Search

How can we help?

Icon

Online Safety Bill set to become law

As part of the government’s manifesto commitments, they promised to introduce a bill that would strengthen online safety in the UK particularly for minors. This commitment has now been met with the introduction of the Online Safety Bill, which has now passed through all the parliamentary stages and is awaiting Royal Assent.

The bill provides for a new regulatory framework which has the general purpose of making the use of internet services regulated and safer for individuals in the UK.

The bill places new regulatory duties on social media companies to hold them responsible for the content that they host. This landmark legislation is designed to mitigate the harms associated with online interactions, including cyberbullying and the dissemination of illegal content.

What action does the bill require Social Media companies to take?

Under the bill, social media platforms will be expected to:

  • remove illegal content quickly or prevent it from appearing in the first place, including content promoting self-harm
  • prevent children from accessing harmful and age-inappropriate content
  • enforce age limits and age-checking measures
  • ensure the risks and dangers posed to children on the largest social media platforms are more transparent, including by publishing risk assessments
  • provide parents and children with clear and accessible ways to report problems online when they do arise

What penalties will the bill enforce?

The bill provides a framework whereby companies can be fined significant amounts if they do not act swiftly to prevent and remove illegal content, and to protect minors from seeing material that is harmful to them.

Ofcom are to be made the regulator for online safety and will have the powers to fine by up to £18 million, or 10% of their global annual revenue, whichever is higher. This therefore poses a significant change and considers the accountability principle as set out in current UK data protection legislation.

When the bill receives Royal Assent, Ofcom intends to consult on a set of standards for social media companies to meet in tackling online harms, including child sexual exploitation, fraud, and terrorism.

Further, the bill provides for the directors of these companies to be held directly liable, and potentially face prison time for the offences.

The bill also introduces legislation which will make it easier to convict individuals who share intimate images without consent, as well as adding new offences for cyber-flashing and the sharing of non-consensual deep fake pornography.

The bill provides for the directors of these companies to be held directly liable, and potentially face prison time for the offences.

What are the difficulties with the law?

The bill itself has been particularly controversial and remains so. The bill is just over 300 pages and very comprehensive, although critics are calling it long and convoluted.

It is unclear yet how it will work alongside Human Rights protections such as Freedom of Speech, and how it will coexist with UK GDPR legislation to protect privacy and personal data. Messaging service WhatsApp for example has already threatened to refuse to comply with the powers in the bill, as it could require them to examine the contents of encrypted messages for illegal content.

Further, Wikipedia, the online Encyclopaedia, has said that it will not comply with the requirement to conduct age checks on users as it would violate their commitment to collect minimal data about readers and contributors.

It is unclear as yet how this will play out in practice, but it seems likely that this bill will face legal scrutiny in the courts when it does come into force, and that it will certainly have a large impact on how social media companies operate in the UK.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Lucy White

Senior Solicitor

View profile

+44 118 960 4655

About this article

Read, listen and watch our latest insights

art
  • 29 April 2026
  • Privacy and Data Protection

UK Data Protection – what’s new?

Having come into force on 19 June 2025, it comes as no surprise that we are now seeing the effects of the Data (Use and Access) Act 2025 (‘DUAA’). This article highlights a few of DUAA’s fundamental reforms, delves into one in particular, and examines how this will impact the recruitment sphere.

art
  • 10 April 2026
  • Privacy and Data Protection

Is your tech discriminatory?

Employers are increasingly reliant on technology to assist with all kinds of functions – from strengthening security to streamlining recruitment processes.

art
  • 01 April 2026
  • Privacy and Data Protection

Recognising DSARs: top tips for organisations

The UK GDPR grants Data Subjects, who are the individuals to whom the personal data relates, rights over their personal data, including the rights of access, correction and erasure.

art
  • 19 March 2026
  • Privacy and Data Protection

WhatsApp in the Workplace

This article explores the potential risks of using WhatsApp for workplace communications, the implications for GDPR compliance and under UK legislation, and provides practical tips for employers to mitigate these risks.

art
  • 02 March 2026
  • Employment

10 facts an employer should know about holding personal data

Personal data is any information that can be used to identify an employee.

art
  • 12 February 2026
  • Privacy and Data Protection

Love is in the air: Is it data at first sight?

As we enter the week of Valentine’s Day, it is important to recognise the significance of data security, particularly where we have seen the number of cybersecurity breaches increase over the last few months.