The United Kingdom has passed a bad law and it just came into effect. It’s called the Online Safety Act of 2023. It’s also not something most website owners should be too worried about, especially outside the UK.
The Online Safety Act (OSA) is one of those laws that seeks to protect children, but instead does a number of destructive things. Worse, England has decided the law has potential jurisdiction over almost every other website in the world that allows user content. The English government is even insisting it can impose criminal penalties and fines on the owners of these sites if they don’t comply with its largely incoherent and expansive law. So yes, the OSA is a poorly written, threatening, and frustrating law, and it’s fine to be upset about it. But, before we get too worried let’s consider who will have to deal with it, how and when.
First, while the Online Safety Act is a bit cagey about it, it’s not a law that allows the regulator to hand out huge fines easily, the way the traffic police hand out tickets.
The OSA has a ‘notice and cure’ provision, meaning that the enforcement process requires UK telecom regulator, “OFcom”, to provide at least one notice to a site about what’s wrong with a its compliance effort and give the site owner a chance to respond. This should give small websites time to either show how they are in compliance, or to shut down and show that there’s no possible issue. This point isn’t especially clear in OFcom’s guidelines on the enforcement process (they do have flowcharts) and even seem to contain some contradictions about when exactly in the long process it can impose fines. Unfortunately, a lack of clarity is a theme with the Online Safety Act, but indications from OFcom suggest it’s looking to simplify and encourage compliance through notice. The elaborate process for notice, response, investigation and appeal also means that OFcom is unlikely to have resources to pursue a huge number of enforcement actions.
Second, the timeline for the Online Safety Act is reasonably long.
While it came into effect December 16, 2024, it does not require any specific action until Spring 2025, when sites that host user content are expected to have completed various risk assessments using the hundreds of pages of confusing guidelines (there will also be trainings). However, other requirements are still being worked out and will be published and implemented over the next two years.
WAIT, ISN’T THIS STILL BAD?
You’re right, it’s not the best … but the slow implementation shows a law that is hard to implement and a regulator that understands this. The scope of the Online Safety Act is enormous, its requirements vague, and the complex multi-sage enforcement process will be a lot of work for the regulator. All of this suggests that the Act, while destructive, will also be impossible to enforce universally, generally or even quickly.
Rather than giving into the fear of this terrible law, it makes sense to pause for a moment and consider how it might all play out?
How will large companies comply with this thing and what will happen to those that don’t?
My guess is that Wikipedia will not be requiring a proof of legal ID to access the site anytime soon, even though it includes numerous pages that qualify as high-risk content under the OSA. I also doubt Signal will backdoor its apps and store the content of its encrypted chats so it can show there’s nothing creepy going on in them … I’m not even sure it can.
For small sites that fall under it, a good way to look at the Online Safety Act is from a risk management perspective. How risky is it to you and your projects?
Assuming one’s site is covered by the OSA, one theoretically has some risk, but that risk doesn’t spread evenly. Instead it will depend on a couple of factors beyond the categories of risky content and audience that OFcom wants sites to consider: location and subject matter.
LOCATION
Laws are always easiest to enforce against people who are in that law’s actual jurisdiction, in this case the UK. Many laws covering the internet, including GDPR and the OSA, claim more universal jurisdictions, but few countries pursue action against sites beyond their borders. For the OSA this means that risk is focused on sites and site owners who are in or connected to the UK:
- People who live in England, Scotland, Wales, North Ireland or any other part of the UK.
- People with servers located in the UK.
- People who want or need to travel to the UK.
- People with assets or investments in the UK.
For website operators outside the United Kingdom, the only real question is if what you are doing is something that the English will want to arrest you or fine you for under the OSA … badly enough to go through the arduous process of seeking extradition or domesticating a fine, and second if your country of residence would even honor their efforts. International extradition and seizures are hard, and generally countries don’t like other countries messing with their citizens for things that aren’t crimes under their own laws. My guess is that for small websites with no physical connection to the UK there is minimal risk. To reduce your risk further you could bar UK users in your Terms of service (and enforce it), avoid taking payment or donations in pounds, and otherwise establish that you are not offering your service to UK users. A site might even block UK users entirely. However, since the OSA’s guidelines here are vague – it claims to have jurisdiction over sites targeted at, or with a “significant number of UK users” it’s hard to say that even that would be entirely sufficient, but it’s even harder to see how the UK could justify a regulatory action against an international site that prevented UK access.
CONTENT
While the Online Safety Act is written as a law to theoretically protect children from online harms, the lobbyists behind its enactment, the current political culture of the United Kingdom, and the extreme vagueness and scope of its key definitions suggest that a large number of others are in the law’s crosshairs. While people hosting illegal content, gore videos, or even mundane pornography are the most at risk, a list of others who may have heightened risk from the law include:
- Sites that contain any content regarding transgender identity, culture, mental health, or healthcare.
- Sites that offer advice to young people about sexuality.
- Sites that offer advice to young people about abuse or domestic violence.
- Sites that offer advice to young people about mental health.
- Sites related to LGBTQ health, identity, culture, mental health or healthcare.
- Sites about mental health, especially domestic violence or suicide prevention.
- Sites critical of England, its history, governance, laws, or politics
- Sites that include any reference or discussion of current events, crime, animals, violence, intoxicating substances, or children (see the 17 categories of content regulated by the OSA).
It’s unclear how much subject matter will direct enforcement efforts by OFcom, especially at first, but the law’s construction and complex enforcement process lend themselves to being enforced selectively and make general enforcement difficult. If a site covers issues (even positively) that the government, online trolls, or outrage stoking internet personalities are likely to target, then the OSA is a more serious threat. Of course because of the law’s vagueness, even good faith efforts to comply may not be enough to avoid regulatory sanction if the law is used punitively.
We really can’t know exactly how OFcom will begin enforcement, and part of dealing with bad regulations is judging one’s willingness to accept risk. The way the OSA is written and OFcom’s posture so far suggests that UK based sites, especially if they cover obviously high-risk subject matter, have a greater degree of risk. For UK based or connected sites a perhaps extreme solution would be to shut down entirely or replace any dynamic site with one that doesn’t allow user to user (“U2U”) interaction (such as comments or posts), and has only non-threatening site created content. Consider this a temporary step, one that allows more time for site compliance and observation. Easy ways or clear standards on OSA compliance may emerge during its implementation. Perhaps the assessments and other OSA requirements will become something simple and formulaic, good FOSS tools for compliance will be developed, or the law will only be enforced in a few big cases against the largest platforms?
WHY WOULD ANYONE PASS A LAW LIKE THIS?
In this sort of post I am usually tempted to offer a bit of detail on the law, but with the OSA I don’t see much point. It’s a messy law with guidance docs that appear well intentioned, but are only slightly less of a disaster. I suspect this is not incompetence, but also intent. My view is that, like the internet content laws proposed by Florida and Texas in the past few years, (see the US Supreme Court’s decision in 2024’s Moody v. Netchoice), the OSA is a species of political law that is meant to be vague and scary. Laws that claim vast jurisdiction and impose harsh penalties on vague grounds allow political parties or insiders to threaten their ideological foes and rivals. When terms and definitions so broad and confusing that almost anyone can be plausibly accused of violating them, the government can use them to target specific people or groups they dislike.
Obviously I could be wrong, and another view of the Online Safety Act is that it’s the product of lobbyist influence from large platforms or a government that lacked the expertise or reflection to understand the law’s potential risks. In the first case the OSA’s stringent requirements are things that largest companies online can comply with or fight, but smaller competitors can’t, so the law will force everyone but the biggest players off the internet or under the protective umbrella of those few companies. In the second case there’s not necessarily ill intent, but the negative effects will linger until the law is rewritten or replaced, even as the regulators attempt to rationalize the law and eliminate bad results.
With the OSA all of these things can be true, but it there’s no way to know what the law’s future holds. For know all one can do as a small website operator is stay aware, and informed. It’s still to early to take drastic protective steps (until March 2025 at the earliest) but it’s useful now to watch and prepare.
CAVEATS
As always, nothing here is legal advice. I can’t give anyone legal advice on this law in this way. Instead, these are my general thoughts on the Online Safety Act and how it appears to someone who has studied online regulation but is not a UK legal professional.
Leave a Reply