I’ve had quite a number of emails on the issue of the Online Safety Act and I hope you will bear with me if I try and cover all of the points that have been made to me.
I am strongly in favour of free speech and agree that freedom of expression and the right to privacy are of crucial importance. Protecting free speech should not, however, stop us from also tackling the growing epidemic of online harm. The safety of children should be our priority, and the age verification rules were introduced to ensure service providers protect children from harmful content, including pornography, and the promotion of suicide and self-harm. That’s why I disagree with those who argue that the state has no role in trying to protect children from online harm or who say it is parents’ responsibility alone or who claim that it is pointless to try because of the existence of VPNs; just because you can’t do everything is not an argument for not trying to do something.
Secondly, I note the point that many of you have raised about what happens to our personal details when we provide age verification information. I would hope that platforms would make it clear what software they use and what their policy is as regards retention or destruction of our age information. But I would also add that we already give large amounts of personal information to companies and organisations online when we buy products or join groups.
As for concerns about the impact of the Act on community forum groups and other small, low-risk sites, the government recognises the contribution and importance that small and medium sized enterprises (SMEs) have made in communities across the country. Proportionality is a core principle of the Act and is built into the duties contained in the Act. Ofcom, the regulator for the online safety regime, must consider the size and risk level of different types and kinds of services when recommending steps providers can take to comply with their duties. Most of the measures they recommend for smaller, low-risk services in their Codes of Practice are a direct result of specific requirements in law.
Some duties will be required of all services in scope of the Act, regardless of size or risk. This includes regular risk assessments, including to determine if children are likely to access their service and, if so, an assessment of the risk of harm to them. While many services carry low risks of harm, the risk assessment duties are key to ensuring that risky services of all sizes do not slip through the net of regulation. For example, the Government is very concerned about small platforms that host harmful content, such as forums dedicated to encouraging suicide or self-harm. Exempting small services from the Act would mean that services like these forums would not be subject to the Act’s enforcement powers. Even forums that might seem harmless carry potential risks, such as where adults come into contact with child users.
If organisations have carried out a suitable and sufficient risk assessment and determined, with good reason, that the risks they face are low, they will only be expected to have basic but important measures to remove illegal content when they become aware of it. These include: easy-to-find, understandable terms and conditions; a complaints tool that allows users to report illegal material when they see it, backed up by a process to deal with those complaints; the ability to review content and take it down if it is illegal (or breaches your terms of service); and a specific individual responsible for compliance, who Ofcom can contact if they need to.
In addition, further duties are reserved for a small subset of user-to-user services with millions of users (referred to in the legislation as Category 1 and Category 2B services). As a result, many of the additional duties will not apply to smaller services in scope of the Act. Ofcom are providing support to online service providers of all sizes to make it easier for them to understand – and comply with – their responsibilities under the UK’s new online safety laws. For example, they have already launched a Regulation Checker to help firms check whether they are covered by the new rules and a number of quick guides to the rules.
Ofcom launched a ‘Digital Support Service’ on 21 January which consists of interactive digital tools for regulated firms and provides a step-by-step guide to the duties and a record-keeping template. These resources have been developed with individuals and SMEs in mind and will help them in complying with the Act’s duties.
When it comes to compliance, Ofcom will focus on services where the risk and impact of harm is highest, including where conduct they are concerned about is ongoing, repeated or flagrant, or if the service has a history of non-compliance. They are not setting out to penalise small, low risk services trying to comply in good faith, and will only take action where it is proportionate and appropriate.
Finally, the implementation of the Act must be compatible with the European Convention of Human Rights, including in relation to freedom of expression. Safeguards for freedom of expression have been built in throughout the Act. This will be particularly important for Ofcom – the regulator in charge of implementing the Act – as it makes enforcement decisions.
In the end, all of this is about trying to strike a reasonable balance, and as with any new laws – remember when GDPR came in ? – it will take time for things to bed in and organisations to understand what it is they are meant to be doing.
I hope that the safeguards in place help reassure you and thank you to those constituents who have contacted me about this important issue.
Best wishes
Rt Hon Hilary Benn
MP for Leeds South
Secretary of State for Northern Ireland