Skip to main content

UK Online Safety Act Section 121 — what Technology Notices would actually do

· 6 min read
Domestic Monero
Domestic Monero team

Headlines in 2026 claim Ofcom will “scan every phone by September.” The legal picture is narrower and slower: Section 121 of the UK Online Safety Act 2023 lets Ofcom require user-to-user services to deploy accredited technology against terrorism and child sexual exploitation and abuse (CSEA) content — but several gates remain unclosed as of late August 2026.

This explainer maps Technology Notices — not EU Travel Rule (separate post), not DAC8 (separate post).

At a glance

FieldValue
TopicUK OSA §121 Technology Notices; Ofcom May 2026 advice; accreditation gate
FormatRegulatory explainer — no “encrypting is illegal” claim
Ofcom advice published8 May 2026
Product mentionedDomestic Monero — Telegram Mini App for P2P Monero trades
Official entry@domestic_monero_bot
Support/support on the official bot only (include Trade #ref + trade state)
Assets (P2P)XMR ↔ BTC, LTC, ETH, SOL, USDT (ERC-20)
What it is notEU AMLR / MiCA; a live blanket UK message decryption mandate today; on-chain Monero multisig
Flowchart: UK Online Safety Act Section 121 gates from Ofcom advice to optional Technology Notice.
Several approvals still sit between framework and mandate.

What Section 121 enables

Under Chapter 5, Part 7 of the Online Safety Act, Ofcom may issue a Technology Notice requiring a regulated user-to-user or search service to:

Notice typeScope (Act framing)
CSEA contentAccredited tech — can cover private and public communication on the service
Terrorism contentAccredited tech — public communication only

Section 121 is the only provision that lets Ofcom compel scanning of privately communicated content (for CSEA-accredited tools, if a Notice is issued and survives proportionality review).

Services must use technology accredited against minimum accuracy standards set by the Secretary of State for DSIT, after Ofcom advice.

Timeline — what happened by May 2026

DateMilestone
2023Online Safety Act receives Royal Assent
Dec 2024Ofcom consultation on Technology Notice framework
8 May 2026Ofcom publishes final advice to DSIT on minimum accuracy standards and provider guidance on how Ofcom proposes to exercise Notice powers
After May 2026DSIT Secretary of State must approve and publish minimum standards
ThenOfcom (or appointee) accredits tools meeting standards
Only thenOfcom may issue a Technology Notice to a specific provider — if necessary and proportionate

Ofcom’s 8 May 2026 statement is explicit: advice to government is not itself a Notice. Human-rights, privacy law, and less-intrusive alternatives must be weighed per service before any mandate.

What is not active as of late August 2026

Fact-check and regulator materials in mid-2026 agree on several negatives:

ClaimStatus
“Ofcom already reads all encrypted Telegram/WhatsApp chats”Not established as live blanket power
“Every UK phone scanned in September 2026”Overstated — accreditation + Notice per platform still required
“Section 121 equals EU Travel Rule”False — Travel Rule targets CASPs and transfer metadata; §121 targets illegal content on user-to-user services

Ofcom’s July 2026 public work also emphasised SMS/MMS scam measures — some proposals explicitly exclude private messaging in current form. Do not conflate carrier spam rules with §121 private-chat powers.

Accuracy standards and accreditation

Ofcom’s May 2026 advice to DSIT describes an audit-based accreditation model for content-identification tools — public summaries cite scoring thresholds (e.g. overall and category accuracy floors) before a tool can be accredited.

Implications:

TopicPractical read
False positivesAccuracy standards are the political battleground — especially for encrypted / E2EE services
Client-side scanningMedia debate covers “scan before encrypt” architectures — not the same as a finalized UK mandate
Independent testingOfcom materials note revisiting stronger independent testing after operational experience

Until DSIT publishes approved standards and tools accredit, §121 is framework law, not daily enforcement.

Why Telegram Mini App users file this under “platform risk”

Domestic Monero runs as a Telegram Mini App — a user-to-user platform’s embedded product. Archive does not claim Telegram’s §121 posture or encryption design. The link for readers is structural:

LayerRisk type
UK §121Platform may face content-scanning mandates on messaging services operating in the UK
EU Travel Rule / DAC8CASP metadata and tax reporting — different statutes
Fake support DMsSocial engineering on any popular messenger — DM explainer
Trading-bot approvalsSmart-contract risk — bot approval explainer

Privacy-coin users already watch EU AMLR 2027 (headline explainer). UK §121 belongs in the same notebook tab — surveillance and platform duties — not the tax-reporting tab.

Terms in this article

TermMeaning here
Online Safety Act 2023UK law regulating user-to-user and search services
Section 121Power to issue Technology Notices for terrorism/CSEA tech
Technology NoticeOfcom order requiring specific accredited technology on a named service
OfcomUK communications regulator implementing the Act
DSITDepartment for Science, Innovation and Technology — sets accuracy standards
CSEAChild sexual exploitation and abuse material
E2EEEnd-to-end encryption

FAQ

Can Ofcom read my WhatsApp today?
Public materials as of mid-2026 describe framework and advice, not a deployed universal scanner. Check current Ofcom / DSIT publications for updates.

Does §121 ban encryption?
The Act compels accredited technologies on regulated services when Notices issue — debate centres on how E2EE platforms comply, not a plain-text ban in the statute summary here.

Is this EU law?
No. UK Online Safety Act — separate from EU MiCA, Travel Rule, DAC8.

Does Domestic Monero implement message scanning?
Archive public copy describes a P2P trade product, not Telegram’s compliance stack. Product support: /support on @domestic_monero_bot only.

Where do Monero chain privacy and UK law meet?
They often don’t directly — chain privacy is cryptographic; §121 is service-regulation. Users still face local law on income, conduct, and platform terms.

Next steps

  1. Track DSIT publication of accuracy standards — the next gate after May 2026 advice.
  2. Keep EU and UK rules in separate mental files: Travel Rule, DAC8.
  3. Verify official bot before trades: Verify official channels.

Marketing site: domesticmonero.com.


Related: EU Travel Rule zero threshold · Telegram support DM scam · Trading bot approval risk