Law / United Kingdom

United Kingdom

19 of 20 named instruments researched to a stage, across all six areas of law we track: 18 in force and 1 proposed. As of 22 September 2026.

When they take effect16 of 19 carry a date, 3 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 4 instruments (4 in force) 2019: 0 instruments 2020: 2 instruments (2 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 3 instruments (3 in force) 2026: 3 instruments (3 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 6
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (282 words)

The United Kingdom has no general, cross-sector artificial intelligence statute; the government's stated approach is to work through existing sectoral regulators rather than adopt dedicated AI legislation.

Since 6 February 2026 the Data (Use and Access) Act 2025 makes it a criminal offence for any person to create, or to request the creation of, a 'purported intimate image' of an adult, a definition that reaches an AI-generated or otherwise fabricated image that merely appears to show a real person in an intimate state, without that person's consent.

A private member's bill, the Artificial Intelligence (Regulation) Bill [HL], was introduced in the House of Lords on 4 March 2025, never received a second reading, and fell when Parliament prorogued on 29 April 2026.

The Data (Use and Access) Act 2025 separately gave the Secretary of State duties to publish an economic impact assessment and a report on the use of copyright works in the development of AI systems, and gave the Information Commissioner's Office a statutory duty, introduced by SI 2026/425, to prepare a binding Code of Practice on AI and automated decision-making; that Code was not expected to take effect before 2027 and creates no duty of its own yet, so it is described here as context rather than as a separate instrument.

The government's Report on Copyright and Artificial Intelligence, published 18 March 2026, confirmed it will not introduce a broad text-and-data-mining exception for AI training; that finding, and the automated-decision-making provisions of the Data (Use and Access) Act 2025, are analysed under the scraping and privacy topics respectively, which own copyright, text-and-data-mining, and personal-data findings under the standing rule that a topic is chosen by what the duty attaches to.

AI prohibited practices

Creating, or Requesting the Creation of, Purported Intimate Image of Adult

Data (Use and Access) Act 2025, c. 18, s. 138, inserting ss. 66E-66H into the Sexual Offences Act 2003official statute text, Data (Use and Access) Act 2025, s. 138, legislation.gov.uk

In force 8 months, effective 6 February 2026. Binds public and private bodies.

What this law does

Section 138 of the Data (Use and Access) Act 2025 inserts new sections 66E to 66H into the Sexual Offences Act 2003.

Section 66E makes it an offence for a person intentionally to create a 'purported intimate image' of another adult without that person's consent, and section 66F makes it a separate offence intentionally to request the creation of such an image, or to request that an image include or exclude a particular thing, without consent; the request offence is committed regardless of whether the image is ever created, of whether it is also requested by someone else, and regardless of where in the world the requester or recipient of the request is located.

A 'purported intimate image' is an image that appears to be, or to include, a photograph or film of the person, but is not, or is not only, an actual photograph or film of them, and that appears to show an adult in an intimate state; a reference to an image expressly includes data stored by any means which is capable of conversion into an image, photograph or film.

Modifying an existing photograph or film of a person does not fall within the offence unless it adds an intimate element, or a person, not shown in the original. Both offences carry a defence of reasonable excuse, and the Secretary of State must review the operation of that defence and lay a report before Parliament within two years of commencement. Section 138 came into force on 6 February 2026.

What it requires

Privacy law7 instruments, 7 in force

Research summary (115 words)

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018, but that copy has now materially diverged: the Data (Use and Access) Act 2025, in force from 5 February 2026, replaced UK GDPR Article 22 with a permit-and-safeguard automated decision-making regime, added a new recognised legitimate interests lawful basis, restructured the cross-border transfer chapter around a new Article 44A, and gave the ICO a statutory duty to write a binding AI and automated decision-making Code of Practice.

The UK's own Supreme Court has separately narrowed the private right of action further than the CJEU's EU-wide line, foreclosing a no-injury, opt-out representative class action in Lloyd v Google.

Breach notification

UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom

UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025legislation.gov.uk, official consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

UK GDPR Articles 33 and 34 retain the same 72-hour and without-undue-delay structure as EU GDPR, with no threshold for how serious a breach must be before it is notifiable. The DUA Act shortened the separate PECR breach-notification window for telecoms and ISP-type breaches from 24 hours to 72 hours, in force 20 August 2025, aligning it with the UK GDPR timeline, and raised the maximum PECR fine to GBP 17.5 million or 4 percent global turnover, up from GBP 500,000.

What it requires

Comprehensive regime

UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025

Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18legislation.gov.uk, official consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.

This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.

What it requires

Cross border transfer

UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom

UK GDPR, Arts. 44A-50, as amended by the Data (Use and Access) Act 2025legislation.gov.uk, official consolidated text, verified directly

In force since 25 May 2018, effective 5 February 2026. Binds public and private bodies.

What this law does

The European Commission's own adequacy decisions for the UK were renewed 18 December 2025 and now run to 27 December 2031. For UK-outbound transfers, the ICO administers its own International Data Transfer Agreement (IDTA) and IDTA Addendum as the appropriate-safeguards mechanism where no UK adequacy regulation covers the destination.

The DUA Act restructured UK GDPR's transfer chapter: the original Article 44 was omitted and replaced from 5 February 2026 by a new Article 44A, which requires that a transfer either be approved by regulations, made subject to appropriate safeguards, or made in reliance on a derogation for specific situations, the same three-track adequacy, safeguards, or derogation structure as EU GDPR Chapter V, run through the UK's own instruments rather than the EU's. This is a real, structured condition on outbound transfer, not an absence of restriction.

What it requires

Data subject rights

Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D

Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425legislation.gov.uk, official consolidated text

In force 8 months, effective 5 February 2026. Binds public and private bodies.

What this law does

Before the DUA Act, UK GDPR Article 22, inherited unchanged from EU GDPR, generally prohibited a decision based solely on automated processing that produces legal or similarly significant effects, subject to narrow exceptions.

Section 80 of the DUA Act replaced Article 22 with four new articles, 22A to 22D, in force from 5 February 2026: solely automated significant decisions are now permitted generally, with the controller required to inform the individual in advance, provide a meaningful human review on request, and let the decision be contested.

The general prohibition now applies only where the automated processing relies entirely or partly on special category data or on the new recognised legitimate interests basis. A related statutory duty, S.I. 2026/425 (made 16 April 2026, in force 12 May 2026), requires the ICO to prepare and publish a binding Code of Practice on AI and automated decision-making. The ICO's own non-binding draft guidance was under public consultation from 31 March to 29 May 2026.

That still-unmade Code is recorded on this same row rather than as a separate instrument, since it exists specifically to implement this reform and does not yet have content of its own to describe.

UK GDPR's own definition of 'controller', now at Article 4(1)(7) following the DUA Act's renumbering of Article 4, names a public authority, agency or other body on the same footing as a natural or legal person, so these Articles 22A to 22D automated decision-making duties bind a government body exactly as they bind a private one.

What it requires

Enforcement supervision

UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement

UK GDPR, Arts. 82-83; Data Protection Act 2018 §169legislation.gov.uk, official consolidated text, verified directly

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Information Commissioner's Office (ICO) is the UK's single supervisory authority, unlike Germany's 17-authority structure, with UK GDPR Article 83 fines up to the greater of GBP 17.5 million or 4 percent of global turnover. Section 169 DPA 2018 supplies a private right of action for contravention of data protection legislation other than UK GDPR itself, while UK GDPR's own Article 82 covers contraventions of the Regulation directly; both cover material and non-material damage.

The UK's own Supreme Court has gone further than the CJEU in limiting what counts: Lloyd v Google LLC [2021] UKSC 50 (10 November 2021) unanimously rejected a representative claim brought on behalf of 4.4 million iPhone users, holding that compensation for a non-trivial data protection breach requires the individual to show tangible financial loss or distress, not a bare loss of control alone, and that such a claim cannot succeed without showing unlawful use and resulting damage for each individual claimant rather than the group as a whole.

What it requires

Sensitive categories

R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police

R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058Court of Appeal (Civil Division) judgment, published by the Judicial Office

In force since 11 August 2020. Binds government bodies.

What this law does

The Court of Appeal held South Wales Police's automated facial recognition trials unlawful, for breach of Article 8 ECHR, the Data Protection Acts 1998 and 2018 (no adequate legal framework, no proper Data Protection Impact Assessment), and the public-sector equality duty.

This is a public-authority case: it establishes that biometric surveillance deployment needs a proper legal framework, not just a lawful basis, and it is recorded here as applying to government even though the underlying UK GDPR and DPA 2018 biometric rules apply to both public and private actors.

What it requires

UK GDPR Article 9, Special Categories of Personal Data Including Biometric Data

UK GDPR, Art. 9; Data Protection Act 2018, Sch. 1legislation.gov.uk, official consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

Biometric data used for identification, fingerprints, facial templates, voiceprints, is special category data under UK GDPR Article 9, the same definition as EU GDPR.

The DPA 2018's Schedule 1 supplies the UK's own list of Article 9(2)(g) substantial public interest conditions, 23 conditions in Part 2 of Schedule 1, in addition to explicit consent, employment and social-security processing authorised by law, vital interests, not-for-profit bodies, data manifestly made public, legal claims, health and social care, public health, and archiving and research.

The ICO's own "Biometric recognition" guidance, published in final form 5 March 2024, states that biometric data becomes special category personal data from the moment of collection once a purpose of unique identification has been determined for it.

The Data (Use and Access) Act 2025 inserted a new Article 11A UK GDPR giving the Secretary of State a ministerial power to expand, by regulation, what description of processing is subject to Article 9's prohibition or its exceptions; no such regulation had been made as of the date shown. The ICO fined Clearview AI Inc GBP 7,552,800 for, among other findings, failing to meet the higher data protection standard biometric data requires.

In October 2025, the Upper Tribunal held that the First-tier Tribunal had wrongly found Clearview's processing outside UK GDPR's material scope, restoring the ICO's jurisdiction to have issued the fine and enforcement notice and remitting the substantive appeal against them to the First-tier Tribunal for determination.

What it requires

Scraping law3 instruments, 3 in force

Research summary (400 words)

The United Kingdom has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act 1990 criminalises causing a computer to perform a function to secure unauthorised access to a program or data; access is 'unauthorised' if the person is not entitled to control access of that kind and does not have the consent of someone who is, and the section's own words do not require that a technical security measure be defeated, unlike some other jurisdictions' computer-misuse statutes.

No reported UK case has been located establishing how section 1 applies to automated collection of content from a public, unauthenticated website, whether a robots.txt disallow directive narrows the access a site owner is taken to consent to, or whether continuing to crawl after a cease-and-desist notice by itself withdraws that consent.

General contract law treats terms a party actively agrees to, such as by ticking a box or opening an account, in the same way as a signed document, binding regardless of whether they were read, and treats terms only referenced by a link as binding only where the site did what was reasonable to bring them to the other party's attention before the contract was made, with more required for an unusual or onerous term; no reported case has applied either rule to a website's terms against a crawler specifically.

The Copyright, Designs and Patents Act 1988 permits text and data mining of lawfully accessed works only for non-commercial research and provides no machine-readable mechanism for a rightsholder to reserve rights against it, and the government's Report on Copyright and Artificial Intelligence, published 18 March 2026, confirmed it will not introduce a broader exception for commercial AI training.

The Copyright and Rights in Databases Regulations 1997 give a sui generis database right to a database's maker where there has been substantial investment in obtaining, verifying or presenting its contents, infringed by extracting or re-utilising all or a substantial part of those contents, including through the repeated and systematic extraction of insubstantial parts.

Public personal data scraped from a UK website remains subject to UK GDPR and the Data Protection Act 2018, which are analysed under the privacy topic. No UK statute or reported case has been located that establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, assigns legal weight to a robots.txt directive, or imposes an AI-training-specific rule beyond the copyright and computer-misuse provisions described above.

Computer misuse

Unauthorised Access to Computer Material

Computer Misuse Act 1990, c. 18, ss. 1 and 17(5), (8)official statute text, Computer Misuse Act 1990, legislation.gov.uk

In force. Binds public and private bodies.

What this law does

Section 1 makes it an offence for a person to cause a computer to perform any function with intent to secure access to a program or data, where that access is unauthorised and the person knows it is unauthorised. Section 17(5) defines access as unauthorised if the person is not themselves entitled to control access of that kind and does not have consent from someone who is; section 17(8) applies the same test, in materially the same words, to an act done in relation to a computer more generally.

Neither definition conditions unauthorised access on defeating a technical security measure. No reported UK case has been located establishing how section 1 applies to the automated collection of content from a public, unauthenticated website that imposes no access control.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (440 words)

The United Kingdom's only enacted product-security duty aimed at a market-facing manufacturer is the Product Security and Telecommunications Infrastructure Act 2022, Part 1, and its Security Requirements for Relevant Connectable Products Regulations 2023, which bans default passwords, and requires a published vulnerability-reporting contact and a published minimum security-update period, for a manufacturer, importer or distributor placing an internet- or network-connectable consumer product on the UK market; the duties apply to firmware and any software that must be installed for the product to work, and are enforced by the Secretary of State acting through the Office for Product Safety and Standards.

There is no UK duty requiring a manufacturer to report an actively exploited vulnerability to a national authority; the closest analogue is a manufacturer's own public disclosure channel for security issues, and the Cyber Resilience Act's Article 14 clock does not apply here.

Sector cyber-resilience regulation runs on the Network and Information Systems Regulations 2018, which impose security and incident-notification duties (up to 72 hours) on operators of essential services (energy, transport, health, drinking water, and digital infrastructure including internet exchange points and domain name system providers) and on relevant digital service providers offering an online marketplace, online search engine, or cloud computing service within the United Kingdom, enforced by twelve sector competent authorities and the Information Commissioner's Office with civil penalties of up to 17,000,000 pounds sterling; none of the services or sectors those regulations name is an activity this corpus can currently flag an app against, so this regime is recorded here rather than raised against a declared activity.

The Cyber Security and Resilience (Network and Information Systems) Bill, introduced 12 November 2025 and in House of Lords committee stage since 1 September 2026, would widen that regime to data centres, managed service providers, large load controllers and designated critical suppliers, shorten incident reporting to a 24-hour initial notice, and raise the penalty ceiling, but it has not received Royal Assent and binds nobody yet.

The Telecommunications (Security) Act 2021 sets a separate security duty on public electronic communications providers, again a sector this corpus cannot yet flag against.

There is no general reasonable-security or information-security-programme statute reaching a business simply because it holds personal data outside the data protection regime; that duty sits in UK GDPR Article 5(1)(f) and Article 32, and the corresponding breach-notification duty sits in UK GDPR Articles 33 and 34, both researched as this jurisdiction's privacy row rather than here.

The National Cyber Security Centre's Cyber Essentials scheme, its Cyber Assessment Framework, and its Secure by Design codes of practice for apps, app stores, software and artificial intelligence are voluntary guidance, not law.

Product security requirements

Product Security Requirements for Connectable Products

Product Security and Telecommunications Infrastructure Act 2022 c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007Official text, legislation.gov.uk, Product Security and Telecommunications Infrastructure Act 2022 and SI 2023/1007

In force since 29 April 2024. Binds private bodies.

What this law does

A manufacturer of a UK consumer connectable product, an internet- or network-connectable product that is not excepted, must comply with the security requirements of the 2023 Regulations, and an importer or distributor who supplies the product must not do so while aware of a manufacturer compliance failure.

Schedule 1 of the Regulations bans universal or easily guessable default passwords and requires the manufacturer to publish a point of contact for reporting a security issue, with a commitment on when the reporter will get an acknowledgment and status updates. The manufacturer must publish the minimum period for which security updates will be provided. That published period cannot later be shortened once it is published.

The duties reach firmware, software pre-installed on the product, and companion software that must be installed for the product's intended purpose. The reporting-contact and update-period duties do not reach the software of a smartphone or a cellular-capable tablet computer. The excepted-products schedule separately excepts a desktop computer, a laptop computer, and a non-cellular tablet computer, unless the product is designed for a child under 14.

It also excepts an electric-vehicle charge point, most medical devices, and an assured smart-meter product from the regime entirely.

The Secretary of State, acting through the Office for Product Safety and Standards under a memorandum of understanding with the Department for Science, Innovation and Technology, enforces the regime with compliance, stop and recall notices and can impose a civil monetary penalty of up to the greater of 10,000,000 pounds sterling or 4% of a person's qualifying worldwide revenue.

OPSS guidance states a further daily penalty of up to 20,000 pounds sterling for continuing non-compliance with an enforcement notice. Failing to comply with an enforcement notice is separately a criminal offence carrying a fine.

What it requires

Age gating law6 instruments, 5 in force, 1 proposed

Research summary (242 words)

The Online Safety Act 2023 imposes two overlapping age assurance regimes enforced by Ofcom: Part 3 requires user-to-user and search services likely to be accessed by children to complete children's risk assessments and adopt safety measures, including highly effective age assurance for pornography and other primary priority content, under Ofcom's Protection of Children Codes of Practice in force since 25 July 2025, while Part 5 separately requires dedicated, non-user-generated pornography providers to use highly effective age verification or estimation since 17 January 2025.

Ofcom opened dozens of Part 5 and Part 3 age assurance investigations through 2025 and issued its first age assurance fines, including GBP 1,000,000 against AVS Group Ltd in December 2025 and GBP 50,000 against the Undress.cc nudification site in November 2025.

The Information Commissioner's Office's Age Appropriate Design Code (Children's Code), a statutory code under the Data Protection Act 2018 in force since 2 September 2020, sets 15 standards for privacy protective design of services likely to be accessed by children. There is no dedicated UK app store or device level age verification statute, only a duty on Ofcom under the Online Safety Act to report on app stores' role in children's online safety.

On 15 June 2026 the government announced a social media ban for under-16s, to be made by regulations under section 214A of the Online Safety Act 2023, expected to be laid before Parliament by the end of 2026 and in force in spring 2027.

Adult content age verification (AV)

Ofcom Guidance on Highly Effective Age Assurance and Other Part 5 Duties

Statement: Age Assurance and Children's Access, Ofcom, published 16 January 2025official Ofcom guidance document

In force since 17 January 2025. Binds private bodies.

What this law does

Ofcom's statutory guidance under section 82 of the Online Safety Act 2023 sets out what counts as highly effective age assurance for Part 5 pornography providers, naming photo ID matching, facial age estimation, credit card checks, open banking checks, and mobile network operator checks as capable methods, and stating that self declaration or a basic checkbox is not sufficient.

Note and primary source

Online Safety Act 2023, Part 5 (duties of providers of regulated provider pornographic content)

Online Safety Act 2023, c. 50, ss. 79-82 (Part 5)official statute text, legislation.gov.uk

In force since 17 January 2025. Binds private bodies.

What this law does

Requires providers that publish or display their own, non-user-generated pornographic content to ensure, using age verification or age estimation or both, that children cannot normally encounter that content. The method used must be highly effective at correctly determining whether a user is a child, and providers must keep written records and publish a public statement on the methods used. The duty in section 81 came into force on 17 January 2025.

Note and primary source

Age-appropriate design code

Age Appropriate Design Code (Children's Code)

Data Protection Act 2018, ss. 123-125; Age Appropriate Design Code of Practice, Information Commissioner's Officeofficial Act text, Data Protection Act 2018 ss. 123 to 125, legislation.gov.uk

In force since 2 September 2020. Binds private bodies.

What this law does

Requires providers of information society services likely to be accessed by children in the UK to apply 15 standards of age appropriate design, such as privacy by default, data minimisation, and not using nudge techniques that weaken children's privacy protections, under a statutory code of practice issued by the Information Commissioner under the Data Protection Act 2018.

The code came into force on 2 September 2020 with a 12 month transition period ending 2 September 2021, after which the Commissioner and courts must take it into account when assessing UK GDPR compliance.

Note and primary source

Social media and minors

Ofcom Protection of Children Codes of Practice

Protection of Children Codes of Practice (illegal content and user-to-user/search services), Ofcom, April to July 2025official Ofcom statement and codes of practice

In force since 25 July 2025. Binds private bodies.

What this law does

Sets out the measures Ofcom expects user-to-user and search services likely to be accessed by children to adopt to comply with the Online Safety Act's children's safety duties, including age assurance, safer default settings and algorithms, and content moderation; providers that follow the Codes are treated as compliant.

Ofcom published the final Codes on 24 April 2025; providers had to complete children's risk assessments by 24 July 2025 and have risk mitigation measures in place from 25 July 2025, after the Codes completed the required Parliamentary process.

Note and primary source

Online Safety Act 2023, Part 3 (children's risk assessment and safety duties)

Online Safety Act 2023, c. 50, ss. 11-12 (Part 3)official statute text, legislation.gov.uk

In force since 10 January 2024. Binds private bodies.

What this law does

Requires providers of user-to-user services and search services likely to be accessed by children in the UK to carry out children's risk assessments and to use proportionate measures, including age verification or age estimation where appropriate, to prevent children encountering primary priority content harmful to children such as pornography, self harm, suicide, and eating disorder content. Sections 11 and 12 came into force on 10 January 2024.

Note and primary source

Under-16 social media minimum age regulations (announced), Online Safety Act 2023 section 214A

Regulations to be made under Online Safety Act 2023 s. 214A, as inserted by the Children's Wellbeing and Schools Act 2026DSIT announcement and consultation outcome, gov.uk

Proposed: draft date not recorded. An announced intention with no published text, dated 15 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

On 15 June 2026 the government announced it will ban under-16s from social media platforms that allow content posting and use algorithmic recommendation feeds (naming Snapchat, TikTok, YouTube, Instagram, Facebook, and X), with messaging services excluded and narrow exemptions for education, e-commerce, and music streaming.

The ban will be made by statutory instrument under section 214A of the Online Safety Act 2023 rather than a new bill, with regulations expected to be laid before Parliament by the end of 2026 and protections in force in spring 2027. The announcement followed the Growing Up in the Online World national consultation (2 March to 26 May 2026, over 116,000 responses), whose government response was published on 15 July 2026. Ofcom is to complete a rapid study on highly effective age assurance for under-16s in autumn 2026.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (213 words)

The United Kingdom has no press-publisher neighbouring right of the kind the European Union created in Article 15 of its Digital Single Market Directive, and no such right has been located in UK law. There is no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code, Canada's Online News Act or the United States' proposed Journalism Competition and Preservation Act.

The only general mechanism reaching an aggregator's reproduction of headlines and snippets is the fair-dealing quotation and news-reporting exception in section 30 of the Copyright, Designs and Patents Act 1988, which carries no headline-length or short-extract cap of its own and no restriction to the press industry; no reported UK decision has applied it specifically to a systematic news aggregator as opposed to an individual quoting a published work.

No distinct hot-news or misappropriation doctrine separate from ordinary copyright law has been located, and no statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer.

The text-and-data-mining opt-out exception at section 29A of the same Act, and its non-commercial-research limit, are analysed under the scraping topic, which owns copyright and text-and-data-mining findings under the standing rule that a topic is chosen by what the duty attaches to.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.