- ICO source for age-assurance and children-code privacy context that can affect user-group and child-access fields.
"It explains how UK GDPR and the DPA 2018 apply, and how the Children's code and the Online"
Risk Assessment Workflow decisions under the UK Online Safety Act should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.
Use this guide to turn official requirements into scope, evidence, owner, and review decisions. This guidance is practical, source-linked, and should be validated against current legal and policy requirements before implementation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page helps you determine when UK Online Safety Act obligations apply, who owns each action, the required evidence, and the review path before escalation.
Run the workflow as online-safety triage: first confirm whether the service is in scope, then check whether children are likely to access it, identify the relevant duty or risk type, decide the mitigation or control, record evidence, assign an owner, and set the next review date. If the service is not in scope, close the item; if it is in scope and the risk is unresolved, escalate before implementation.
A useful template captures service type, user group, risk type, child-access result, code measure, mitigation owner, evidence, review date, and unresolved assumptions. Each field should support a decision, not just store a label.
Review the workflow after Ofcom code updates, feature changes, algorithm changes, user-base changes, incident trends, complaints, enforcement notices, or transparency-report cycles. Use each review to decide whether the current controls still reduce the identified risk, whether the evidence is sufficient, and whether the item should stay open, be escalated, or be closed.
Use this UK Online Safety Act guide to turn Risk Assessment Workflow into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.
Turn Risk Assessment Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"It explains how UK GDPR and the DPA 2018 apply, and how the Children's code and the Online"
"This document is described as an interim impact review of the Children's code"
"Ofcom must keep the codes of practice under review."
"Section 47(1) of the OSA require Ofcom to keep under review each code of practice."