Artifact GuideUKTransparency Reporting

UK Online Safety Act Transparency Reporting

The Online Safety Act transparency-reporting duty applies to providers of Category 1, Category 2A, and Category 2B services after an Ofcom notice, not to every regulated service.

Use the notice and Schedule 8 to identify the required information, reporting period, publication method, deadline, and accountable data owners. Keep this process separate from ad hoc Ofcom information notices.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Sections 77 and 78 and establish annual transparency reporting for , , and services. The duty to produce a particular report starts with an Ofcom for that categorised service. The notice controls the requested information, reporting period, format, working-day deadline, submission, and publication method. A voluntary report or response to a separate Ofcom information notice is not the section 77 report.

Section 1

Who reports, and what can Ofcom require?

Section 77 applies only to a provider of a service entered on Ofcom's register as , , or . Ofcom must give a separate notice for each categorised service, even where one provider operates several. Providers should use the July 2026 register to confirm the exact service, provider, category, and regulated part rather than report at group or brand level by default.

Ofcom published the first register on 30 June 2026 and updated it on 10 July 2026. The register identifies the services subject to the transparency regime, but it does not supply the reporting fields or deadline. Ofcom first shares a draft notice so the provider can make written representations, then issues the final notice that creates the report-specific requirements.

limits the subjects Ofcom may request. and 2B notices can require user-to-user information about the listed matters; notices can require search-engine information. For a combined service listed in both Category 2A and Category 1 or 2B, Ofcom may require both. If the combined service is listed only in Category 2A, the notice can require only search-engine information.

Possible subjects include the incidence and dissemination of illegal or child-harmful content, assumed user exposure, reports and complaints, moderation and ranking systems, algorithms, risk assessment, safety measures, age assurance, CSEA reporting, user support, media literacy, and cooperation with public bodies. The list is a legal ceiling, not a requirement to report every item in every cycle; the final notice selects the information for that service.

For each reported figure, retain the numerator, denominator, population, time zone, date range, inclusion and exclusion rules, deduplication logic, source system, query version, owner, and known limitation. Explain material changes in methodology or coverage instead of presenting unlike periods as a trend.

Ofcom's final guidance is regulator guidance under section 78, not the notice itself. It explains how Ofcom will choose information, engage with providers, use reports, and enforce the framework. The Act, , the categorisation register, and the final notice control the binding obligation.

  • Trigger: confirm the service's register entry, then log receipt and effective requirements of its final Ofcom notice.
  • Scope: map each requested item to the , 2A, or 2B service part and the applicable matter.
  • Control: convert each notice item into a definition, source system, calculation, owner, reviewer, approval, submission field, and publication field.
  • Outcome: submit and publish a complete, accurate, standalone report in the format, manner, and number of working days specified.
Section 2

Who owns the report, and what evidence proves it is complete and accurate?

Assign one accountable report owner and a data owner for every notice item. Safety and product teams define the underlying operation; data and engineering reproduce the metric; privacy and security review disclosure risks; legal checks the notice and statutory basis; communications controls the published version. Ofcom's final guidance expects appropriate governance and sign-off by an appropriately senior accountable person.

The evidence pack should contain the notice and any pre-notice engagement, service and reporting-period scope, notice-to-field matrix, data dictionary, source-system map, query or calculation, extract, reconciliation, limitation note, reviewer sign-off, senior approval, submitted report, published report, URL, publication date, and any correction. Keep the pack at the same service-part level as the notice.

  • Name the accountable owner, metric owner, calculation reviewer, legal reviewer, privacy reviewer, and publication approver.
  • Freeze or version the query, data extract, definitions, evidence cut, submitted report, and publication copy.
  • Reconcile totals across related metrics and explain known mismatches, sampling, estimates, and unavailable fields.
  • Record Ofcom submission and public publication separately, then preserve any corrected version, reason, approval, and replacement date.
Section 3

Which service and data boundaries cause reporting errors?

A notice attaches to one categorised service, not automatically to every product operated by the provider. For a combined service, check whether the register and notice cover the user-to-user part, the search engine, or both. Keep unrelated functions out of the denominator unless the notice includes them.

Check whether a metric can be compared across the entire reporting period. Acquisitions, launches, taxonomy changes, model changes, duplicate accounts, automated-versus-human actions, restored content, changed age-assurance methods, and incomplete historical logging can break comparability. State the break and its effect instead of silently combining unlike data.

Do not omit a requested item because it is difficult to obtain. Escalate the gap during Ofcom's engagement process, document available and unavailable data, and follow the final notice. Providers remain responsible for complete and materially accurate reports, and Ofcom says foreseeable data or resourcing failures are unlikely to excuse non-compliance.

  • Distinguish users, accounts, active users, impressions, pieces of content, reports, complaints, decisions, and enforcement actions.
  • State whether figures are exact, sampled, estimated, deduplicated, or produced from incomplete coverage.
  • Explain a definition, service-boundary, or methodology change beside the affected figures and avoid an unsupported year-on-year comparison.
  • Keep the final Ofcom guidance, the final service notice, separate information notices, draft consultations, and voluntary-report standards labelled by legal status.
Section 4

What is the reporting sequence?

Before the final notice, preserve data readiness and use Ofcom's engagement process to clarify service boundaries, feasibility, definitions, and likely reporting burden. After receipt, parse every requirement into a reporting matrix: requested item, matter, reporting period, regulated part, definition, source, calculation, limitation, owner, reviewer, approval, submission instruction, and publication instruction.

Run a dry close using the same extraction and approval path. Resolve missing ownership and inconsistent definitions, freeze the reporting cut, reproduce and reconcile the figures, complete the narrative, obtain senior sign-off, submit to Ofcom, and publish the standalone report exactly as the notice directs. The deadline is the number of working days in the notice; the Act does not supply one universal date for every provider.

If an error is found, preserve the original, assess materiality, notify the accountable owner and Ofcom where appropriate, correct the public and submitted versions through a controlled process, and record what changed. Failure to report, missed notice items, wrong format, late submission or publication, and material inaccuracy can lead to enforcement.

  • Maintain a notice-to-field matrix, controlled data dictionary, service-boundary record, and reporting calendar.
  • Test extraction, reconciliation, senior sign-off, Ofcom submission, public publication, and correction before the live deadline.
  • Track open data gaps with an owner, interim explanation, decision, and escalation date.
  • Repeat annually when Ofcom issues the next notice, and update the process after a register change, final-guidance change, service redesign, methodology change, or material reporting error.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Final guidance for pre-notice engagement, annual cycles, working-day deadlines, standalone reports, completeness, accuracy, governance, submission, publication, and enforcement.
legislation.gov.uk
Referenced sections
  • Primary legislation showing the transparency-reporting chapter and Schedule 8 information topics.
"CHAPTER 5 Transparency reporting"
legislation.gov.uk
Referenced sections
  • Current commencement source for paragraph 12 of Schedule 8 in the CSEA-reporting implementation package.
"paragraph 12 of Schedule 8 (transparency reports: matters about which information may be required)"
legislation.gov.uk
Referenced sections
  • Current commencement source for paragraph 12 of Schedule 8; use section 77 and Schedule 8 for the wider reporting workflow.
"paragraph 12 of Schedule 8 (transparency reports: matters about which information may be required)"
gov.uk
Referenced sections
  • Government policy statement supporting risk- and evidence-based provider approaches; it does not establish the transparency-reporting workflow.
"Providers must use risk and evidence-based approaches to ensure there is no room for illegal content and activity on their platforms."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.