The Office of Communications, commonly known as Ofcom (the regulator for communications services), is calling on tech firms to make ‘the online world safer for women and girls’.
When the Online Safety Act (the OSA) was passed in late 2023, Ofcom was granted broad powers to regulate online service providers. The OSA established a new regulatory regime, imposing various legal requirements on providers of online services to protect people in the UK from illegal and harmful content accessed online, including social media platforms, blogging platforms and gaming sites. The OSA imposes legal requirements on regulated user-to-user services, search services and pornographic services to keep users safe online. Please see our previous article here for more detailed information on the OSA.
As part of this regulatory regime under the OSA, Ofcom has initiated a new consultation on its draft guidance (the Guidance). The Guidance sets out a broad suite of measures online service providers should take not only to protect women and girls from illegal and harmful content, but also to take active steps against harmful content and activity that disproportionately affects women and girls. The draft Guidance is to be read alongside, and in addition to, Ofcom’s already published final codes and risk assessment guidance on how it expects online service providers to take action to prevent harmful content.
Under the OSA, online service providers have a general duty to protect all users from illegal harm. What this Guidance does is recognise ‘the unique risks’ that women and girls face online, requiring online service providers to take this duty one step further by calling for ambitious action to improve women’s and girls’ safety, including in relation to online domestic abuse and online misogyny. Ofcom has made it clear that its role will be to hold tech companies to account, specifically pointing out that it has drawn on practical, real-world examples to show how companies can, and are expected to, do more.
Key areas of harm
The Guidance focuses on the following key areas of harm for online service providers to address:
- Online misogyny – content that actively encourages misogynistic ideas or behaviours. This includes both illegal content, such as unlawful threats, and content which is legal but harmful to children, such as content normalising gender-based or sexual violence.
- Pile-ons and online harassment – content targeted against a specific woman or girl, or groups of women or girls. This includes both illegal content, such as harassment, and legal content that is harmful to children, such as misogynistic abuse.
- Online domestic abuse – coercive and controlling behaviours in the context of an intimate relationship.
- Image-based sexual abuse – the abuse of, and non-consensual sharing of, intimate images, including cyberflashing (sending explicit images to someone without their consent).
Notably, Ofcom is seeking to address a wide spectrum of potential harms, reflecting both the breadth of online content and the constantly evolving challenges involved in ensuring online platforms remain safe for users.
Recommended actions for online service providers
Ofcom’s draft Guidance sets out nine areas where online service providers can contribute towards improving women’s and girls’ online safety under three broad categories: (1) taking responsibility; (2) designing services to prevent harm; and (3) supporting users. Following a ‘safety by design’ approach, Ofcom recommends that providers:
- Ensure governance and accountability processes address online gender-based harm. Ofcom expects firms not only to improve the technical operation of their platforms but also to adopt a top-down approach to governance, embedding responsibility for online safety into leadership decision-making. Good practice includes setting policies on online gender-based harm, consulting subject matter experts when drafting platform terms and conditions, and providing relevant staff with appropriate training.
- Conduct risk assessments focused on harm to women and girls. Building on Ofcom’s existing Illegal Content Risk Assessment Guidance and Draft Children’s Risk Assessment Guidance, firms are expected to understand user behaviour and the experiences of women and girls, including through user surveys and external assessments of emerging threats.
- Be transparent about women’s and girls’ online safety. Good practice includes sharing information about which posts are, and are not, flagged through automated content moderation.
- Conduct abusability evaluations and product testing. Firms are encouraged to anticipate how platform features could be misused, for example by improving content filters, updating blocklists and removing nudity from training datasets.
- Set safer defaults. This includes implementing stronger default privacy settings while allowing users greater control over interactions, privacy and geolocation. Examples include automatically removing metadata from uploaded images or allowing users to share their location only for a specified period.
- Reduce the circulation of online gender-based harms. Recognising that there is no single solution, Ofcom encourages firms to adopt an appropriate combination of measures, including behavioural nudges and carefully designed automated moderation processes.
- Give users greater control over their online experience. Suggested measures include allowing users to delete or change the visibility of uploaded content, block or mute multiple accounts simultaneously, and control the content recommended by automated systems.
- Enable users experiencing online gender-based harms to make reports. Good practice includes adopting a trauma-informed approach when designing reporting and flagging mechanisms.
- Take appropriate action when online gender-based harms occur. Ofcom encourages firms to take proactive enforcement action against users who repeatedly breach platform rules, including using strike-based policies, restricting access to services or imposing permanent bans.
Conclusion
If it has not already been made clear by Ofcom’s existing guidance, this Guidance reinforces the regulator’s expectation that online service providers must take proactive steps to demonstrate compliance with the OSA. Ofcom recognises that not every recommendation will be appropriate for every platform and does not expect all providers to implement every foundational or good practice measure, particularly where services present a lower level of risk.
However, online service providers will need to evaluate not only the operation, design and functionality of their services, but also the governance and decision-making processes that underpin those design choices. A ‘comply or explain’ approach to governance, design and implementation, supported by robust risk assessments, may provide an effective way of demonstrating compliance while justifying proportionate alternative approaches.
Providers will also need to consider carefully how their obligations under the UK General Data Protection Regulation interact with their duties under the OSA. For example, effective automated content moderation may require the processing of personal data. For advice or assistance in assessing compliance with the OSA, related guidance and data protection requirements, please get in touch. The consultation closes on 23 May 2025.
Further information
If you have any questions regarding this blog, please contact Caroline Sheldon in our Corporate, Commercial & Finance team.
About the author
Caroline Sheldon joined the Corporate, Commercial & Finance team in August 2022 as an Associate and specialises in advising on commercial matters. She advises entrepreneurs, start-ups and established businesses across a variety of sectors, with a particular focus on technology businesses.