All news
Regulation August 28, 2026 5 min

Seven sites switched off the UK rather than protect children

Ofcom, 28 August: seven high-risk services blocked UK access and two introduced age checks. Eighteen months into the Online Safety Act: over a hundred platforms examined and more than £6 million in fines

In short

On 28 August 2026 Ofcom, the UK online safety regulator, published an update on the work of the teams that engage with platforms before a formal investigation is needed. The result: seven sites posing a significant risk of harm to children blocked access from the UK, and two more introduced age assurance.

What happened

Ofcom runs a taskforce dedicated to "small but risky" services: modest sites whose main content is harmful material. Under that pressure, two sites dedicated to graphic violence and serious injury content deployed age assurance to keep UK children out. Seven others preferred to shut the door on the UK entirely: five hosted graphic violence, two hosted suicide content.

Blocking UK IP addresses — geoblocking — is a route Ofcom accepts: if the service is no longer reachable, the risk to UK users falls away. But it is also the cheapest route, and it changes nothing for users in every other country.

The first eighteen months in numbers

  • More than 100 platforms examined since the Act came into force
  • Over £6 million in fines against 10 providers
  • 9 services which, in this update alone, blocked the UK or introduced age checks
  • Earlier Ofcom research had already found children first encounter this content while still at primary school, and describe it as an inevitable part of being online

The open letter to platforms

On the same day Ofcom wrote to platforms to remind them of something some were evidently taking for granted: existing duties are not suspended by the UK Government's announced ban on social media for under-16s. The new measures are expected from spring 2027; until then, and after, Online Safety Act duties stand. In October the regulator will publish a rapid assessment of what "highly effective age assurance" means at the sixteen threshold.

Why this matters outside the UK too

The British model — safety duties for anyone reachable from the country, with geoblocking as the only alternative — is becoming a reference point. If a European company runs a user-generated content service reachable from the UK, the question is not whether the GDPR is enough: these are two different regimes, and the second applies by user territory, not by company seat.

Honestly: nine services are not a revolution, and the seven that left still exist for everyone else. But the interesting part of the update is not the count, it is the method. Ofcom argues that persuasion before formal investigation delivers results faster than proceedings that take years. That is a claim European data protection authorities, sitting on multi-year backlogs, would do well to read.

Official source:Ofcom - UK children protected from more high-risk sites as a result of Ofcom action (28 agosto 2026)Official source:Ofcom - Our approach to online safety supervision and compliance (28 agosto 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min