Artifact GuideUKPenalties and Fines

UK Online Safety Act Penalties and Fines

For a regulated service provider, Ofcom's maximum Online Safety Act penalty is the greater of GBP18 million and 10% of qualifying worldwide revenue for the provider's most recent complete accounting period.

The maximum is a ceiling, not an automatic fine. Ofcom must set an appropriate and proportionate amount and may use a single penalty, a daily penalty for a continuing failure, or both.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Online Safety Act penalties depend on the recipient, breach, revenue rules, and facts of the case. For a regulated service provider, the ceiling is the greater of GBP18 million and 10% of for its most recent complete accounting period. Ofcom considers seriousness, harm, gain, prevention, knowledge, remediation, history, cooperation, size, and turnover when setting an amount.

Section 1

What is the maximum Online Safety Act penalty?

Schedule 13 sets the maximum penalty for the provider of a regulated service at the greater of GBP18 million and 10% of the provider's for its most recent complete accounting period. If GBP18 million is greater than 10% of that revenue, GBP18 million is the ceiling; otherwise the 10% figure is the ceiling.

The ceiling does not predict the actual penalty. Ofcom may decide not to impose a financial penalty, or may impose an amount below the maximum, after considering the contravention and the statutory process. Different Schedule 13 rules apply to some penalties imposed on persons who are not providers, so do not apply the provider formula without identifying the recipient.

Where Ofcom makes qualifying related entities or controlling individuals jointly and severally liable under Schedule 15, the Act contains a group-revenue ceiling. Joint liability depends on the statutory relationship and conditions; it is not automatic for every member of a corporate group.

  • Identify the recipient, regulated service, alleged obligation, contravention period, and accounting period.
  • Calculate both GBP18 million and 10% of the applicable , then use the greater only as the statutory ceiling.
  • Check Schedule 15 before including group entities or controlling individuals in the liability analysis.
  • Keep the calculation assumptions, accounting records, currency conversion, and legal basis together.
Section 2

How does Ofcom decide the actual penalty amount?

Ofcom considers all circumstances of the case and must regard the penalty as appropriate and proportionate. Its Penalty Guidelines identify potentially relevant factors including the seriousness and duration of the contravention, actual or potential harm, financial or other gain, preventive steps, whether conduct was deliberate or reckless, senior-management knowledge, how quickly the breach ended, remediation, previous contraventions, and cooperation.

Schedule 13 also requires Ofcom to consider representations and evidence from the person and the effects of the failure. For a penalty imposed through a confirmation decision or penalty notice, relevant compliance and remedial steps must be considered. Evidence of harm or risk of harm to children informs Ofcom's application of the penalty factors.

Cooperation and remediation can affect the assessment, but neither guarantees that Ofcom will close a case or waive a penalty. A settlement discount is a separate procedural matter and requires the admissions and conditions in Ofcom's Enforcement Guidance.

  • Build a dated chronology of the failure, discovery, escalation, containment, remediation, and verification.
  • Quantify actual or potential user harm and any gain only where the evidence supports the method and assumptions.
  • Document what senior management knew, when it knew it, and what action followed.
  • Provide evidence of prevention, cooperation, and remediation without describing corrective work as proof that no breach occurred.
Section 3

When can Ofcom impose daily penalties?

Ofcom may impose a single penalty, a daily penalty, or both. A daily penalty may apply where the identified contravention is continuing and a confirmation decision requires action to bring the recipient into compliance. The decision specifies the daily rate and period, generally ending when the required action is completed or when the specified maximum period ends.

Daily penalties are not an automatic addition to every fine. The statutory power, proposed notice, final decision, continuing nature of the failure, and required action determine whether one applies. The final penalty generally cannot exceed the type, amount, or period proposed in the earlier notice for the same breach, subject to the Act's joint-liability exception.

Keep evidence of the date compliance was achieved and notify Ofcom through the route stated in the decision. Internal completion is not enough if the decision requires submission, verification, or another specified step.

  • Read the provisional notice and confirmation decision together to identify the permitted type and amount of penalty.
  • Track continuing failures daily and retain evidence for the first day on which every required action was complete.
  • Do not confuse a daily penalty with interest, an unpaid fee, or debt-enforcement costs.
  • Escalate immediately if the required action depends on a third party or cannot be completed by the stated deadline.
Section 4

What happens after Ofcom imposes a fine?

The confirmation decision or penalty notice states the amount, reasons, relevant aggravating or mitigating factors, and payment date. Record the payment obligation separately from any remedial steps because paying the fine does not itself complete a required correction.

If a penalty is not paid, Ofcom can pursue recovery as a debt. Ofcom has clarified that non-payment alone does not allow it to seek a court order blocking the service. Business disruption measures require continuing non-compliance with Online Safety Act duties and a court order; they do not amount to a global shutdown.

A person with a sufficient interest in an appealable Ofcom decision may appeal to the Upper Tribunal. The decision, Act, and applicable procedural rules control the deadline and grounds, so obtain case-specific advice immediately.

  • Calendar the payment, remedial, reporting, and appeal dates as separate entries.
  • Assign finance to payment mechanics and legal or regulatory affairs to the decision, appeal, and Ofcom communications.
  • Preserve proof of payment and proof of every required remedial step.
  • Check whether an appeal changes or suspends any obligation in the decision; do not assume that it does.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Sets out Ofcom's deterrence objective and the factors it may consider when determining an appropriate and proportionate amount.
legislation.gov.uk
Referenced sections
  • Binding source for penalty notices, recovery, confirmation decisions, appeals, and business disruption measures.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.