acthub.beta

OFCOM's guidance about transparency reports

universal formatas at 22 Jul 202577 references

OFCOM's guidance about transparency reports

Online Safety Transparency Reporting

Final Transparency Guidance

Published 21 July 2025
For more information on this publication, please visit ofcom.org.uk

Contents

Section

1. Overview ............................................................................................................................. 3
2. Background ......................................................................................................................... 4
3. How Ofcom determines what transparency reports should cover: principles and factors ......................................................................................................... 7
4. How Ofcom determines what transparency reports should cover: engagement ...................................................................................................................... 16
5. How information from providers’ transparency reports will be used to produce Ofcom’s transparency reports ........................................................................... 20
6. Compliance ....................................................................................................................... 24

Annex

A1. Matters about which information may be required ........................................................ 27

Section 1 Overview

Introduction

Ofcom is the United Kingdom’s (UK) communications regulator, overseeing sectors including telecommunications, post, broadcast TV, radio, and online services. We were appointed the online safety regulator under the Online Safety Act 2023 (“the Act”) in October 2023.
1.1 All online services within scope of the Online Safety regime must protect all UK users from illegal content and, where applicable, protect children from online harm. In addition, a small proportion of these services will be categorised and designated as category 1, 2A or 2B services if they meet certain thresholds set out in secondary legislation by Government.
1.2 Providers of categorised services will be required to comply with a range of additional requirements, largely focused on bringing an appropriate level of safety, transparency, and accountability to the online world, reflecting the nature of such services.
1.3 For transparency, providers will be required to publish annual transparency reports based on requirements that Ofcom will issue to service providers by notice. Ofcom must publish its own transparency report summarising industry trends and setting out good practice based on service transparency reports and any additional information, such as new research, to help contextualise those findings for the public.

Summary of the information in this document

1.4 Ofcom is required by the Act to produce guidance about the transparency reporting framework.1 This guidance document has been produced pursuant to that duty. Among other things, it will address: a) Ofcom’s approach to transparency reporting; b) how Ofcom will determine what information service providers should include in their transparency reports, including details about the principles and factors Ofcom will consider when deciding what should be included; c) how Ofcom will engage with service providers throughout each reporting cycle; d) how the information in services’ transparency reports will be used to produce Ofcom’s own transparency reports; and e) how providers are expected to comply with their duties in respect of transparency reporting.
1 Section 78(1) of the Act

Section 2 Background

Section 3 How Ofcom determines what transparency reports should cover: principles and factors

What this section covers

3.1 In this chapter we explain how we will use key principles to determine the information in a transparency notice.
3.2 We will always endeavour to engage with providers before we formally issue a transparency notice, so there are opportunities to ask questions about its contents or the process more generally. It is therefore important that providers understand our decision-making process so that they can make the most of that engagement process (which we discuss in more detail in the next chapter).

What we can require in reports: illustrative examples

3.3 As discussed in the previous chapter, the matters that Ofcom can require a user-to-user or search service to produce in its transparency report are listed in Schedule 8 to the Act. The Schedule covers a wide variety of matters relating to online safety, including in relation to the service itself (regarding its systems and processes, design, operation and user base), the incidence of regulated content on the service, and the safety measures adopted for the purpose of complying with certain duties in the Act, among other things. For ease of reference, we have reproduced the matters from Schedule 8 in the Annex to this Guidance.
3.4 In the table below, we set out a few illustrative examples of the information that we might request in our notices from user-to-user and search services by reference to some of the matters listed in Schedule 8.
Matter
Examples of types of information
The incidence of illegal content, content that is harmful to children, relevant content 19 and content to which section 15(2) applies on a service. 20
We may require information about how often
content appears on a user-to-user service that is
illegal or harmful to children. For instance, in
existing industry transparency reports, some
services report a variety of metrics relating to
incidence for content that violates the terms of
service, which together help build a picture of the
availability of this content on the service and how it
is tackled.
Matter
Examples of types of information
The incidence of illegal search content and
We may require information about how often search content that is illegal or harmful to children appears on a search service.
search content that is harmful to children on a
service.
The dissemination of illegal content, content that is harmful to children, relevant content and content to which section 15(2) applies by means of a service.
We may ask user-to-user services about
functionalities21 or systems on a service that affect
the dissemination of illegal content and content
harmful to children, such as the speed or breadth
with which illegal content and content harmful to
children is shared on the service before being
removed, or the speed of enforcement action. For
instance, some services report on average time
taken for a piece of content to be reviewed and/or
enforced after it received a user report.
We may also require information that helps us
understand the risks of cumulative harm to children
as a result of being repeatedly exposed to illegal
content and content harmful to children. An
example of this could be the average number of
individual pieces of content that are harmful to
children encountered by each unique user/account
within an agreed time period.
The number of users who are assumed to have encountered illegal content, content that is harmful to children, relevant content or content to which section 15(2) applies by means of the service.
We may require information about how many users have been exposed to illegal content and content harmful to children in a given period. For example, in existing industry transparency reports, some services use ‘prevalence’ or ‘violative view rate’ to show the percentage of views on the service which were of content that violates policies.
Matter
Examples of types of information
The systems and processes that a provider operates— (a) to direct users of the service to information about how they can protect themselves from harm in relation to illegal content and content that is harmful to children, and (b) to counteract or provide support to users of the service in relation to illegal content and content that is harmful to children present on the service.
We may ask for information that tells us about how
users engage with informational pages about safety
measures. For instance, we might ask for the
frequency of UK user visits to informational pages
such as terms of service, transparency reports, user
policies, or governance processes.
We may ask for information that tells us how
effective user reporting tools are for supporting
users against illegal content and content harmful to
children they may encounter on a service.
We may ask for the actions taken by a service,
including procedures to mitigate the risk of harm
arising from illegal content being encountered. This
can be either human or automated, or a
combination of the two, and include technology.
We may require information that tells us about the
accuracy of systems and processes for identifying
content that is illegal or harmful to children. For
instance, the proportion of content that was
incorrectly identified as violative of terms of service.
This may tell us about the effectiveness of content
moderation systems.
Functionalities designed to help users manage
We may ask for information that tells us about the functionalities search services offer to users to help manage risks relating to content that is harmful to children, for instance, content that promotes self harm or suicide. This could include information about safety settings for children or tools that enable users to have control over the search results children can view, and the take-up of these tools.
risks relating to search content that is harmful
to children—
In relation to a search service, a functionality
includes (in particular):
(a) a feature that enables users to search
websites or databases;
(b) a feature that makes suggestions relating
to users’ search requests (predictive search
functionality). 22
19 As defined in paragraph 41 of Schedule 8 to the Act. 20 Section 15(2) of the Act imposes a duty on Category 1 services to include in a service features which adult users may use or apply if they wish to increase their control over content, to the extent that it is proportionate to do so. This includes features that reduce the likelihood of the user encountering content or alert the user to content present on the service that is a particular kind of content.
21 “’functionality’, in relation to a user-to-user service, includes any feature that enables interactions of any description between users of the service by means of the service”. section 233(1) of the Act. Please refer to section 233(2) of the Act for a non-comprehensive list of user-to-user functionalities.

How Ofcom determines what to require in reports

The wider context

3.5 Ofcom has identified four key outcomes that we expect the overall implementation of the Act to achieve to ensure UK citizens are safer online. We will draw on these to help us prioritise what information we will require each year and for each service in the notices. To support our mission to ensure people in the UK are safer online, we are committed to an
22 Section 233(3) of the Act.
approach that, so far as possible: (i) strengthens safety governance in online services, (ii) ensures online services are designed and operated with safety in mind, (iii) gives greater choice for users so they may have more meaningful control over their online experiences, and (iv) promotes trust in services’ safety measures.23
3.6 To drive forward these aims, we will seek to deliver an effective transparency reporting regime that will drive improvements on services and empower UK users with information to live safer lives online. To achieve this in practice, we will need to ensure that through our notices, we are requiring information that is meaningful for our audiences.
3.7 We will draw on these four aims to help inform our priority areas for transparency reporting every year: they will direct our focus towards key risks, safety measures or governance practices. They will inform our efforts to shine a light on deficiencies or best practices from industry that can help drive improvements across the sector.

Our approach: Key principles and factors

3.8 Our approach for determining what user-to-user information or search engine information we will require each year, and for each service, will be guided by certain key principles: relevance, appropriateness and proportionality. We have identified these principles as important building blocks for delivering our transparency powers effectively.
3.9 Our aim is to ensure that the information we request is not only relevant to the service(s) in question, but also appropriate to ask for in the circumstances having regard to our strategic priorities. Our overall intention is for the reports produced by categorised services to be sufficiently tailored to ensure that they reflect the way in which each service is designed, used and operated, whilst also being sufficiently standardised to allow for meaningful comparison in certain areas.
3.10 As with all our work, we will act proportionately in our decision-making. In each case, we will only consider requesting information that is necessary for the purpose of helping us meet our aims and policy objectives, with the overall goal to protect UK citizens from harm online. We expect the information that we request to be targeted and effective for meeting relevant strategic objectives.
3.11 We also recognise that providers record information in different ways, and face different challenges in producing it to fit certain specifications, so will take steps to ensure that the requirements are not unduly onerous.
3.12 In applying these principles, we will always take account of at least the following factors, reflecting the requirements in paragraph 37 of Schedule 8 to the Act:24 a) the kind of service; b) the functionalities of the service; c) the number of users of the service; d) the capacity of the provider; e) the duties set out in Chapter 2 or 3 of Part 3, or Chapters 1 to 4 of Part 4 that apply in relation to the service (“the relevant duties”); f) the proportion of users of the service who are children.
23 See Figure 1, Roadmap in Ofcom's approach to implementing the Online Safety Act - Ofcom 24 See Chapter 2 for full discussion of the legal framework; in Annex 1 we reproduce the matters detailed in Schedule 8 to the Act for ease of reference.
3.13 While we may place more or less weight on any of these factors in a given case, none of the above takes precedence over others listed; we will look to consider them holistically. The discussion below explores how we will consider these factors and apply the principles discussed above.
3.14 The kind of service. To ensure that our assessment leads to requests that are appropriately tailored, we will consider whether the service is of a kind that gives rise to particular risks. Our understanding of the specific risks associated with a given kind of service will help us to narrow the topics of information that we require providers to report on and ensure the relevance of the information for the public. We will typically seek to prioritise requesting information about risks that are generated by the kind of service in question. One source of information that we will draw on is Ofcom’s risk profiles.25 The risk profiles are lists of risk factors that providers may consider for the purposes of conducting their own risk assessments.26 Service type is one of the factors considered in the risk profiles. However, we will also call on other sources of evidence about the relationship between the kind of service and risk of harm to inform our process. This might include third-party research, Ofcom research, or information published by services themselves. It could also include information from providers’ own risk assessments, where available. By way of example, Ofcom’s draft risk profiles presently consider the provision of “messaging services” as a risk factor for high severity harms such as CSEA, grooming and terrorism due to the nature of that service type.27 In considering what information we require a messaging service to produce in its transparency report, we would therefore prioritise information about the risk of these kinds of harms and relevant safety systems and processes.
3.15 Functionalities of the service. We will adopt a similar approach regarding the functionalities of the service. To understand how functionalities might affect risk, we will typically use findings from Ofcom’s registers of risk (for illegal offences and for content harmful to children), the associated risk profiles and available research, including Ofcom’s own and third-party studies. These findings will inform our understanding of how the functionalities on a given service generate certain risks, either independently or in combination with other factors, and guide our decision-making when we come to making requests in our notices. Generally, where we know that the functionalities on a given service are likely to generate specific risks of harm, we will prioritise asking for information about those issues, as well as any safety measures that might be particularly relevant to those issues. For example, Ofcom’s risk profiles consider livestreaming functionality as a risk factor for harms derived from specific terrorism offences. For a service that provides livestreaming as one of its many functionalities, we may therefore prioritise seeking information about the safety systems that service has in place for livestreaming and the effectiveness of those systems in mitigating the related risks.
3.16 The number of users on a service. Ofcom will consider the evidence available to us to understand how the number of active United Kingdom users on a service might affect the nature of risks posed by the service. First, we will seek to understand how the size of the user base interacts with other features, including the functionalities of the service, to affect risk. Based on this, we will tailor our requirements to prioritise information about risks that
25 Note that references to different “kinds” of service (such as this) include references to services grouped together for this purpose in Ofcom’s risk profiles: see section 236(4) of the Act. 26 See Appendix A of Ofcom’s illegal harms Service Risk Assessment Guidance. 27 See Appendix A of Ofcom’s illegal harms Service Risk Assessment Guidance
may be particularly prevalent based on the size of the user base and characteristics of the service.
3.17 Second, the safety systems that providers put in place for the purposes of making their services safer may differ considerably on account of the size of the user base at a given time. For instance, a service with a fast-growing user base may have semi-automated systems in place for risk detection and risk mitigation due to the initial scale of user-generated content present on the service. However, safety systems may need to change to deal with a change in the number of users, for example in cases where a service might experience a sudden increase in user numbers. We will generally look to ensure that the requests we make about safety systems and processes are relevant to the size of the service’s user base.
3.18 Third, we will have regard to changes in the size of the service’s user base over time. This will allow us to identify services that have a quickly expanding user base in the UK. Ofcom’s draft assessment of risks of illegal harm found that, “[a] fast-growing user base may negatively affect a service’s ability to moderate effectively, given the increased scale and sophistication of the moderation technologies and processes required to keep track of a fast-growing user base (particularly since the sources of risk, and kinds of harms on the service, can change quickly as the user base develops)”.28 Therefore, where we identify such services, we may include requirements in their notices to generate information about their governance systems and the safety measures that they have in place to protect their increasing number of UK users.
3.19 The proportion of users of the service that are children. We will take into account how the proportion of users that are children on a service might require us to tailor our information requirements. We will draw on various sources to understand where children in the UK are spending their time online, including the results of providers’ Child Access Assessments, Ofcom’s evidence base and external research. We may also consider information about how children interact with the services that they use to further refine any questions that we ask about the measures that services have in place to protect children. For services that have any child users on their service, we may ask questions specific to children, including any specific risks relevant to children, measures in place on the service to protect children and information that demonstrates how effective those measures are. Where a service has a significant proportion of children on their service, our transparency notices will typically require services to publish information about how they keep children safe, including detailed and specific information about relevant risks and safety measures.
3.20 The relevant duties. We will always take account of the relevant duties that apply to the service, specifically those falling within Chapter 2 or 3 of Part 3 or Chapters 1 to 4 of Part 4 of the Act. Broadly, the duties in Part 3 cover the illegal content safety duties (including those that target services likely to be accessed by children). These apply to all user-to-user services and search services respectively. Chapter 2 of Part 3 contains some additional duties that apply in respect of Category 1 services. Similarly, Chapters 1 to 4 of Part 4 cover a series of other duties that apply in respect of certain categorised services.29
3.21 In deciding what to request through transparency notices, we will be particularly mindful of the category within which a service falls and the duties that apply to the service as a
28 Volume 2: The causes and impacts of online harm – Ofcom, 2023, p.321. 29 The exception is Chapter 2 which relates to the reporting of CSEA content (and which applies more widely).
consequence. In our notices, we will not ask services to publish information about duties that it is not required to comply with. We recognise that, in some cases, services may be categorised or de-categorised during the reporting year (and that additional duties may apply for different periods of time). Where we ask for information or data relating to how a service is complying with such additional duties, we will only ask services to produce information about duties that the service must comply with at the time we issue the notice.
3.22 Our consideration of the duties of the service provider also concerns whether the service provider is required to comply with the protection of children duties. We might not ask service providers to report information about risks concerning content harmful to children, if they are not subject to the children’s safety duties, nor specific measures intended to mitigate these kinds of risks. However, we may ask for information about risks concerning illegal content that is harmful to children and adults. Where relevant, we may ask service providers not subject to the children’s safety duties about the processes that they have in place to prevent children from accessing their services. All service providers are required to comply with illegal content safety duties, so we will always retain the option to ask for information about how services are complying with these duties through our transparency notices.
3.23 The capacity of the service provider. When considering capacity, we are principally (though not exclusively) concerned with the providers’ financial resources and the level of technical expertise available, or which it is reasonable to expect would be available to the provider given its size and financial resources.30
3.24 In principle, we expect providers to have resources at their disposal to fulfil their transparency duties in a timely fashion. We will consider a service provider's capacity in developing our notices, but we do not anticipate that the absence of capacity on behalf of a service provider will be determinative of how we choose to frame our requests, particularly where the subject matter may be regarded as routine or typical in the circumstances. However, we recognise that cases may differ, and we will engage with providers during the draft notice process, discussed in the following chapter, to allow the opportunity for representations about the likely time, cost and effort to give effect to the proposals in the draft notices.

Other factors that will affect the design of transparency notices

3.25 Beyond the factors set out in the Act, there are two other factors that will affect the requirements included in transparency notices.
3.26 The first is Ofcom’s consideration of whether the information has already been provided or published by the service. We will take note of the information that services already include in their voluntary transparency reports and published reports required under other regulatory regimes. This may be used to inform considerations of what information is feasible for services to collect and where it may be useful to require UK-specific versions of data that has already been published.
3.27 The second is our consideration of how we can best use our powers to reveal patterns or trends derived from service transparency reports, with a focus on whether some information should be reported consistently over time and/or across the industry. We are required to summarise important patterns or trends that we have identified in our own
30 See section 236(1) of the Act (definition of “capacity”).
transparency report, which will draw upon this information. More information on this process is outlined in Chapter 5.
3.28 An important component of the decisions we make about our notices will therefore be whether we will require certain pieces of information to be reported consistently over time – what we are calling ‘core’ information requirements – or on a one-off basis, which might support our ability to establish patterns across the industry, but not across time.
3.29 The consistent reporting of information over time can support our efforts to provide users and the UK public with analysis of trends in industry safety performance. For instance, to shed light on the impact of dissemination of illegal content and content harmful to children on users of a service, we may ask for information about the number of users that are likely to have encountered illegal content and content harmful to children in consecutive notices. The publication of these metrics in continuous transparency cycles would allow Ofcom and other readers of the reports to reflect on changes in users’ exposure to risk over time and therefore to consider the potential reasons for such changes.
3.30 Not all information that we require services to publish in a notice will be “core” information. In our efforts to assess safety trends, we will seek to analyse trends across the industry as well as across time. To do this, there may also be some information that we wish to ask about on an ad-hoc basis: a “thematic” set of information requirements that focus on areas that Ofcom has identified based on its areas of regulatory focus each year. We may, for instance, seek to prioritise information around specific priority illegal harms for one reporting year, and the protection of children in another.
An example of thematic information requirements would be a focus on the efficacy of measures to address specific manifestations of CSAM across relevant services. We may ask for detailed information about the governance processes, internal KPIs or safety measure outcomes relating to this topic. Our consideration of services' functionalities and service type would help us to identify which services do and do not generate risks of CSAM and would therefore receive these additional information requirements.
3.31 These thematic requirements will enable Ofcom to compare different industry efforts on specific topics, whether a priority area of risk or a certain type of safety measure. We may also identify priority topics for focus based on extraneous or topical events, such as UK elections or terror incidents, that may warrant reporting.
3.32 We will require thematic information from a sub-set of service providers each year; this will not be optional. Relevant providers will be required to produce thematic information where it is included in their notice.
3.33 Focus areas may change annually and the information we require will be tailored to individual services and may differ in scope and scale. We will apply our principles and factors set out above when considering if we will require more detailed and specific information from some services over others. Depending on the focus area, some providers may be excluded from thematic reporting requirements in a given year if the focus area is not relevant to their service. We may require information on the specific focus area for just one reporting year, or several, depending on the specific nature of the topic and the information produced.
3.34 In addition to considering the value of information reported ad hoc or across time, we will also assess where there may be opportunities to ask for the same information across multiple services. Rather than enabling comparison over time, this kind of information
would enable comparisons across the industry. When we decide what information to require of services each year, we will therefore consider if it is possible to do so in a way that produces comparable information from different services or if that information needs to be bespoke to the specific service in order to remain appropriate and relevant.
3.35 Once we have settled on the substance and form of our requests, we will issue the provider with the draft notice(s) accordingly.
3.36 Ofcom will seek to announce its thematic focus each year alongside our plans for the reporting year, including any specific commitments for stakeholder engagement activities.

Confidentiality and commercial sensitivity

3.37 Ofcom may require information to be produced in a report in respect of a service that provider considers commercially sensitive or confidential for other reasons. Before deciding on whether to require such information to be published, Ofcom will provide an opportunity during the draft notice process to the provider to present any concerns arising out of such publication, including around the confidentiality of the information, and will take this into account when reaching a decision.
3.38 When considering any concerns, we will typically have to balance the provider’s concerns around publication, including possible harm to legitimate business interests, against the extent to which publication of the information is necessary to exercise our functions around transparency. In some cases, we may consider alternatives to our requested information, where appropriate, if the alternative information is sufficient, reasonable and meets our aims.

Section 4 How Ofcom determines what transparency reports should cover: engagement

4.1 In this chapter, we explain how Ofcom will deal with providers of services prior to issuing a formal transparency notice. We consider that timely and constructive engagement on these matters is essential to ensuring that the transparency reporting regime operates effectively.

Our approach

4.2 Ofcom will engage with providers during each transparency reporting cycle to inform decisions about information requirements and improve providers’ understanding of the transparency reporting regime. While we aim to be consistent about when and why we engage with providers, we may pursue different types of activities depending on the nature and depth of the discussion, whilst ensuring all providers are treated consistently. For example, we may offer in-person meetings to providers that have been newly categorised to ensure that they understand the full scope of their duties. For providers whose service/s have been categorised for some time, we may use lighter-touch modes of communication, including email correspondence.
4.3 There are some engagement activities that we plan to carry out in respect of each annual reporting cycle. In particular, before we formally give a provider a transparency notice, we will first issue it to them in draft form to allow the opportunity for representations to be made in respect of its requirements. We discuss more about the nature and purpose of this engagement below from paragraph 4.6.
4.4 As the transparency regime evolves, Ofcom will gather evidence about what types of transparency information are the most valuable for improving user safety in the UK. As our understanding develops, we will seek to build consistency into the design of transparency notices, where possible.
4.5 In cases where Ofcom does not know enough about how a particular service operates to inform our decisions about the contents of our notices, we may consider additional engagement to gather such information. Where appropriate, this might include the use of our statutory information gathering powers or voluntary engagement activities, such as publishing Calls for Input (CFIs) to seek input about the suitability of certain metrics.

Transparency notices: the engagement process

4.6 Once published, the register of categorised services will be updated at appropriate intervals, and this may result in Ofcom adding or removing services from the public register. Ofcom may contact providers that have been newly categorised, including for the first time, to inform them of any upcoming transparency notices that they may be required to comply with and to confirm that we hold all the correct contacts details for issuing notices.
4.7 Each year Ofcom will share with providers a draft transparency notice (or, where the provider provides more than one categorised service, drafts of the transparency notices),
containing the information Ofcom proposes to require services to produce in their transparency reports. This will offer the opportunity for providers to make written representations on the proposed information to be produced within the report before the notice is formally issued. Among other things, this process is intended to ensure the requests are clear, targeted and proportionate to the technical capabilities and capacity of the provider.
4.8 The process of issuing the draft notices through to final notices will be administered with the assistance of Ofcom’s Information Registry (‘the Registry’).31 The Registry supports project teams across Ofcom in issuing and coordinating information requests and responses. The process for issuing notices can be understood broadly as three steps:

Step 1 – Ofcom shares a draft notice

4.9 Prior to formally exercising its powers to issue a notice under the Act each year, Ofcom will send draft transparency notices to providers. Timings for this may differ between reporting periods and services, depending on various factors such as how we choose to stagger the notices, and the level of engagement that is required. The draft notice will set out Ofcom’s proposals for the information required, the format that the information needs to be published in, including a template where applicable, the proposed timescales the service will have to produce its report, and any other information about the matter of its publication.

Step 2 - Providers may make written representations in respect of the draft

4.10 Service Providers may make written representations on the proposed notice, including the matters we propose to include and the manner and format in which that information is required, including the template where applicable. Providers may also make representations on the proposed timescale they have to produce their report.
4.11 Ofcom will give due consideration to any written representations received on a draft notice. However, Ofcom will take the final decision on what the final notice information requirements will be.
4.12 Additionally, the provider may ask for clarifications on the information required. The draft notice will contain details on how providers should make their written representations.
4.13 Ofcom will expect to receive representations by the deadline set in the draft notice. We will consider all representations in the preparation of the final notice.

Step 3 - Ofcom formally issues the notice

4.14 We will formally issue the provider with their transparency notice after the representations process is completed. Once the notice has been formally issued, we do not expect to engage further with providers about the transparency notices or the contents of their report, because all such issues should have been resolved through the draft notice process. If we decide to make material changes to the final notice from the draft notice, we will include a covering letter outlining what changes we have made.
4.15 Ofcom may in certain circumstances decide to liaise with providers following the issuing of the final notice, for example for necessary clarifications or urgent extension requests. However, such engagement will be considered only where necessary and, on a case-by-case basis. If a provider cannot produce a report by the date set out in the final notice, they
31 Information requests from Ofcom: why you have one and what you need to do - Ofcom
should inform us immediately and explain why. Deadlines to produce a final report will have taken into account relevant written representations made in response to the draft notice and therefore will consider deadline extensions only where there is a good reason for doing so, like the unexpected absence of a key employee responsible for producing the required information, technical difficulties or other exceptional circumstances beyond the service provider’s control. Every extension request will be considered on its own merits.
4.16 The notices will be served on persons who are providers of the relevant regulated service(s) in accordance with the service requirements set out in the Act.32
4.17 Once all notices have been formally issued, Ofcom will communicate to the public an overview of the information we requested in our transparency notices. The document will also set out our expectations of what to expect in future transparency reports produced by service providers.

Engaging with non-platform stakeholders

4.18 Ofcom will endeavour to engage with non-platform stakeholders, such as civil society and researchers during each transparency reporting cycle to inform decisions about information requirements in notices and for the purposes of gaining feedback on our processes and our subsequent analysis. There are two points at which Ofcom will engage with non-platform stakeholders in each cycle: a) When developing transparency notices; b) When drafting and publishing Ofcom’s own transparency report.
4.19 We will aim to establish consistent, annual engagement activities where relevant, such as regular channels for engaging with stakeholders about Ofcom’s reports.
4.20 We will remain flexible to allow for ad-hoc engagement where more appropriate, for example to gather insights or expertise from stakeholders about a topical event or external development that may affect the design of our notices or our transparency reports. While we aim to be consistent about when and why we engage with stakeholders, we may pursue different types of activities depending on the nature and depth of the discussion.

Developing transparency notices

4.21 There are some engagement activities that we plan to carry out in respect of each annual reporting cycle. While we are drafting our notices, we are likely to engage with people who have expertise in our chosen thematic area to understand more about research that may have been undertaken on the topic, or to consider the experiences of those with lived experiences of relevant illegal offences or harms to children. We will also seek to engage with stakeholders where useful to inform the information that we will include in our transparency notices based on their expertise or to gain understanding about how we can make our reports useful for these audiences

Developing Ofcom’s own reports

4.22 While preparing Ofcom’s own transparency reports, we will engage with non-platform stakeholders to gather insights where they may inform Ofcom’s reports. This may include
32 Section 208(1)-(2) of the Act
engaging with organisations that can help us to ensure our reports are as accessible as possible, or research organisations that hold relevant contextual data or information.
4.23 We will proactively request feedback about our approach to transparency reporting through our programme of stakeholder engagement.

Section 5 How information from providers’ transparency reports will be used to produce Ofcom’s transparency reports

5.1 This chapter sets out detail about the transparency report that Ofcom must produce each year, which must be based on the information in providers’ transparency reports. This will always include a summary of conclusions drawn from provider transparency reports regarding any patterns or trends which we have identified as important to share along with a summary of measures which we consider to be good practice (but may cover other things too).33

Our approach

What we plan to achieve

5.2 While provider transparency reports will typically offer insight into how individual services address risks and mitigate harms on their services, Ofcom’s transparency reports will contextualise those findings, drawing out points of comparison between services and highlighting examples of best and poor practice for the wider industry.
5.3 In summarising patterns and trends in Ofcom’s annual transparency reports, including industry best practice, we will seek to meet two ambitions. The first is to encourage services to improve their safety systems and processes. We will hold services to account by commenting on gaps in their systems and processes and enable learning from practices across the wider industry. The second is to empower UK users with relevant and accurate information about risks and safety outcomes on services so that they can take informed decisions about how to live their lives online.

How we will get there

5.4 In putting together Ofcom’s transparency reports, we want to provide the general public and industry with information that is comprehensive, informative, and accessible. To deliver this, we focus on the following areas.
5.5 Converting data into insight: Ofcom’s reports will translate technical information in provider reports into accessible insights for users. Such insights will highlight the implications of reported data about risks and safety outcomes, so that users can make informed choices about the services they use. Once published, we may look to engage with expert organisations (among others) to ensure our report is properly understood and any improvements we can take forward for future reporting.
33 Section 159 of the Act.
5.6 Seeking comparability: We will seek to compare findings from provider reports to understand developments or concerns in trends across the industry. Ofcom’s reports will highlight patterns and trends from the information requirements explained in Chapter 3. The types of information published by services (core and thematic, comparable and bespoke – outlined from 3.28 to 3.32) will affect our approach to presenting and communicating our conclusions. Where information is comparable over time and/or across services, we will focus on identifying and presenting patterns and trends in our reports. Where information is not standardised in this way, we will present individual insights and seek to place them in the relevant context. We hope that through comparability, we can incentivise services to pursue self-improvements and demonstrate leadership in the industry around good safety practice on certain issues and areas. We may seek to make comparisons in the following ways within, and between services:
5.7 We may seek to compare how individual services are performing over time focusing on specific metrics or qualitative information, and providing commentary on the implications of those changes, or lack of, from one period to the next. This will enable us to identify benchmarks for good practice that are specific and relevant to the service in question. For example, we may monitor harm reduction metrics or changes to staffing. These comparisons would enable us to review service-specific context, considering the drivers of those changes and their implications relative to the size of the services and the level of risk to users. We may also seek to compare a metric or piece of information that has been reported across multiple services, where the same information has been required across the industry. Any longitudinal or comparative analysis over time or between services will take into account differences in how individual services report information, including variations in definitions and data collection methodologies. Shining a light on best practice and gaps in industry efforts: We will seek to identify examples of good practice and highlight the different approaches services can take to address various issues related to online safety, and the benefits and limitations of those approaches. By doing this, we hope to support services across the industry, including small and newly created services, to learn from the experiences of other companies. Our analysis will also seek to identify any gaps or deficiencies in industry or specific services’ efforts to protect UK users.
5.8 We will include the necessary information to contextualise our findings and mitigate the risk of misinterpretation where we draw out points of comparison between services.

The process

5.9 The process for analysing and producing Ofcom’s transparency reports can be understood broadly as these steps outlined in Figure 2.
Fig 2. The transparency reporting cycle
5.10 There will be some information that we choose to report on year on year to show changes or trends over time. This will be drawn from the “core” information requirements that we discuss in chapter three. We will seek to present our findings in a way that enables users to compare the safety actions and outcomes of different services, where possible.
5.11 Ofcom’s reports may also assess any “thematic” information published by service providers, as discussed in chapter three. This will enable us to draw out insights and best practices about certain risks or safety measures alongside a more general assessment of industry trends. Ofcom may choose to publish more than one report a year to serve these different purposes.
5.12 We will seek to communicate our proposed areas of focus for the year ahead of transparency reporting. This will give providers an idea of what kind of information they may be required to report on, and the issues Ofcom will be looking to shine a light on in its report for that year.
5.13 Ofcom will carefully consider the information we include in our annual report(s) and provider reports to ensure alignment with our overarching strategy for transparency reporting for that year. This will ensure that we can optimise the information in provider reports to support the thematic areas of focus in our transparency reports.

Sources of information for Ofcom’s reports

5.14 Ofcom will primarily use information from providers’ transparency reports to inform its own reports. However, we may also draw on information from other sources. This might include trends, insights, or data from third parties such as academics, independent research organisations and Ofcom’s own research.
5.15 Ofcom may also draw on information obtained through formal and informal information gathered from providers, including through our statutory powers to issue information notices and through broader engagement with stakeholders. Where such information has been gathered for a different purpose, we will engage with providers on this.
5.16 Where we draw on additional data or information sources for the purposes of producing Ofcom's transparency reports, we will ensure the information is accurate and all necessary caveats are clearly stated.
5.17 For any information provided to Ofcom in advance of publication of its transparency report that was not included in the providers' transparency report, Ofcom will have regard to the need to exclude from publication confidential matters in accordance with Section 164 of the Act. Ofcom will also consider the restrictions on disclosing information under section 393 of the Communications Act 2003.

Confidentiality and commercial sensitivity

5.18 In some cases, service providers may have submitted information to Ofcom that has not been formally requested and that is not intended for publication and may be considered by them as confidential. Ofcom is prohibited from disclosing information received from a business unless we receive consent from the relevant business or can justify the disclosure under section 393(2) of the Communications Act 2003. Therefore, if Ofcom were considering the disclosure of such information, we may engage directly with the relevant service provider about the proposed disclosure.34
34 Section 393(2) of the Communications Act.

Section 6 Compliance

6.1 Providers are required by the Act to meet the requirements of their transparency notice(s) and produce accurate and complete information in their reports. These duties are enforceable requirements under the Act.35 In this Chapter, we elaborate on our approach to compliance and enforcement.

Our approach

What we expect from service providers

6.2 Providers of services have a legal duty to produce a transparency report in accordance with the requirements of the notice and must ensure that the information in the report is complete and accurate. This is fundamental for ensuring Ofcom, users, industry, and other audiences of transparency reporting can rely on and make informed decisions from the information provided. Where we are concerned about potential non-compliance with the notice requirements, we will assess the issue in line with our Online Safety Enforcement Guidance36 and consider whether it is appropriate to take enforcement action in the circumstances.37
6.3 Ofcom may take enforcement action where a provider has failed to produce a transparency report, in relation to relevant service, or if it fails to: a) include information of a kind specified or described in the notice; b) produce the report in the format specified in the notice; c) submit the report to Ofcom by the date specified in the notice; and/or d) publish the report in the manner and by the date specified in the notice
6.4 Providers must produce their transparency reports in the number of working days set out in the final transparency notice.
6.5 To meet their duties under the Act, providers will need to produce a standalone transparency report which is separate to the other reports that they may have regulatory duties to produce, or voluntary reports that they may choose to produce. Providers can publish their transparency report alongside other reports on their website, but the transparency report submitted to Ofcom must be a standalone report.
6.6 Ofcom may also take enforcement action where a provider’s transparency report contains information which is not complete and/or accurate in all material respects.
6.7 Providers of services are responsible for ensuring the information included in their reports is complete and accurate, in line with their legal duties. Providers should conduct appropriate checks and governance processes to ensure that the report is properly reviewed and interrogated prior to submission to Ofcom and publication. This should
35 Section 131 of the Act lists the duties in section 77(3) and (4) as enforceable requirements. 36 Ofcom, ‘Protecting people from illegal harms online: Annex 11: Enforcement guidance (draft for consultation),’ (9 November 2023). 37 Ofcom’s enforcement powers are set out in Chapter 6 of Part 7 of the Act and enable us to enforce the duties and requirements applying to service providers and, where relevant, other persons or third parties.
include being signed off by an appropriately senior accountable person. Providers should consider the following prior to submission and publication of their reports: a) the level of detail they have provided in response to each request; b) whether they have sufficiently addressed all the requests in the notice; and c) the approach taken to quality assure information and data provided.
6.8 We are unlikely to accept failures by providers to comply with their duties either because of delays or failures to meet the requirements of our notices for reasons which could have been anticipated and prepared for in advance. For instance, through the engagement we have had with the relevant provider prior to issuing the transparency notice, we expect providers to take the appropriate steps to ensure they have the necessary resource and mechanisms to fulfil their transparency reporting duties in a timely and efficient manner.
6.9 If Ofcom is made aware that the information provided may be inaccurate or incomplete, either through our own checks or reported to us by the public, researchers, civil society organisations, journalists, and other audiences of the transparency reports, we may take enforcement action in response.

Enforcement action by Ofcom

6.10 Failure to comply with transparency reporting duties in the Act may result in Ofcom taking enforcement action. Our approach to enforcement action for non-compliance with transparency duties will be in line with the Act and our Online Safety Enforcement Guidance,38 which sets out how we decide whether to take enforcement action, and the processes that we would typically follow.
6.11 Where we consider that a service provider may not be meeting its obligations under the Act, we have a variety of tools available to us to drive change and improve compliance. These include opening an investigation and using our statutory powers under the Act to investigate whether a service provider has contravened its obligations and take a decision to that effect. In addition to these statutory powers, Ofcom also has a range of non-statutory tools which we may use in response to a potential compliance concern instead of opening an investigation. Ofcom’s Online Safety Enforcement Guidance provides more information on the action we can take should services fail to comply with their transparency duties.
6.12 Ofcom may take separate enforcement action in relation to one or more failures to comply with such a requirement(s) with powers to impose a penalty where it finds non-compliance. A penalty can be up to 10% of qualifying worldwide revenue or £18 million (whichever is greater).39 We can also require the provider to take steps to comply with the transparency duties or remedy the failure to comply with that duty.
38 Our Online Safety Enforcement Guidelines provide further information about the circumstances in which enforcement action may be applied to related entities. 39 Penalties will be determined and set in accordance with our Penalty Guidelines and will consider all the circumstances of the case and will take into account the potentially relevant factors set out in the Penalty Guidelines published in September 2017.
6.13 Where Ofcom takes enforcement action against a provider of a regulated service, these measures may, in certain circumstances, also be applied to any other entity related to the provider of the service or an individual controlling the provider of the service.40
40 Schedule 15 to the Act gives Ofcom powers to issue notices that may hold companies and individuals jointly and severally liable for a contravention. Our Online Safety Enforcement Guidelines provide further information about the circumstances in which enforcement action may be applied to related entities.

A1 Matters about which information may be required

A1.1 This Annex contains the list of matters in Schedule 8 to the Act about which kinds of information may be required about online safety matters from Category 1 and 2B user-to-user services (Part 1) and Category 2A search services (Part 2).41 There are special rules that apply to which of these kinds of information may be required of a combined service, depending on the parts of Ofcom’s register of categorised services it is listed under.42

Part 1. Matters about which information may be required: user-to-user part of service

1. The incidence of illegal content, content that is harmful to children, relevant content and content to which section 15(2) applies on a service. 2. The dissemination of illegal content, content that is harmful to children, relevant content and content to which section 15(2) applies by means of a service. 3. The number of users who are assumed to have encountered illegal content, content that is harmful to children, relevant content or content to which section 15(2) applies by means of the service. 4. The formulation, development, scope and application of the terms of service. 5. The systems and processes for users to report content which they consider to be illegal content, content that is harmful to children or relevant content. 6. The systems and processes that a provider operates to deal with illegal content, content that is harmful to children and relevant content, including systems and processes for identifying such content and taking it down. 7. Functionalities designed to help users manage risks relating to content that is harmful to children and relevant content. 8. Features, including functionalities, that a provider considers may contribute to risks of harm to individuals using the service, and measures taken or in use by the provider to mitigate and manage those risks. 9. The design and operation of algorithms which affect the display, promotion, restriction or recommendation of illegal content, content that is harmful to children, relevant content or content to which section 15(2) applies. 10. Measures taken or in use by a provider to comply with any duty set out in Chapter 2 or 4 of Part 3 or section 38 (including in particular measures that are described in a code of practice under section 41).
41 Parts 1 and 2 of Schedule 8to the Act. 42 Section 77(8) and (9) of the Act. If a combined service is both a Category 2A service and a Category 1 or 2B service, Ofcom may require the production of user-to-user information or search engine information or both. If a combined service is only a Category 2A service and not also a Category 1 or 2B service, then Ofcom may only require the production of search engine information.
11. Measures taken or in use by a provider to comply with the duty set out in section 64(1) (user identity verification). 12. Arrangements that a provider has in place for the reporting (in the United Kingdom or elsewhere) of content relating to child sexual exploitation and abuse, and measures taken or in use by a provider to comply with a requirement under section 66. 13. Measures taken or in use by a provider to comply with any duty set out in section 71 or 72 (terms of service). 14. Measures taken or in use by a provider to comply with any duty set out in section 75 (deceased child users). 15. The systems and processes by which a provider assesses the risk of harm to individuals from the presence of illegal content or content that is harmful to children— a) when the service is initially being designed or developed, b) when any further development or update to the service is being considered, and c) while the service is in operation. 16. The systems and processes that a provider operates— a) to direct users of the service to information about how they can protect themselves from harm in relation to illegal content and content that is harmful to children, and b) to counteract or provide support to users of the service in relation to illegal content and content that is harmful to children present on the service. 17. Co-operation by a provider with government, regulatory or other public sector bodies in the United Kingdom, in particular those involved in the enforcement of the criminal law. 18. Measures taken or in use by a provider to provide for a higher standard of protection for children than for adults. 19. Measures taken or in use by a provider to improve the media literacy43 of users, and an evaluation of the effectiveness of such measures. 20. Any other measures taken or in use by a provider which relate to online safety matters.

Part 2. Matters about which information may be required: search engine

21. The incidence of illegal search content and search content that is harmful to children on a service. 22. The number of users who are assumed to have encountered illegal search content or search content that is harmful to children. 23. The formulation, development, scope and application of the statements of policies and procedures mentioned in sections 27(5) and 29(5). 24. The systems and processes for users to report search content which they consider to be illegal content or content that is harmful to children, or other content which they consider breaches any statements of policies and procedures which have been made publicly available by the provider of a service.
43 See section 11 Communications Act 2003 for an explanation of media literacy in relation to Ofcom’s duties to promote media literacy.
25. The systems and processes that a provider operates to deal with illegal search content and search content that is harmful to children, including systems and processes for identifying such content and minimising the risk of those kinds of content being encountered by means of the service. 26. Functionalities designed to help users manage risks relating to search content that is harmful to children. 27. The design and operation of algorithms which affect the display, promotion, restriction or recommendation of illegal search content or search content that is harmful to children. 28. Measures taken or in use by a provider to comply with any duty set out in Chapter 3 or 4 of Part 3 or section 39 (including in particular measures that are described in a code of practice under section 41). 29. Arrangements that a provider has in place for the reporting (in the United Kingdom or elsewhere) of content relating to child sexual exploitation and abuse, and measures taken or in use by a provider to comply with a requirement under section 66. 30. Measures taken or in use by a provider to comply with any duty set out in section 75 (deceased child users). 31. The systems and processes by which a provider assesses the risk of harm to individuals from illegal search content or search content that is harmful to children— a) when the service is initially being designed or developed, b) when any further development or update to the service is being considered, and c) while the service is in operation. 32. The systems and processes that a provider operates— a) to direct users of the service to information about how they can protect themselves from harm in relation to illegal content and content that is harmful to children, and b) to counteract or provide support to users of the service in relation to illegal search content and search content that is harmful to children. 33. Co-operation by a provider with government, regulatory or other public sector bodies in the United Kingdom, in particular those involved in the enforcement of the criminal law. 34. Measures taken or in use by a provider to provide a higher standard of protection for children than for adults. 35. Measures taken or in use by a provider to improve the media literacy of users, and an evaluation of the effectiveness of such measures. 36. Any other measures taken or in use by a provider which relate to online safety matters.