# Online Safety Act (New OfCom Rules)

**URL:** https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713
**Category:** Support
**Tags:** online-safety-act
**Created:** [December 16, 2024, 6:13pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713 "2024-12-16T18:13:55Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![SeanDrownedinSound](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@SeanDrownedinSound](https://meta.discourse.org/u/SeanDrownedinSound)
#### Post date: [December 16, 2024, 6:13pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/1 "2024-12-16T18:13:55Z")

</div>

Hello

The UK government are planning to change the laws of online safety and I was curious what measures Discourse are taking to address this or if there is a suggested response for anyone who is hosting in the UK?

[https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/time-for-tech-firms-to-act-uk-online-safety-regulation-comes-into-force/](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/time-for-tech-firms-to-act-uk-online-safety-regulation-comes-into-force/)

Our community are looking into this but it’s unclear to me if the onus is on us or Discourse, which in theory would mean every WhatsApp groupchat or Discord server would need to do this.

Thanks in advance for any help (I did check but couldn’t find a recent thread about this)

---

<div class="post-metadata">

### Author: ![ondrej](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ondrej/32/198804_2.png) [@ondrej](https://meta.discourse.org/u/ondrej)
#### Post date: [December 16, 2024, 6:43pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/2 "2024-12-16T18:43:16Z")

</div>

From Ofcom’s website: “firms are now legally required to start taking action to tackle criminal activity on their platforms”

I think that Discourse already provides a way to tackle criminal activity by the ‘Its Illegal’ flag to alert staff of illegal activity on the site. Realistically, other than putting in measures like the illegal flag option is there much else that can be done?

 ![image](https://global.discourse-cdn.com/meta/original/4X/2/a/e/2ae18abe68349bc227ccae3628bc0cb8a67c32c2.png)

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [December 17, 2024, 2:32am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/3 "2024-12-17T02:32:03Z")

</div>

Yup we’re on top of it. We have been monitoring it for most of the year and are prepared.

> [@SeanDrownedinSound](#):
>
> Our community are looking into this but it’s unclear to me if the onus is on us or Discourse

It’s on both of us. We provide the tools to comply with the OSA (because we have to comply here on Meta) but you are responsible for how you use them.

The key considerations are:

> [@](#):
>
> **Proactive Moderation:** Discourse must have systems in place to identify and remove illegal or harmful content swiftly.

We have this with the illegal content flag that @ondrej posted above, which should trigger you to use the existing tools to remove the content in a compliant way and do the appropriate reporting.

> [@](#):
>
> **Report Harmful Content:** Provide mechanisms for users to report harmful or illegal content, and ensure rapid responses to such reports.

As above – the illegal flag or other custom flag types are available for you to use. We are making a change so that not logged in users can also flag illegal content. Do we have an ETA for that @tobiaseigen?

> [@](#):
>
> **Content Takedown Procedures:** Have a clear procedure for the removal of harmful content, including transparency reports showing how content is moderated.

You will need to define your internal processes yourself, but the data is all logged so you will be able to report on it when required.

> [@](#):
>
> **Annual Transparency Reports:** Platforms (i.e. Discourse customers) must submit annual transparency reports detailing how they are handling harmful content, the volume of takedowns, and actions taken to protect users.

See above.

> [@](#):
>
> **User Empowerment:** Provide users with clear information on content risks and moderation policies, including what actions are taken against violations.

This is on you to create.

> [@](#):
>
> **Conduct Risk Assessments:** Perform mandatory risk assessments to identify potential harm to users, particularly children. Update these assessments regularly.

Also on you to organise.

> [@](#):
>
> **Respond to Violations:** Have a plan in place for quickly responding to violations or incidents that may arise, ensuring proper reporting to authorities where necessary.

Also on you.

> [@](#):
>
> **Regular Audits:** Conduct internal audits to ensure continuous compliance and readiness for Ofcom inspections or enforcement actions.

And… also on you.

---

<div class="post-metadata">

### Author: ![SeanDrownedinSound](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@SeanDrownedinSound](https://meta.discourse.org/u/SeanDrownedinSound)
#### Post date: [December 17, 2024, 9:50am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/12 "2024-12-17T09:50:25Z")

</div>

For all of the things that are on us, do you have suggested processes and copy?

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [December 17, 2024, 10:44am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/13 "2024-12-17T10:44:35Z")

</div>

Out of curiosity: how is UK defining small, medium and large service providers?

---

<div class="post-metadata">

### Author: ![ondrej](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ondrej/32/198804_2.png) [@ondrej](https://meta.discourse.org/u/ondrej)
#### Post date: [December 17, 2024, 12:40pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/14 "2024-12-17T12:40:20Z")

</div>

I’m interested too so if anyone can find it out I’d like to know too. Although I can’t find a specific definition it appears that different sized services are treated slightly differently to larger service providers. “we aren’t requiring small services with limited functionality to take the same actions as the largest corporations.” [Gov.uk, para. 6](https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer)

---

<div class="post-metadata">

### Author: ![Ed\_S](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_s/32/134015_2.png) [@Ed\_S](https://meta.discourse.org/u/Ed_S)
#### Post date: [December 17, 2024, 1:09pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/15 "2024-12-17T13:09:23Z")

</div>

Can the forum software readily provide a list of mod actions over a year? Or perhaps mod actions filtered by, say, responding to flags? I wouldn’t want to have to keep a separate record. (Sometimes I will delete a user because of a flag - that isn’t an option when responding to a flag.)

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [December 17, 2024, 5:20pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/16 "2024-12-17T17:20:57Z")

</div>

> [@SeanDrownedinSound](#):
>
> For all of the things that are on us, do you have suggested processes and copy?

No and I’m afraid it’s unlikely that we will provide those. As with GDPR we provide the tools to comply but you will need to seek your own legal advice.

---

<div class="post-metadata">

### Author: ![Ed\_S](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_s/32/134015_2.png) [@Ed\_S](https://meta.discourse.org/u/Ed_S)
#### Post date: [December 17, 2024, 6:52pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/17 "2024-12-17T18:52:11Z")

</div>

> [@Jagster](#):
>
> how is UK defining small, medium and large service providers?

There’s a discussion on HN [here](https://news.ycombinator.com/item?id=42433044) (concerning a specific case where a person running 300 forums has decided to close them all) which contains useful information and links to official docs.

AFAICT, 700 thousand monthly active UK users is the threshold for medium. 7 million is the threshold for large.

Note that, I think, some aspects of the law are not sensitive to the size of the service, where others are.

For more, see  
(Draft) [Illegal content Codes of Practice for user-to-user services](https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/illegal-harms/illegal-content-codes-of-practice-for-user-to-user-services.pdf) (ofcom link)

I think this is a case of the risk to forum owners being low-probability but high-cost. Individual judgement, and perception of risk and attitude to risk will be in play.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [December 17, 2024, 6:58pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/18 "2024-12-17T18:58:15Z")

</div>

Thanks. So, it apply only to a few, in its full power anyway.

One of my friend living in UK is partly reason why I’m curious, because she in panicking quite a lot because of this.

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [December 17, 2024, 11:52pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/19 "2024-12-17T23:52:09Z")

</div>

Here are the risk assessment guidelines: [https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/illegal-harms/risk-assessment-guidance-and-risk-profiles.pdf?v=387549](https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/illegal-harms/risk-assessment-guidance-and-risk-profiles.pdf?v=387549)

---

<div class="post-metadata">

### Author: ![Ed\_S](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_s/32/134015_2.png) [@Ed\_S](https://meta.discourse.org/u/Ed_S)
#### Post date: [December 22, 2024, 5:34pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/20 "2024-12-22T17:34:46Z")

</div>

Thanks Hawk. (I see the pdf link resolves to the latest, despite looking like a link to a specific version.)

[Here’s](https://russ.garrett.co.uk/2024/12/17/online-safety-act-guide/) a sensible (but not authoritative) description of what the new laws might mean to self-hosted small-scale forums which don’t specifically target children or offer porn. The main point, I think, is to understand the law and document your approach. From there:

> ## Duties
> 
> As a small user-to-user service, the OSA requires you to:
> 
> - Assess the risk of _illegal content_ _([s9](https://www.legislation.gov.uk/ukpga/2023/50/section/9/enacted))_
> - Take proportionate measures to mitigate the illegal content risks you identified _([s10(2)(c)](https://www.legislation.gov.uk/ukpga/2023/50/section/10/enacted))_
> - Take proportionate measures to prevent people encountering _priority content_ _([s10(2)(a)](https://www.legislation.gov.uk/ukpga/2023/50/section/10/enacted))_
> - Take proportionate measures to mitigate the risk of people committing _priority offences_ _([s10(2)(b)](https://www.legislation.gov.uk/ukpga/2023/50/section/10/enacted))_
> - Allow users to easily report illegal content, and content which is harmful to children, and take it down _([s20](https://www.legislation.gov.uk/ukpga/2023/50/section/20/enacted))_
> - Allow users to complain about reports, takedowns, etc _([s21](https://www.legislation.gov.uk/ukpga/2023/50/section/21/enacted))_
> - “Have particular regard to the importance of protecting users’ right to freedom of expression” _([s22(2)](https://www.legislation.gov.uk/ukpga/2023/50/section/22/enacted))_
> 
> You don’t have to worry too much about these duties directly – the risk assessment process guides you through what you need to do to comply with them.

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [February 26, 2025, 12:54am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/21 "2025-02-26T00:54:15Z")

</div>

By now everyone should have all the information required from OfCom in order to carry out risk assessments. Once you have carried out your risk assessment you will have a list of identified risks that you may want to mitigate for. I am pretty confident that we have all the tools in place, but if anyone is unsure we can have the discussion here.

---

<div class="post-metadata">

### Author: ![ahaiku](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ahaiku/32/491341_2.png) [@ahaiku](https://meta.discourse.org/u/ahaiku)
#### Post date: [February 27, 2025, 2:13am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/22 "2025-02-27T02:13:59Z")

</div>

> [@Ed\_S](#):
>
> AFAICT, 700 thousand monthly active UK users is the threshold for medium. 7 million is the threshold for large.

Do you have a reference for this? We did extensive searching and couldn’t find anything that defined number of users to “size” (which honestly is one of my biggest complaints about the OSA as written.)

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [February 27, 2025, 4:50am UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/23 "2025-02-27T04:50:24Z")

</div>

I also found that one of the most difficult things to ascertain. I wasn’t sure whether we were responsible for assessing risk on Meta (as administrators of the community), or the risk of using Discourse more generally (the risk for our customers).

If the latter, I didn’t know what size category that would put us in. Turns out it was the former.

What we learned at a seminar is that Ofcom have already reached out to the platforms that they currently believe fall into a category which requires anything more than annual self-assessment and have let them know they will have to formally submit their assessment. If you have not been contacted, I think you can assume that you are required to do your self-assessment, complete any mitigation, and reassess annually or when there are significant changes to scope. You will need to be able to show your assessment work if asked, but you don’t need to submit it anywhere.

But note that I am as new to this as the rest of you so **please consider this my opinion, rather than compliance advice**. You will need to do your own research.

---

<div class="post-metadata">

### Author: ![Ed\_S](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_s/32/134015_2.png) [@Ed\_S](https://meta.discourse.org/u/Ed_S)
#### Post date: [February 27, 2025, 12:45pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/24 "2025-02-27T12:45:05Z")

</div>

> [@ahaiku](#):
>
> couldn’t find anything that defined number of users to “size”

I’ve just checked the [current draft guidance](https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/illegal-harms/illegal-content-codes-of-practice-for-user-to-user-services.pdf) and it defines large but not medium. But it does in several places have notes for services of 700k users, for example:

 ![The image shows a table detailing measures recommended for "ICU C10" to detect and remove content matching CSAM URLs, applying specifically to large services with high CSAM risk and those with over 700,000 monthly active UK users, with the operations outlined in Section 10(2) and (3). (Captioned by AI)](https://global.discourse-cdn.com/meta/original/4X/d/9/8/d98eb5666afabfdbb0fa8c7a9815a25012307b9f.png)

---

<div class="post-metadata">

### Author: ![Ed\_S](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_s/32/134015_2.png) [@Ed\_S](https://meta.discourse.org/u/Ed_S)
#### Post date: [February 27, 2025, 3:22pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/25 "2025-02-27T15:22:29Z")

</div>

There was an OfCom webinar “Indie and Community Web Compliance” for our kinds of sites, see this link for notes, links, and videos:

> **[\#4: Update from Ofcom webinar](https://buttondown.com/indie-and-community-web-compliance-/archive/4-update-from-ofcom-webinar)**
>
> Includes videos of the webinar, outlines a couple of major outstanding issues relating to Mastodon and proportionate enforcement, and suggests what ofcom might do next.

---

<div class="post-metadata">

### Author: ![RCheesley](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rcheesley/32/455409_2.png) [@RCheesley](https://meta.discourse.org/u/RCheesley)
#### Post date: [March 6, 2025, 8:14pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/26 "2025-03-06T20:14:16Z")

</div>

Hi @HAWK , I wondered if it might be possible to have a simple, single page (or forum post) which documents how Discourse functionality addresses the issues raised?

Currently I am piecemeal pointing to your responses in this thread, other posts about reporting [illegal content](https://meta.discourse.org/t/new-its-illegal-reason-when-flagging-posts/294866), [admins in chat channels](https://meta.discourse.org/t/strengthening-community-safety-in-group-chats/354941) etc as part of our evidence, it’d be a bit more helpful perhaps if there was an ‘official’ page that listed the core functions which the product itself brings to the table so that it could be referenced as evidence? Maybe also helpful for folks reviewing the platform to have confidence that it satisfies the requirements.

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [March 6, 2025, 8:52pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/27 "2025-03-06T20:52:10Z")

</div>

Hey Ruth,  
I’m happy to help but I need to clarify a something first.

> [@RCheesley](#):
>
> how Discourse functionality addresses the issues raised?

Which issues are you referring to specifically? The ones that you have identified in your risk assessment? If that is the case, feel free to list the things you are trying to mitigate for and I can help you with tooling suggestions.

Everyone will have different risks to mitigate and different levels of tolerance for those risks. As such, I can’t post any kind of definitive list. For example, we don’t allow kids under 13 on Meta so we don’t need to mitigate for a lot of the high risks pertaining to children.

If you are happy to share your assessment, I’m happy to use it as an example.

---

<div class="post-metadata">

### Author: ![HAWK](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hawk/32/86627_2.png) [@HAWK](https://meta.discourse.org/u/HAWK)
#### Post date: [March 6, 2025, 8:56pm UTC](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713/28 "2025-03-06T20:56:59Z")

</div>

For anyone that doesn’t know where to get started, this tool walks you through the process.

[https://www.ofcom.org.uk/os-toolkit/assessment-tool/](https://www.ofcom.org.uk/os-toolkit/assessment-tool/)

[Next page](https://meta.discourse.org/t/online-safety-act-new-ofcom-rules/342713.md?page=2)
