Artifact GuideUKICO Overlap

UK Online Safety Act ICO Overlap

Online Safety Act duties do not displace UK data protection law. A safety control that processes personal data must satisfy the applicable Ofcom duty and the UK GDPR and Data Protection Act 2018.

Assess the safety purpose, legal basis, necessity, proportionality, accuracy, fairness, transparency, retention, security, user rights, and vendor roles before launch, then monitor both safety and privacy outcomes.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Run one joined design review whenever an Online Safety Act measure uses personal data, but record separate conclusions under each regime. Ofcom regulates online-safety duties; the Information Commissioner's Office regulates UK data protection law and the Children's Code. Complete a before high-risk processing, connect the data used to a defined safety purpose and lawful basis, and retain evidence that the chosen design is necessary, proportionate, fair, accurate, secure, and no more intrusive than the risk requires.

Section 1

When do online-safety and data-protection duties apply together?

The overlap begins when a provider processes personal data to assess or reduce an Online Safety Act risk. Common examples are checking age, profiling users for risk, ranking or suppressing recommended content, detecting illegal content or coordinated abuse, reviewing reports and appeals, sharing child-safety information, and measuring whether a control works. The Online Safety Act supplies the safety duty; it does not automatically settle the UK GDPR lawful basis, purpose, or method.

For age assurance, the March 2026 Ofcom-ICO joint statement says all methods process personal data. An in-scope service may use personal data where the method is necessary and proportionate to its risks and complies with data protection law. Where the Online Safety Act requires highly effective age assurance, the service must meet Ofcom's effectiveness criteria as well as UK GDPR requirements. Self-declaration alone is not effective for preventing underage access.

The Children's Code is a statutory data-protection code for information society services likely to be accessed by children. It can apply even where the service is outside the Online Safety Act. If the provider cannot establish age with confidence appropriate to its data-processing risks, ICO guidance says it should apply the Code's standards to all users rather than assume they are adults.

  • Scope both regimes: regulated service part and Online Safety Act duty; controller, processor, data subjects, data categories, purposes, and Children's Code status.
  • Select the lawful basis for each purpose and, where relevant, the separate condition for special-category or criminal-offence data; do not reuse a safety justification as a complete data-protection analysis.
  • Test necessity and proportionality against less intrusive methods, then document effectiveness, accuracy, circumvention, bias, exclusion, accessibility, and challenge routes.
  • Define collection, access, sharing, retention, deletion, security, processor instructions, international transfers, privacy information, and rights handling before launch.
Section 2

What decisions and evidence should the joined review produce?

The product or safety owner should define the Online Safety Act risk and required outcome. The controller should assign a privacy owner who can change the processing design, with legal, security, data, accessibility, child-safety, and engineering review. A vendor can operate the tool, but outsourcing does not remove the provider's safety duties or the controller's data-protection accountability.

Keep the Online Safety Act assessment and the linked but distinct. The first explains the service risk and proportionate safety measure; the second explains the personal-data processing, lawful basis, necessity, rights risks, safeguards, and residual risk. Record any disagreement and who accepted or escalated it.

  • Safety evidence: scope memo, illegal-content or children's risk assessment, risk-to-control mapping, applicable Ofcom code measure or alternative-measure rationale, and effectiveness target.
  • Privacy evidence: processing map, lawful-basis analysis, Children's Code assessment, screening and record, privacy notice, retention schedule, security review, and rights procedure.
  • Technical evidence: data fields, model or rule version, test population, false-positive and false-negative results, bias and accessibility testing, circumvention testing, human review, vendor instructions, and deletion verification.
  • Operational evidence: age or moderation challenge records, correction outcomes, incident logs, control metrics, complaints, approvals, review dates, and unresolved residual risks.
Section 3

Which borderline cases change the analysis?

An Online Safety Act duty can require highly effective age assurance without prescribing one technology. The provider must choose a method that meets Ofcom's standard and separately complies with data protection law. Conversely, a service outside the Online Safety Act can still need age assurance or child-appropriate design to avoid unlawful processing and meet the Children's Code.

A minimum age in terms does not prove that younger children are absent. The 2026 joint statement says self-declaration is not effective to prevent underage access and gives facial age estimation, digital identity, and one-time photo matching as current examples for enforcing a minimum age of 13; these are examples, not mandatory methods or regulator endorsements.

Safety analytics can be personal data even when names are removed, and a processor's score can still affect a user. Pseudonymisation reduces some risk but does not take data outside UK GDPR where re-identification remains possible. A provider should also separate legal obligations from optional product analytics or reuse for advertising, because those purposes can need different lawful-basis and compatibility analysis.

  • Logged-out access: test whether harmful content or provider pornography can be reached before an age check and whether identifiers created for the check are necessary and disclosed.
  • Children and adults: test wrongful exclusion, age-estimation error, accessibility, and a prominent way to challenge an inaccurate decision.
  • Automated moderation: document the information used, the action taken, human review, correction route, and whether UK GDPR restrictions on solely automated significant decisions apply.
  • Data sharing: identify controller roles, purpose, legal basis, minimised fields, recipient, retention, security, transfer mechanism, and whether disclosure is required or voluntary.
Section 4

What sequence should teams follow before launch and during operation?

Start with the service-scope and child-access decisions, then identify the exact safety duty and risk. Describe the personal-data processing needed to meet that outcome, screen for a , compare methods, approve the least intrusive effective design, and test it before release. Where unmitigated high data-protection risk remains, consult the ICO before processing.

After launch, monitor both sides of the decision. Safety metrics should show whether users encounter less illegal or harmful content; privacy metrics should show error, exclusion, complaints, rights requests, incidents, retention, vendor performance, and unexpected reuse. Update the connected records rather than treating approval as permanent.

  • Trigger: a new or changed age-assurance, moderation, recommender, profiling, reporting, complaints, measurement, or safety-data-sharing process.
  • Decision: record the safety duty, data purpose, lawful basis, method comparison, necessity, proportionality, safeguards, residual risks, approvers, and launch conditions.
  • Operation: version the system, monitor effectiveness and errors, handle challenges and rights requests, verify deletion, audit vendors, and feed findings into both assessments.
  • Reassess after a significant service or model change, new data or purpose, changed vendor or transfer, serious incident, material error pattern, updated Ofcom or ICO guidance, or a change in the relevant risk profile.
Primary sources

References and citations

gov.uk
Referenced sections
  • Boundary and edge-case support for this artifact page.
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.