Illegal content code of practice for search services
[DRAFT]Illegal content Codes of Practice for search services
We are consulting on the amendments shown in red text. Please refer to the Illegal Harms Updates, New priority offences: serious self-harm and cyberflashing consultation (published 24 March 2026) which explains the proposed changes.
For reference, amendments proposed in a previous consultation are also shown in this document in blue text. We have not yet made any final decisions about these amendments, and they are not part of the current consultation. For further information, please see the Additional Safety Measures: Online Safety consultation (published 30 June 2025).
Draft published for consultation: 24 March 2026
Contents¶
1. Introduction .............................................................................................................. 4 The Illegal content Codes of Practice for search services .............................................................. 4 The recommended measures ......................................................................................................... 4 Data protection ............................................................................................................................... 5 2. Application and scope ............................................................................................... 6 3. Index of recommended measures .............................................................................. 7 4. Recommended measures ........................................................................................ 11 A. Governance and accountability ................................................................................................ 11 B. [Not used] ................................................................................................................................. 15 C. Search moderation ................................................................................................................... 16 D. Reporting and complaints ........................................................................................................ 25 E. [Not used] ................................................................................................................................. 34 F. Settings, functionalities and user support ................................................................................ 35 G. Publicly available statements ................................................................................................... 38 5. Definitions and interpretation ................................................................................. 40 Risks of illegal harm ...................................................................................................................... 51 User numbers ............................................................................................................................... 58
Section 1 Introduction¶
The Illegal content Codes of Practice for search services¶
The recommended measures¶
complying with the duties set out in section 33(2) (in respect of freedom of expression) and section 33(3) (in respect of privacy).
Data protection¶
Section 2 Application and scope¶
Section 3 Index of recommended measures¶
† So far as relating to the complaints set out in section 32(4).
Section 4 Recommended measures¶
A Governance and accountability¶
ICS A1 Annual review of risk management activities¶
Application¶
ICS A1.1 This measure applies to a provider in respect of each large general search service it provides.
Recommendation¶
ICS A1.2 The provider’s most senior governance body in relation to the service should carry out and record an annual review of risk management activities having to do with illegal harm as it relates to individuals in the UK, including in relation to risk that is remaining after the implementation of appropriate Codes of Practice measures. The review should include how developing risks are being monitored and managed.
ICS A2 Individual accountable for illegal content safety duties and reporting and complaints duties¶
Application¶
ICS A2.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS A2.2 The provider should name an individual accountable to the most senior governance body for compliance with the illegal content safety duties and the reporting and complaints duties.
ICS A2.3 Being accountable means being required to explain and justify actions or decisions regarding:
to the most senior governance body.
ICS A3 Written statements of responsibilities¶
Application¶
ICS A3.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS A3.2 The provider should have written statements of responsibilities for senior managers who make decisions about the management of risks having to do with illegal harm in relation to individuals in the UK.
ICS A3.3 A statement of responsibilities is a document which clearly shows the responsibilities that the senior manager performs in relation to the management of risks having to do with illegal harm in relation to individuals in the UK and how they fit in with the provider’s overall governance and management arrangements in relation to the service.
ICS A4 Internal monitoring and assurance¶
Application¶
ICS A4.1 This measure applies to a provider in respect of each service it provides that is both a large service and a multi-risk service.
Recommendation¶
ICS A4.2 The provider should have an internal monitoring and assurance function to provide independent assurance that measures taken to mitigate and manage the risks of harm to individuals identified in the risk assessment are effective on an ongoing basis. This function should report to, and its findings should be considered by, either:
ICS A4.3 This independent assurance may be provided by an existing internal audit function.
ICS A5 Tracking evidence of new and increasing illegal harm¶
Application¶
ICS A5.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS A5.2 The provider should track evidence of new kinds of search content that is illegal content that may be encountered in or via its search results, and unusual increases in particular kinds of illegal content or illegal content proxy. Relevant evidence may include, but is not limited to, that derived from:
ICS A5.3 The provider should ensure that any new kinds of illegal content or unusual increases in particular kinds of illegal content or illegal content proxy are regularly reported through relevant governance channels to the most senior governance body.
ICS A5.4 To understand this, the provider should establish a baseline understanding of how frequently particular kinds of illegal content or illegal content proxy occur to the extent possible based on its internal data and evidence. The provider should use this baseline to identify unusual increases in the relevant data.
ICS A5.5 References in this Recommendation ICS A5 to “illegal content” or “illegal content proxy” are to be read as references to illegal content or illegal content proxy that may be encountered by United Kingdom users in the search content of the service.
ICS A6 Code of conduct regarding protection of users from illegal harm¶
Application¶
ICS A6.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS A6.2 The provider should have a code of conduct that sets standards and expectations for individuals working for the provider around protecting United Kingdom users from risks of illegal harm.
ICS A7 Compliance training¶
Application¶
ICS A7.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS A7.2 The provider should secure that individuals working for the provider who are involved in the design and operational management of the service are trained in the service’s approach to compliance with the illegal content safety duties and the reporting and complaints duties, sufficiently to give effect to them. This measure does not apply in relation to volunteers.
ICS A7.3 This does not affect Recommendation ICS C6 (provision of training and materials to individuals working in search moderation (non-volunteers)).
B [Not used]¶
[Intentionally left blank]
C Search moderation¶
ICS C1 Having a search moderation function designed to action illegal content¶
Application¶
ICS C1.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS C1.2 The provider should, as part of its search moderation function, have systems and processes designed to review, assess and where relevant take appropriate moderation action in relation to search content the provider has reason to suspect may be illegal content.
ICS C1.3 For this purpose, when the provider has reason to suspect that search content may be illegal content, the provider should either:
ICS C1.4 For the purpose of ICS C1.2 and ICS C1.3, "appropriate moderation action" includes any action applied to the search content concerned that results in it:
ICS C1.5 For the avoidance of doubt, the action specified in ICS C1.4(b) does not require illegal content to appear lower than other search content in search results where this is not possible in response to a given search request because:
ICS C1.6 In designing the systems and processes referred to in ICS C1.2, and in particular the aspects of those systems and processes relating to what appropriate moderation action to take (including the extent to which search content is given a lower priority in the overall ranking of search results presented to United Kingdom users) the provider should have regard to the following:
ICS C1.7 This does not affect Recommendation ICS C7 (removing listed CSAM URLs from search results).
Safeguards for freedom of expression and privacy¶
ICS C1.8 The following measures are safeguards to protect United Kingdom users’ and interested persons’ rights to freedom of expression and the privacy of United Kingdom users:
ICS C2 Setting internal content policies¶
Application¶
ICS C2.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS C2.2 The provider should set and record (but need not publish) internal content policies setting out rules, standards and guidelines around:
ICS C2.3 The policies should be drafted in such a way that appropriate moderation action is taken in accordance with Recommendation ICS C1 (having a search moderation function designed to action illegal content).
ICS C2.4 The provider should:
ICS C3 Performance targets¶
Application¶
ICS C3.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS C3.2 The provider should set and record performance targets for its search moderation function, covering at least:
ICS C3.3 In setting its targets, the provider should balance the need to take appropriate moderation action swiftly against the importance of making accurate moderation decisions.
ICS C3.4 The provider should effectively measure and monitor its performance against its performance targets.
ICS C4 Prioritisation¶
Application¶
ICS C4.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS C4.2 The provider should prepare and apply a policy in respect of the prioritisation of search content for review. In setting the policy, the provider should have regard to at least the following:
ICS C5 Resourcing¶
Application¶
ICS C5.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS C5.2 The provider should resource its search moderation function so as to give effect to its internal content policies and performance targets, having regard to at least:
ICS C6 Provision of training and materials to individuals working in search moderation (non-volunteers)¶
Application¶
ICS C6.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS C6.2 The provider should ensure individuals working in search moderation receive training and materials that enable them to fulfil their role in moderating search content including in relation to Recommendation ICS C1 and the internal content policies set in accordance with Recommendation ICS C2. This measure does not apply in relation to volunteers.
ICS C6.3 The provider should ensure that in doing so:
ICS C7 Removing listed CSAM URLs from search results¶
Application¶
ICS C7.1 This measure applies to a provider in respect of each general search service it provides.
Key definition¶
ICS C7.2 In this Recommendation ICS C7, “CSAM URL” means a URL at which CSAM is present, or a domain which is entirely or predominantly dedicated to CSAM.
ICS C7.3 For the purpose of ICS C7.2, a domain is “entirely or predominantly dedicated” to CSAM if the content present at the domain, taken overall, entirely or predominantly comprises CSAM (such as indecent images of children) or content related to CSEA content).
Recommendation¶
ICS C7.4 The provider should source one or more lists of CSAM URLs from a person (or persons) with expertise in the identification of CSAM and who meets (in relation to the list) the requirements set out in ICS C7.5.
ICS C7.5 The requirements are that the person has arrangements in place:
ICS C7.6 The provider should take action to ensure that United Kingdom users of the service do not encounter, in or via search results, search content present at or sourced from listed URLs or URLs that contain a listed domain.
1 2010 c. 15.
ICS C7.7 The provider should ensure that action taken in relation to a listed URL or listed domain for the purpose of ICS C7.6 is swiftly reversed when the URL or domain is removed from the list, unless the provider considers that it would be inappropriate to do so.
ICS C7.8 The provider should ensure that the list or lists are regularly monitored for the purposes of ICS C7.6 and ICS C7.7.
ICS C7.9 The provider should ensure that an appropriate policy is put in place, and that measures are taken in accordance with that policy, to secure any copy of a list held for the purposes of this Recommendation ICS C7 from unauthorised access, interference or exploitation (whether by persons who work for the provider or are providing a service to the provider, or any other person).
Safeguards for freedom of expression¶
ICS C7.10 The following elements of this Recommendation ICS C7 are safeguards to protect United Kingdom users’ and interested persons’ rights to freedom of expression:
ICS C7.11 The following measures are also safeguards to protect United Kingdom users’ and interested persons’ rights to freedom of expression:
ICS C8 Hash matching for intimate image abuse content¶
Application¶
ICS C8.1 This measure applies to a provider in respect of each large general search service it provides.
Key definition¶
ICS C8.2 In this Recommendation ICS C8 “relevant content” means any search content in the form of photographs, videos or visual images (whether or not combined with written material) that United Kingdom users can encounter in or via search results.
Recommendation¶
ICS C8.3 The provider should ensure that perceptual hash matching technology is used effectively to analyse relevant content to assess whether it is intimate image abuse content.
ICS C8.4 The provider should:
ICS C8.5 For the purposes of ICS C8.3, the provider should ensure that:
ICS C8.6 For the use of perceptual hash matching technology to be effective, it should:
The set of hashes¶
ICS C8.7 For the set of hashes to be appropriate, it should include hashes of intimate image abuse content that meet the requirements set out in ICS C8.9 and sourced from either (or both) of the following:
ICS C8.8 Where the set of hashes includes hashes of intimate image abuse content sourced from the provider’s own database in accordance with ICS C8.7(b), the provider should ensure that:
ICS C8.9 The requirements are that the provider or the person(s) maintaining the database has arrangements in place:
ICS C8.10 The provider should ensure that where the set of hashes includes hashes of intimate image abuse content sourced from a person in accordance with ICS C8.7(a) and ICS C8.9, the latest versions of any databases sourced are regularly obtained and then used for the purposes of ICS C8.3.
ICS C8.11 The provider should ensure an appropriate policy is put in place, and that measures are taken in accordance with that policy, to secure any hashes of intimate image abuse content held for the purposes of this Recommendation ICS C8 from unauthorised access, interference or exploitation (whether by persons who work for the provider or are providing a service to the provider, or any other person).
Technical configuration¶
ICS C8.12 In configuring the technology so that its performance strikes an appropriate balance between precision and recall, the provider should ensure that the following matters are taken into account:
available to the provider about the prevalence of relevant content that is intimate image abuse content on the service;
ICS C8.13 The provider should ensure that the performance of the technology, and whether the balance between precision and recall continues to be appropriate, is reviewed at least every six months.
ICS C8.14 The provider should ensure that a written record is made of how this balance has been struck in configuring the technology, including what information has been considered, and information about reviews and steps taken in response.
Safeguards for freedom of expression and privacy¶
ICS C8.15 Paragraphs ICS C8.6 to ICS C8.14 of this Recommendation ICS C8 are safeguards to protect United Kingdom users’ and interested persons right to freedom of expression and the privacy of United Kingdom users and interested persons.
ICS C8.16 The following measures are also safeguards to protect United Kingdom users’ and interested persons’ right to freedom of expression and the privacy of United Kingdom users and interested persons:
D Reporting and complaints¶
ICS D1 Enabling complaints¶
Application¶
ICS D1.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS D1.2 The provider should have systems and processes which enable prospective complainants to make each type of relevant complaint in a way which will secure that the provider will take appropriate action in relation to them.
ICS D2 Having easy to find, easy to access and easy to use complaints systems and processes¶
Application¶
ICS D2.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS D2.2 The systems and processes referred to in ICS D1.2 should be operated to ensure that:
ICS D2.3 In designing the systems and processes referred to in ICS D1.2, including its reporting tool or function, the provider should consider the accessibility needs of its United Kingdom user base having regard to:
ICS D2.4 For the purposes of ICS D2.3(d), the systems and processes referred to in ICS D1.2 should be designed for the purposes of ensuring usability for those dependent on assistive technologies including:
ICS D3 Appropriate action – sending indicative timeframes¶
Application¶
ICS D3.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS D3.2 The provider should acknowledge receipt of each relevant complaint and provide the complainant with an indicative timeframe for deciding the complaint.
ICS D3.3 ICS D3.2 does not apply if:
ICS D4 Appropriate action – sending further information about how the complaint will be handled¶
Application¶
ICS D4.1 This measure applies to a provider in respect of each service that is likely to be accessed by children it provides that is either (or both) of the following:
Recommendation¶
ICS D4.2 In the acknowledgment of receipt of each relevant complaint, referred to in Recommendation ICS D3, the provider should set out:
ICS D5 Opt-out from communications following a complaint¶
Application¶
ICS D5.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS D5.2 The provider should enable the complainant to opt out of receiving any non-ephemeral communications in relation to a relevant complaint.
ICS D6 Appropriate action for relevant complaints about suspected illegal content¶
Application¶
ICS D6.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS D6.2 When the provider receives a relevant complaint about search content which may be illegal content:
ICS D6.3 ICS C6.2 does not apply to a complaint identified as manifestly unfounded in accordance with ICS D12.2.
ICS D7 Appropriate action for relevant complaints which are appeals – determination (large general or multi-risk services)¶
Application¶
ICS D7.1 This measure applies to a provider in respect of each service it provides that is either (or both) of the following:
Recommendation¶
ICS D7.2 The provider should determine relevant complaints which are appeals.
ICS D7.3 The provider should, as a minimum, monitor its performance against performance targets relating to the following:
and should resource itself so as to give effect to those targets.
ICS D7.4 The provider should have regard to the following matters in determining what priority to give to review of a relevant complaint which is an appeal:
ICS D8 Appropriate action for relevant complaints which are appeals – determination (services that are neither large general nor multi-risk)¶
Application¶
ICS D8.1 This measure applies to a provider in respect of each service it provides that is neither a large general search service nor a multi-risk service.
Recommendation¶
ICS D8.2 The provider should determine relevant complaints which are appeals promptly.
ICS D9 Appropriate action for relevant complaints which are appeals – action following determination¶
Application¶
ICS D9.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS D9.2 If, in relation to a relevant complaint that is an appeal, the provider reverses a decision that search content was illegal content, the provider should:
ICS D10 Appropriate action for relevant complaints about proactive technology, which are not appeals¶
Application¶
ICS D10.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS D10.2 This Recommendation ICS D10 applies to relevant complaints, which are not appeals, about the use of proactive technology on the service when:
ICS D10.3 The provider should inform the complainant of the action the provider may take in response to the complaint.
ICS D10.4 ICS D10.3 does not apply to a complaint identified as manifestly unfounded in accordance with ICS D12.2.
ICS D11 Appropriate action for all other relevant complaints¶
Application¶
ICS D11.1 This measure applies to a provider in respect of each service that it provides.
Recommendation¶
ICS D11.2 This Recommendation ICS D11 applies to relevant complaints that the provider is not complying with:
ICS D11.3 The provider should nominate a responsible individual or a team to ensure that such complaints are directed to an appropriate individual or team to be processed.
ICS D11.4 Relevant complaints should be handled:
ICS D11.5 ICS D11.3 and ICS D11.4 do not apply in relation to a complaint identified as manifestly unfounded in accordance with ICS D12.2.
ICS D12 Exception: manifestly unfounded complaints¶
Application¶
ICS D12.1 This measure applies to a provider in respect of each service that it provides.
Recommendation¶
ICS D12.2 When the provider receives a relevant complaint that is not an appeal, it may disregard the complaint only if:
ICS D12.3 In designing a policy for the purposes of ICS D12.2(a), the provider should have regard to:
ICS D12.4 The provider should, at minimum, carry out an annual review of the policy to ensure it is not incorrectly identifying relevant complaints as manifestly unfounded.
ICS D12.5 If the policy is incorrectly identifying relevant complaints as manifestly unfounded, the provider should make changes to it with a view to ensuring its accuracy.
ICS D12.6 The provider should keep a record of its review process and any changes it has made.
ICS D13 Dedicated reporting channel for trusted flaggers to report fraud¶
Application¶
ICS D13.1 This measure applies to a provider in respect of each service it provides that is a large general search service and is at medium or high risk of fraud.
Recommendation¶
ICS D13.2 In this Recommendation ICS D13, a ‘recommended trusted flagger’ is each of the following:
ICS D13.3 The provider should establish and maintain a dedicated reporting channel for, at minimum, the recommended trusted flaggers, and relating to, at minimum, fraud, in the circumstances set out in this Recommendation ICS D13.
ICS D13.4 The provider should publish a clear and accessible policy on its processes relating to the establishment of a dedicated reporting channel for, at minimum, the recommended trusted flaggers, covering any relevant procedural matters.
ICS D13.5 If a request is made in accordance with the policy by a recommended trusted flagger, the provider should ensure a dedicated reporting channel, run in accordance with ICS D13.3 to ICS D13.8, is made available and maintained for, at minimum, recommended trusted flaggers. The provider may make an existing dedicated reporting channel available to the recommended trusted flagger, if that dedicated reporting channel is run in accordance with ICS D13.3 to ICS D13.8.
ICS D13.6 The provider should engage with the recommended trusted flagger at the start of the relationship to understand the recommended trusted flagger’s needs with respect to the dedicated reporting channel.
ICS D13.7 At least every two years, the provider should seek feedback from, at minimum, the recommended trusted flaggers with which it has made such arrangements, on whether any reasonable adjustments or improvements might be made to the operation of the dedicated reporting channel.
ICS D13.8 ICS D13.9 applies where the provider receives a complaint from a trusted flagger through a dedicated reporting channel established for that trusted flagger if the complaint:
ICS D13.9 The provider should treat the complaint as reason to suspect that the search content may be illegal content and review the search content in accordance with Recommendation ICS C1.
E [Not used]¶
[Intentionally left blank]
F Settings, functionalities and user support¶
ICS F1 Reporting and removal of predictive search suggestions¶
Application¶
Recommendation¶
ICS F2 Provision of CSAM content warnings¶
Application¶
ICS F2.1 This measure applies to a provider in respect of each large general search service it provides.
Recommendation¶
ICS F2.2 The provider should use systems and processes to detect and provide warnings in response to search requests made by United Kingdom users where:
Warnings should not be provided in response to search requests using terms which, on their face, do not relate to CSAM.
ICS F2.3 A warning should:
The information referred to in paragraph (c)(i) should be comprehensible and suitable in tone and content for as many United Kingdom users as possible, including children.
ICS F2.4 An appropriate list of search terms that meet the description in ICS F2.2 should be developed and maintained by, or sourced from, a person with expertise in the terms commonly used to search for CSAM.
ICS F2.5 The provider should ensure that there are arrangements in place to ensure (so far as possible) that:
ICS F3 Provision of suicide and self-harm crisis prevention information¶
Application¶
ICS F3.1 This measure applies to a provider in respect of each large general search service it provides.
Recommendation¶
ICS F3.2 The provider should use systems and processes to detect, and provide crisis prevention information in response to, search requests made by United Kingdom users that contain:
ICS F3.3 The crisis prevention information should:
G Publicly available statements¶
ICS G1 Publicly available statements: substance (all services)¶
Application¶
ICS G1.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS G1.2 The provider should include the following in the publicly available statement:
ICS G2 Publicly available statements: substance (Category 2A services)¶
Application¶
ICS G2.1 This measure applies to a provider in respect of each Category 2A service it provides.
Recommendation¶
ICS G2.2 The provider should summarise the findings of its risk assessment (including as to levels of risk and as to the nature, and severity, of potential harm) in the publicly available statement.
ICS G3 Publicly available statements: clarity and accessibility¶
Application¶
ICS G3.1 This measure applies to a provider in respect of each service it provides.
Recommendation¶
ICS G3.2 The provider should ensure that the provisions included in the publicly available statement in accordance with Recommendation ICS G1 are:
Section 5 Definitions and interpretation¶
Table B - Terms used in these Codes that have the meaning given in the Act¶
Risks of illegal harm¶
Risk of a kind of illegal harm¶
a) the risk assessment of the service identified a medium or high risk2 (as the case may be) in relation to the offences (taken together) specified in relation to that kind of harm in table C; or b) by virtue of a confirmation decision given under section 134 of the Act in relation to a risk of serious harm, the duty set out in section 27(2) of the Act applies in relation to the service as if an illegal content risk assessment carried out by the provider pursuant to section 26 of
2 Ofcom has given guidance on risk assessments entitled ‘Risk Assessment Guidance and Risk Profiles’ (16 December 2024).
the Act had identified a medium or high risk of serious harm (as the case may be) in relation to that kind of harm.
Multi-risk services¶
a) from such time as the average number of monthly active United Kingdom users is more than that number; and b) until such time as the average number of monthly active United Kingdom users has been at or below that number for a continuous period of six months.
a) the six-month period ending with the month preceding the time in question; or b) where the service has been in operation for less than six months, the period for which the service has been in operation.