Artifact GuideUKUser-to-user and Search Services

UK Online Safety Act User-to-user and Search Services

Classify the service by what users can do, who controls the relevant functions, whether the service has UK links, and whether a specific exemption or service-part rule applies.

A regulated service then has baseline duties. Child access, combined-service functions, and category status determine which additional duties apply.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
14

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use four tests in order. First, identify every user-content and search function. Second, identify the entity that controls access to the user-to-user functionality or controls search operations. Third, decide whether the service has . Fourth, apply the specific Schedule 1 exemptions, Schedule 2 treatment, and any rules that disapply the Act to part of a service. This sequence determines whether the product is a regulated , , or and which duties follow.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How do you classify the service functionality?

A user-to-user classification turns on functionality, not branding. Ask whether content generated, uploaded, or shared by one user may be encountered by another. Public or group posts, user profiles, uploaded media, marketplace listings, in-game chat, collaborative spaces, and messaging can meet the test. The amount of user-generated content does not matter, and a Schedule 1 exemption must be tested separately.

For search, ask whether a person can search more than one website or database. General search and vertical search for products, jobs, travel, academic material, or another topic can qualify. A tool restricted to one website or one database does not meet the section 229 search-engine definition merely because it uses filters, recommendations, or sophisticated ranking.

If one product has both functions, apply the section 3 tie-breaker. Unless its only user-generated content falls within the specified exempt types, it is treated as user-to-user. If the same provider also operates a public search engine, it is a and the search duties apply to that engine.

  • Inventory every function through which a user creates, uploads, shares, searches, comments on, or encounters content.
  • Record whether communications are public, group, one-to-one, live, aural, asynchronous, internal, or attached to provider content.
  • For each search function, record the websites and databases searched and the entity that controls indexing, ranking, requests, and results.
  • Classify distinct functions and service parts before deciding whether an exemption covers the whole product or only a defined part.
Citations
Question 3

Which exemptions and service boundaries must be checked?

Schedule 1 exemptions use specific statutory conditions. They include services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications; defined limited-functionality services; qualifying internal business services; specified public-body services; and qualifying education or childcare services. A broad product or sector label does not establish an exemption, and some exemptions operate at service-part level.

The limited-functionality exemption generally concerns comments or reviews on provider content, reactions to that content, and sharing those comments or reviews elsewhere. It does not exempt a service that also enables wider user interaction. The education and childcare exemption applies only to the providers and purposes described in Schedule 1, not every product sold to a school or used by a child.

Schedule 2 addresses certain services combining otherwise exempt user-to-user or search functions with provider pornographic content. Such a service may remain regulated under Part 5 even when the Part 3 user-to-user or search duties do not apply. Section 5 can also disapply the Act to a qualifying internal-business part of a Part 3 service or a specified part of a regulated without removing the whole service from scope.

  • Test the exact content, functionality, provider, user, and purpose conditions for an exemption.
  • Check the exception in Schedule 1 paragraph 6 to the email, messaging, aural, limited-functionality, and combination exemptions.
  • For internal tools, document the corporate relationship, permitted users, purpose, and any public or customer-facing part.
  • For pornography, education, childcare, and public-body cases, record the separate conditions and any duty that remains under another Part.
Citations
Question 4

What follows after classification?

Every regulated Part 3 service must complete an illegal-content risk assessment and maintain the applicable safety, reporting, complaints, freedom-of-expression, privacy, record-keeping, and review controls. The safety duties differ by service type: user-to-user services address user-generated content and use of the service to commit or facilitate priority offences, while search services address risks arising through search content and results.

The provider must also complete a children's access assessment. If the service or a relevant part is likely to be accessed by children, the children's risk-assessment and safety duties apply. Category status can add transparency, user-empowerment, fraudulent-advertising, and other duties, but it does not replace the baseline scope decision.

  • Approve a scope memo with the feature inventory, provider entity, UK-links evidence, exemption analysis, service-part boundaries, and unresolved questions.
  • Open separate duty maps for the user-to-user and search components of a .
  • Reassess before adding public comments, messaging, uploads, group interaction, multi-database search, or a UK market.
  • Keep child-access and category decisions as later branches; do not use them to erase baseline Part 3 duties.

Is a service outside the Act because it has few UK users?

Not necessarily. A significant number of UK users is one route to . A UK target market is another. A service accessible in the UK can also qualify where there are reasonable grounds to believe its content or functionality creates a material risk of significant harm to individuals in the UK.

Is an internal search box a ?

Not if it searches only one website or one database. Section 229 excludes a service or functionality limited to one website or database. A vertical search engine covering multiple websites or databases can qualify even if it covers only one topic.

Are email and private messages always exempt?

No. Schedule 1 exempts services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications, subject to the schedule's conditions and exceptions. A wider service with posts, group communications, profiles, uploads, comments, or other interaction needs a function-by-function analysis.

Does a service need to meet a category threshold before baseline duties apply?

No. Category thresholds determine additional duties for Category 1, 2A, or 2B services. They are not a minimum threshold for baseline Part 3 scope. A service that meets the functionality, UK-links, and non-exemption tests can have baseline duties without being categorised.

Citations
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for service definitions, regulated status, exemptions, service-part boundaries, provider identity, and the duties following classification.
legislation.gov.uk
Referenced sections
  • Binding treatment of certain services combining exempt user-to-user or search functions with regulated provider pornographic content.
legislation.gov.uk
Referenced sections
  • Binding search-engine definition, including the exclusion for a search limited to one website or database.
legislation.gov.uk
Referenced sections
  • Binding allocation of duties to regulated search services and the search engine of a combined service.
legislation.gov.uk
Referenced sections
  • Binding definitions and tie-breaker for services that include both user-generated content and a search engine.
legislation.gov.uk
Referenced sections
  • Binding regulated-service and UK-links tests, including targeting and material risk of significant harm.
gov.uk
Referenced sections
  • Official overview confirming the broad application to search services and services that let users post content or interact, including providers outside the UK where the UK-links test is met.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.