The Online Safety Act complaints procedure requirement
In-scope services need a complaints procedure: a clear, easy-to-find way for users to raise issues — about illegal content, about content that should have been removed, or about your own moderation decisions — and a consistent way you handle them.
For a small operator this is mostly about being reachable and organised, not about running a call centre.
What your complaints route should let people do
Users should be able to report content they believe is illegal, complain if you take down (or refuse to take down) something, and get their complaint considered rather than ignored. The route needs to be easy to find and usable — a clearly linked form or address is fine.
You should handle complaints in a consistent, timely way and be able to show how you dealt with them. That record ties directly into your record-keeping duty.
A simple setup that works
Many small services meet this with a dedicated reporting link or email, a short internal note of how complaints are triaged, and a log of what came in and what you did. Keep it proportionate and keep the evidence.
Where to put it so people actually find it
“Easy to find” is doing real work in this duty, and it is the part small services most often get wrong — the route exists, but it is three clicks into a help centre. A footer link on every page is the usual baseline, because it is the one place users already look.
Better still is a report control next to the content itself: a report link on a post, a message, or a profile. That is what turns a complaints route into one people use, and it also tells you which piece of content the complaint is about without the user having to describe it.
Whatever you choose, make sure it works for someone who is not logged in and not a member. People reporting illegal content are often not your users.
What to record about each complaint
Keep it to a handful of fields, or it will not get filled in: when it came in, what it was about, what you decided, why, and when you closed it. A spreadsheet is a perfectly good complaints log for a small service.
That log is the bridge between this duty and record-keeping. It is also the most useful document you will have if your approach is ever questioned, because it shows the system running rather than describing it in the abstract.
Not sure if this applies to you?
Run the free scope checker — seven questions, about three minutes, a cited verdict at the end.
Frequently asked
- Is a contact email enough for a complaints procedure?
- A monitored, clearly-signposted email or form can be enough for a small service, provided complaints are actually considered, handled consistently, and recorded. The mechanism matters less than that it works and is easy to find.
- Do I have to respond within a set time?
- The Act expects complaints to be dealt with in an appropriate and timely way rather than fixing a single universal deadline. Check the current Ofcom guidance for how this applies to your service.
- What if my service gets almost no complaints?
- That is common for a small service and it is not a problem. The duty is to have a route that works and to handle what does come in — not to generate volume. An empty log is fine; not having a route at all is not.
- Do I need a separate route for illegal content?
- Not necessarily a separate channel, but users do need to be able to report content they believe is illegal, and to complain about your own take-down decisions. One well-signposted route that handles both, with a way to say which kind of complaint it is, is usually enough for a small service.
- Can I use a third-party form or helpdesk tool?
- Yes. What matters is that it is easy to find, actually monitored, and that you can produce the record of what came in and how you handled it. If a tool holds that history for you, that works in your favour.
Sources
General guidance to help you prepare records — not legal advice, and following it does not make you “compliant”.
More guides
Want a tool that walks you through these duties when we build it?