Artifact GuideUKOfcom Enforcement

UK Online Safety Act Ofcom Enforcement

Ofcom can assess a concern, compel information, investigate a suspected breach, issue provisional findings, and reach a final confirmation decision after representations.

The provider should preserve source records, control every notice deadline, verify each submitted fact, and track remediation separately from its response to the alleged breach.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Ofcom enforcement under the Online Safety Act is not a single-step fine process. Ofcom can use supervision and information powers before or during an investigation, give the recipient an opportunity to respond to provisional findings, and issue a that requires remedial steps, a penalty, or both. Court approval is required for business disruption measures.

Section 1

How does Ofcom enforce the Online Safety Act?

Ofcom may receive a complaint, identify a concern through supervision or an enforcement programme, or use its information powers to test compliance. It first assesses the issue and may seek voluntary compliance, provide remediation time, gather more information, open a formal investigation, or take no further action. Not every concern reaches a formal breach decision.

If Ofcom opens an investigation, it normally tells the subject the scope and legal provisions under review and may issue information notices, require interviews, appoint a skilled person, or use other statutory powers. The subject must continue meeting the underlying Online Safety Act duties while the investigation runs.

Where Ofcom considers there are reasonable grounds to believe an enforceable requirement has been breached, it may issue a . A final breach finding is made through a after the recipient has had an opportunity to make representations.

Ofcom enforces provider duties, can require information, investigate suspected failures, issue confirmation and penalty decisions, and seek court orders that restrict access or business support in serious cases. The maximum financial penalty is generally the greater of £18 million or 10% of qualifying worldwide revenue, subject to the statutory route and calculation rules.

Readiness starts before an investigation: keep current scope and assessment records, the measures adopted under each duty, code or alternative-measure reasoning, terms enforcement, complaints data, testing, governance approvals, and change history. A notice-response procedure should authenticate the notice, preserve records, assign legal and factual owners, validate data, meet the stated deadline, and retain submission evidence.

  • Identify the Ofcom stage: initial assessment, supervision or remediation, formal investigation, provisional notice, or .
  • Confirm the exact statutory duty and service under review rather than responding at company level only.
  • Calendar every notice-specific deadline and preserve the material used to prepare the response.
  • Continue remediation without presenting corrective work as proof that no past breach occurred.
  • Record whether the requirement is a provider duty, an information requirement, an interview or inspection obligation, or a remedial step in a decision.
  • Identify the legal entity, regulated service or service part, UK user group, system, and period covered by the investigation.
  • Map each requested fact to its source record, factual owner, legal reviewer, submission approver, and any known limitation.
  • Escalate questions about statutory exemptions, overseas providers, related entities, controlling individuals, criminal offences, or court orders for case-specific advice.
Section 2

What evidence should a provider prepare for Ofcom?

Give legal or regulatory affairs one response record for the matter, supported by the product or operations owner who controls the relevant service. Record the exact obligation, service, period, Ofcom stage, response deadline, preservation scope, factual position, and remediation decision.

The evidence depends on the issue. It may include service-scope decisions, risk-assessment records, underlying data, moderation and recommender-system documentation, age-assurance testing, complaints and reporting records, terms of service, governance approvals, implementation logs, and communications with Ofcom. Preserve source data and explain limitations rather than reconstructing a cleaner record after the event.

  • Name a response lead, factual owner, legal reviewer, and person authorised to approve submissions.
  • Preserve relevant documents, messages, datasets, code or configuration history, and decision records.
  • Trace every submitted fact to a source and state any known gap, estimate, or qualification.
  • Keep remediation tickets and completion evidence separate from representations about whether a breach occurred.
Section 3

What can happen at the end of an Ofcom investigation?

After investigating, Ofcom may close the case without a provisional notice, issue a , or use another compliance route. A provisional notice states the obligations and period in question, Ofcom's reasons, and any proposed penalty or remedial steps. The recipient can make representations before a separate final decision maker reaches a final outcome.

Ofcom may then close the case, issue a further provisional notice where the legal conditions are met, settle the case, or issue a . A confirmation decision may find a breach, require specified steps, and impose a financial penalty. Closure after remediation does not necessarily mean Ofcom found that no breach occurred; the published case statement and decision explain the outcome.

  • Read the provisional notice, evidence package, and response instructions together.
  • Distinguish provisional findings from a final .
  • Track required remedial steps and financial penalties as separate obligations.
  • Do not describe a closed investigation as exoneration unless Ofcom's published decision supports that conclusion.
Section 4

How should a provider respond to an Ofcom notice?

Treat an Ofcom or enforcement notice as a controlled regulatory response. Confirm the legal entity and service, record when and how the notice was received, identify every request and definition, preserve relevant material, and assign owners for collection, verification, legal review, approval, and submission.

Information must be complete, accurate in all material respects, and provided in the required form and by the stated deadline. If a request is unclear or the provider needs more time, use Ofcom's stated contact route promptly. Do not assume that a discussion changes the deadline unless Ofcom confirms that change.

The response record should also capture service scope, affected user groups, the relevant risk assessment, code or alternative-measure reasoning, child-access status, mitigation owner, and Ofcom correspondence.

The output depends on the notice: it may be a verified information return, representations on provisional findings, a remedial plan, evidence that required steps are complete, or a combination of those records.

  • Break the notice into numbered requests and map each one to a data owner, reviewer, source, and completion status.
  • Record searches performed, systems checked, assumptions, exclusions, and quality-control steps.
  • Escalate missing data, inconsistent records, possible inaccuracies, and deadline risk as soon as they are identified.
  • Retain the final submission, proof of delivery, follow-up questions, remedial commitments, and evidence that each commitment was completed.
  • Record the Ofcom stage and legal power at intake so the team does not answer an as though it were a provisional breach finding.
  • Map every answer to a request number, source, owner, reviewer, approval, and submission status.
  • Check related assessment, complaints, age-assurance, terms-enforcement, and transparency records for consistency before approval.
  • Update the response procedure when Ofcom changes its enforcement or information-gathering guidance, or when a completed matter exposes a repeatable evidence gap.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for Ofcom's information powers, enforceable requirements, investigation notices, confirmation decisions, penalties, and business disruption measures.
legislation.gov.uk
Referenced sections
  • Official explanatory notes supporting the maximum-penalty statement for regulated services.
"Paragraph 4(1) of Schedule 13 says that the maximum penalty that OFCOM can impose on the provider of a regulated service is the greater of £18 million and 10% of the person’s "qualifying worldwide revenue" for the person’s most recent complete accounting period."
legislation.gov.uk
Referenced sections
  • Primary legislation for the court-based service-restriction route within the Act's business-disruption measures.
"Service restriction orders"
gov.uk
Referenced sections
  • Supports this page's Ofcom Enforcement analysis under the UK Online Safety Act.
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
gov.uk
Referenced sections
  • Official government correspondence urging timely implementation and effective enforcement of the Act.
"However, it is imperative that the Act is now implemented in its entirety as quickly as possible, with a long-term plan for effective enforcement across all aspects of the Act and with services of all sizes."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.