Artifact GuideUKModeration and Appeals

UK Online Safety Act Moderation and Appeals

Regulated user-to-user and search services need accessible content-reporting and complaints procedures, appropriate action when complaints are upheld, and moderation systems that match their assessed risks.

The Act does not impose one universal appeal window or notice template. The required complaint route depends on the service type, the complainant, the content, the moderation action, and any additional Category 1 duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
18

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Build the reporting, moderation, and complaint paths around the duty that applies. All regulated user-to-user and search services need systems for reporting specified content and a for the complaint types listed in the Act. An can have a statutory route even without an account. User-to-user services may also need to review action taken against content, accounts, or users. The Act requires appropriate action when a complaint is upheld, but it does not set one general appeal deadline, reviewer model, or notification wording for every service. Providers must also protect freedom of expression and privacy when choosing and operating safety measures.

Section 1

Which reports and complaints must a service accept?

A regulated user-to-user service must let users and affected persons report illegal content. If the service is likely to be accessed by children, it must also enable reports of content harmful to children on parts children can access. Section 21 then requires complaints routes for the content and system failures specified for that service, including complaints that the provider did not act on illegal content or that its reporting or complaints process does not operate as required.

The user-to-user complaints duty also covers specified actions taken by the provider against content or a user, such as removal or access restriction, suspension or banning, or restrictions on use. The exact route depends on which statutory duty caused the action. Additional complaint types apply where Category 1 duties or other Part 3 duties apply.

Search services have parallel reporting and complaints duties in sections 31 and 32. Their process must account for people affected by indexed content even if they never used the search service.

  • Identify whether the reporter is a user, an , or a person acting for someone else, and do not require an account where the Act protects a non-user.
  • Separate a first report of content from a complaint about the provider's decision or failure, while allowing evidence to move between the two records.
  • Route complaints by service type, content category, affected duty, moderation action, child-access status, and any Category 1 duty.
  • Explain the available routes in clear terms or a public statement, including what information is needed and what outcomes the provider can take.
Section 2

When does the Act require an appeal?

The baseline Act speaks mainly in terms of reports, complaints, and appropriate action, not a universal appeal right with a fixed deadline. A provider can use an internal appeal as its method for handling a complaint about removal, restriction, suspension, or another moderation decision, but the process still has to cover every statutory complaint type that applies.

Some additional duties are more specific. Category 1 protections for news publisher and journalistic content include dedicated procedures and, in defined circumstances, notification and an opportunity to make representations before action is taken. Those provisions should not be copied into a baseline process and described as applying to every service or every item of content.

Ofcom does not decide individual user complaints and cannot order a service to remove or reinstate particular content through its ordinary complaints portal. Individuals should first use the service's own process; information later sent to Ofcom can inform regulatory monitoring.

  • Do not advertise a statutory appeal right, deadline, or independent reviewer unless the applicable provision or the provider's terms create it.
  • Record the outcome and action. If a complaint is upheld, remove illegal content, restore content removed in error, reverse an account action, or repair the process; if it is not upheld, give a supported explanation.
  • Keep special Category 1, news publisher, journalistic-content, democratic-importance, and terms-of-service routes separate from the baseline illegal-content workflow.
  • Tell users accurately what Ofcom can do with an individual complaint and avoid implying that Ofcom is a merits appeal body.
Section 3

How should moderation decisions be made and reviewed?

For a judgement that content is illegal, section 192 requires the provider to use all relevant information reasonably available. The provider should infer that content is illegal only where there are reasonable grounds to infer the elements of a relevant offence and no reasonable grounds to infer a defence. The rule applies to human and automated judgements, although the information reasonably available can differ.

must also match the most recent risk assessment and the systems described in the provider's terms or public statement. Sections 22 and 33 require particular regard to users' legal rights to freedom of expression and privacy when the provider decides on and implements safety measures.

Data protection still applies when moderation uses personal data, profiling, age assurance, or automated tools. Ofcom and the ICO state that online safety and data protection are compatible but must be considered together; neither regime displaces the other.

  • Decision record: content or account identifier, applicable rule, relevant offence or harm category, available evidence, possible defence, decision, action, and decision-maker.
  • System record: detection source, model or rule version, confidence or escalation threshold, human-review path, staffing, training, quality sample, and error correction.
  • Complaint record: complainant status, original decision, grounds, new evidence, reviewer, outcome, action, response date, and any systemic issue opened.
  • Policy record: the exact terms or public statement in force at the time and evidence that similar cases were handled consistently.
Section 4

What workflow and evidence should the provider maintain?

Assign one operational owner for reporting and complaints, but keep product, trust and safety, legal, privacy, accessibility, and engineering responsibilities explicit. Test the public path without a logged-in account, with assistive technology, and with a child-appropriate journey where children can use it.

Measure whether the process produces timely and appropriate action for the assessed risk. The Act does not supply one universal turnaround time, so internal targets should be justified by harm severity, evidence needs, legal uncertainty, and the measures in the applicable Ofcom code.

Does every moderation decision need an appeal under the Online Safety Act?

No single appeal rule applies to every moderation decision. Sections 21 and 32 require complaints procedures for specified matters, and those procedures must provide appropriate action when a complaint is upheld. A provider may implement that duty through an appeal process. Separate Category 1 provisions create more specific challenge and notification requirements for defined content, including news publisher and journalistic content.

Can a person complain if they do not have an account?

Yes, where they meet the applicable affected-person test. The reporting and complaints duties protect specified non-users, including people who are the subject of content or otherwise affected in a way covered by the Act. The service should not force those people to create an account merely to reach the required route.

Can Ofcom reinstate content after an individual complaint?

No. Ofcom says it cannot respond to or investigate individual complaints or instruct a service to remove or reinstate specific content. The person should use the service's process first. Information submitted to Ofcom can still help it assess whether a provider is meeting its wider duties.

  • Publish: covered report and complaint types, who may submit, required information, stages, possible outcomes, and any provider-created time limits.
  • Operate: triage imminent harm, preserve evidence, assess the applicable rule, take interim action where justified, decide, communicate, and allow the required challenge.
  • Correct: reverse wrong decisions, repair affected records or rankings, notify relevant teams, and feed recurring errors into risk assessment and control review.
  • Evidence: retain decisions, response times, uphold rates, error themes, accessibility results, training, quality assurance, vendor controls, and policy versions.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Official distinction between eligible organisations' super-complaints and individual complaints, including Ofcom's inability to order removal or reinstatement in an individual case.
legislation.gov.uk
Referenced sections
  • Binding source for content reporting, complaints, moderation-related safety duties, freedom of expression, privacy, records, and Category 1 content protections.
legislation.gov.uk
Referenced sections
  • Official explanation of who must be able to report and complain, which complaint types apply, and examples of appropriate corrective action.
legislation.gov.uk
Referenced sections
  • Binding Category 1 duty to operate a dedicated and expedited complaints procedure for journalistic content.
legislation.gov.uk
Referenced sections
  • Binding user-to-user complaints requirements, including covered complaints, appropriate action, accessibility, transparency, and terms-of-service publication.
legislation.gov.uk
Referenced sections
  • Binding rules for code measures, alternative measures, and safeguards for freedom of expression and privacy.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.