UK Online Safety Act Section 121 — what Technology Notices would actually do
Headlines in 2026 claim Ofcom will “scan every phone by September.” The legal picture is narrower and slower: Section 121 of the UK Online Safety Act 2023 lets Ofcom require user-to-user services to deploy accredited technology against terrorism and child sexual exploitation and abuse (CSEA) content — but several gates remain unclosed as of late August 2026.
This explainer maps Technology Notices — not EU Travel Rule (separate post), not DAC8 (separate post).
At a glance
| Field | Value |
|---|---|
| Topic | UK OSA §121 Technology Notices; Ofcom May 2026 advice; accreditation gate |
| Format | Regulatory explainer — no “encrypting is illegal” claim |
| Ofcom advice published | 8 May 2026 |
| Product mentioned | Domestic Monero — Telegram Mini App for P2P Monero trades |
| Official entry | @domestic_monero_bot |
| Support | /support on the official bot only (include Trade #ref + trade state) |
| Assets (P2P) | XMR ↔ BTC, LTC, ETH, SOL, USDT (ERC-20) |
| What it is not | EU AMLR / MiCA; a live blanket UK message decryption mandate today; on-chain Monero multisig |

What Section 121 enables
Under Chapter 5, Part 7 of the Online Safety Act, Ofcom may issue a Technology Notice requiring a regulated user-to-user or search service to:
| Notice type | Scope (Act framing) |
|---|---|
| CSEA content | Accredited tech — can cover private and public communication on the service |
| Terrorism content | Accredited tech — public communication only |
Section 121 is the only provision that lets Ofcom compel scanning of privately communicated content (for CSEA-accredited tools, if a Notice is issued and survives proportionality review).
Services must use technology accredited against minimum accuracy standards set by the Secretary of State for DSIT, after Ofcom advice.
Timeline — what happened by May 2026
| Date | Milestone |
|---|---|
| 2023 | Online Safety Act receives Royal Assent |
| Dec 2024 | Ofcom consultation on Technology Notice framework |
| 8 May 2026 | Ofcom publishes final advice to DSIT on minimum accuracy standards and provider guidance on how Ofcom proposes to exercise Notice powers |
| After May 2026 | DSIT Secretary of State must approve and publish minimum standards |
| Then | Ofcom (or appointee) accredits tools meeting standards |
| Only then | Ofcom may issue a Technology Notice to a specific provider — if necessary and proportionate |
Ofcom’s 8 May 2026 statement is explicit: advice to government is not itself a Notice. Human-rights, privacy law, and less-intrusive alternatives must be weighed per service before any mandate.
What is not active as of late August 2026
Fact-check and regulator materials in mid-2026 agree on several negatives:
| Claim | Status |
|---|---|
| “Ofcom already reads all encrypted Telegram/WhatsApp chats” | Not established as live blanket power |
| “Every UK phone scanned in September 2026” | Overstated — accreditation + Notice per platform still required |
| “Section 121 equals EU Travel Rule” | False — Travel Rule targets CASPs and transfer metadata; §121 targets illegal content on user-to-user services |
Ofcom’s July 2026 public work also emphasised SMS/MMS scam measures — some proposals explicitly exclude private messaging in current form. Do not conflate carrier spam rules with §121 private-chat powers.
Accuracy standards and accreditation
Ofcom’s May 2026 advice to DSIT describes an audit-based accreditation model for content-identification tools — public summaries cite scoring thresholds (e.g. overall and category accuracy floors) before a tool can be accredited.
Implications:
| Topic | Practical read |
|---|---|
| False positives | Accuracy standards are the political battleground — especially for encrypted / E2EE services |
| Client-side scanning | Media debate covers “scan before encrypt” architectures — not the same as a finalized UK mandate |
| Independent testing | Ofcom materials note revisiting stronger independent testing after operational experience |
Until DSIT publishes approved standards and tools accredit, §121 is framework law, not daily enforcement.
Why Telegram Mini App users file this under “platform risk”
Domestic Monero runs as a Telegram Mini App — a user-to-user platform’s embedded product. Archive does not claim Telegram’s §121 posture or encryption design. The link for readers is structural:
| Layer | Risk type |
|---|---|
| UK §121 | Platform may face content-scanning mandates on messaging services operating in the UK |
| EU Travel Rule / DAC8 | CASP metadata and tax reporting — different statutes |
| Fake support DMs | Social engineering on any popular messenger — DM explainer |
| Trading-bot approvals | Smart-contract risk — bot approval explainer |
Privacy-coin users already watch EU AMLR 2027 (headline explainer). UK §121 belongs in the same notebook tab — surveillance and platform duties — not the tax-reporting tab.
Terms in this article
| Term | Meaning here |
|---|---|
| Online Safety Act 2023 | UK law regulating user-to-user and search services |
| Section 121 | Power to issue Technology Notices for terrorism/CSEA tech |
| Technology Notice | Ofcom order requiring specific accredited technology on a named service |
| Ofcom | UK communications regulator implementing the Act |
| DSIT | Department for Science, Innovation and Technology — sets accuracy standards |
| CSEA | Child sexual exploitation and abuse material |
| E2EE | End-to-end encryption |
FAQ
Can Ofcom read my WhatsApp today?
Public materials as of mid-2026 describe framework and advice, not a deployed universal scanner. Check current Ofcom / DSIT publications for updates.
Does §121 ban encryption?
The Act compels accredited technologies on regulated services when Notices issue — debate centres on how E2EE platforms comply, not a plain-text ban in the statute summary here.
Is this EU law?
No. UK Online Safety Act — separate from EU MiCA, Travel Rule, DAC8.
Does Domestic Monero implement message scanning?
Archive public copy describes a P2P trade product, not Telegram’s compliance stack. Product support: /support on @domestic_monero_bot only.
Where do Monero chain privacy and UK law meet?
They often don’t directly — chain privacy is cryptographic; §121 is service-regulation. Users still face local law on income, conduct, and platform terms.
Next steps
- Track DSIT publication of accuracy standards — the next gate after May 2026 advice.
- Keep EU and UK rules in separate mental files: Travel Rule, DAC8.
- Verify official bot before trades: Verify official channels.
Marketing site: domesticmonero.com.
Related: EU Travel Rule zero threshold · Telegram support DM scam · Trading bot approval risk
