Skip to content

UK Online Safety Act vs EU DSA: Platform Obligations Compared

Online Safety Act vs Digital Services Act: Ofcom duties of care, OSA Category 1 designation, DSA VLOP threshold at 45 million EU users, recommender-system transparency, and enforcement fines compared.

Comparison diagram of UK OSA versus EU DSA across duties, thresholds, transparency.

The Online Safety Act is a UK platform regulation that imposes duties of care on providers of regulated user-to-user services and search services, while its EU counterpart, the Digital Services Act, applies a tiered obligation framework scaled by platform size and reach across EU member states.

Both regimes target similar harms: illegal content, children's safety, and opaque algorithmic systems. The compliance mechanics, however, diverge in scope triggers, obligation layers, advertising rules, and enforcement architecture. For any platform with users in the UK and the EU, understanding where the two regimes align and where they require separate compliance tracks is a practical operational question.

What the Online Safety Act and DSA Regulate

Comparison diagram of UK Online Safety Act, EU DSA across Use case, Strengths, Trade-offs

The Online Safety Act and the Digital Services Act both target platform obligations, but they define their scope differently. The UK regime builds its scope around the concept of a regulated user-to-user service: any service that enables users to generate, upload, or share content that can be accessed by other users. Regulated search services form a parallel category. Any provider of a regulated user-to-user service or regulated search service with UK links falls under Ofcom's jurisdiction, regardless of where the company is incorporated.

The EU rules use a different organizing concept: the intermediary service. The Digital Services Act (DSA) covers hosting services, online platforms, and very large platforms, scaling obligations up the chain. Where the UK regime focuses on the nature of user interaction, the DSA focuses on the nature of the service and, crucially, its audience size inside the EU.

Online Safety Act (OSA): regulated user-to-user service
Any service that allows users to generate or share content visible to other users, including social networks, forums, video platforms, and dating apps. Regulated search services form a separate but parallel category. UK nexus is sufficient; incorporation location is irrelevant.
Digital Services Act: intermediary service
Any service that transmits, caches, or hosts third-party information. The DSA sub-divides this into mere conduits, caching services, hosting services, online platforms, and very large online platforms. Obligation depth depends on which tier a service falls into, not solely on whether it hosts user content.

Obligations at a Glance: Side-by-Side Comparison

The Online Safety Act and DSA share a core illegal-content removal mandate but diverge significantly on how platform size triggers additional obligations. The table below maps the main obligation axes across both regimes.

Obligation axisOnline Safety Act (UK)Digital Services Act (EU)
Scope triggerRegulated user-to-user service or regulated search service with UK linksIntermediary service offered to EU users; obligation depth scales by tier
Illegal-content dutiesRisk assessment plus removal duties for all regulated services; priority illegal content listed in the priority-offences scheduleNotice-and-action mechanism required of all hosting services; statements of reasons for removal decisions
Children's protectionChildren risk assessment mandatory for services likely accessed by children; age assurance required for harmful content categoriesComplete ban on targeted advertising to children; providers must implement age assurance for adult content categories
Recommender system transparencyThe top tier of regulated services must publish user empowerment tools including non-recommender feed optionsVery large online platforms must offer at least one recommender system not based on profiling
Ad libraryNo equivalent mandatory public ad repository in primary legislationVLOPs must maintain a publicly searchable ad repository with advertiser identity and targeting criteria
Annual auditNot required under primary legislation; Ofcom codes of practice set operational standardsVLOPs and very large online search engines must undergo annual independent audits
Enforcement bodyOfcom (UK Communications Regulator)European Commission for VLOPs; national Digital Services Coordinators for smaller platforms
Maximum fineUp to 10 percent of qualifying worldwide revenueUp to 6 percent of global annual turnover for VLOPs

How the OSA Categorizes Platform Risk

The Online Safety Act sorts platform obligations into tiers based on a category designation that Ofcom applies through secondary legislation. The duty structure is set out in the Act's duty matrix, which assigns duties of care by service type rather than a single numeric user threshold (legislation.gov.uk, s.7). Three layers of platform obligations build on each other:

  1. All regulated services. Every provider of a regulated user-to-user service must complete an illegal content risk assessment (s.9) and fulfill the corresponding illegal content duties (s.10). These cover identifying, mitigating, and managing the risk that the service is used to disseminate priority illegal content listed in Schedule 7 (legislation.gov.uk, Part 3). This baseline applies regardless of platform size.
  2. Services likely accessed by children. Where a service is likely to be accessed by children, providers must also complete a children's risk assessment (s.11) and implement age assurance or age verification measures for content categories harmful to minors. The risk assessment must be kept up to date.
  3. Category 1 services. Ofcom designates the highest-reach, highest-risk platforms as Category 1 services through secondary legislation made under the Act's duty matrix (legislation.gov.uk, s.7). These providers face additional duties: an adult empowerment risk assessment (s.14), adult empowerment duties including user-controlled content filters (s.15), and specific protections for news publisher content (s.18). The criteria for designation include user numbers, functionalities, and risk profile, assessed under the relevant statutory instrument rather than a fixed count.

The layered approach means that a small forum with few users bears the baseline illegal-content duties but escapes the category 1 service obligations reserved for the largest regulated services. Providers must track Ofcom's ongoing secondary legislation and codes of practice because the designation thresholds sit outside the primary Act text (legislation.gov.uk, Part 3).

How the DSA Scales Obligations by Platform Size

The Digital Services Act applies a four-tier structure that reserves its most demanding obligations for platforms designated as very large online platforms (VLOPs). The VLOP threshold is 45 million monthly active users in the EU. Designation triggers a four-month compliance window and additional systemic-risk obligations (digital-strategy.ec.europa.eu, DSA VLOPs).

  1. All intermediary services. Basic notice-and-action obligations apply to all covered services. Providers must publish transparency reporting on content moderation decisions and maintain a point of contact for authorities. These baseline duties apply regardless of size.
  2. Hosting services. Providers that store user content must provide statements of reasons whenever they remove or restrict content. Users have the right to challenge those decisions through an internal complaint mechanism.
  3. Online platforms. Services that allow the public to interact with hosted content must add an internal complaint-handling system, offer access to out-of-court dispute settlement, and comply with ad transparency requirements including clear labeling of targeted advertising with advertiser identity and the targeting logic used (digital-strategy.ec.europa.eu, DSA impact on platforms).
  4. VLOPs and very large online search engines (VLOSEs). Platforms exceeding the 45 million EU user threshold must complete annual independent audits, grant researchers structured data access, offer users at least one recommender system option not based on profiling, and maintain a public ad repository. The European Commission has direct enforcement authority over these platforms.

Transparency and Advertising Rules Compared

Advertising transparency is where the Digital Services Act and Online Safety Act diverge most sharply. The DSA introduces obligations that the OSA does not replicate, particularly for child-directed advertising and recommender system disclosure (digital-strategy.ec.europa.eu, Digital Services Act overview).

Key points of divergence on transparency and advertising:

  • DSA: complete ban on targeted advertising to children. VLOPs and online platforms may not display targeted advertising to users they know to be minors. The prohibition covers profiling-based ad delivery regardless of the content category.
  • DSA: mandatory public ad repository. Very large online platforms must maintain a searchable repository disclosing each advertisement displayed, the advertiser's identity, the period of display, and the targeting parameters used. No equivalent obligation exists under the OSA's primary text.
  • DSA: recommender system transparency reporting. VLOPs must publish clear descriptions of each recommender system they deploy and offer users a non-profiling alternative feed. The DSA defines a recommender system as any system that uses automated means to suggest, rank, or prioritize content.
  • OSA: fraudulent advertising duties. The UK regime imposes duties on the largest regulated services in relation to fraudulent paid-for advertising under Chapter 5, Part 3. The largest, highest-reach services must have systems to detect and remove fraudulent ads.
  • OSA: children risk assessment constrains ad delivery indirectly. Although the OSA does not ban profiling-based ads categorically, the children risk assessment framework requires platforms to assess whether advertising formats contribute to harm. Mitigation measures may restrict certain ad-delivery methods for younger users.
  • Both regimes: content moderation transparency reporting. The OSA requires transparency reports from regulated services, covering volumes of illegal content identified and actioned. The DSA imposes transparency reporting obligations at every tier, with the depth of disclosure scaling up through the four levels.

Enforcement: Ofcom vs the European Commission

Enforcement authority under the Online Safety Act rests with Ofcom in the UK, while DSA enforcement splits between the European Commission for VLOPs and national Digital Services Coordinators for smaller platforms.

  • Ofcom (OSA). The regulator issues codes of practice that set the operational standards providers must meet to demonstrate compliance. Ofcom can require disclosure of user data and internal risk assessments, issue enforcement notices, and seek court orders to block access to non-compliant services. The maximum financial penalty for a breach is up to 10 percent of qualifying worldwide revenue (legislation.gov.uk, Part 3).
  • European Commission (DSA: VLOPs and VLOSEs). The Commission holds direct enforcement jurisdiction over designated very large online platforms and very large online search engines. For systemic-risk breaches, the Commission can impose fines of up to 6 percent of global annual turnover and, for serious or repeated infringements, impose temporary restrictions on service access (digital-strategy.ec.europa.eu, DSA VLOPs).
  • Digital Services Coordinators (DSA: smaller platforms). Each EU member state appoints a national Digital Services Coordinator responsible for enforcing the DSA's obligations on platforms below the VLOP threshold operating in that jurisdiction. Coordination between national authorities and the Commission is required for cross-border enforcement.
  • Criminal liability. The OSA creates senior-manager liability for obstructing Ofcom investigations, a personal accountability mechanism the DSA does not replicate at the primary-legislation level.

What Platforms Operating in Both Markets Must Do

Platforms with users in both the UK and the EU face overlapping but non-identical compliance obligations under the Online Safety Act and DSA. A practical compliance strategy maps the two requirement sets against each other to identify where a single program serves both and where separate tracks are necessary.

Areas of alignment: Both regimes require providers to assess the risk of illegal content, establish notice-and-action workflows, and produce transparency reports on content moderation activity. A shared operational process for illegal-content detection, a combined risk assessment that satisfies both statutory frameworks, and consolidated transparency reporting infrastructure can reduce duplication. Children's protection obligations also overlap: both regimes require providers to assess risk to younger users and implement age assurance where harmful content categories are accessible.

Areas requiring separate compliance tracks: The OSA's category 1 service designation and the DSA's VLOP threshold use different criteria and produce different obligation sets. A platform designated as a category 1 service under the UK regime is not automatically a VLOP under the DSA, and vice versa. The DSA's ban on targeted advertising to children and its mandatory ad repository have no direct OSA equivalent; those obligations require separate engineering and operational controls. The DSA's recommender system profiling opt-out is also structurally distinct from the OSA's user empowerment duties, even though both address algorithmic feed transparency. The enforcement contact points also differ: Ofcom for UK matters, the relevant member state Digital Services Coordinator (and the European Commission for VLOP-classified services) for EU matters.

For context on how adjacent regulatory frameworks shape platform compliance burdens, the GDPR impact on US tech companies analysis covers data-processing obligations that interact with both the OSA and DSA frameworks. The Section 230 platform liability framework provides the US counterpart for operators managing tri-jurisdiction exposure. Technical teams implementing moderation infrastructure will find relevant architecture detail in the overview of how platforms build content moderation pipelines.

References

Frequently Asked Questions

Which platforms does the UK Online Safety Act cover that the DSA does not?

The Online Safety Act covers any regulated user-to-user service or regulated search service with links to the UK, regardless of where the provider is incorporated. The DSA applies to intermediary services established in or targeting EU users, using a tiered scope that splits obligations between micro, small, large, and very large platforms. A US-based forum with a small UK user base falls under Ofcom jurisdiction but may sit below the DSA thresholds entirely.

What triggers very large platform status under each law?

Under the DSA, the Commission designates a platform as a very large online platform (VLOP) when it exceeds 45 million monthly active users in the EU. The Online Safety Act uses a categorization system: Ofcom designates the top tier of regulated services based on user numbers, functionality, and risk profile set by secondary legislation, not a single fixed numeric threshold.

How do enforcement powers compare between Ofcom and the European Commission?

Ofcom can impose fines up to 10 percent of qualifying worldwide revenue for OSA breaches and can seek court orders to block non-compliant services. The European Commission enforces DSA obligations against VLOPs directly, with fines up to 6 percent of global annual turnover and the ability to impose temporary restrictions for serious, repeated infringements. National Digital Services Coordinators handle enforcement for smaller platforms under the DSA.

Does the Digital Services Act ban targeted advertising to children?

Yes. The DSA introduces a complete ban on showing targeted advertisements to children. The Online Safety Act takes a different approach, requiring platforms to carry out children risk assessments and implement age assurance measures, which may restrict certain content and advertising formats, but does not contain an equivalent categorical ad ban.

Share this guide

Sofía Reyes

Sofía Reyes edits techshooked's tech-policy and regulation coverage: privacy law, the EU AI Act, antitrust, platform liability, and online-safety rules. She reads regulatory text the way an engineer reads source code, asking what the rule actually requires, where it conflicts with other instruments, and which concrete steps satisfy it without theater.