Home › Blog

🔍 From RIPA to the Online Safety Act: different law, same risk pattern The UK’s Regulation

🔍 From RIPA to the Online Safety Act: different law, same risk pattern

The UK’s Regulation of Investigatory Powers Act (RIPA, 2000) taught us how wide powers plus thin safeguards can quickly lead to mission creep.
Councils used covert powers for minor offences. Police accessed journalists’ phone records. Courts later ruled parts of the bulk-interception regime unlawful.

Fast-forward: the Online Safety Act (2023) aims to make the internet safer, but it gives Ofcom sweeping authority to shape compliance through codes, guidance, and notices. The risk? Broad discretionary power can expand in practice, just as RIPA did.

Echoes of RIPA:
• Scope creep: “Serious threats” under RIPA became routine use. OSA’s broad “systems and processes” duties could do the same.
• Private communications: RIPA under-protected journalists’ data; OSA raises similar privacy and encryption concerns.
• Opaque implementation: RIPA’s safeguards only emerged after court challenges. OSA’s real-world rules will live in Ofcom codes still being drafted.

What good looks like this time:
1️⃣ Strict necessity and proportionality tests.
2️⃣ Real protections for encrypted and private communication.
3️⃣ Transparent, independent oversight of Ofcom’s powers.
4️⃣ Clear exemptions and redress for journalism and public-interest speech.

⚖️ Lesson: We don’t need to choose between safety and rights — but we do need tight statutes, transparent rules, and hard limits so today’s safeguards don’t become tomorrow’s overreach.

#OnlineSafetyAct#RIPA#Privacy#Encryption#TechPolicy#UKLaw#DigitalRights
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing