Ofcom’s effort to turn the UK Online Safety Act into an enforceable regulatory system has entered a consequential new phase. Meta, TikTok and X have challenged demands for information that Ofcom says it needs to examine how major social media services identify, assess and manage online-safety risks.
The dispute is not simply an argument over paperwork. It goes to the heart of how digital regulation works when the evidence required to assess compliance is held inside the companies being regulated. Ofcom needs access to reliable information about platform systems, users and safeguards. The platforms, meanwhile, argue that regulatory requests must remain within lawful boundaries, be sufficiently precise and protect confidential material.
As of October 2026, the challenges should not be treated as proof that the platforms are refusing all oversight, nor as evidence that every Ofcom demand is automatically justified. They raise legal and practical questions about the scope of the regulator’s powers, the proportionality of its requests and the safeguards governing commercially sensitive data. Their outcome could influence how aggressively the UK enforces online-safety obligations across the technology industry.
What is behind the Meta, TikTok and X Ofcom dispute?
The conflict centres on formal online safety data requests made as Ofcom carries out its duties under the UK Online Safety Act. The legislation gives the regulator responsibility for supervising services that host user-generated content or allow users to search for content. That includes major social networks, video platforms, messaging features and other online services used by people in the UK.
To determine whether a platform is following the rules, Ofcom cannot rely solely on public policy pages or statements from executives. It may need internal evidence showing how a service operates in practice. The Act therefore gives Ofcom information-gathering powers, including the ability to issue formal notices and require explanations, records or data relevant to its regulatory functions.
Meta, TikTok and X have challenged data demands directed at their services. Publicly described objections focus on issues such as the requests’ scope, legal basis, proportionality, confidentiality and compliance burden. Not every underlying notice or schedule has been published in full, so claims about undisclosed fields, internal discussions or strategic motives should be treated cautiously.
What is confirmed is that the companies are contesting aspects of Ofcom’s demands through legal processes. A challenge to an information request does not necessarily amount to opposition to the entire online-safety regime. It can instead ask a court or tribunal to decide where the statutory limits sit and whether a particular notice has been drafted and issued lawfully.
The precise requirements can differ by company and service, and some details remain confidential. However, the disputed online safety data demands concern the types of internal information Ofcom needs to understand risks, protective systems and compliance. Based on the regulator’s published framework and publicly described requests, relevant categories can include:
- Data about the number and characteristics of UK users, including evidence concerning whether children access a service.
- Information about how recommender systems rank, personalise and distribute content.
- Metrics showing how users encounter potentially illegal or harmful material.
- Details of content moderation processes, automated detection tools and human review systems.
- Figures relating to user reports, complaints, appeals, removals and account enforcement.
- Evidence about risk assessments and the methods used to test whether safety controls are effective.
- Information about age assurance, child-access assessments and protections designed for younger users.
- Internal records or technical explanations needed to verify claims made in formal compliance submissions.
These categories matter because headline removal statistics rarely tell the full story. A service may remove millions of posts while still allowing harmful material to spread rapidly through recommendations. Conversely, a large volume of reports does not by itself prove that a platform is unsafe; it could reflect an accessible reporting system or a particularly active user base.
Meaningful oversight therefore requires context. Ofcom may need definitions, methodologies, sampling information and system-level explanations alongside numerical data. A figure for removed content has limited value if the regulator cannot establish what was counted, how quickly action occurred, how many users saw the material or whether similar content continued to be recommended.
Ofcom’s role under the UK Online Safety Act
The UK Online Safety Act introduced duties intended to make regulated services address illegal content and, where applicable, risks affecting children. Ofcom is responsible for developing codes and guidance, supervising regulated providers, gathering evidence and taking enforcement action where legal requirements are not met.
Its responsibilities include assessing whether services have completed suitable risk assessments, implemented proportionate safeguards and maintained appropriate reporting and governance processes. Ofcom must also determine whether statements made by technology companies are supported by operational evidence.
The regulator’s information powers are central to those tasks. Without access to non-public platform data, an Ofcom social media investigation could be forced to depend on external research, user complaints and information selected for publication by the companies themselves. Those sources are valuable, but they may not reveal how ranking models, enforcement tools and internal decision-making systems operate.
At the same time, the existence of broad statutory powers does not remove the need for discipline. Ofcom must connect its requests to functions granted by Parliament, explain what it requires and handle sensitive information appropriately. Its wider approach to supervision and enforcement is set out through the regulator’s online safety guidance and regulatory materials.
Why Meta, TikTok and X are objecting
The platforms’ stated objections, as publicly characterised, concern the lawfulness and practical reach of the requests rather than a single shared objection to regulation. Although Meta, TikTok and X are often grouped together in coverage, each company operates different services, technical systems and compliance structures. Their legal positions should therefore not be assumed to be identical.
Questions about scope and relevance
A major concern is whether requested datasets and documents are sufficiently connected to Ofcom’s statutory purpose. Large platforms hold enormous quantities of information across multiple products and countries. A notice that uses broad definitions or long time periods may capture material beyond the UK service or issue being investigated.
Platforms can argue that an information request should identify the relevant product, jurisdiction, user group, risk or compliance duty with reasonable precision. Ofcom may respond that system-level risks cannot always be understood through narrowly selected data, particularly when infrastructure and moderation operations are shared globally.
The legal basis for individual demands
The Meta Ofcom legal challenge and the actions involving TikTok and X also test how the Online Safety Act’s information powers apply in specific circumstances. A regulator must act within the authority granted by legislation. Disagreement can arise over whether a requested item is necessary for a defined function, whether procedural requirements were followed or whether Ofcom has interpreted a statutory power too expansively.
That is a legal question rather than something that can be settled through assumptions about either side’s intentions. A ruling that limits one notice would not necessarily undermine the Act as a whole. Equally, a decision upholding Ofcom’s approach could strengthen the regulator’s ability to obtain comparable information from other services.
Confidentiality and data security
Online safety data requests may involve commercially sensitive information, including details of ranking systems, moderation technology, security controls and internal performance measures. Some material could also contain personal data or information whose disclosure might help malicious actors evade platform safeguards.
Meta, TikTok and X have legitimate reasons to ask how information will be stored, accessed, shared and protected. Ofcom also has confidentiality obligations and established processes for handling protected information. The dispute is therefore not simply about whether secrecy should prevail, but about what safeguards are appropriate for particularly sensitive datasets.
Cost and operational burden
Producing reliable regulatory data is rarely as simple as exporting a spreadsheet. Different teams may use different definitions, metrics may not align with Ofcom’s requested format, and global systems may not automatically separate UK activity. Companies may need engineers, lawyers, privacy specialists and trust-and-safety teams to locate, verify and explain the material.
Technology companies can object when they believe the burden is disproportionate to the regulatory value. Ofcom, however, must consider whether a provider’s size and technical complexity make detailed scrutiny more necessary, not less. A platform cannot automatically defeat an information request merely because its systems are complicated or costly to examine.
Why platform data matters for online safety enforcement
The central regulatory challenge is information asymmetry. Social media companies know far more than governments, researchers or users about how their services distribute content. They can observe impressions, recommendation pathways, user reports, model outputs and enforcement decisions at a scale unavailable to outside parties.
Access to appropriately defined data can help Ofcom test whether risks identified in a platform assessment match real-world outcomes. It can also reveal whether safety measures work consistently, whether children are exposed to unsuitable material and whether policy violations are amplified before moderators intervene.
Data can support comparisons over time and across services, although comparisons require care. Platforms define concepts such as views, active users, prevalence and removal differently. Effective platform transparency requirements therefore need common definitions and enough methodological detail to prevent misleading conclusions.
Information is also essential for proportionate enforcement. Detailed evidence could expose serious shortcomings, but it might equally demonstrate that a company has implemented effective controls. Regulatory access should not be understood only as a route to penalties; it can help distinguish substantiated failures from anecdotal allegations.
The cases could clarify the boundary between strong oversight and excessive regulatory intrusion. If Ofcom’s notices are upheld, the regulator may gain greater confidence when seeking granular evidence from other platforms. Companies could face stronger expectations to maintain auditable datasets, document safety decisions and produce UK-specific compliance information.
If parts of the demands are narrowed or rejected, Ofcom may need to draft more targeted notices, explain relevance in greater detail or use alternative evidence-gathering methods. Such an outcome would not necessarily prevent online safety enforcement. It could establish procedural standards that make future requests more predictable and legally durable.
The dispute may also accelerate investment in regulatory technology. Platforms increasingly need systems capable of separating UK data, preserving audit trails and mapping internal metrics to Ofcom online safety rules. Regulators, in turn, need secure infrastructure and specialist staff who can interpret complex datasets without drawing simplistic conclusions.
For users and civil society, the key issue is whether the eventual framework produces meaningful transparency. Confidential submissions can be necessary, but entirely closed oversight makes it difficult for the public to understand whether the regime is working. Aggregated findings, methodological explanations and enforcement decisions may provide accountability without exposing personal data or trade secrets.
A test of accountability rather than a simple standoff
It is tempting to portray the dispute as a battle between resistant technology companies and a determined regulator. That framing overlooks the harder questions. Ofcom must be able to obtain enough evidence to enforce Parliament’s rules, while Meta, TikTok and X remain entitled to challenge demands they consider unlawful, unclear or disproportionate.
The most durable outcome would define workable standards for relevance, confidentiality, technical feasibility and regulatory necessity. That could make online safety compliance more consistent across the market while reducing disputes caused by ambiguous or excessively broad requests.
Whatever the legal outcomes, the challenges show that UK digital regulation is moving beyond voluntary transparency reports. Platform accountability increasingly depends on regulators being able to inspect evidence rather than accept public assurances. The unresolved question is how far those inspection powers should reach and what protections should accompany them.
Frequently asked questions
Why are Meta, TikTok and X challenging Ofcom?
The companies are contesting aspects of Ofcom online safety data demands on grounds publicly associated with scope, legal authority, proportionality, confidentiality and operational burden. Their exact arguments can differ, and a legal challenge does not necessarily mean that they reject every obligation under the Online Safety Act.
Relevant requests can cover UK user numbers, child access, recommender systems, exposure to harmful content, moderation results, user complaints, appeals, risk assessments and the effectiveness of safety controls. Some detailed requirements remain confidential, so reports should not imply that every requested field is publicly known.
Can Ofcom force platforms to provide information?
The Online Safety Act gives Ofcom formal information-gathering and enforcement powers. Those powers are not unlimited: requests must have a lawful basis and comply with relevant procedural requirements. Courts or tribunals can be asked to resolve disputes over how the powers apply.
Could the dispute weaken UK online safety rules?
Not necessarily. The cases could limit particular requests, uphold Ofcom’s interpretation or produce a mixed outcome. In each scenario, they may clarify how future notices should be structured and what evidence platforms must retain for online safety compliance.
Users may not see immediate product changes, but the outcome could affect how effectively Ofcom investigates platform risks and verifies safety claims. It may also shape how much information about algorithms, moderation and child protection becomes available to regulators and the wider public.