UK OSA Section 28 — Record-keeping and review duties
Make and keep written records of all risk assessments and compliance steps, review compliance regularly, and be able to provide records to Ofcom on request
Where this comes from
Provision: Section 28 — Record-keeping and review duties
Instrument: UK Online Safety Act 2023
Citation: Online Safety Act 2023, c. 50, Section 28; Ofcom Record-Keeping Guidance (2024)
Text version: Online Safety Act 2023 c. 50, as enacted (legislation.gov.uk)
Who it applies to
It applies when all of these are true:
- Service allows user-generated content
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Each recordable event is written at the time it occurs, on the request path, not batched later
- A record identifies what happened, when (ISO 8601), which system/version produced it, and who or what acted
- Records are append-only and tamper-evident (chained or write-once); an edit or deletion is detectable
- A retention floor and ceiling are set per record type and enforced by a scheduled job
- Records carry hashes or references instead of copies of the underlying personal data
Questions people ask
- Does UK OSA Section 28 — Record-keeping and review duties apply to my service?
- It applies when Service allows user-generated content.
- From when does this apply?
- UK OSA Section 28 — Record-keeping and review duties applies from 26 October 2023. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.