After the contentious passing of the landmark Online Safety Act, Ofcom has now released a new draft Code of Practices tech firms must comply with to protect users from illegal content online.
As laid out in the Act, Ofcom is now exercising its newfound powers in the tech sphere, detailing the duties social media, gaming, pornography, search and sharing sites follow.
Ofcom says its role will be to force these tech firms to tackle the “causes” of online harm, by making their services “fundamentally” safer.
The regulator, however, will not be making decisions about individual content posts or accounts, or responding to individual complaints about illegal or harmful content.
Instead, tech firms will be required to assess the risks of users being harmed by illegal content on their platform, and take appropriate steps to protect users from it.
There will be particular focus on “priority offences” set out in the legislation, such as child abuse, grooming, and encouraging suicide – but it could be any illegal content.
“Regulation is here, and we’re wasting no time in setting out how we expect tech firms to protect people from illegal harm online, while upholding freedom of expression,” Dame Melanie Dawes, chief executive of Ofcom said.
“Children have told us about the dangers they face, and we’re determined to create a safer life online for young people in particular.”
Combatting Child Sexual Abuse and Grooming
Protecting children will be its first priority, the regulator says.
Scattergun friend requests are frequently used by adults looking to groom children for the purposes of sexual abuse, and Ofcom’s new report sets out the scale of and nature children’s online experiences of potentially unwanted and inappropriate contact online.
Three in five secondary-school-aged children (11-18 years) have been contacted online in a way that potentially made them feel uncomfortable.
This includes over one in ten (13%) children who have been sent pictures or videos of naked or half-dressed people, and 10% who have ever been asked to share these types of pictures or videos themselves.
For 11-13-year-olds, these figures drop only to still significant 6% and 4% respectively.
But children are already protecting themselves online to keep these numbers down, with 30% receiving an unwanted friend or follow request.
Recommended reading
- Users Want More Fact-checking From Social Media Networks
- EU to Big Tech: Crack Down on Disinformation, Or We’ll Crack Down On You
- UNESCO Reveals Plan for Regulating Social Media Platforms
“Our figures show that most secondary-school children have been contacted online in a way that potentially makes them feel uncomfortable. For many, it happens repeatedly,” Dame Melanie said.
“If these unwanted approaches occurred so often in the outside world, most parents would hardly want their children to leave the house. Yet somehow, in the online space, they have become almost routine. That cannot continue.”
The range and diversity of services within the scope of Ofcom’s regulatory powers means that it is not taking a one-size-fits-all approach.
Instead, Ofcom has proposed some measures for all services in scope, and other measures that depend on the risks the service has identified in its illegal content risk assessment and the size of the service.
Larger and higher-risk services should ensure by default:
- Children are not presented with lists of suggested friends
- Children do not appear in other users’ lists of suggested friends
- Children are not visible in other users’ connection lists
- Children’s connection lists are not visible to other users
- Accounts outside a child’s connection list cannot send them direct messages
- Children’s location information is not visible to any other users
Further, Ofcom is proposing that larger and higher-risk services should use a technology called ‘hash matching’ – which is a way of identifying illegal images of child sexual abuse by matching them to a database of illegal images, to help detect and remove child sexual abuse material circulating online.
In conjunction with this, they should also use automated tools to detect URLs that have been identified as hosting CSAM.
To combat the risks of suicide, all large general search services should provide crisis prevention information in response to search requests regarding suicide and queries seeking specific, practical, or instructive information regarding suicide methods.
Fighting Fraud and Terrorism
Ofcom’s draft Code of Practice also proposes targeted steps to combat fraud and terrorism.
Among the measures for large higher-risk services include automatic detection of keywords for stolen credential sales to mitigate fraud, and verifying accounts to reduce the risk of fraudulent accounts reaching more people.
To battle terrorism, all services should block accounts run by proscribed terrorist organisations. These are, assumedly, terrorist organisations that are deemed so by the UK government.
More broadly, Ofcom is proposing a core list of measures that services can adopt to mitigate the risk of all types of illegal harm, including naming a person accountable for compliance and creating teams to tackle harmful content.
Further, Ofcom is tasking large tech companies to make it easier for users to report harmful content and block users, as well as creating safety tests for their recommender algorithms to ensure they are not disseminating illegal content
Next Steps
Following these initial steps, Ofcom will soon release guidance on how adult sites should comply with their duty to ensure children cannot access pornographic content.
In Spring 2024, the regulator will publish a consultation on additional protections for children, from harmful content promoting suicide, self-harm, eating disorders, and cyberbullying, among other things.





