The British Online Harms Bill Takes Shape

The British Government have announced that there will be new rules about how online technolgy firms will be held accountable towards certain types of online content. Social media platforms and other firms will now have a duty of care to protect children from online harms and look to remove any illegal content that may be shared from users including 'child sexual abuse material', 'terrorist content' and 'suicide material'.

Measures to criminalise cyber-flashing and give a right to appeal against the removal of social media posts are among changes the UK Government has proposed to its Online Harms Bill.
The bill, which also seeks to tackle access to harmful material online, has been introduced to parliament.

It would give regulator Ofcom the power to fine firms or block access to sites that fail to comply with the new rules.

Harmful online content and activity includes cyberbullying, racism, misogynistic abuse, pornography, and material promoting violence and self-harm. The Covid-19 pandemic has seen social media platforms used to spread anti-vaccine disinformation. Critics, including parliamentary committees, academics, and children’s charities, have argued that self-regulation by Internet companies is not enough to keep users safe and that statutory regulation should be introduced.

The Bill Addresses A Wide Range Of Topics Relating To Harmful Online Content

Big social media companies will be required to assess risks of the types of legal harms against adults which could arise on their services, and will have to set out how they will deal with them, and enforce these terms consistently. Definitions of these legal harms will be set out in additional legislation, but potential examples could include material promoting self-harm, eating disorders or harassment. 

Some of the additional aspects of the bill announced as it was introduced to Parliament include:

  • Criminalising the sending of unsolicited sexual images to people using social media, known as cyber-flashing.
  • Giving people the right to appeal if they feel their social media posts were removed unfairly.
  • Preventing online scams, such as paid-for fraudulent adverts, investment fraud and romance scammers.
  • Requiring pornography websites to verify their users' ages

Culture Secretary Nadine Dorries said the bill meant technology companies would not be left to "check their own homework.. Tech firms haven't been held to account when harm, abuse and criminal behaviour have run riot on their platform" she said.

The bill will give new powers to Ofcom, which will be able to request information from companies, and executives who do not comply could face up to two years in prison within two months of the bill becoming law. Senior managers would also be criminally liable if they destroyed evidence, did not attend an Ofcom interview, provided false information, or otherwise obstructed the regulator from entering offices. 

Any firm breaching the rules would face a fine of up to 10% of its turnover, while non-compliant websites could be blocked entirely.

Children's charity Barnardo's welcomed the announcement sites showing pornographic material would have to check the ages of users. A City of London Police Authority Board spokesperson said included paid-for advertising in the legislation was "a major step forward in the fight to reduce online crime, and helps cement the benefits of including fraud as a priority harm".

The opposition Labour Party says delays to the bill mean disinformation in the UK has increased and shadow culture secretary Lucy Powell commented that bill's delays had "allowed the Russian regime's disinformation to spread like wildfire online... Other groups have watched and learned their tactics, with Covid conspiracy theories undermining public health and climate deniers putting our future at risk."

The legislation has taken some time to reach the stage where a bill is now to be laid before Parliament. An Online Harms White Paper was published in April 2019 by the Conservative government, then led by Theresa May. At the time, privacy organisations such as the Open Rights Group warned that the bill could threaten freedom of expression.

Jim Killock, Open Rights Group executive director told the BBC "The fact that the bill keeps changing its content after four years of debate should tell everyone that it is a mess, and likely to be a bitter disappointment in practice."

Gov.UK:     British Parliament:     BBC:       SWGfl:      

You Might Also Read: 

Protecting Children In The Digital Age:

 

« Anonymous Hackers Aim To Undermine Russia
The Pentagon Gets $250m Extra To Spend On AI »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Digitus Biometrics

Digitus Biometrics

Digitus Biometrics is a market leader in biometric access control. We can secure access to any entry point, from the front door to the server rack cabinet.

Baker McKenzie

Baker McKenzie

Baker & McKenzie is an international law firm. Practice areas include Data & Technology.

KE-CIRT/CC

KE-CIRT/CC

KE-CIRT/CC is the national Computer Incident Response Team for Kenya.

Guardian360

Guardian360

The Guardian360 platform offers unrivalled insight into the security of your applications and IT infrastructure.

Sasa Software

Sasa Software

Sasa Software is a cybersecurity software developer specializing in the prevention of file-based network attacks.

CyberProof

CyberProof

CyberProof aims to give clarity and confidence to businesses worldwide using a new risk-based approach to cyber security services.

Cyber Threat Alliance

Cyber Threat Alliance

CTA is working to improve cybersecurity of our digital ecosystem by enabling near real-time cyber threat information sharing among companies and organizations in the cybersecurity field.

Apozy

Apozy

Apozy replaces a secure web gateway to nullify phishing, malware and impersonation attacks.

Reed

Reed

reed.co.uk is a leading job site in the UK, providing a full online service for anyone looking for a new job.

jobsDB.com

jobsDB.com

jobsDB Singapore is a search engine for jobs throughout Singapore.

ActZero

ActZero

ActZero’s security platform leverages proprietary AI-based systems and full-stack visibility to detect, analyze, contain, and disrupt threats.

LiveAction

LiveAction

LiveAction provides end-to-end visibility of network and application performance from a single pane of glass.

Redbot Security

Redbot Security

Redbot Security provides industry leading manual penetration testing. Protecting critical systems and data - red team attack and breach simulations, (OT) critical infrastructure testing.

Integris

Integris

Integris offers best-in-class services like dedicated vCIOs, specialized security and compliance advisory services, a 24/7 help desk, and more.

Hilltop Technologies

Hilltop Technologies

Hilltop Technologies is a cybersecurity company specialized in managed security services and consulting tailored for all sectors from higher education to publicly traded companies.

PureID

PureID

Protect your enterprise with PureAUTH #IAMFirewall, Resilient SSO platform, purpose built to provide Passwordless Authentication & Zero Trust Access, by default.