British Online Safety Act Takes Effect

The first set of new UK online safety rules legally requiring social media and other sites to take action against illegal content that have been published by Ofcom, the regulator enforcing the UK's internet safety law. That means that online platforms operating in the UK must review whether their services expose users to illegal material by 16th March 2025 or face financial punishments as the UK’s Online Safety Act (OSA) begins taking effect.

The regulator has said platforms now have three months to assess the risk of their users encountering illegal content and implement safety measures to mitigate those risks, or face enforcement action if they fail to comply with their new duties once they come into force.

Failure to comply could result in a financial penalty as much as  up to 10% of global turnover.

Some of the child safety features required by Ofcom's codes include ensuring that social media platforms stop suggesting people befriend children's accounts, as well as warning them about risks of sharing personal information. 

Certain platforms must also use a technology called hash-matching to detect child sexual abuse material (CSAM), a requirement that now applies to smaller file hosting and storage sites. Hash matching is where media is given a unique digital signature which can be checked against hashes belonging to known content - in this case, databases of known CSAM.

Many large technology  firms have already brought in safety measures for teenage users and have given control to parents concerning their social media use in a bid to tackle dangers for teens and pre-empt regulations. Right now, Facebook, Instagram and Snapchat users under the age of 18 cannot be discovered in search or messaged by accounts they do not follow. 

In October 2024, Instagram also began blocking some screenshots in messages to try and combat sextortion attempts, which experts have warned are on the rise, often targeting young men.

Concerns have been raised throughout the OSA's journey over its rules applying to a huge number of varied online services, with campaigners also frequently warning about the privacy implications of platform age verification requirements. Parents of children who died after exposure to illegal or harmful content have criticised Ofcom for not doing more. 

Social media platforms are being told they must have measures in place to prevent users from accessing outlawed material by 16th March.

However, this is in contrast to the relaxation of content moderation on Meta's platforms in the US - Facebook, Instagram - along with Elon Musk's X, announced only a few days before President-elect Trump's inauguration on 17th January. 

Ofcom   |    Gov.UK    |    BBC  |   Irish News   |   Guardian  |    GNC   |  

Image: Beytullah ÇİTLİK

You Might Also Read: 

Teach Your Children About Safer Cyber Security:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Which Cybersecurity Trends Will Dominate 2025?
Cyber Attack On Slovakia’s Land Registry »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Security Current

Security Current

Security Current's proprietary content and events provide insight, actionable advice and analysis giving executives the latest information to make knowledgeable decisions.

MailXaminer

MailXaminer

MailXaminer is an advance and powerful email investigation platform that scans digital data, performs analysis, reports on findings and preserves them in a court validated format.

StackRox

StackRox

StackRox delivers a container-native security platform that adapts detection and response to new threats.

Cyber Army Indonesia (CyberArmyID)

Cyber Army Indonesia (CyberArmyID)

Cyber Army Indonesia (CyberArmyID) is the first platform in Indonesia to collect and validate reports from hackers (referred to as Bug Hunter) regarding vulnerabilities that exist in an organization.

BlueKrypt

BlueKrypt

BlueKrypt is a consulting firm for the security of IT systems and their management.

Eco Recycling (Ecoreco)

Eco Recycling (Ecoreco)

Eco Recycling is India's first and leading professional E-waste Management Company that has set industry benchmarks with its innovative & environment friendly disposal practices.

Securis

Securis

Securis provides organizations and agencies with the highest level of professional, ultra-secure data destruction and IT recycling.

Amadeus Capital Partners

Amadeus Capital Partners

Amadeus Capital Partners offers over 20 years’ experience in technology investment. Our areas of focus include AI & machine learning and cyber security.

Noetic Cyber

Noetic Cyber

Noetic provides a proactive approach to cyber asset and controls management, empowering security teams to see, understand, and optimize their cybersecurity posture.

Twingate

Twingate

Twingate help organizations secure and manage access to their technology resources in a world where people work from anywhere.

ProjectDiscovery

ProjectDiscovery

ProjectDiscovery is an open-source, cybersecurity company that builds a range of software for security engineers and developers.

SecurEnvoy

SecurEnvoy

SecurEnvoy are a leader in designing zero access trust solutions using the latest cutting-edge technologies, to protect your users, devices and data, whatever the location.

Jot Digital

Jot Digital

Jot Digital is a full-service technology company specializing in digital engineering, application modernization and business transformation.

Panoptic Cyber

Panoptic Cyber

Panoptic Cyber are a team of elite Armed Forces Veterans who hold a wealth of experience in Information Security, Cyber Security, Data Protection and Risk Management.

Nothreat

Nothreat

Nothreat has revolutionized how businesses like yours protect themselves from damaging cyber attacks. Our tech learns and adapts in real time, protecting clients from even zero-day attacks.

Liverton Security

Liverton Security

Liverton Security is a New Zealand-owned cyber security provider offering consultancy and security-related products to government and commercial customers throughout New Zealand.