Artifact GuideUKSenior Manager Liability

UK Online Safety Act Senior Manager Liability

Section 110 can make an individual named in an Ofcom information-notice response personally liable when the entity commits a specified information offence and the individual failed to take all reasonable steps to prevent it.

Section 110 does not impose automatic liability for every breach of an online-safety duty. Section 202 separately covers corporate officers where an entity offence was committed with their consent or connivance or was attributable to their neglect.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
13

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Personal liability under the Online Safety Act is tied to specific offences and facts. Under section 110, a can commit an offence only if the entity commits one of the listed information offences and the individual failed to take to prevent it. Under section 202, a can commit the entity's offence where consent, connivance, or neglect is proved. These routes do not make every executive personally criminally liable whenever a service breaches a safety duty.

Section 1

When can section 110 apply?

Ofcom may require an entity receiving an to name one individual who is a senior manager and can reasonably be expected to ensure compliance. The notice must require the entity to inform that individual and explain the consequences of non-compliance. Naming happens in the entity's response; an internal allocation made before the notice is useful governance but is not the statutory trigger.

Section 110 then covers failure to prevent specified entity offences: failure to comply with the ; knowingly or recklessly providing materially false information; providing encrypted information in a form that prevents Ofcom from understanding it with the required intent; suppressing, destroying, or altering required information or documents with the required intent; and the later offence concerning intentional deletion or alteration of information required by a data-preservation notice for an investigation into a child's death.

For each route, the entity must commit the underlying offence and the named individual must have failed to take to prevent it. The legislation does not require the entity to be prosecuted first merely to establish the section 110 offence, but the underlying entity offence must be proved.

  • Authenticate the notice, legal power, recipient entity, covered service, requirements, deadline, format, preservation scope, and naming requirement.
  • Name an individual who meets section 103 and has enough authority, access, time, and organisational support to ensure compliance.
  • Issue written collection and preservation instructions, identify data owners and systems, and block routine deletion where the notice requires retention.
  • Verify completeness, material accuracy, encryption usability, explanations, approvals, and delivery before the deadline.
Section 2

What defences and separate liability routes matter?

For a failure-to-comply charge under section 110(2), it is a defence that the person held the relevant senior-manager role for such a short time after the notice was given that they could not reasonably have been expected to prevent the offence. For the false-information, encryption, destruction, and data-preservation routes, it is a defence that the person was not a section 103 senior manager when the relevant act occurred. For every section 110 charge, lack of knowledge that the person had been named is a defence.

Section 201 governs the burden once sufficient evidence raises a statutory defence: the court must assume the defence is satisfied unless the prosecution proves otherwise beyond reasonable doubt. These defences are fact-specific and should not be treated as substitutes for notice controls.

Section 202 is different. If a relevant entity commits an offence and the offence was committed with an officer's consent or connivance, or was attributable to the officer's neglect, the officer also commits the offence. It does not require the section 103 naming process.

  • Keep section 110 analysis separate from section 202 analysis; their covered people, triggers, and legal tests differ.
  • Record when the person learned they were named, when they met the section 103 role test, and what authority and time they had.
  • Preserve evidence of decisions, instructions, escalations, challenges, corrections, and unresolved limitations without rewriting the record after the event.
  • Route any personal-liability assessment to qualified counsel; this page cannot determine whether a criminal offence or defence is proved in a specific case.
Section 3

What should the notice-response control contain?

Treat an Ofcom notice as a controlled legal and evidence process. The named individual needs a live requirements matrix, clear authority to direct business and technical teams, access to legal and technical reviewers, and immediate escalation when a requirement cannot be met as written.

The response process should cover information held by vendors and overseas teams, explain data lineage, validate calculations and samples, preserve source material, and confirm that encrypted information is intelligible to Ofcom. If a data-preservation notice applies, the hold must prevent both intentional deletion and routine irreversible deletion for the required period.

The record should show what the manager did, when, with what information, and how problems were addressed. It should not claim that governance paperwork proves ; that conclusion depends on the full facts.

  • Requirements matrix: each question or retention requirement, owner, source system, format, legal issue, reviewer, status, and deadline.
  • Preservation record: systems, custodians, vendors, backups, automated deletion, hold start, verification, exceptions, and release authority.
  • Accuracy record: source-to-answer trace, calculation method, material assumptions, known gaps, technical validation, legal review, and final approval.
  • Escalation record: blocker, impact, options, decision-maker, contact with Ofcom where appropriate, remediation, and closure evidence.
Section 4

What should boards and executives do before a notice arrives?

Maintain an information-governance map for each regulated service: provider entity, accountable executives, data owners, vendors, retention schedules, technical contacts, legal reviewers, and access to source systems. Run a notice-response exercise against a realistic deadline and include overseas data, encryption, backups, and routine deletion.

Do not pre-name someone as a substitute for Ofcom's statutory request. Instead, identify people who could meet the section 103 test, confirm succession and absence cover, and give them authority to obtain evidence and escalate non-cooperation.

Can a senior manager be liable for every Online Safety Act breach?

No. Section 110 is limited to an individual named under an Ofcom , a specified underlying entity information offence, and the individual's failure to take to prevent it. Section 202 is a separate route for an officer where an entity offence involved the officer's consent or connivance or was attributable to the officer's neglect. Other statutes may create different personal-liability regimes.

Must Ofcom name the senior manager?

No. Ofcom may require the provider entity to name an individual in its response to an . The entity selects a person who meets the statutory senior-manager test and can reasonably be expected to ensure compliance. The notice must require the entity to inform the individual and explain the consequences.

Does a policy prove that were taken?

No. A policy can support the evidence, but section 110 asks what the individual actually did in the circumstances. Relevant records can include timely instructions, preservation holds, ownership and authority, verification, escalation, correction, and action on known gaps. Whether the legal test is met depends on the full evidence.

Is the Crime and Policing Act 2026 unlawful-weapons-content regime the same as section 110?

No. Chapter 1 of Part 2 of the Crime and Policing Act 2026 establishes a separate content-removal notice and civil-penalty regime for unlawful weapons content, including a provider's content manager, but those provisions are not yet in force. It should not be described as the Online Safety Act section 110 information-offence route. Providers potentially covered by both need separate legal and operational mappings.

  • Approve a response protocol that starts on receipt, preserves evidence, and logs every requirement and decision.
  • Test whether data can be exported accurately, explained, decrypted for use, and retained across production, analytics, vendor, and backup systems.
  • Train likely managers and data owners on false-information, destruction, alteration, preservation, and escalation risks.
  • Review the protocol after service, entity, vendor, retention, encryption, or regulatory-guidance changes.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Enacted source for the separate unlawful-weapons content-removal and content-manager civil-penalty regime; section 255 requires commencement regulations before these provisions come into force.
legislation.gov.uk
Referenced sections
  • Binding source for information notices, naming, information offences, named-senior-manager liability, defences, corporate-officer liability, and extraterritorial application.
legislation.gov.uk
Referenced sections
  • Binding entity and individual offences connected with information notices, including non-compliance, false information, encryption, destruction, and data preservation.
legislation.gov.uk
Referenced sections
  • Binding extraterritorial application of service references and Ofcom's information-gathering powers.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.