10 February 2025

The implementation of the Online Safety Act: understanding Ofcom’s new requirements

Following the enactment of the Online Safety Act (OSA) in October 2023, Ofcom has prepared a multi-stage implementation plan. Under this legislation, online service providers are subject to a number of new obligations, and Ofcom has a duty to ensure compliance with these requirements.

1. Who do these new obligations apply to?

As defined by section 3 of the OSA, the legislation and the resulting obligations apply to two types of online service providers:

  • Regulated user-to-user services
    This includes internet services through which content may be generated, uploaded or shared by one user and then encountered by other users through the platform. Examples include Instagram and Wikipedia.
  • Search services
    This includes internet services that are, or include, a search engine. Examples include Google and Amazon.

2. What are the new requirements?

Illegal harms

In December 2024, Ofcom published the first edition of its Illegal Harms Codes of Practice and accompanying guidance on illegal content risk assessments.

Under the Code, by mid-March 2025 all providers of services within the scope of the OSA must assess the risks of illegal content appearing on their services.

The assessment must be suitable and sufficient to identify all relevant risks. From 31 March 2025, Ofcom expects relevant services to provide their risk assessments on request.

Protection of children

On 16 January 2025, Ofcom published guidance for providers of online services that host pornographic content. Under this guidance, providers must use highly effective age assurance measures to prevent children from accessing such content.

Providers must ensure, through age verification, age estimation, or a combination of both, that children are not normally able to encounter pornographic content. Self-declaration of age will no longer be sufficient. Instead, providers will be expected to use methods from Ofcom’s non-exhaustive list of highly effective age assurance measures, including open banking, photo identification and credit card checks.

By 16 April 2025, providers must complete a Children’s Access Assessment to determine whether their service is likely to be accessed by children. Where the answer is yes, they must complete a children’s risk assessment by July 2025. Ofcom expects relevant services to provide those assessments from 31 July 2025.

Protecting women and girls

In February 2025, Ofcom was due to publish draft guidance on protecting women and girls online, containing advice on addressing content and activity that disproportionately affects them.

Once the relevant Codes of Practice have passed through Parliament, service providers will be expected either to implement the measures set out in those Codes or adopt alternative measures that are equally effective in protecting users.

Transparency duties

A limited number of regulated services that meet thresholds set out in secondary legislation will be subject to additional transparency obligations.

These are expected to include transparency reporting requiring providers to produce evidence demonstrating the effectiveness of their online safety measures. It is anticipated that these reporting requirements will come into force towards the end of 2025.

3. What powers does Ofcom have to ensure compliance?

Ofcom expects online service providers to comply with their obligations and has stated that it will launch enforcement action where companies fail to act promptly to address the risks posed by their services. It has powers to issue formal and legally enforceable information requests and has made clear its intention to use those powers where appropriate.

Where compliance failures are identified, Ofcom may impose fines of up to £18 million or 10% of a service provider’s qualifying worldwide revenue, whichever is greater. In the most serious cases, Ofcom may seek a court order requiring business disruption measures, including requiring third-party providers such as payment processors or advertising services to withdraw or limit access to a service within the UK.

Service providers may also commit criminal offences if they fail to comply with an information notice or, without reasonable excuse, fail to take compliance action specified in an Ofcom decision concerning breaches of certain child safety duties, including those relating to child sexual exploitation and abuse. In such circumstances, directors and other senior managers may also face personal criminal liability.

Related INSIGHTS

Read More

Contact_us

Let us take it from here

Whatever your legal needs, we’re here to help.

Contact us