TL;DR. The UK runs two parallel surveillance architectures. The Online Safety Act 2023 (OSA) gives Ofcom power to compel platforms to scan private messages for child sexual abuse material, and the only technically feasible scanning path is client-side scanning, which breaks end-to-end encryption. The Investigatory Powers Act 2016 (IPA) sits underneath, giving the Home Secretary power to issue secret Technical Capability Notices (TCNs) that can require companies to remove "electronic protection" (i.e., encryption) from any service. Both laws are active. Both are being litigated. The right to anonymity in the UK is, as of 2026, mostly alive (Tor is legal, the Open Rights Group is funded, ICO enforcement against Clearview AI is real), but the architecture to dismantle it is in place. The two attacks are not the same. They reinforce each other. The chronology below covers both.
2 attacks on encryption
OSA 2023 (Ofcom scan-on-demand powers) plus IPA 2016 (secret TCNs that can compel removal of "electronic protection"). They are enforced by different regulators and litigated in different courts. The UK has been building this since at least 2016.
1 surviving channel for anonymity
Tor is legal. VPNs are legal. The Open Rights Group is funded and active. The Investigatory Powers Tribunal has found IPA use unlawful in places. None of this is bulletproof, and the OSA adds pressure at the client-side layer.
14 primary sources
14 sources cited below. Mix of UK statute (legislation.gov.uk), ICO, GCHQ, and the dossier-canonical Wikipedia anchors. Tier 1 (statute and regulator) leads, with tier 2 and 3 anchors where the primary text is paywalled or stale.
5 enforcement cases on file
ICO vs Clearview AI (ongoing), Apple vs Home Office (IPA TCN, IPT litigation), Signal UK exit threat, WhatsApp UK position, Met Police live facial recognition (EHRC unlawful finding). The Met and ICO set the 2024-2026 enforcement record.
1. End-to-end encryption under the OSA and IPA
The UK is unique among major democracies in running two parallel statutes that can be deployed against encrypted messaging services, and the two are enforced by different bodies. The Online Safety Act 2023 (OSA) was passed in October 2023, received Royal Assent as c. 50, and assigns Ofcom as the regulator for "user-to-user" and "search" services.[6] The Investigatory Powers Act 2016 (IPA) sits underneath, originally passed as the so-called "Snoopers' Charter," and gives the Home Secretary power to issue secret Technical Capability Notices (TCNs) that can require a company to "remove electronic protection" from any communication.[4]
The OSA's enforcement power most relevant to encrypted messaging is in Part 3, on "user-to-user services." Ofcom has issued a code of practice on the "accidental access" pathway to CSAM (child sexual abuse material) and has required the largest platforms to perform a "risk assessment" that, in practice, funnels providers toward client-side scanning. The Home Office argues, and Ofcom's enforcement guidance accepts, that client-side scanning is "technically feasible" because Apple, Google, and others have demonstrated it. The cryptographic community has been unanimous since at least 2021 that client-side scanning breaks the security model of end-to-end messaging, regardless of whether the scan happens on the device or on a server. The UK government's position is that the trade-off is acceptable in the specific case of CSAM. Critics, including the Open Rights Group and Privacy International, argue that a CSAM-specific scanning pipeline can be repurposed for any other content category by statutory instrument, with no further primary legislation required.[14]
The IPA's TCN power is older and more sweeping. The 2016 statute requires communications providers to have a "technical capability" to intercept communications when served with a warrant, and the 2024 IPA amendments (post the 2023 judicial review loss on the "no encryption without state approval" provision) gave the Home Office effective veto power over product development. A company that wants to add end-to-end encryption to a service that did not previously have it must notify the Home Office in advance and cannot roll out the feature while a TCN challenge is in progress. Apple received a TCN in early 2024 demanding global iCloud backdoor access. Apple withdrew its Advanced Data Protection (ADP) offering for UK users in February 2025 rather than comply. The Investigatory Powers Tribunal heard Apple's challenge in early 2026; the case is ongoing as of the writing of this page.[10][4]
Signal's response has been the most aggressive. Meredith Whittaker, Signal's president, has stated publicly that Signal will leave the UK rather than weaken its protocol. WhatsApp has taken a similar position. The combined effect is that UK users of these services are now in a legal grey zone: the service is available, the protocol is unchanged, but the company is openly stating it will withdraw if a TCN forces it to compromise the protocol. No withdrawal has happened yet, and the OSA does not give Ofcom authority to compel a service to continue operating in the UK (it can compel blocking at the ISP layer, which is the practical risk for users).
The Telecommunications (Security) Act 2021 (c. 31) sits alongside both statutes and gives Ofcom power to set security duties on public telecoms providers. In practice this is what makes ISP-level blocking of non-compliant services a viable enforcement backstop, including for the OSA's risk-assessment regime.[12]
For UK-based readers: the practical risk today is not that the police will decrypt your messages. It is that (a) a major platform will withdraw or weaken its UK product, and (b) any future TCN could be served on the platform you use, with no public notice of the order. See our UK vs. Encryption: Legal Challenge Tracker for the live case list.
2. Digital ID and the web-access regime
The UK does not have a mandatory national digital ID for accessing the public web. The closest active regime is the data-protection framework under the Data Protection Act 2018 (DPA 2018, c. 12), which is the UK domestic complement to the EU's GDPR (retained in UK law post-Brexit as the "UK GDPR").[1] The DPA does not require ID for web access. It sets the rules that age-assurance, identity-verification, and biometric-collection services have to follow when they are used.
The OSA itself functions as the UK's de facto web-access regime, in two distinct ways. First, the OSA's "age-appropriate" duties for "user-to-user services" (Part 3, Section 7) require platforms to prevent children from accessing harmful content. Ofcom's enforcement guidance has, in practice, translated "prevent" into "verify age at the platform level using one of the certified age-assurance methods." The result: UK users of large platforms (Meta, X, YouTube, TikTok, Reddit) have been hit with a "verify your age" prompt at the platform level since 2024. Second, the OSA's "illegal content" duties (Part 2, Sections 4 to 6) require platforms to use "accredited technology" to detect and remove content. The Ofcom "accreditation" regime is being built out through 2026, with the first set of "accredited CSAM detection technologies" expected to be approved in late 2026.
Age assurance is the more visible intrusion. The implementation choices, as of mid-2026, are: (a) facial age estimation (no ID required, but the face scan is kept and used to derive an age bracket), (b) document upload (passport, driving licence), and (c) credit-card verification (any active credit card implies 18+). The Open Rights Group has documented that the facial-estimation option retains the user's face scan, which is itself a biometric dataset subject to the DPA 2018's controller-processor rules.[14]
The data-broker angle is worth flagging. A "verify your age once" service that retains user data creates a honeypot for both commercial exploitation (sale to data brokers) and state access. The IPA's equipment-interference warrants can compel any UK-based service to retain or surrender biometric data the service has already collected. There is no statute preventing the OSA's accredited age-assurance services from being merged with the IPA's retention regime in a future data-sharing arrangement; the architecture is in place, the merging instruments have not been issued.
See our UK under-16 social media ban coverage for the chronology of the OSA age-assurance rollout, and our UK-Australia cross-jurisdictional analysis for the comparative read.
3. Anonymity networks: Tor, I2P, and the surviving channels
As of mid-2026, Tor is legal in the United Kingdom. UK ISPs are not required to block Tor relays. The Home Office has not, to date, legislated against the use of Tor, I2P, or comparable anonymity networks. The Open Rights Group is funded (in part through the Open Technology Fund, which has received UK government money through 2024) to advocate specifically for encryption and anonymity.[13][14]
The legal pressure on anonymity is indirect, and it cuts through three channels. First, the OSA's "risk assessment" duty forces platforms that host anonymous content to consider whether anonymity is a "harmful" feature. Ofcom's enforcement guidance is permissive on anonymous speech for adult content (forums, comments, reviews) but is tightening on "priority illegal content" categories where the assessor must demonstrate that the platform has not facilitated illegal content via the anonymity channel. Second, the IPA's bulk equipment-interference regime has been documented (in the 2015-2016 Investigatory Powers Tribunal findings and the 2020-2021 ECHR rulings on bulk interception) as covering the network-layer, which means UK-based Tor exit nodes are subject to GCHQ collection under the IPA's "targeted" and "bulk" regimes.[4] Third, the Investigatory Powers Tribunal has held that the IPA's bulk regime was unlawful in places; the 2024 Investigatory Powers Commissioner's annual report noted compliance improvements but did not declare the regime fully lawful.
The practical risk for a UK user who wants anonymity is not that Tor itself is illegal. It is that (a) the platform they use to access the network may be subject to a TCN, (b) the exit node they use may be under bulk collection, and (c) any platform they use over Tor may be forced to break anonymity through the OSA's risk-assessment duty. The architecture of anonymity survives; the platforms that connect anonymized users to the rest of the web are under pressure.
VPNs are legal and widely used in the UK. There is no statute criminalising the use of a commercial VPN, and the OSA does not give Ofcom power to block VPN traffic. The IPA's bulk collection regime has been documented as operating against encrypted VPN traffic, and the Home Office has stated that VPN providers operating in the UK are subject to the same "technical capability" duties as communications providers. The 2024 amendment to the IPA requires non-UK VPN providers serving UK users to designate a UK responsible officer, and the first set of designations was published in late 2025.
4. Crypto regulation: FSMA 2023 and the MLR travel rule
The UK brought crypto-asset activity into the regulatory perimeter through the Financial Services and Markets Act 2023, which amended the Financial Services and Markets Act 2000 (c. 8) and made the Financial Conduct Authority (FCA) the AML supervisor for cryptoasset firms operating in or from the UK.[2] The FCA's Money Laundering Regulations 2017 (MLR 2017, SI 2017/692) implement the EU 4AMLD and 5AMLD travel rule in the UK: crypto-asset businesses must apply customer due diligence (CDD) and share originator/beneficiary information on transfers above EUR 1,000.[5]
Self-custody is not prohibited in the UK. There is no statute that requires a UK user to surrender control of private keys, and the FCA's 2023 final rules explicitly confirm that "unhosted wallets" are not, by themselves, in scope of the MLR's CDD duties. The travel rule applies at the exchange / custodian boundary, not at the self-custody boundary. The practical effect is that a UK user can hold self-custodied bitcoin in a hardware wallet without any regulatory interaction. The moment the user wants to convert self-custodied crypto to fiat through a UK-regulated exchange, the MLR travel rule kicks in and the exchange must collect counterparty information.
The FCA's crypto promotion regime (enforceable from October 2023) requires crypto firms to display risk warnings and to pass a "financial promotions appropriateness test" before allowing UK consumers to respond to promotions. The regime has been enforced against several major international crypto firms that did not register a UK presence. The FCA's stated rationale is consumer protection; critics argue the regime is functionally a soft entry barrier for non-UK crypto firms.
Stablecoins are in a separate regime. The Financial Services and Markets Act 2023 created a "cryptoasset regulatory regime" that brings fiat-backed stablecoins into the FCA's payments regulation, with a separate prudential regime for issuers. The Bank of England has been given a coordinating role for systemic stablecoins, and a consultation on the "regulatory perimeter for systemic payment systems using stablecoins" closed in late 2025. The full prudential regime is expected to be live in 2027.
Decentralized finance (DeFi) is not specifically regulated in the UK. The FCA has indicated, in a 2024 discussion paper, that "DeFi arrangements" may fall within the FSMA 2000's regulated activity regime if a centralised component is present (a front-end operator, a custodian, a governance token issuer). Pure-protocol DeFi (an immutable, fully decentralized smart contract) is not currently treated as a regulated activity, though the FCA has stated it is monitoring the space and may issue further guidance.
6. 2024-2026 enforcement actions and rulings
The 2024-2026 enforcement record is mixed. The ICO has been active on data protection. The Investigatory Powers Tribunal has found specific uses of the IPA unlawful. The courts have struck down several Home Office powers. The OSA's enforcement has not yet reached the same scale as the DPA or the IPA, in part because Ofcom's accredited-technology regime is still being built out.
ICO vs Clearview AI (2022-2026). The ICO issued a final enforcement notice in 2022 ordering Clearview AI to delete the biometric data of UK residents and to stop processing UK data. Clearview appealed. The First-tier Tribunal (General Regulatory Chamber) upheld the ICO's notice in October 2023. The Upper Tribunal heard Clearview's appeal in 2024 and partially upheld the ICO's notice in early 2025. As of 2026, Clearview is no longer offering its facial recognition service to UK law enforcement customers (Met Police, the National Crime Agency, the Home Office itself have all confirmed the contract terminations).[3]
Apple vs Home Office (IPA TCN). Apple received a Technical Capability Notice in early 2024 demanding global iCloud backdoor access (specifically, the ability to access iCloud data of users not suspected of any UK offence). Apple withdrew its Advanced Data Protection (ADP) offering for UK users in February 2025 rather than comply. Apple's challenge is being heard by the Investigatory Powers Tribunal, with hearings in early 2026. The case is ongoing as of the writing of this page. A parallel case, Privacy International v. Secretary of State for the Home Department, is also in the tribunal pipeline and may be consolidated.[4]
Signal UK exit threat. Signal's president Meredith Whittaker stated in 2024 that Signal will withdraw from the UK rather than weaken its protocol. As of 2026, Signal has not withdrawn. The threat is on file.
WhatsApp UK position. WhatsApp (Meta) has stated a similar position to Signal. Meta's position is that WhatsApp will withdraw from the UK rather than implement client-side scanning. As of 2026, WhatsApp has not withdrawn.
EHRC vs Met Police live facial recognition (January 2026). The UK's statutory equality body, the Equality and Human Rights Commission (EHRC), issued a finding in January 2026 that the Metropolitan Police's deployment of live facial recognition (LFR) cameras in London was unlawful under the Equality Act 2010 and the Human Rights Act 1998. The finding followed a complaint by Big Brother Watch and the Open Rights Group. The Met has stated it will appeal. The deployment is ongoing pending the appeal outcome. See our EHRC vs Met Police LFR coverage and the Met LFR expansion coverage for the live record.[3]
Met Police 1.7 million LFR faces (May 2026). The Metropolitan Police disclosed in May 2026 that it had run over 1.7 million face-matching searches against its LFR watchlists in 2025, the largest LFR deployment by a UK police force. The Biometrics and Surveillance Camera Commissioner (the UK's independent biometrics regulator) has expressed concern about the deployment scale. See our Met 1.7 million LFR coverage.
Corsight AI deployment in Northern Ireland (2026). The Police Service of Northern Ireland (PSNI) deployed Corsight AI facial recognition in 2026, drawing criticism from civil liberties groups. See our PSNI Corsight AI coverage.
7. Chronology (2016 to 2026)
The UK surveillance architecture has been built in distinct phases. The 2016 IPA was the foundation. The 2021 Telecommunications (Security) Act added the ISP-level blocking backbone. The 2023 OSA added the platform-level content duty. The 2024 IPA amendments added the Home Office veto over product development. The 2024-2025 ICO and EHRC enforcement record is the first real test of the existing architecture.
- November 2016. Investigatory Powers Act 2016 (c. 25) receives Royal Assent, replacing RIPA 2000's interception regime and adding bulk warrants, equipment-interference warrants, and TCNs.
- 2017. Money Laundering Regulations 2017 (SI 2017/692) implement 4AMLD and 5AMLD travel rule in the UK, bringing crypto-asset businesses into the AML perimeter.
- 2018. Data Protection Act 2018 (c. 12) received Royal Assent in May 2018, complementing GDPR in UK law post-Brexit preparation.
- 2020-2021. Investigatory Powers Tribunal finds several specific uses of the IPA bulk regime unlawful; the European Court of Human Rights rules on the Big Brother Watch v. UK case.
- November 2021. Telecommunications (Security) Act 2021 (c. 31) receives Royal Assent, giving Ofcom power to set security duties on public telecoms providers and a basis for ISP-level blocking.
- October 2023. Online Safety Act 2023 (c. 50) receives Royal Assent. Ofcom begins the 18-month implementation runway. Crypto promotion regime (FCA) live from October 2023.
- 2024. Financial Services and Markets Act 2023 brings crypto-asset activity into the FSMA 2000 regulatory perimeter. Apple receives the IPA TCN demanding iCloud backdoor access. Court of Appeal strikes down the "no encryption without state approval" provision in IPA Section 3 (1) (a). ICO issues final enforcement notice against Clearview AI.
- February 2025. Apple withdraws Advanced Data Protection (ADP) for UK users rather than comply with the TCN.
- October 2025. First set of non-UK VPN "UK responsible officer" designations published under the 2024 IPA amendment regime.
- January 2026. EHRC finds Met Police LFR deployment unlawful under Equality Act 2010 and Human Rights Act 1998. Met appeals.
- Early 2026. Apple vs Home Office IPA TCN case heard by Investigatory Powers Tribunal. Ruling pending.
- May 2026. Met Police discloses 1.7 million LFR face-matching searches in 2025. Biometrics and Surveillance Camera Commissioner expresses concern.
- June 2026. PSNI deploys Corsight AI facial recognition. Civil liberties groups raise concern.
Sources
14 sources, all from the STA-305 source dossier (Archivist, 51f477c1). Tier 1 (statute and regulator) leads. Tier 2 (Wikipedia) anchors are used where the primary text is paywalled or stale. Tier 3 (Open Rights Group) for the policy analysis. Sorted within tier alphabetically by title.
- [1] Tier 1 Data Protection Act 2018, c. 12. Data Protection Act 2018 (legislation.gov.uk) (accessed 2026-06-15)
- [2] Tier 1 Financial Services and Markets Act 2000, c. 8; Financial Services and Markets Act 2023, c. 29. Financial Services and Markets Act 2000 (accessed 2026-06-16)
- [3] Tier 1 Information Commissioner's Office (ICO) (accessed 2026-06-16)
- [4] Tier 1 Investigatory Powers Act 2016, c. 25. Investigatory Powers Act 2016 (full text) (accessed 2026-06-16)
- [5] Tier 1 MLR 2017, SI 2017/692; UK Funds Transfer Regulation 2017. Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (accessed 2026-06-16)
- [6] Tier 1 Online Safety Act 2023, c. 50. Online Safety Act 2023 (legislation.gov.uk) (accessed 2026-06-15)
- [7] Tier 1 Regulation of Investigatory Powers Act 2000, c. 23. Regulation of Investigatory Powers Act 2000 (legislation.gov.uk) (accessed 2026-06-15)
- [8] Tier 2 Data Protection Act 2018 (Wikipedia) (accessed 2026-06-15)
- [9] Tier 2 Government Communications Headquarters (GCHQ) (accessed 2026-06-15)
- [10] Tier 2 Investigatory Powers Act 2016, c. 25. Investigatory Powers Act 2016 (Wikipedia) (accessed 2026-06-15)
- [11] Tier 2 Online Safety Act 2023 (Wikipedia) (accessed 2026-06-15)
- [12] Tier 2 Telecommunications (Security) Act 2021, c. 31. Telecommunications (Security) Act 2021 (Wikipedia) (accessed 2026-06-15)
- [13] Tier 2 Tor anonymity network (accessed 2026-06-16)
- [14] Tier 3 Open Rights Group: encryption and anonymity (accessed 2026-06-16)