Artifact GuideUKOnline Safety Act vs DSA

UK Online Safety Act Online Safety Act vs DSA

A service offered in both markets may fall under both laws. The UK Act covers specified UK-linked services; the EU DSA covers intermediary services offered to recipients in the EU.

Classify each service and function separately, then map its duties, dates, evidence, and regulator. A UK risk assessment does not replace a DSA notice, transparency, platform, or systemic-risk record.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The UK Online Safety Act and the can both apply to one product. The UK test asks whether a user-to-user, search, combined, or provider-pornography service has the required UK links. The DSA asks whether an intermediary service is offered to recipients in the EU, then assigns duties by service class and, for the largest platforms and search engines, formal designation. Run both tests when the same service reaches both populations.

Side-by-side comparison

UK Online Safety Act vs EU Digital Services Act

Compare Online Safety Act and through scope, actors, triggers, duties, evidence, deadlines, enforcement, and operational decision rules.

Review all sources
First framework
Online Safety Act

The UK Act regulates UK-linked user-to-user, search, and provider-pornography services through harm-specific risk, safety, complaints, records, and Ofcom-supervised duties.

Second framework
DSA

The EU regulates intermediary services offered to recipients in the EU, with layered duties for hosting services, online platforms, marketplaces, and designated VLOPs/VLOSEs.

Comparison row 1

Scope and covered activity

Online Safety Act

UK OSA: test each user-to-user, search, combined-service, and provider-pornography function; apply the UK-link rules and statutory exemptions.

DSA

: test whether the service is an intermediary service, hosting service, online platform, marketplace, search engine, or very large platform/search engine serving EU users.

Operational implication

Write two scope findings first: where Online Safety Act applies, where applies, and which facts are outside one side even if evidence can be reused.

Comparison row 2

Who must act

Online Safety Act

UK OSA: the provider of the regulated service owns the duties; service-level facts, child access, Part 5 status, and Ofcom categorisation change which duties apply.

DSA

: the provider's role as intermediary, hosting service, online platform, marketplace, or designated VLOP/VLOSE determines the duty layer; non-EU providers may need an EU legal representative.

Operational implication

Map the same product to a UK regulated-service type and an EU intermediary-service type separately; the labels are not interchangeable.

Comparison row 3

Trigger or threshold

Online Safety Act

UK OSA: UK-linked regulated service scope triggers core duties; likely child access, provider pornography, and entry on Ofcom's category register trigger additional duty sets.

DSA

: start from the service category and EU-recipient reach, including whether the provider is an intermediary, hosting service, online platform, online marketplace, search engine, or a platform or search engine with at least 45 million average monthly active recipients in the EU that the Commission has designated as very large.

Operational implication

Start with the trigger so teams do not apply the wrong regime to the wrong facts.

Comparison row 4

Exemptions and service boundaries

Online Safety Act

UK OSA: apply the Act's own exclusions and exemptions to each function, including any limited-function or combined-service analysis; status does not decide UK scope.

DSA

: public dissemination that is only minor and purely ancillary may fall outside the online-platform definition, and micro or small enterprises are exempt from specified platform duties unless designated as VLOPs; other applicable DSA duties remain.

Operational implication

Record the facts and provision for every exclusion. Reassess after changes to functionality, user reach, corporate size, market targeting, or designation.

Comparison row 5

Core obligations

Online Safety Act

UK OSA: illegal-content risk and safety duties apply to regulated Part 3 services; child-access findings can add children's risk and safety duties; Part 5 has provider-pornography age-assurance duties; Category 1 services face user-empowerment duties, and categorised services can face transparency-reporting duties.

DSA

: intermediaries face baseline contact-point and terms-and-conditions duties, while micro and small enterprises are exempt from Article 15 transparency reporting unless they are VLOPs; hosting services add notice-and-action and reasons; platforms add complaints and advertising duties, with trader-traceability duties for marketplaces and safeguards for minors; VLOPs/VLOSEs add systemic-risk, mitigation, audit, data-access, and crisis duties.

Operational implication

A shared moderation or reporting system can support both regimes, but the required risk taxonomy, legal trigger, service boundary, notice, and evidence must remain traceable to each law.

Comparison row 6

Evidence and records

Online Safety Act

UK OSA: retain scope and child-access assessments, illegal and children's risk assessments, records of measures, terms enforcement, complaints evidence, age-assurance rationale, and Ofcom submissions.

DSA

: retain service classification, notice-and-action decisions and reasons, complaint outcomes, recommender and advertising disclosures, trader traceability, transparency data, and, where applicable, systemic-risk and audit records.

Operational implication

Create a control crosswalk, but keep separate legal conclusions and regulator-ready evidence indexes.

Comparison row 7

Timing and cadence

Online Safety Act

UK OSA: core illegal-content duties became enforceable on 17 March 2025 and child-safety duties on 25 July 2025; new or changing services use event-based assessment timing, and Ofcom notices set additional deadlines.

DSA

: the general regime has applied since 17 February 2024; designated VLOPs/VLOSEs became subject to their additional duties four months after notification, with recurring annual risk and audit cycles.

Operational implication

Maintain two calendars: UK assessment and notice triggers do not replace EU recurring transparency, risk, and audit dates.

Comparison row 8

Enforcement or assurance route

Online Safety Act

UK OSA: Ofcom investigates and enforces, with information powers, compliance and penalty decisions, and court-based service-restriction routes; the provider maximum is generally the greater of GBP18 million or 10% of qualifying worldwide revenue.

DSA

: national Digital Services Coordinators supervise most providers while the European Commission has primary VLOP/VLOSE powers; maximum fines for failure to comply with DSA obligations can reach 6% of annual worldwide turnover, with separate limits for information failures and periodic penalty payments.

Operational implication

Regulator ownership, notice procedure, penalty basis, and escalation channel differ even where the underlying product control is shared.

Comparison row 9

Overlap and reuse

Online Safety Act

UK risk assessments focus on illegal-content and child-harm duties for the regulated service, including algorithms and functionalities that affect exposure.

DSA

VLOP/VLOSE systemic-risk assessments cover a broader EU risk set and designated-service boundary; smaller DSA services do not inherit that annual systemic-risk duty merely because the UK OSA applies.

Operational implication

Reuse inventories, metrics, testing, complaints data, and governance evidence, but preserve each regime's risk categories, population, cadence, and approval record.

Comparison row 10

Practical decision rule

Online Safety Act

Run the UK OSA workstream where the service has relevant UK links and fits a regulated-service type, regardless of whether the same product is also offered in the EU.

DSA

Run the workstream where an intermediary service is offered to EU recipients, then apply the duties for its DSA service tier and any designation.

Operational implication

For products serving both markets, expect both regimes. Share operational systems only after writing separate scope, duty, date, and evidence mappings.

Practical decision rule

How to use the Online Safety Act vs DSA comparison

  • Run the Online Safety Act workstream when a service has the required UK links and fits a regulated-service class, then add the duties triggered by child access, Part 5 status, or categorisation.
  • Run the workstream when an intermediary service is offered to EU recipients, then add the duties for its hosting, platform, marketplace, search, or designated-service class.
  • Run both workstreams when both tests are met. Keep the legal conclusions, deadlines, and evidence indexes separate even when one operational control supports both.
Section 1

Which law applies to the service?

Start with the service, not the company. For the UK Act, identify each user-to-user, search, combined, or Part 5 provider-pornography function and apply the UK-link test and statutory exemptions. For the , decide whether the activity is mere conduit, caching, or hosting, then whether a hosting service also disseminates information to the public as an online platform or lets consumers conclude distance contracts with traders as an online marketplace.

A provider outside the UK can still fall within the Online Safety Act where the service has the required UK links. A provider outside the EU can still fall within the where it offers an intermediary service to recipients in the EU under Article 2(1); Article 13 then requires a legal representative in an EU Member State unless the provider is established in the EU.

The largest platforms and search engines acquire the additional VLOP or VLOSE duties only after a Commission designation based on the statutory threshold and process. UK Category 1, 2A, or 2B status likewise depends on Ofcom's register. Neither designation is a substitute for the baseline scope test.

  • List each service, function, provider entity, user population, country of establishment, target market, and route by which users encounter content.
  • Write a UK outcome for each function: regulated, exempt, outside the UK-link test, Part 3, Part 5, or awaiting a fact needed for the decision.
  • Write an EU outcome for each function: outside the , mere conduit, caching, hosting, online platform, marketplace, search engine, or designated VLOP or VLOSE.
  • Run both duty maps where both tests are met; do not use compliance with one law as evidence that the other law does not apply.
Section 2

Who owns the comparison, and what evidence proves it?

Give legal or regulatory affairs ownership of the two legal classifications, but assign each control to the team that can change the service. Product, trust and safety, advertising, marketplace operations, privacy, data, and engineering may own different parts of the same duty map.

Keep a separate scope memo and evidence index for each law. The UK record should cover service type, UK links, exemptions, illegal-content and child-access decisions, risk assessments, safety measures, complaints, terms, age assurance, and Ofcom submissions. The record should cover intermediary class, EU offering and establishment, notices and reasons, internal complaints, transparency data, recommender and advertising disclosures, trader traceability, and any VLOP or VLOSE risk, audit, data-access, and mitigation records.

Shared moderation, reporting, age-assurance, and governance systems can produce evidence for both laws. Record which rule each control satisfies, the population and service boundary tested, the data period, the owner, and the next review trigger.

  • Name one accountable legal owner for each regime and one operational owner for each implemented control.
  • Keep the service inventory, classification decision, source provision, product evidence, implementation ticket, test result, and approval linked.
  • Use dated evidence for user counts, market targeting, notices, risk assessments, vendor controls, user journeys, transparency reports, and regulator submissions.
  • Reassess after a new service or market launch, acquisition, material feature change, changed user count, new designation, regulator notice, or amendment to the controlling law.
Section 3

Which exclusions and edge cases change the answer?

The two regimes classify functions differently. A product can contain an Online Safety Act user-to-user service, a hosting or platform service, and functions outside one or both regimes. Assess a combined service by its relevant parts instead of assigning one label to every feature.

Under the , a hosting service is not an online platform where public dissemination is only a minor and purely ancillary feature that cannot be used without the principal service. Micro and small enterprises receive exemptions from specified online-platform duties unless they are designated as VLOPs, but they remain subject to the DSA provisions that still apply to their service class. The UK Act has its own statutory exemptions and limited-function rules; a DSA exemption or small-enterprise status does not create a UK exemption.

Age and child protection also differ. The UK Act uses children's access, child-risk, safety, and age-assurance duties for relevant services. Article 28 requires online platforms accessible to minors to use appropriate and proportionate measures for a high level of privacy, safety, and security and restricts profiling-based advertising where the provider knows with reasonable certainty that the recipient is a minor.

  • Split combined products into functions before applying either law.
  • Record the facts supporting every exemption, ancillary-function conclusion, or small-enterprise status and review them when the product or organisation changes.
  • Do not map UK children's access findings directly to the test for an online platform accessible to minors.
  • Escalate marketplace, search, private-messaging, ancillary-comment, and mixed provider-content cases when the service class depends on detailed product facts.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Official European Commission overview supporting the DSA service tiers, duties, application, VLOP/VLOSE threshold, and enforcement context used on this side of the comparison.
"The DSA regulates online intermediaries and platforms"
legislation.gov.uk
Referenced sections
  • Binding source for the UK classification and duty sequence.
gov.uk
Referenced sections
  • GOV.UK collection used to ground Online Safety Act implementation materials and official guidance references.
"The Online Safety Act 2023 (the Act) protects children and adults online."
gov.uk
Referenced sections
  • GOV.UK source for the Online Safety Act comparison side, including child and adult online protection context.
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."
gov.uk
Referenced sections
  • GOV.UK correspondence source for Online Safety Act implementation and Ofcom enforcement context.
"One of my top priorities as DSIT Secretary of State is to protect children, tackle illegal content and facilitate effective and responsible compliance from service providers."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.