Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Online Safety Act Becomes Law Despite Rights-Group Encryption Warnings

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The UK’s Online Safety Bill received Royal Assent on 26 October 2023, becoming the Online Safety Act 2023. Rights groups warned that its powers could pressure messaging services to scan private communications or weaken end-to-end encryption. The Act does not impose an immediate blanket ban on encryption, but its technology-notice regime remains the central privacy dispute as implementation continues.

What Royal Assent changed

Royal Assent ended the bill’s passage through Parliament and converted it into the Online Safety Act 2023. It did not, however, bring every obligation into force on the same day. Many duties depended on commencement arrangements, Ofcom’s codes of practice and staged implementation.

The Act created a regulatory framework for online services rather than a single rule applying identically to every website or app. Ofcom is responsible for implementing and enforcing much of the regime.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the Online Safety Act covers

The main regulated categories are:

  • User-to-user services, where users can publish or share content with other users.
  • Search services, which help users find information online.
  • Services likely to be accessed by children, subject to the relevant statutory tests and duties.
  • Certain pornography providers and other services falling within the Act’s categories or thresholds.
  • Services based outside the UK where they have the required UK connection or affect UK users.

Depending on the service, providers must assess risks, maintain safety systems, deal with illegal content, protect children from specified harms, provide reporting and complaints routes, meet transparency obligations and in some circumstances use age-assurance measures. The Act also created or amended offences including threatening communications, false communications, cyberflashing and encouraging or assisting serious self-harm. The government’s overview is available in its Online Safety Act explainer.

Why rights groups focused on encryption

End-to-end encryption is designed so that the sender and recipient control the keys needed to read a message. The service provider generally cannot read the content while it is being transmitted.

That creates a technical tension with routine content scanning. A provider cannot preserve a strict model in which only the sender and recipient can access message content while also giving a third party or a provider-controlled system ordinary access to inspect that content.

Critics therefore warned that the Act could create pressure for services to introduce measures such as:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Client-side scanning before a message is encrypted.
  • Scanning after content is decrypted on a user’s device.
  • Other detection systems that alter the service’s existing security architecture.

Open Rights Group and Big Brother Watch criticised the potential impact on privacy and encrypted communications. Open Rights Group told Ofcom that services including WhatsApp, Signal and Element had indicated they might consider withdrawing from the UK if encryption were compromised. Such warnings show how providers perceive the risk; they do not prove that the Act requires any particular company to leave or to scan messages.

Critics’ concerns extend beyond the content of individual messages. They argue that scanning could create new attack surfaces, expose private communications to automated errors, enable mass surveillance or encourage “function creep” into areas beyond the original purpose.

What the law actually empowers Ofcom to do

Ofcom must produce codes of practice addressing duties relating to illegal content and child safety. Providers can use methods different from those recommended in a code, provided they meet their legal obligations. However, the code may be taken into account by Ofcom or a court when assessing compliance.

Technology notices are a separate and particularly controversial mechanism. Subject to statutory conditions and procedures, Ofcom may require a regulated service to use accredited technology to identify terrorism content or child sexual exploitation and abuse material.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is not the same as an automatic power to decrypt everyone’s messages. The important distinctions are:

  1. The Act creates a statutory power under specified conditions.
  2. Ofcom would need to follow the required legal process.
  3. A technology notice would concern a particular regulated service, not automatically every platform.
  4. The provider would then have to decide how to respond, including whether to alter its product, challenge the notice or potentially restrict UK availability.

The Act and its explanatory material require relevant regulatory measures to take account of privacy and freedom of expression. Those safeguards matter legally, but they do not by themselves settle the engineering question of whether a proposed scanning method can preserve confidentiality and security.

The government has maintained that the regime is technology-neutral, contains safeguards and does not create a general ban on end-to-end encryption. The more precise criticism is that a future notice could require technology that makes strict end-to-end encryption difficult or impossible to maintain.

The wider free-expression concern

Encryption is not the only objection. Rights organisations have also warned that broad safety duties may encourage platforms to remove lawful but controversial material to reduce regulatory risk. Automated moderation can produce false positives involving journalism, political speech, satire, sexual-health information or benign personal communications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These concerns do not mean that every removal is required by the Act. Platforms may remove material under their own terms of service, even where the content is lawful. Nor are all online communications equivalent: public posts, private messages, metadata and message content present different privacy and regulatory questions.

Why supporters back the Act

The government and supporters argue that platforms have too often been slow or inconsistent in dealing with illegal material and foreseeable risks to children. They say providers should be required to identify risks, improve their systems and take action rather than waiting for individual complaints.

Supporters also point to stronger accountability, transparency requirements and enforceable duties. A risk-based framework can impose different expectations depending on a service’s size, design, audience and level of risk rather than applying identical controls to every provider.

The policy trade-off is therefore substantial: improving the detection of terrorism and child-sexual-abuse material while preserving secure private communication. Any detection system must be judged separately for technical reliability, privacy impact, security, proportionality, error rates, transparency and the ability of users to challenge mistakes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What companies face

Enforcement can involve information requests, transparency obligations, risk-assessment and compliance requirements, financial penalties and, in serious cases, measures capable of disrupting a non-compliant service. The statutory framework also includes specified personal-liability provisions and criminal offences.

Contemporaneous reporting referred to potential fines of up to £18 million or 10% of annual turnover. The precise calculation depends on the statutory terminology and enforcement framework, so “turnover” should not be treated as interchangeable with terms such as qualifying worldwide revenue. Providers should consult Ofcom’s current enforcement guidance and the enacted legislation.

Small services may face different expectations from large, high-risk platforms, while overseas companies can still fall within scope if they serve UK users and meet the statutory connection tests.

What users should understand

  • Royal Assent made the bill an Act; it did not mean every provision became enforceable immediately.
  • The Act covers more than social media, including search services and certain pornography providers.
  • It does not automatically require every encrypted messaging service to scan every message.
  • A future technology notice could still create serious consequences for how an encrypted service operates.
  • Age assurance, moderation and reporting requirements may affect how users access or interact with online services.
  • A provider’s decision to change its product or withdraw from the UK would be separate from the Act’s enactment itself.

Timeline after Royal Assent

  • 26 October 2023: The Online Safety Bill received Royal Assent and became the Online Safety Act 2023.
  • December 2024: The government published the illegal-content codes and related explanatory material.
  • 2025: Child-safety risk-assessment and code implementation milestones followed.
  • 2026: The government published draft amendments and continued developing the illegal-content regime.

The official Online Safety Act collection records the current implementation material. Ofcom’s implementation roadmap explains why duties have been introduced in stages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The bottom line on encryption

The Online Safety Act is a broad online-safety regime, not an explicit blanket encryption ban. Its most contentious feature is the possibility that Ofcom’s technology-notice powers could pressure a service to introduce scanning or another mechanism that changes the privacy and security properties of end-to-end encrypted communication. Whether that happens depends on future notices, technical feasibility, legal safeguards and providers’ responses.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.