation method, material assumptions, known gaps, technical validation, legal review, and approval.
- Escalation record: blocker, impact, options, decision-maker, contact with Ofcom where appropriate, remediation, and closure evidence.

Sources for this answer:

- [Ofcom - Online Safety Information Powers Guidance](https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/consultation-on-data-preservation-notices/online-safety-information-gathering-guidance-dec2025.pdf?v=409377&ref=sorena.io) - Current official guidance on statutory information requests, naming, completeness and accuracy, information offences, reasonable steps, and data-preservation notices.
- [Ofcom - Responding to requests for information](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/how-to-comply-with-the-online-safety-act-responding-to-ofcoms-requests-for-information?language=en&ref=sorena.io) - Official provider guidance to respond clearly, completely, accurately, and by the deadline in a statutory information notice.

### [Common questions about Senior Manager Liability](/artifacts/uk/online-safety-act/faq/senior-manager-liability.md#common-questions-about-senior-manager-liability)

*Module: [When Are Senior Managers Liable Under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/senior-manager-liability.md)*

The answers below separate the statutory trigger from useful governance. They explain the general law, not whether an offence or defence is proved in a particular case.

- Escalate immediately if the entity, notice requirement, deadline, data source, preservation scope, accuracy, or authority to direct the response is unclear.
- Obtain case-specific legal advice before making a personal-liability conclusion.

Sources for this answer:

- [Online Safety Act 2023 section 110](https://www.legislation.gov.uk/ukpga/2023/50/section/110?ref=sorena.io) - Binding source for the notice-specific senior-manager offence and its defences.
- [Online Safety Act 2023 section 202](https://www.legislation.gov.uk/ukpga/2023/50/section/202?ref=sorena.io) - Binding source for the separate corporate-officer liability route.

### [When is highly effective age assurance required?](/artifacts/uk/online-safety-act/faq/age-assurance.md#when-is-highly-effective-age-assurance-required)

*Module: [When is age assurance required under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/age-assurance.md)*

Part 5 providers that publish or display regulated provider pornographic content must use age verification or age estimation that is highly effective at determining whether a user is a child, so children are not normally able to encounter that content. Those duties took effect on 17 January 2025.

- Identify the exact statutory or code trigger and the service part, content class, and age boundary it controls.
- Do not rely on a date-of-birth box or self-declaration alone where highly effective age assurance is required.
- Keep an accessible fallback and complaints route for users who cannot complete or are wrongly classified by the primary method.

Sources for this answer:

- [Ofcom - Age assurance duties under the Online Safety Act](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/age-assurance?language=en&ref=sorena.io) - Explains the Part 3 and Part 5 age-assurance duties and their implementation dates.
- [Ofcom - Children's access assessment duties](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/childrens-access-assessment-duties-under-the-online-safety-act?ref=sorena.io) - Explains when highly effective age assurance can establish that children cannot normally access a service or part of it.
- [Online Safety Act 2023](https://www.legislation.gov.uk/ukpga/2023/50/section/81?ref=sorena.io) - Sets the Part 5 age-assurance duty for regulated provider pornographic content.

### [What makes an age-assurance process highly effective?](/artifacts/uk/online-safety-act/faq/age-assurance.md#what-makes-an-age-assurance-process-highly-effective)

*Module: [When is age assurance required under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/age-assurance.md)*

Ofcom assesses the whole process, not the vendor label. Its criteria are technical accuracy, robustness, reliability, and fairness. The provider should test the method in the real user journey, including circumvention, repeat attempts, false acceptance of children, false rejection of adults, bias across relevant groups, outages, and the effect of fallbacks.

- Set measurable acceptance criteria for accuracy, circumvention resistance, reliability, fairness, and completion rates before launch.
- Document vendor due diligence, test populations, thresholds, model or rule versions, security controls, retention, deletion, and incident handling.
- Monitor performance after launch and reassess after material product, vendor, threshold, or threat changes.

Sources for this answer:

- [Ofcom - Use of Age Assurance Report 2026](https://www.ofcom.org.uk/online-safety/protecting-children/use-of-age-assurance-report-2026?ref=sorena.io) - Reports Ofcom's 2026 findings on deployed methods, circumvention, age inference, vendor due diligence, and provider responsibility.
- [Ofcom - Age assurance duties under the Online Safety Act](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/age-assurance?language=en&ref=sorena.io) - Sets out Ofcom's highly effective age-assurance criteria and method guidance.

### [How do privacy duties apply?](/artifacts/uk/online-safety-act/faq/age-assurance.md#how-do-privacy-duties-apply)

*Module: [When is age assurance required under the UK Online Safety Act?](/artifacts/uk/online-safety-act/faq/age-assurance.md)*

Every age-assurance method processes personal data. UK GDPR and the Data Protection Act 2018 continue to apply alongside the Online Safety Act. The organisation must identify a lawful basis, use only data needed for the stated age decision, explain the processing, secure it, set retention limits, support rights, and assess processors and international transfers.

- Keep the online-safety assessment, data protection impact assessment, privacy notice, vendor terms, and deletion evidence aligned.
- Separate age tokens or results from identity data where the purpose does not require identity disclosure.
- Give users a clear explanation and a practical route to challenge an incorrect result.

Sources for this answer:

- [Ofcom and ICO - Joint statement on age assurance](https://ico.org.uk/media2/5ybpmabf/ofcom-ico-joint-statement.pdf?ref=sorena.io) - Explains how Online Safety Act and UK data-protection duties apply together to age assurance, including necessity, proportionality, self-declaration, and circumvention.
- [ICO - Age assurance for the Children's Code](https://ico.org.uk/about-the-ico/what-we-do/information-commissioners-opinions/age-assurance-for-the-childrens-code/?ref=sorena.io) - Explains data-protection expectations and the Children's Code context for age assurance.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/uk/online-safety-act/faq/items](/artifacts/uk/online-safety-act/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/uk/online-safety-act/faq/items.md) | [2](/artifacts/uk/online-safety-act/faq/items/page/2.md) | [3](/artifacts/uk/online-safety-act/faq/items/page/3.md)

[Previous page](/artifacts/uk/online-safety-act/faq/items/page/2.md)

*Recommended next step*

*Placement: after the practical guidance*

## Document the Online Safety Act duty map

Record the scope, source, owner, evidence, decision, and review trigger for Online Safety Act duties.

- [Create the assessment record](/solutions/assessment.md): Create scoped questions, evidence fields, owners, and review tasks for Online Safety Act duties.
- [Check the source evidence](/solutions/research-copilot.md): Answer follow-up questions against cited legislation and regulator guidance.
- [Review the implementation](/contact.md): Review the scope, evidence, controls, owners, and open decisions for Online Safety Act duties.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/online-safety-act/faq/items/page/3.md
