Online Safety Regulation Increases Privacy Risk: Evidence from the UK Online Safety Act
arXiv SecurityArchived Jun 08, 2026✓ Full text saved
arXiv:2606.05273v1 Announce Type: cross Abstract: Governments worldwide are increasingly regulating digital platforms to reduce online harms, particularly those affecting children. However, access restrictions can alter user behaviour and introduce new privacy and security risks. The UK Online Safety Act (OSA), passed in October 2023, illustrates this trend: it extends age-assurance and safety requirements to social media, search, and pornography services, and rolled out in phases. Ofcom's illeg
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Computers and Society
[Submitted on 3 Jun 2026]
Online Safety Regulation Increases Privacy Risk: Evidence from the UK Online Safety Act
Dhyey Mehta (University of Edinburgh), Eldar Jalilzade (Newcastle University), Maksim Kalameyets (Newcastle University), Rebecca Owens (Durham University), Marc Juarez (University of Edinburgh), Stergios Aidinlis (Durham University), Lei Shi (Newcastle University), Tuğrulcan Elmas (University of Edinburgh)
Governments worldwide are increasingly regulating digital platforms to reduce online harms, particularly those affecting children. However, access restrictions can alter user behaviour and introduce new privacy and security risks. The UK Online Safety Act (OSA), passed in October 2023, illustrates this trend: it extends age-assurance and safety requirements to social media, search, and pornography services, and rolled out in phases. Ofcom's illegal content enforcement duties came into force in March 2025, and mandatory age verification for adult content took effect in July 2025. This phased rollout enables real-time observation of behavioural responses to regulation. To address this, we analyse Reddit discourse across VPN and UK Politics communities and conduct a privacy-policy risk analysis of 69 unique VPN services.
We find that each of these three milestones produced significant stepwise increases in VPN-related discussion on Reddit: among UK-based users, posts and comments explicitly about VPN use in a regulatory or privacy context rose by +100%, +217%, and +415% respectively. UK Politics communities showed even larger effects, with OSA-related political discourse rising by +213%, +545%, and +464%, respectively, among UK-based users. UK VPN search interest on Google rose by +89% at the age-verification deadline. Users primarily framed this response around privacy, surveillance, and distrust of age-verification intermediaries rather than simple access-seeking. Demand increased across low, medium, and high-risk VPNs, but the proportional distribution remained broadly stable. These findings suggest that online safety regulation can create secondary privacy costs even when it does not disproportionately shift attention toward higher-risk providers.
Comments: 14 pages, 9 figures. Submitted to PoPETs 2027
Subjects: Computers and Society (cs.CY); Cryptography and Security (cs.CR)
Cite as: arXiv:2606.05273 [cs.CY]
(or arXiv:2606.05273v1 [cs.CY] for this version)
https://doi.org/10.48550/arXiv.2606.05273
Focus to learn more
Submission history
From: Dhyey Mehta [view email]
[v1] Wed, 3 Jun 2026 17:24:28 UTC (1,751 KB)
Access Paper:
HTML (experimental)
view license
Current browse context:
cs.CY
< prev | next >
new | recent | 2026-06
Change to browse by:
cs
cs.CR
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)