- Supports this page's Risk Assessments Playbook analysis under the UK Online Safety Act.
"UK GDPR and the DPA 2018"
Use one operating playbook to assign assessment inputs, challenge weak evidence, approve mitigations, and reopen decisions when the service changes.
The playbook coordinates the work; it does not merge the Act's separate illegal-content, children's access, and children's risk-assessment duties.
Structured answer sets in this page tree.
Cited legal and guidance references.
A risk-assessment playbook sets the operating rules around the Part 3 legal assessments: who opens them, which evidence each team supplies, how risks are challenged, who approves controls, and what reopens the record. Use it for every regulated user-to-user and search service, while keeping the illegal-content assessment, children's access assessment, and any children's risk assessment identifiable as separate outputs with their own statutory tests and deadlines.
Intake opens a versioned assessment for a defined service, a new or newly in-scope service, or a proposed . Legal or regulatory owners confirm the applicable duty and deadline; product and engineering describe the design; trust and safety supplies harm and enforcement evidence; data teams quantify prevalence, reach, recommender exposure, search pathways, complaints, and uncertainty; privacy, security, accessibility, and child-safety specialists test proposed controls.
A challenge meeting tests scope, missing evidence, foreseeable misuse, groups at greater risk, design choices that amplify harm, control dependencies, and the residual-risk conclusion. Unsupported conclusions return for more evidence rather than converting uncertainty into a low score.
Approval links each material risk to a current control, owner, delivery date, monitoring signal, and in-force Ofcom code measure or documented effective alternative. The Act sets the binding duty; Ofcom codes describe a compliance route, guidance explains Ofcom's approach, and consultations do not impose current requirements. The accountable owner approves only after urgent actions and launch gates are explicit.
Operations monitors the assumptions. Product change, new harm evidence, control failure, or an Ofcom update creates a review ticket and identifies which assessment versions must be reopened.
Maintain an assessment register with service, assessment type, version, statutory provision, owner, approval date, next scheduled review, event-driven review trigger, significant-change decision, open actions, and evidence location. Within each assessment, keep separate rows for each content or harm pathway and each materially affected user group.
Review the playbook when assessments repeatedly miss the same evidence, actions remain overdue, control tests cannot be reproduced, or product teams bypass the significant-change gate. Review the underlying statutory assessment whenever the Act's accuracy or significant-change trigger is met; an annual calendar alone is not enough.
Use the playbook to assign evidence, challenge conclusions, approve controls, monitor assumptions, and reopen assessments when the service changes.
Turn Risk Assessments Playbook into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"UK GDPR and the DPA 2018"
"Children's code"
"Online Safety Act"
"Online Safety Act"
"The Online Safety Act 2023 (the Act) is a new set of laws that protects children and adults online."