Artifact GuideUKUser-to-user and Search Services

UK Online Safety Act User-to-user and Search Services

A service can fall within Part 3 if users can encounter content generated, uploaded, or shared by other users, or if it provides a search engine across more than one website or database.

The provider must then check UK links, Schedule 1 and Schedule 2, disapplied service parts, and who controls the relevant functionality. Company location and service size do not decide scope by themselves.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
14

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use four tests in order. First, decide whether the product contains a , a , or both. Second, identify the entity that controls access to the user-to-user functionality or controls search operations. Third, decide whether the service has . Fourth, test the specific and Schedule 2 exemptions and any disapplied parts. A regulated service then has baseline illegal-content, reporting, complaints, record-keeping, and assessment duties; child-access and category status can add further duties.

Section 1

How do you classify the service functionality?

A user-to-user classification turns on functionality, not the product label. Ask whether content generated, uploaded, or shared by one user may be encountered by another. Comments, public or group posts, user profiles, user-uploaded media, marketplace listings, in-game chat, collaborative spaces, and some messaging functions can meet the test. The exemptions still need separate analysis.

For search, ask whether a person can search more than one website or database. A general search engine and a vertical search engine for products, jobs, travel, academic material, or another topic can qualify. A search tool restricted to one website or database does not meet section 229 merely because it has filters or sophisticated ranking.

If the service has both functions, apply the section 3 tie-breaker. Unless the only user content is within the specified exempt types, it is treated as a ; if the same provider also operates a public search engine, it is a and search duties apply to that engine.

  • Inventory every function through which a user creates, uploads, shares, searches, ranks, recommends, comments on, or encounters content.
  • Record whether communications are public, group, one-to-one, live, aural, asynchronous, internal, or attached to provider content.
  • For each search function, record the websites and databases searched and the entity that controls indexing, ranking, and results.
  • Classify distinct functions and service parts before deciding whether an exemption or section 5 disapplication covers all or only part of the product.
Section 3

Which exemptions and boundaries must be checked?

exemptions are specific, not broad sector labels. They cover services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications; defined limited-functionality services; qualifying internal business services; specified public-body services; and qualifying education or childcare services. Each exemption has conditions, and some operate at service-part level.

The limited-functionality exemption generally concerns comments or reviews on provider content and sharing those comments or reviews elsewhere. It does not exempt a service that also enables wider user interaction. The education and childcare exemption applies only to the providers and purposes described in , not every product sold to a school or used by a child.

Schedule 2 deals with certain services that combine otherwise exempt user-to-user or search functions with provider pornographic content. Those services may remain regulated under Part 5 even when the Part 3 user-to-user or search duties do not apply. Section 5 can also disapply the Act to defined low-risk parts without taking the whole service out of scope.

  • Test the exact content and functionality conditions for an exemption; do not stop at the product name or industry.
  • Check the exception to the email, messaging, aural, limited-functionality, and combination exemptions in paragraph 6.
  • For internal tools, document the corporate relationship, permitted users, purpose, and whether a public or customer-facing part sits outside the exemption.
  • For pornography, education, childcare, and public-body cases, record the separate statutory conditions and any duty that remains under another Part.
Section 4

What follows from the classification?

Every regulated must complete an illegal-content risk assessment and maintain the required reporting, complaints, freedom-of-expression, privacy, record-keeping, and review controls. The safety duties differ: user-to-user services address user-generated content and the use of the service to commit or facilitate priority offences, while search services address risks arising through search content and results.

The provider must also complete a . If the service or a relevant part is likely to be accessed by children, children's risk-assessment and safety duties apply. Category status can add transparency, user-empowerment, fraudulent-advertising, and other duties, but it does not replace the baseline classification.

Is a service outside the Act because it has few UK users?

Not necessarily. A significant number of UK users is only one route to . A UK target market is another. A service accessible in the UK can also qualify where there are reasonable grounds to believe its user-generated content or search content creates a material risk of significant harm to people in the UK.

Is an internal search box a ?

Not if it searches only one website or one database. Section 229 requires search across some or all websites or databases and expressly excludes a service or functionality limited to one website or database. A vertical search engine covering multiple sources can qualify even if it covers only one topic.

Are email and private messages always exempt?

No. exempts services whose only user-generated content is email, SMS or MMS, or one-to-one live aural communications, subject to the schedule's conditions and exceptions. A wider service with posts, group communications, profiles, uploads, comments, or other user interaction needs a function-by-function analysis.

  • Approve a scope memo with the feature inventory, provider entity, UK-links evidence, exemption analysis, service-part boundaries, and unresolved questions.
  • Open separate duty maps for the user-to-user and search components of a .
  • Trigger reassessment before adding public comments, messaging, uploads, group interaction, multi-database search, or a new UK market.
  • Keep child-access and category decisions as later branches; do not use them to erase baseline Part 3 duties.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for service definitions, regulated status, exemptions, service-part boundaries, provider identity, and the duties following classification.
legislation.gov.uk
Referenced sections
  • Binding treatment of certain services combining exempt user-to-user or search functions with regulated provider pornographic content.
legislation.gov.uk
Referenced sections
  • Binding search-engine definition, including the exclusion for a search limited to one website or database.
legislation.gov.uk
Referenced sections
  • Binding definitions and tie-breaker for services that include both user-generated content and a search engine.
legislation.gov.uk
Referenced sections
  • Binding regulated-service and UK-links tests, including targeting and material risk of significant harm.
gov.uk
Referenced sections
  • Official overview confirming that the duties apply to search services and services that allow users to post content or interact with each other, including providers outside the UK with UK links.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.