OpusBUSINESS EXPERT

Your comments box is exempt from the Online Safety Act. Your members' area might not be

Andy Shepherd7 min read

The question usually arrives in the wrong shape. Somebody has read about age checks on social media, or seen a headline about Ofcom enforcement, and wants to know whether the reviews ought to come off the website before anyone notices.

For most firms around here they can stay. The reason is more specific than being too small, and worth ten minutes, because the same reasoning puts a few ordinary business websites inside a law nobody told them about.

Size is not the test

Ofcom's own estimate is that over 100,000 online services are likely to be in scope of the Online Safety Act, "from the largest social media platforms to the smallest community forum". There is no headcount or turnover floor: a twelve-person firm with the wrong feature is regulated, and a large company with the right one is not.

Comments and reviews are exempt by name

Schedule 1 of the Act lists the services that fall outside it. Paragraph 4 covers what it calls limited functionality services, and a service is exempt if the only ways users can communicate are these: posting comments or reviews relating to the provider's own content, sharing those comments on another internet service, and expressing a view on them by applying a like or dislike button, an emoji, yes/no voting, or a star or numerical rating.

Ofcom's guidance on regulated services gives the two examples that matter to a small business: a site where users can only write below-the-line comments on articles, and one where they can only post reviews of goods or services the provider itself offers. Neither is squeezed into the exemption by a clever reading: they are the examples the regulator chose.

So the comment thread under your news page and the reviews wall under your products are, on the face of it, outside the Act.

What does put an ordinary firm in scope

One thing, in various costumes: users able to reach each other.

  • a forum, community area or discussion board, however quiet
  • private messaging between users, including inside an app
  • a members' area where what one member posts is visible to the others
  • a classifieds or marketplace page where customers list things themselves
  • file sharing or photo uploads that go between users rather than only to you

Put the question to whoever built the site in one line: can a user put something here that another user can see or receive. If the answer is yes, and it is not a comment or review on something you published, assume you are in scope until the checker tells you otherwise.

The exemptions nobody knows they have

Email is exempt. So are SMS and MMS messages, and one-to-one live voice calls over the internet. A one-to-one video call is not, and neither is a recording of a call shared on a regulated service. That distinction is Ofcom's, not mine.

Internal business tools are exempt too, under paragraph 7, and this is the one that settles most nerves. An internal tool for your own business, provided by your own business, available only to a closed group of your officers, the people who work for you, and others you authorise for the purposes of the business, is outside the Act. The examples the Act itself gives for that last group are a contractor, a consultant or an auditor. Your intranet is not a regulated platform, and neither is the internal help desk your staff log into.

The genuinely uncertain case is the client portal, where each client can see and send things to your team but never to another client. It has users and messages, and it is not quite the intranet the exemption describes. If that is what you have, do not take a view on it from a blog post. Run it through the checker and keep the answer.

If you are in scope, the dates have already gone

16 Mar 2025
Illegal content risk assessment due
16 Apr 2025
Children's access assessment due
24 Jul 2025
Children's risk assessment, where relevant

The illegal content codes came into force on 17 March 2025 and the protection of children codes on 25 July 2025. A firm working this out now is not getting ahead of something. It is late, and better off knowing.

In practice that is less alarming than the penalties in the coverage suggest. Ofcom says it will engage with a provider to explain its concerns and in most cases give them a chance to put things right before moving to formal action, and that it is "not setting out to penalise small, low risk services trying to comply in good faith". The maximum penalty in the Act, up to 10% of qualifying worldwide revenue or £18 million, whichever is greater, was written for the companies the Act was aimed at. The fees regime has a worldwide revenue threshold far above anything a local firm turns over, so there is no invoice coming either.

Where a service has done a suitable and sufficient risk assessment and reasonably concluded the risk is low, Ofcom says the expectation is four things: terms and conditions a user can find and understand, a complaints tool that lets people report illegal or harmful material with a process behind it, the ability to review content and take it down quickly, and one named individual responsible for compliance who the regulator can contact.

Three of those are an afternoon. The risk assessment is the actual work, and Ofcom publishes a quick guide and an interactive toolkit for it, which beats a template somebody sells you.

What I would actually do

Start with Ofcom's own checker. It takes a couple of minutes and it is written by the people who would be asking the questions.

Then ask what the feature earns you. A forum with nine posts since 2019, a members' area two people log into, a comment section that collects nothing but spam: those are liabilities with no revenue attached, and the honest recommendation is often to turn them off rather than to wrap them in a compliance process. Removing a feature that earns nothing is a recommendation we are willing to give.

If you decide to keep it, keep it properly. A report button that goes to a mailbox nobody owns is worse than none, for the same reason an unmonitored contact form is: it creates an expectation the business then fails. That is a systems problem rather than a legal one.

We build and host the sites, so "can a user reach another user here" is usually a question we can answer the same day, and switching a feature off or putting a working report route behind it is configuration rather than a project.

I am not a solicitor and this is not legal advice on whether your service is regulated. It is the engineering half of the question, which is the half that decides the answer. Ask us if you want a straight read on what your own site lets people do, and if the honest answer is that you are outside the Act and have nothing to fix, that is what you will get.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy