A service offered in both markets may fall under both laws. The UK Act covers specified UK-linked services; the EU DSA covers intermediary services offered to recipients in the EU.
Classify each service and function separately, then map its duties, dates, evidence, and regulator. A UK risk assessment does not replace a DSA notice, transparency, platform, or systemic-risk record.
The UK Online Safety Act and the can both apply to one product. The UK test asks whether a user-to-user, search, combined, or provider-pornography service has the required UK links. The DSA asks whether an intermediary service is offered to recipients in the EU, then assigns duties by service class and, for the largest platforms and search engines, formal designation. Run both tests when the same service reaches both populations.
Side-by-side comparison
UK Online Safety Act vs EU Digital Services Act
Compare Online Safety Act and through scope, actors, triggers, duties, evidence, deadlines, enforcement, and operational decision rules.
The UK Act regulates UK-linked user-to-user, search, and provider-pornography services through harm-specific risk, safety, complaints, records, and Ofcom-supervised duties.
Second framework
DSA
The EU regulates intermediary services offered to recipients in the EU, with layered duties for hosting services, online platforms, marketplaces, and designated VLOPs/VLOSEs.
: test whether the service is an intermediary service, hosting service, online platform, marketplace, search engine, or very large platform/search engine serving EU users.
UK OSA: the provider of the regulated service owns the duties; service-level facts, child access, Part 5 status, and Ofcom categorisation change which duties apply.
: the provider's role as intermediary, hosting service, online platform, marketplace, or designated VLOP/VLOSE determines the duty layer; non-EU providers may need an EU legal representative.
: start from the service category and EU-recipient reach, including whether the provider is an intermediary, hosting service, online platform, online marketplace, search engine, or a platform or search engine with at least 45 million average monthly active recipients in the EU that the Commission has designated as very large.
UK OSA: apply the Act's own exclusions and exemptions to each function, including any limited-function or combined-service analysis; status does not decide UK scope.
: public dissemination that is only minor and purely ancillary may fall outside the online-platform definition, and micro or small enterprises are exempt from specified platform duties unless designated as VLOPs; other applicable DSA duties remain.
Record the facts and provision for every exclusion. Reassess after changes to functionality, user reach, corporate size, market targeting, or designation.
UK OSA: illegal-content risk and safety duties apply to regulated Part 3 services; child-access findings can add children's risk and safety duties; Part 5 has provider-pornography age-assurance duties; Category 1 services face user-empowerment duties, and categorised services can face transparency-reporting duties.
: intermediaries face baseline contact-point and terms-and-conditions duties, while micro and small enterprises are exempt from Article 15 transparency reporting unless they are VLOPs; hosting services add notice-and-action and reasons; platforms add complaints and advertising duties, with trader-traceability duties for marketplaces and safeguards for minors; VLOPs/VLOSEs add systemic-risk, mitigation, audit, data-access, and crisis duties.
A shared moderation or reporting system can support both regimes, but the required risk taxonomy, legal trigger, service boundary, notice, and evidence must remain traceable to each law.
UK OSA: retain scope and child-access assessments, illegal and children's risk assessments, records of measures, terms enforcement, complaints evidence, age-assurance rationale, and Ofcom submissions.
: retain service classification, notice-and-action decisions and reasons, complaint outcomes, recommender and advertising disclosures, trader traceability, transparency data, and, where applicable, systemic-risk and audit records.
UK OSA: core illegal-content duties became enforceable on 17 March 2025 and child-safety duties on 25 July 2025; new or changing services use event-based assessment timing, and Ofcom notices set additional deadlines.
: the general regime has applied since 17 February 2024; designated VLOPs/VLOSEs became subject to their additional duties four months after notification, with recurring annual risk and audit cycles.
UK OSA: Ofcom investigates and enforces, with information powers, compliance and penalty decisions, and court-based service-restriction routes; the provider maximum is generally the greater of GBP18 million or 10% of qualifying worldwide revenue.
: national Digital Services Coordinators supervise most providers while the European Commission has primary VLOP/VLOSE powers; maximum fines for failure to comply with DSA obligations can reach 6% of annual worldwide turnover, with separate limits for information failures and periodic penalty payments.
UK risk assessments focus on illegal-content and child-harm duties for the regulated service, including algorithms and functionalities that affect exposure.
VLOP/VLOSE systemic-risk assessments cover a broader EU risk set and designated-service boundary; smaller DSA services do not inherit that annual systemic-risk duty merely because the UK OSA applies.
Reuse inventories, metrics, testing, complaints data, and governance evidence, but preserve each regime's risk categories, population, cadence, and approval record.
Run the UK OSA workstream where the service has relevant UK links and fits a regulated-service type, regardless of whether the same product is also offered in the EU.
For products serving both markets, expect both regimes. Share operational systems only after writing separate scope, duty, date, and evidence mappings.
: test whether the service is an intermediary service, hosting service, online platform, marketplace, search engine, or very large platform/search engine serving EU users.
UK OSA: the provider of the regulated service owns the duties; service-level facts, child access, Part 5 status, and Ofcom categorisation change which duties apply.
: the provider's role as intermediary, hosting service, online platform, marketplace, or designated VLOP/VLOSE determines the duty layer; non-EU providers may need an EU legal representative.
: start from the service category and EU-recipient reach, including whether the provider is an intermediary, hosting service, online platform, online marketplace, search engine, or a platform or search engine with at least 45 million average monthly active recipients in the EU that the Commission has designated as very large.
UK OSA: apply the Act's own exclusions and exemptions to each function, including any limited-function or combined-service analysis; status does not decide UK scope.
: public dissemination that is only minor and purely ancillary may fall outside the online-platform definition, and micro or small enterprises are exempt from specified platform duties unless designated as VLOPs; other applicable DSA duties remain.
Record the facts and provision for every exclusion. Reassess after changes to functionality, user reach, corporate size, market targeting, or designation.
UK OSA: illegal-content risk and safety duties apply to regulated Part 3 services; child-access findings can add children's risk and safety duties; Part 5 has provider-pornography age-assurance duties; Category 1 services face user-empowerment duties, and categorised services can face transparency-reporting duties.
: intermediaries face baseline contact-point and terms-and-conditions duties, while micro and small enterprises are exempt from Article 15 transparency reporting unless they are VLOPs; hosting services add notice-and-action and reasons; platforms add complaints and advertising duties, with trader-traceability duties for marketplaces and safeguards for minors; VLOPs/VLOSEs add systemic-risk, mitigation, audit, data-access, and crisis duties.
A shared moderation or reporting system can support both regimes, but the required risk taxonomy, legal trigger, service boundary, notice, and evidence must remain traceable to each law.
UK OSA: retain scope and child-access assessments, illegal and children's risk assessments, records of measures, terms enforcement, complaints evidence, age-assurance rationale, and Ofcom submissions.
: retain service classification, notice-and-action decisions and reasons, complaint outcomes, recommender and advertising disclosures, trader traceability, transparency data, and, where applicable, systemic-risk and audit records.
UK OSA: core illegal-content duties became enforceable on 17 March 2025 and child-safety duties on 25 July 2025; new or changing services use event-based assessment timing, and Ofcom notices set additional deadlines.
: the general regime has applied since 17 February 2024; designated VLOPs/VLOSEs became subject to their additional duties four months after notification, with recurring annual risk and audit cycles.
UK OSA: Ofcom investigates and enforces, with information powers, compliance and penalty decisions, and court-based service-restriction routes; the provider maximum is generally the greater of GBP18 million or 10% of qualifying worldwide revenue.
: national Digital Services Coordinators supervise most providers while the European Commission has primary VLOP/VLOSE powers; maximum fines for failure to comply with DSA obligations can reach 6% of annual worldwide turnover, with separate limits for information failures and periodic penalty payments.
UK risk assessments focus on illegal-content and child-harm duties for the regulated service, including algorithms and functionalities that affect exposure.
VLOP/VLOSE systemic-risk assessments cover a broader EU risk set and designated-service boundary; smaller DSA services do not inherit that annual systemic-risk duty merely because the UK OSA applies.
Reuse inventories, metrics, testing, complaints data, and governance evidence, but preserve each regime's risk categories, population, cadence, and approval record.
Run the UK OSA workstream where the service has relevant UK links and fits a regulated-service type, regardless of whether the same product is also offered in the EU.
For products serving both markets, expect both regimes. Share operational systems only after writing separate scope, duty, date, and evidence mappings.
How to use the Online Safety Act vs DSA comparison
Run the Online Safety Act workstream when a service has the required UK links and fits a regulated-service class, then add the duties triggered by child access, Part 5 status, or categorisation.
Run the workstream when an intermediary service is offered to EU recipients, then add the duties for its hosting, platform, marketplace, search, or designated-service class.
Run both workstreams when both tests are met. Keep the legal conclusions, deadlines, and evidence indexes separate even when one operational control supports both.
Start with the service, not the company. For the UK Act, identify each user-to-user, search, combined, or Part 5 provider-pornography function and apply the UK-link test and statutory exemptions. For the , decide whether the activity is mere conduit, caching, or hosting, then whether a hosting service also disseminates information to the public as an online platform or lets consumers conclude distance contracts with traders as an online marketplace.
A provider outside the UK can still fall within the Online Safety Act where the service has the required UK links. A provider outside the EU can still fall within the where it offers an intermediary service to recipients in the EU under Article 2(1); Article 13 then requires a legal representative in an EU Member State unless the provider is established in the EU.
The largest platforms and search engines acquire the additional VLOP or VLOSE duties only after a Commission designation based on the statutory threshold and process. UK Category 1, 2A, or 2B status likewise depends on Ofcom's register. Neither designation is a substitute for the baseline scope test.
List each service, function, provider entity, user population, country of establishment, target market, and route by which users encounter content.
Write a UK outcome for each function: regulated, exempt, outside the UK-link test, Part 3, Part 5, or awaiting a fact needed for the decision.
Write an EU outcome for each function: outside the , mere conduit, caching, hosting, online platform, marketplace, search engine, or designated VLOP or VLOSE.
Run both duty maps where both tests are met; do not use compliance with one law as evidence that the other law does not apply.
Who owns the comparison, and what evidence proves it?
Give legal or regulatory affairs ownership of the two legal classifications, but assign each control to the team that can change the service. Product, trust and safety, advertising, marketplace operations, privacy, data, and engineering may own different parts of the same duty map.
Keep a separate scope memo and evidence index for each law. The UK record should cover service type, UK links, exemptions, illegal-content and child-access decisions, risk assessments, safety measures, complaints, terms, age assurance, and Ofcom submissions. The record should cover intermediary class, EU offering and establishment, notices and reasons, internal complaints, transparency data, recommender and advertising disclosures, trader traceability, and any VLOP or VLOSE risk, audit, data-access, and mitigation records.
Shared moderation, reporting, age-assurance, and governance systems can produce evidence for both laws. Record which rule each control satisfies, the population and service boundary tested, the data period, the owner, and the next review trigger.
Name one accountable legal owner for each regime and one operational owner for each implemented control.
Keep the service inventory, classification decision, source provision, product evidence, implementation ticket, test result, and approval linked.
Use dated evidence for user counts, market targeting, notices, risk assessments, vendor controls, user journeys, transparency reports, and regulator submissions.
Reassess after a new service or market launch, acquisition, material feature change, changed user count, new designation, regulator notice, or amendment to the controlling law.
Which exclusions and edge cases change the answer?
The two regimes classify functions differently. A product can contain an Online Safety Act user-to-user service, a hosting or platform service, and functions outside one or both regimes. Assess a combined service by its relevant parts instead of assigning one label to every feature.
Under the , a hosting service is not an online platform where public dissemination is only a minor and purely ancillary feature that cannot be used without the principal service. Micro and small enterprises receive exemptions from specified online-platform duties unless they are designated as VLOPs, but they remain subject to the DSA provisions that still apply to their service class. The UK Act has its own statutory exemptions and limited-function rules; a DSA exemption or small-enterprise status does not create a UK exemption.
Age and child protection also differ. The UK Act uses children's access, child-risk, safety, and age-assurance duties for relevant services. Article 28 requires online platforms accessible to minors to use appropriate and proportionate measures for a high level of privacy, safety, and security and restricts profiling-based advertising where the provider knows with reasonable certainty that the recipient is a minor.
Split combined products into functions before applying either law.
Record the facts supporting every exemption, ancillary-function conclusion, or small-enterprise status and review them when the product or organisation changes.
Do not map UK children's access findings directly to the test for an online platform accessible to minors.
Escalate marketplace, search, private-messaging, ancillary-comment, and mixed provider-content cases when the service class depends on detailed product facts.
Official European Commission overview supporting the DSA service tiers, duties, application, VLOP/VLOSE threshold, and enforcement context used on this side of the comparison.
"The DSA regulates online intermediaries and platforms"
GOV.UK correspondence source for Online Safety Act implementation and Ofcom enforcement context.
"One of my top priorities as DSIT Secretary of State is to protect children, tackle illegal content and facilitate effective and responsible compliance from service providers."