π€ AI Summary
This study investigates how the phased implementation of the UK Online Safety Act may exacerbate user privacy risks, particularly following the introduction of mandatory age verification measures. Leveraging the regulatory rollout as a natural experiment, the research combines Reddit discussion data, Google search trends, and a risk assessment of privacy policies from 69 VPN providers to empirically analyze the impact of regulation on user behavior. Findings reveal that key legislative milestones significantly increased both online discourse and search interest related to VPNs, primarily driven by user concerns over privacy breaches and surveillance. Notably, demand rose concurrently for both high- and low-privacy-risk VPN services, establishing a causal link between online safety regulation and heightened user exposure to privacy risks.
π Abstract
Governments worldwide are increasingly regulating digital platforms to reduce online harms, particularly those affecting children. However, access restrictions can alter user behaviour and introduce new privacy and security risks. The UK Online Safety Act (OSA), passed in October 2023, illustrates this trend: it extends age-assurance and safety requirements to social media, search, and pornography services, and rolled out in phases. Ofcom's illegal content enforcement duties came into force in March 2025, and mandatory age verification for adult content took effect in July 2025. This phased rollout enables real-time observation of behavioural responses to regulation. To address this, we analyse Reddit discourse across VPN and UK Politics communities and conduct a privacy-policy risk analysis of 69 unique VPN services.
We find that each of these three milestones produced significant stepwise increases in VPN-related discussion on Reddit: among UK-based users, posts and comments explicitly about VPN use in a regulatory or privacy context rose by +100%, +217%, and +415% respectively. UK Politics communities showed even larger effects, with OSA-related political discourse rising by +213%, +545%, and +464%, respectively, among UK-based users. UK VPN search interest on Google rose by +89% at the age-verification deadline. Users primarily framed this response around privacy, surveillance, and distrust of age-verification intermediaries rather than simple access-seeking. Demand increased across low, medium, and high-risk VPNs, but the proportional distribution remained broadly stable. These findings suggest that online safety regulation can create secondary privacy costs even when it does not disproportionately shift attention toward higher-risk providers.