Children's online safety code of practice for user-to-user services
Protection of Children Code of Practice for user-to-user services
Draft consolidated version incorporating amendments in relation to PCU C11 and C12 that Ofcom intends to submit to the Secretary of State in accordance with section 43(1) of the Online Safety Act.¶
[VERSION NOT IN FORCE: This version incorporates amendments that Ofcom intends to submit to the Secretary of State, but which are not in force. For the current version of the Codes of Practice, see here]
Contents¶
1. Introduction ........................................................................................................................ 4 The Protection of Children Code of Practice for user-to-user services .......................................... 4 The recommended measures ......................................................................................................... 4 Data protection ............................................................................................................................... 5 2. Application and scope ........................................................................................................ 6 3. Index of recommended measures ..................................................................................... 8 4. Recommended measures ................................................................................................. 18 A. Governance and accountability ................................................................................................ 18 B. Age assurance ........................................................................................................................... 22 C. Content moderation ................................................................................................................. 30 D. Reporting and complaints ........................................................................................................ 42 E. Recommender systems ............................................................................................................. 51 F. Settings, functionalities and user support ................................................................................ 56 G. Terms of service ...................................................................................................................... 62 H. [Not used] ................................................................................................................................. 64 I. [Not used] .................................................................................................................................. 65 J. User controls ............................................................................................................................. 66 5. Definitions and interpretation ......................................................................................... 72 Risks of harm................................................................................................................................. 89 User numbers ............................................................................................................................... 90 Highly effective age assurance ..................................................................................................... 90 Content prohibited on a service ................................................................................................... 91
Section 1 Introduction¶
The Protection of Children Code of Practice for user-to-user services¶
The recommended measures¶
1 So far as relating to content that is harmful to children.
comply with the duty to have particular regard to the importance of protecting United Kingdom users' right to freedom of expression and the privacy of United Kingdom users.
Data protection¶
Section 2 Application and scope¶
b) the duties set out in Chapter 2 of Part 3 of the Act which must be complied with in relation to a combined service do not extend to:
c) the duties set out in Chapter 2 of Part 3 of the Act which must be complied with in relation to a user-to-user service extend only to:
Section 3 Index of recommended measures¶
2 Recommendations PCU C9 to PCU C10 are left intentionally blank because Ofcom has consulted on adding them to the Code. See Annex 9 ([DRAFT] Protection of Children Code of Practice for User-to-user services) to OFCOM’s consultation titled ‘Additional Safety Measures. Online Safety’, published on 30 June 2025 (at: https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/online-safety-additional-safety- measures).
* So far as it relates to content that is harmful to children, present on a part of the service that it is possible for children to access. † So far as relating to the complaints set out in section 21(4)(b)(ii) (so far as relating to content that is harmful to children) and (5).
Section 4 Recommended measures¶
A Governance and accountability¶
PCU A1 Annual review of risk management activities¶
Application¶
PCU A1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is a large service.
Recommendation¶
PCU A1.2 The provider’s most senior governance body in relation to the service should carry out and record an annual review of risk management activities having to do with harm to children, including as to risk remaining after the implementation of appropriate Code of Practice measures. The review should include how developing risks are being monitored and managed.
PCU A2 Individual accountable for the safety duties protecting children and reporting and complaints duties¶
Application¶
PCU A2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU A2.2 The provider should name an individual accountable to the most senior governance body for compliance with the safety duties protecting children and the reporting and complaints duties.
PCU A2.3 Being accountable means being required to explain and justify actions or decisions regarding:
to the most senior governance body.
PCU A3 Written statements of responsibilities¶
Application¶
PCU A3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU A3.2 The provider should have written statements of responsibilities for senior managers who make decisions about the management of risks having to do with harm to children.
PCU A3.3 A statement of responsibilities is a document which clearly shows the responsibilities that the senior manager performs in relation to the management of risks having to do with harm to children and how those responsibilities fit in with the provider’s overall governance and management arrangements in relation to the service.
PCU A4 Internal monitoring and assurance¶
Application¶
PCU A4.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is both a large service and multi-risk (children).
Recommendation¶
PCU A4.2 The provider should have an internal monitoring and assurance function to provide independent assurance that measures taken to mitigate and manage the risks of harm to children identified in the children’s risk assessment are effective on an ongoing basis. This function should report to, and its findings should be considered by, either:
PCU A4.3 This independent assurance may be provided by an existing internal audit function.
PCU A5 Tracking evidence of new and increasing harm to children¶
Application¶
PCU A5.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU A5.2 The provider should track evidence of new kinds of primary priority content or priority content, and unusual increases in particular kinds of content that is harmful to children or content that is harmful to children proxy, on child-accessible parts of the service. Relevant evidence may include, but is not limited to, that derived from:
PCU A5.3 The provider should ensure that any new kinds of primary priority content or priority content or unusual increases in particular kinds of content that is harmful to children or content that is harmful to children proxy are regularly reported through relevant governance channels to the most senior governance body.
PCU A5.4 To understand this, the provider should establish a baseline understanding of how frequently particular kinds of content that is harmful to children or content that is harmful to children proxy occur on child-accessible parts of the service to the extent possible based on its internal data and evidence. The provider should use this baseline to identify unusual increases in the relevant data.
PCU A6 Code of conduct regarding protection of children from harmful content¶
Application¶
PCU A6.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU A6.2 The provider should have a code of conduct that sets standards and expectations for individuals working for the provider around protecting children in the United Kingdom from risks of harm to children.
PCU A7 Compliance training¶
Application¶
PCU A7.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU A7.2 The provider should secure that individuals working for the provider who are involved in the design and operational management of the service are trained in the service’s approach to compliance with the safety duties protecting children and the reporting and complaints duties, sufficiently to give effect to them. This measure does not apply in relation to volunteers.
PCU A7.3 This does not affect Recommendations PCU C7 (provision of training and materials to individuals working in content moderation (non-volunteers)) and PCU C8 (provision of materials to volunteers).
B Age assurance¶
PCU B1 Implementing an age assurance process¶
Application¶
PCU B1.1 This measure applies to a provider in respect of each service likely to be accessed by children that uses highly effective age assurance to identify which United Kingdom users of the service are child users for the purpose of targeting measures recommended in this Code at such users, their user accounts or their content feeds (whether because any of Recommendations B2 to B7 apply to the service or otherwise).
Recommendation¶
PCU B1.2 The provider should have regard to the following when implementing highly effective age assurance on the service:
PCU B1.3 The provider should ensure that users are able to easily access information about what a provider’s highly effective age assurance process is intended to do and how the provider’s highly effective age assurance process works prior to commencing the highly effective age assurance process for the service.
PCU B1.4 The provider should not publish content that directs or encourages United Kingdom users to circumvent the highly effective age assurance process, or content controls or access controls used in conjunction with it, on the service.
3 Information Commissioner's Opinion - Age Assurance for the Children's Code
PCU B2 Use of highly effective age assurance - services where the principal purpose is the hosting or dissemination of primary priority content¶
Application¶
PCU B2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides where the principal purpose of the service is the hosting or dissemination of one or more kinds of primary priority content.
PCU B2.2 For the purposes of paragraph PCU B2.1, the principal purpose of a service is the hosting or dissemination of one or more kinds of primary priority content if the main activity or objective pursued by the service is the hosting or dissemination of one or more kinds of primary priority content. Factors that are relevant when determining whether the principal purpose of a service is the hosting or dissemination of one or more kinds of priority content include, but are not limited to:
Recommendation¶
PCU B2.3 The provider should use highly effective age assurance to target access controls to prevent all United Kingdom users of the service from accessing any user-to-user part of the service unless they have been determined to be an adult by the use of highly effective age assurance.
PCU B2.4 The provider should have systems and processes which enable a United Kingdom user who is unable to access the service, or parts of it, because the age assurance process used to comply with PCU B2.3 has determined them to be a child user, to request that this decision be rectified where it is incorrect. The provider should deal with any such requests promptly.
Safeguards for freedom of expression and privacy¶
PCU B2.5 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU B3 Use of highly effective age assurance - services where the principal purpose is the hosting or dissemination of priority content¶
Application¶
PCU B3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides where the principal purpose of the service is the hosting or dissemination of one or more kinds of priority content.
PCU B3.2 For the purposes of PCU B3.1, the principal purpose of a service is the hosting or dissemination of one or more kinds of priority content if the main activity or objective pursued by the service is the hosting or dissemination of one or more kinds of priority content. Factors that are relevant when determining whether the principal purpose of a service is the hosting or dissemination of one or more kinds of priority content include, but are not limited to:
Recommendation¶
PCU B3.3 The provider should use highly effective age assurance to target access controls to prevent all United Kingdom users of the service from accessing any user-to-user part of the service unless they have been determined to be an adult by the use of highly effective age assurance.
PCU B3.4 The provider should have systems and processes which enable a United Kingdom user who is unable to access the service, or parts of it, because the age assurance process used to comply with PCU B3.3 has determined them to be a child user, to request that this decision be rectified where it is incorrect. The provider should deal with any such requests promptly.
Safeguards for freedom of expression and privacy¶
PCU B3.5 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU B4 Use of highly effective age assurance - services that do not prohibit primary priority content¶
Application¶
PCU B4.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides where:
Recommendation¶
PCU B4.2 For the purpose of targeting content controls or access controls recommended by PCU C2.3(b) and PCU C2.4 at children, the provider should use highly effective age assurance to determine whether or not United Kingdom users of any child-accessible part of the service are children. (But see PCU C2.3(b), PCU C2.4 and PCU C2.12 in relation to where it is not technically feasible to apply HEAA content controls or HEAA access controls.)
PCU B4.3 The age assurance process referred to in PCU B4.2 can be carried out:
so that (in either case) appropriate moderation action for primary priority content does not restrict the access to content of those users determined to be adults.
Safeguards for freedom of expression and privacy¶
PCU B4.4 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU B5 Use of highly effective age assurance – services that do not prohibit priority content¶
Application¶
PCU B5.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides where:
Recommendation¶
PCU B5.2 For the purpose of targeting control controls or access controls recommended by PCU C2.6(b) and PCU C2.7 at children, the provider should use highly effective age assurance to determine whether or not United Kingdom users of any child-accessible part of the service are children. (But see PCU C2.6(b), PCU C2.7 and PCU C2.12 in relation to where it is not technically feasible to apply HEAA content controls, or either not technically feasible or not considered proportionate to apply HEAA access controls.)
PCU B5.3 The age assurance process referred to in PCU B5.2 can be carried out:
so that (in either case) appropriate moderation action for priority content does not restrict the access to content of those users determined to be adults.
Safeguards for freedom of expression and privacy¶
PCU B5.4 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU B6 Use of highly effective age assurance - services with a content recommender system that pose a risk of primary priority content¶
Application¶
PCU B6.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU B6.2 For the purpose of excluding content indicated potentially to be primary priority content from children’s content feeds in accordance with Recommendation PCU E1, the provider should use highly effective age assurance to determine whether or not United Kingdom users of any child-accessible part of the service which has a content recommender system are children.
PCU B6.3 The age assurance process referred to in PCU B6.2 can be carried out:
so that (in either case) content indicated potentially to be primary priority content is not excluded from the content feeds of those users determined to be adults.
Safeguards for freedom of expression and privacy¶
PCU B6.4 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU B7 Use of highly effective age assurance - services with a content recommender system that pose a risk of priority content or non-designated content¶
Application¶
PCU B7.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU B7.2 For the purpose of excluding content indicated potentially to be either priority content or an identified kind of non-designated content from children’s content feeds, or giving such content a low degree of prominence, in accordance with Recommendation PCU E2, the provider should use highly effective age assurance to determine whether or not United Kingdom users of any child-accessible part of the service which has a content recommender system are children.
PCU B7.3 The age assurance process referred to in PCU B7.2 can be carried out:
so that (in either case) content indicated potentially to be either priority content or an identified kind of non-designated content is not excluded from the content feeds of those users determined to be adults.
Safeguards for freedom of expression and privacy¶
PCU B7.4 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
C Content moderation¶
PCU C1 Having a content moderation function to review and assess suspected content that is harmful to children¶
Application¶
PCU C1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU C1.2 The provider should, as part of its content moderation function, have systems and processes designed to review and assess content present on a child-accessible part of the service that the provider has reason to suspect may be relevant content that is harmful to children.
PCU C1.3 For the purpose of PCU C1.2, when the provider has reason to suspect that the content may be relevant primary priority content, the provider should review the content and either:
PCU C1.4 For the purpose of PCU C1.2, when the provider has reason to suspect that the content may be relevant priority content, the provider should review the content and either:
PCU C1.5 For the purpose of PCU C1.2, when the provider has reason to suspect that the content may be relevant non-designated content the provider should review the content and either:
Safeguards for freedom of expression and privacy¶
PCU C1.6 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
PCU C2 Having a content moderation function that allows for swift action against content harmful to children¶
Application¶
PCU C2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU C2.2 The provider should, as part of its content moderation function, have systems and processes designed to:
of which it is aware (see also PCU C1.2).
Primary priority content¶
PCU C2.3 When the provider determines that content is in breach of its terms of service (pursuant to PCU C1.3(a)) the provider should:
PCU C2.4 When the provider determines that the content is relevant primary priority content (pursuant to PCU C1.3(b)), the provider should take appropriate moderation action for primary priority content, unless it is not currently technically feasible to apply HEAA content controls or HEAA access controls.
PCU C2.5 Appropriate moderation action for primary priority content means swiftly applying HEAA content controls or HEAA access controls.
Priority content¶
PCU C2.6 When the provider determines that the content is in breach of its terms of service (pursuant to PCU C1.4(a)) the provider should:
PCU C2.7 When (pursuant to PCU C1.4(b)) the provider determines that the content is relevant priority content, the provider should take appropriate moderation action for priority content, unless:
PCU C2.8 Appropriate moderation action for priority content means:
Non-designated content¶
PCU C2.9 When the provider determines that the content is in breach of its terms of service (pursuant to PCU C1.5(a)) the provider should:
PCU C2.10 When (pursuant to PCU C1.5(b)) the provider determines that the content is relevant non-designated content, the provider should take appropriate moderation action for non-designated content unless it is not currently technically feasible to apply other content level actions.
PCU C2.11 Appropriate moderation action for non-designated content means swiftly applying other content level actions (or, where the provider chooses to do so, HEAA content controls or HEAA access controls instead of or as well as other content level actions).
PCU C2.12 If, in designing the systems and processes referred to in PCU C2.2, the provider concludes that:
the provider should make and keep a written record of how technical feasibility and/or proportionality (as applicable) has been assessed and the reasons for reaching that conclusion.
PCU C2.13 In designing the systems and processes referred to in PCU C2.2(b) and (c) and in particular the aspects of those systems and processes relating to:
the provider should have regard to at least the following factors:
Safeguards for freedom of expression and privacy¶
PCU C2.14 The following measures are safeguards to protect United Kingdom users' right to freedom of expression and the privacy of United Kingdom users:
freedom of expression or privacy, and ICU D12, in the Illegal content Codes of Practice for user-to-user services.
PCU C3 Setting internal content policies¶
Application¶
PCU C3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU C3.2 The provider should set and record (but need not publish) internal content policies setting out rules, standards and guidelines around:
PCU C3.3 The policies should be drafted in such a way that moderation action is taken in accordance with Recommendation PCU C2 (having a content moderation function that allows for swift action against content harmful to children).
PCU C3.4 The provider should:
PCU C4 Performance targets¶
Application¶
PCU C4.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both):
Recommendation¶
PCU C4.2 The provider should set and record performance targets for its content moderation function covering at least:
PCU C4.3 In setting its targets, the provider should balance the need to take relevant content moderation action swiftly against the importance of making accurate moderation decisions.
PCU C4.4 The provider should effectively measure and monitor its performance against those targets.
PCU C4.5 For the purpose of PCU C4.2 and PCU C4.3, “relevant content moderation action” refers to the action recommended in PCU C1.3 to PCU C1.5 and PCU C2.3 to PCU C2.11.
PCU C5 Prioritisation¶
Application¶
PCU C5.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both):
Recommendation¶
PCU C5.2 The provider should prepare and apply a policy in respect of the prioritisation of content present on the service for review. In setting the policy, the provider should have regard to at least the following:
PCU C6 Resourcing¶
Application¶
PCU C6.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both):
Recommendation¶
PCU C6.2 The provider should resource its content moderation function so as to give effect to its internal content policies and performance targets having regard to at least:
PCU C7 Provision of training and materials to individuals working in content moderation (non-volunteers)¶
Application¶
PCU C7.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both):
Recommendation¶
PCU C7.2 The provider should ensure individuals working in content moderation receive training and materials that enable them to fulfil their role in moderating content present on a child-accessible part of the service including in relation to Recommendations PCU C1 and PCU C2 and the internal content policies set in accordance with Recommendation PCU C3. This measure does not apply in relation to volunteers.
PCU C7.3 The provider should ensure that in doing so:
PCU C8 Provision of materials to volunteers¶
Application¶
PCU C8.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both):
Recommendation¶
PCU C8.2 The provider should ensure volunteers in its content moderation function have access to materials that enable them fulfil their role in moderating content present on a child-accessible part of the service including in relation to Recommendations PCU C1 and PCU C2 and the internal content policies set in accordance with Recommendation PCU C3.
PCU C8.3 The provider should ensure that in doing so:
PCU C9 [Not used]¶
PCU C10 [Not used]¶
PCU C11 Crisis response¶
Application¶
PCU C11.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets either of the following conditions:
Key definitions¶
PCU C11.2 In this Recommendation PCU C11: “crisis” means an extraordinary situation in which there is a serious threat to public safety in the United Kingdom which is highly likely to:
“relevant harmful content” means any of the following kinds of content:
Recommendation¶
PCU C11.3 The provider should prepare and apply (but need not publish) a written internal protocol (“crisis response protocol”) to identify and respond to a crisis, for the purposes of mitigating and managing the risks arising from a significant increase in relevant harmful content on the service during a crisis.
PCU C11.4 The provider’s crisis response protocol should include, but need not be limited to, the following:
PCU C11.5 If Ofcom gives a public statement notice to the provider by virtue of section 175(3) of the Act, the provider should consider this, in addition to the indicators referred to in PCU C11.4(a), in determining whether a crisis is occurring or is likely to occur.
PCU C11.6 Where the provider determines that any of the indicators referred to in PCU C11.4(a) no longer remain relevant, or where new indicators are identified or existing indicators require updating, it should update its crisis response protocol accordingly.
PCU C11.7 When the provider determines that the crisis has ended, or 90 days after the crisis began, if earlier, the provider should conduct and record (but need not publish) a post-crisis analysis recording key decisions made during the crisis and assessing whether the crisis response protocol remains appropriate for mitigating and managing the risks arising from a significant increase in relevant harmful content on the service during a crisis. The provider should then use the post-crisis analysis to make changes to the crisis response protocol, as needed, to address any identified deficiencies.
Safeguards for freedom of expression and privacy¶
PCU C11.8 The following measures are safeguards to protect United Kingdom users’ right to freedom of expression and the privacy of United Kingdom users:
PCU C12 Crisis response (dedicated channel for law enforcement)¶
Application¶
PCU C12.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is a large service at medium or high risk of one or more of the following kinds of content:
Key definitions¶
PCU C12.2 In this Recommendation PCU C12: “crisis” means an extraordinary situation in which there is a serious threat to public safety in the United Kingdom which is highly likely to:
“relevant harmful content” means any of the following kinds of content:
Recommendation¶
PCU C12.3 If the provider determines that a crisis is occurring or is likely to occur, it should ensure there is a dedicated channel for law enforcement to contact the provider on matters related to the crisis.
D Reporting and complaints¶
PCU D1 Enabling complaints¶
Application¶
PCU D1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D1.2 The provider should have systems and processes which enable prospective complainants to make each type of relevant complaint in a way which will secure that the provider will take appropriate action in relation to them.
PCU D2 Having easy to find, easy to access and easy to use complaints systems and processes¶
Application¶
PCU D2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D2.2 The systems and processes referred to in PCU D1.2 should be operated to ensure that:
PCU D2.3 In designing the systems and processes referred to in PCU D1.2, including its reporting tool or function, the provider should consider the accessibility needs of its United Kingdom user base having regard to:
PCU D2.4 For the purposes of PCU D2.3, the systems and processes referred to in PCU D1.2 should be designed for the purpose of ensuring usability for those dependent on assistive technologies including:
PCU D3 Provision of information prior to the submission of a complaint¶
Application¶
PCU D3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D3.2 The provider should ensure that the reporting function or tool for relevant complaints regarding a specific piece of content enables prospective complainants to easily access information on the following matters prior to the submission of a complaint:
and, if so,
PCU D4 Appropriate action – sending indicative timeframes¶
Application¶
PCU D4.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D4.2 The provider should acknowledge receipt of each relevant complaint and provide the complainant with an indicative timeframe for deciding the complaint.
PCU D4.3 PCU D4.2 does not apply if:
PCU D5 Appropriate action – sending further information about how the complaint will be handled¶
Application¶
PCU D5.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D5.2 In the acknowledgment of receipt of each relevant complaint, referred to in Recommendation PCU D4, the provider should set out:
PCU D6 Opt-out from communications following a complaint¶
Application¶
PCU D6.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D6.2 The provider should enable the complainant to opt out of receiving any non-ephemeral communications in relation to a relevant complaint.
PCU D7 Appropriate action for relevant complaints about content considered harmful to children¶
Application¶
PCU D7.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D7.2 When the provider receives a relevant complaint about content present on a child-accessible part of the service which may be content that is harmful to children:
PCU D7.3 PCU D7.2 does not apply to a complaint identified as manifestly unfounded in accordance with PCU D14.2.
PCU D8 Appropriate action for content appeals – determination (services that are large or multi-risk)¶
Application¶
PCU D8.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D8.2 The provider should determine relevant complaints which are content appeals.
PCU D8.3 The provider should, as a minimum, monitor its performance against performance targets relating to the following:
and should resource itself so as to give effect to those targets.
PCU D8.4 The provider should have regard to the following matters in determining what priority to give to review of a relevant complaint which is a content appeal:
PCU D9 Appropriate action for content appeals – determination (services that are neither large nor multi-risk)¶
Application¶
PCU D9.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is neither of the following:
Recommendation¶
PCU D9.2 The provider should determine relevant complaints which are content appeals promptly.
PCU D10 Appropriate action for content appeals – action following determination¶
Application¶
PCU D10.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D10.2 If, in relation to a relevant complaint that is a content appeal, the provider reverses a decision that content was content that is harmful to children, the provider should:
PCU D11 Appropriate action for age assessment appeals (services that are large or multi-risk)¶
Application¶
PCU D11.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
PCU D11.2 The provider should have regard to the following matters in determining what priority to give to consideration of an age assessment appeal:
PCU D11.3 The provider should, as a minimum, monitor its performance against performance targets relating to the following:
and should resource itself so as to give effect to those targets.
PCU D11.4 If the provider determines that the user’s age was incorrectly assessed, the provider should take any necessary steps to enable the user to access content to which access was restricted as a result of that incorrect assessment (so far as appropriate and possible for the purpose of restoring the position to what it would have been had the assessment been correct).
PCU D11.5 The provider should monitor trends in age assessment appeals to help improve any age assurance process used on the service.
PCU D12 Appropriate action for age assessment appeals (services that are neither large nor multi-risk)¶
Application¶
PCU D12.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is neither a large service nor multi-risk (children).
Recommendation¶
PCU D12.2 The provider should determine age assessment appeals promptly.
PCU D12.3 If the provider determines that the user’s age was incorrectly assessed, the provider should take any necessary steps to enable the user to access content to which access was restricted as a result of that incorrect assessment (so far as appropriate and possible for the purpose of restoring the position to what it would have been had the assessment been correct).
PCU D12.4 The provider should monitor trends in age assessment appeals to help improve any age assurance process used on the service.
PCU D13 Appropriate action for complaints about non-compliance with certain duties¶
Application¶
PCU D13.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D13.2 This Recommendation PCU D13 applies to relevant complaints that the provider is not complying with:
PCU D13.3 The provider should nominate a responsible individual or a team to ensure that such complaints are directed to an appropriate individual or team to be processed.
PCU D13.4 Relevant complaints should be handled:
PCU D13.5 PCU D13.3 and PCU D13.4 do not apply in relation to complaints identified as manifestly unfounded in accordance with PCU D14.2.
PCU D14 Exception: manifestly unfounded complaints¶
Application¶
PCU D14.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU D14.2 When the provider receives a relevant complaint that is not a content appeal or an age assessment appeal, it may disregard the complaint only if:
PCU D14.3 In designing a policy for the purposes of PCU D14.2(a), the provider should have regard to:
PCU D14.4 The provider should, at minimum, carry out an annual review of the policy to ensure it is not incorrectly identifying relevant complaints as manifestly unfounded.
PCU D14.5 If the policy is incorrectly identifying relevant complaints as manifestly unfounded, the provider should make changes to it with a view to ensuring its accuracy.
PCU D14.6 The provider should keep a record of its review process and any changes it has made.
E Recommender systems¶
PCU E1 Content recommender systems: excluding potential primary priority content¶
Application¶
PCU E1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU E1.2 In this Recommendation, “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance (and see Recommendation PCU B6 (use of highly effective age assurance by services with a content recommender system that pose a risk of primary priority content).
PCU E1.3 The provider should ensure that any content recommender system on a child-accessible part of the service is designed and operated so that content indicated potentially to be primary priority content on the basis of relevant available information is excluded from relevant users’ content feeds.
PCU E1.4 For the purposes of PCU E1.3, the provider should:
PCU E1.5 If the service’s content moderation function reviews content indicated (for the purposes of this Recommendation) potentially to be primary priority content and determines it not to be relevant primary priority content in accordance with PCU C1.3, this Recommendation no longer applies to that content.
PCU E1.6 This Recommendation does not recommend the use of any specific kind of proactive technology, or the use of proactive technology to analyse user-
generated content communicated privately or metadata relating to user-generated content communicated privately.4
Safeguards for freedom of expression and privacy¶
PCU E1.7 The following measures are safeguards to protect United Kingdom users’ right to freedom of expression and the privacy of United Kingdom users:
PCU E2 Content recommender systems: excluding or giving a low degree of prominence to potential priority content and non-designated content¶
Application¶
PCU E2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU E2.2 In this Recommendation, “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance (and see Recommendation PCU B7 (use of highly
4 Ofcom has published guidance on content communicated ‘publicly’ and ‘privately’ under the Online Safety Act.
effective age assurance by services with a content recommender system that pose a risk of priority content or non-designated content).
PCU E2.3 The provider should ensure that any content recommender system on a child-accessible part of the service is designed and operated so that content indicated potentially to be either priority content or an identified kind of non-designated content on the basis of relevant available information is excluded from, or given a low degree of prominence in, relevant users’ content feeds.
PCU E2.4 For the purposes of PCU E2.3, the provider should:
PCU E2.5 In designing the systems and processes for the action to be taken by the content recommender system in relation to content indicated potentially to be either priority content or an identified kind of non-designated content, the provider should take account of the service’s children’s risk assessment (including its findings as to risk of harm to children in different age groups).
PCU E2.6 The provider should also ensure that content which the service’s content moderation function has determined to be relevant priority content or relevant non-designated content is excluded from, or given a low degree of prominence in, relevant users’ content feeds.
PCU E2.7 If the service’s content moderation function reviews content indicated (for the purposes of this Recommendation) potentially to be either priority content or an identified kind of non-designated content and determines it not to be relevant priority content or relevant non-designated content in accordance with PCU C1.4 or PCU C1.5, this Recommendation no longer applies to that content.
PCU E2.8 This Recommendation does not recommend the use of any specific kind of proactive technology, or the use of proactive technology to analyse user-generated content communicated privately or metadata relating to user-generated content communicated privately.5
5 Ofcom has published guidance on content communicated ‘publicly’ and ‘privately’ under the Online Safety Act.
Safeguards for freedom of expression and privacy¶
PCU E2.9 The following measures are safeguards to protect United Kingdom users’ right to freedom of expression and the privacy of United Kingdom users:
PCU E3 Content recommender systems: enabling children to give negative feedback¶
Application¶
PCU E3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets all of the following conditions:
Recommendation¶
PCU E3.2
PCU E3.3 The provider should ensure that a feature is included enabling relevant users to give negative feedback on pieces of regulated user-generated content
encountered as a result of the operation of a content recommender system on a child-accessible part of the service.
PCU E3.4 The feature should not make visible to other users of the service:
PCU E3.5 Where a relevant user has given negative feedback on a specific piece of content, that piece of content should be excluded from that user’s content feed.
PCU E3.6
PCU E3.7 This Recommendation does not recommend the use of proactive technology to analyse user-generated content communicated privately, or metadata relating to user-generated content communicated privately.6
Safeguards for freedom of expression and privacy¶
PCU E3.8 Recommendations ICU D1 and ICU D2, so far as they relate to complaints by United Kingdom users and affected persons if they consider that the provider is not complying with its duties in relation to freedom of expression or privacy, and ICU D12 in the Illegal content Codes of Practice for user-to-user services are safeguards to protect United Kingdom users’ right to freedom of expression and the privacy of United Kingdom users.
6 Ofcom has published guidance on content communicated ‘publicly’ and ‘privately’ under the Online Safety Act.
F Settings, functionalities and user support¶
PCU F1 Providing age-appropriate user support materials for children¶
Application¶
PCU F1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is multi-risk (children).
Recommendation¶
PCU F1.2 The provider should make publicly available (including to United Kingdom users who are not registered to use the service and persons in the United Kingdom who are not users of the service) materials which explain:
PCU F1.3 Where a child-accessible part of the service includes the feature in question, the provider should also make publicly available (including to United Kingdom users who are not registered to use the service and persons in the United Kingdom who are not users of the service) materials which explain:
PCU F1.4 The materials should in each case include:
PCU F1.5 The section of the materials aimed at children should be clear, comprehensible and easy for a child user to understand.
PCU F1.6 The materials should not include any material which would be content that is harmful to children if it were regulated user-generated content in relation to a service.
PCU F1.7 If it is possible to register to use the service, the provider should ensure that the materials are provided to United Kingdom users during the registration process.
PCU F1.8 The provider should ensure that the materials are easy to find on the service.
PCU F2 Providing information to children when they restrict content or interactions with other accounts¶
Application¶
PCU F2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is both a large service and multi-risk (children).
Recommendation¶
PCU F2.2 In this Recommendation “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU F2.3 PCU F2.4 applies when, on a child-accessible part of the service, a relevant user seeks to:
PCU F2.4 The provider must provide the relevant user with information about:
PCU F2.5 The information should be:
PCU F3 Signposting children to support when they report harmful content¶
Application¶
PCU F3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that is at medium or high risk of one or more of the following kinds of content:
Recommendation¶
PCU F3.2 In this Recommendation: “relevant harmful content” means any of the following kinds of content in respect of which the service is at medium or high risk:
“relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU F3.3 PCU F3.4 and F3.5 apply where a relevant user reports regulated user-generated content on the service using a reporting function or tool.
PCU F3.4 Where the provider:
the provider should signpost that user to appropriate support for that kind (or those kinds) of content as quickly as possible after the report is made.
PCU F3.5 Otherwise, the provider should signpost that user to appropriate support for all kinds of relevant harmful content as quickly as possible after the report is made.
PCU F3.6 Appropriate support for a kind of relevant harmful content is support that:
PCU F3.7 Before signposting to support provided by a third party organisation which is not a public body, the provider should have regard to any terms published by the relevant organisation relating to the use of its support, including as to obtaining its consent.
PCU F4 Signposting children to support when they post harmful content¶
Application¶
PCU F4.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets all of the following conditions:
Recommendation¶
PCU F4.2 In this Recommendation: “relevant harmful content” means any of the following kinds of content in respect of which the service is at medium or high risk:
“relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU F4.3 Where the provider becomes aware (through their systems and processes) that content posted by a relevant user on a child-accessible part of the service is or might be relevant harmful content of a specific kind (or kinds), the provider should signpost that user to appropriate support for that kind (or those kinds) of content as quickly as possible after becoming so aware.
PCU F4.4 Appropriate support for a kind of relevant harmful content is support that:
PCU F4.5 Before signposting to support provided by a third party organisation which is not a public body, the provider should have regard to any terms published by the relevant organisation relating to the use of its support, including as to obtaining its consent.
PCU F5 Signposting children to support when they search for harmful content¶
Application¶
PCU F5.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU F5.2 In this Recommendation: “relevant harmful content” means any of the following kinds of content in respect of which the service is at medium or high risk:
“relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU F5.3 Where the provider becomes aware (through their systems and processes) that a relevant user on a child-accessible part of the service has searched:
the provider should signpost that user to appropriate support for the kind of relevant harmful content to which the search request relates as quickly as possible after becoming so aware.
PCU F5.4 Appropriate support for a kind of relevant harmful content is support that:
PCU F5.5 Before signposting to support provided by a third party organisation which is not a public body, the provider should have regard to any terms published by the relevant organisation relating to the use of its support, including as to obtaining its consent.
G Terms of service¶
PCU G1 Terms of service: substance (all services)¶
Application¶
PCU G1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU G1.2 The provider should include the following in the terms of service:
PCU G1.3 The provider should apply the provisions referred to in PCU G1.2(d) consistently.
PCU G2 Terms of service: substance (Category 1 services)¶
Application¶
PCU G2.1 This measure applies to a provider in respect of each Category 1 service that is likely to be accessed by children it provides.
Recommendation¶
PCU G2.2 The provider should summarise the findings of its children’s risk assessment (including as to levels of risk and as to the nature, and severity, of potential harm to children) in the terms of service.
PCU G3 Terms of service: clarity and accessibility¶
Application¶
PCU G3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides.
Recommendation¶
PCU G3.2 The provider should ensure that the provisions included in the terms of service in accordance with Recommendation PCU G1 are:
H [Not used]¶
[Intentionally left blank]
I [Not used]¶
[Intentionally left blank]
J User controls¶
PCU J1 User blocking and muting¶
Application¶
PCU J1.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets all of the following conditions:
PCU J1.2 The kinds of content are:
Recommendation¶
PCU J1.3 In this Recommendation “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU J1.4 PCU J1.5 and PCU J1.7 apply in relation to any child-accessible part of the service which has user connection functionality, posting content functionality or user communication (including but not limited to direct messaging functionality and commenting on content functionality).
PCU J1.5 The provider should make available to all relevant users who are registered to use the service the option to block each of:
PCU J1.6 “Block” means to take action that will result in:
and “blocking” is to be read accordingly. “Blocked account” means the user account that action has been taken against.
“Blocking account” means the user account through which the action resulting in blocking has taken place. “Blocked user” means the user operating the blocked account. “Blocking user” means the user operating the blocking account.
PCU J1.7 The provider should make available to all relevant users who are registered to use the service the option to mute other user accounts (whether or not connected to that relevant user’s user account) on the service.
PCU J1.8 “Mute” means to take action that will result in the muting user being unable to encounter any content posted on the service using the muted account, including:
by means of the muting account, unless the muting user visits the user profile associated with the muted account, in which case the muting user will experience that user profile as if the muted account had not been muted, and “muting” is to be read accordingly. “Muting account” means the user account through which the action resulting in muting has taken place. “Muted account” means the user account that the action has been taken against. “Muted user” means the user operating the muted account. “Muting user” means the user operating the muting account.
PCU J1.9 For the avoidance of doubt:
Muting is reciprocal where a user has through a user account (“A”) muted a user account (“B”), and a user has through user account B also muted user account A.
PCU J2 Disabling comments¶
Application¶
PCU J2.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
PCU J2.2 The kinds of content are:
Recommendation¶
PCU J2.3 In this Recommendation “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU J2.4 PCU J2.5 and PCU J2.6 apply in relation to any child-accessible part of the service which has commenting on content functionality.
PCU J2.5 The provider should make available to all relevant users who are registered to use the service a feature which, if used or applied by a relevant user in relation
to a piece of content posted using that user’s user account, will prevent other users of the service from commenting on that content.
PCU J2.6 Relevant users should be able to use or apply the feature referred to in PCU J2.5 when posting content or after having posted content.
PCU J3 Invitations to group chats¶
Application¶
PCU J3.1 This measure applies to a provider in respect of each service likely to be accessed by children it provides that meets both of the following conditions:
Recommendation¶
PCU J3.2 In this Recommendation: “group chat invitation” means a notification sent to the user account of a relevant user (the “invited user”) informing the invited user that another user (the “inviting user”) has sought to make the invited user part of a particular group chat; “relevant user” means any United Kingdom user of the service, other than any user determined to be an adult by the use of highly effective age assurance.
PCU J3.3 The provider should ensure that a relevant user only becomes part of a group chat on a child-accessible part of the service (including a group chat that the user has previously been part of) once the user has received a group chat invitation and has actively confirmed that they wish to become part of that group chat.
PCU J3.4 A group chat invitation should:
PCU J3.5 A group chat invitation should not be designed in a way that encourages the invited user to confirm that they wish to become part of the group chat.
PCU J3.6 The provider should ensure that the invited user is given a reasonable period of time after receiving the group chat invitation to decide whether they wish to become part of the relevant group chat (and if so to give that confirmation).
PCU J3.7 The provider should not directly notify the inviting user if the invited user declines to be part of the relevant group chat.
Section 5 Definitions and interpretation¶
Table A - Definitions of terms in bold used in this Code¶
Table B - Terms used in this Code that have the meaning given in the Act¶
Risks of harm¶
Risk of harm¶
Multi-risk (children)¶
User numbers¶
Highly effective age assurance¶
b) the provider has ensured that the age assurance measures forming part of the age assurance process for the service have been tested in multiple different environments during the development of the age assurance process; and
c) the provider has identified, and taken appropriate steps to mitigate against, methods of circumvention that are easily accessible to children in the United Kingdom and where it is reasonable to assume that children in the United Kingdom may use them.
b) The provider has taken steps to ensure that any evidence relied upon as part of the age assurance process comes from a trustworthy source.