Search arXivSearch

arXiv · 2606.05273

Online Safety Regulation Increases Attention to VPNs: Privacy Implications of the UK Online Safety Act

Abstract

Governments worldwide are increasingly regulating digital platforms to reduce online harms, but access restrictions can alter user behaviour and create new privacy risks. The UK Online Safety Act, passed in 2023, rolled out in phases - illegal-content enforcement in March 2025 and mandatory age verification in July 2025. We analyse Reddit discourse across VPN and UK Politics communities and conduct a privacy-policy risk analysis of 69 VPN services. We find that the behavioural response is concentrated at the July 2025 deadline, when platforms hosting pornographic content were required to deploy age checks. UK VPN search interest on Google increased by 147% at this deadline. UK-resident users' VPN-subreddit activity increased by 145%. Their regulatory- or privacy-related VPN posts and comments rose by 1,265% at this deadline. UK Politics communities show the same concentration at a larger magnitude, with OSA-related political discourse rising by 1481%. These effects were far smaller or statistically indistinguishable from pre-existing trends at Royal Assent and the illegal-harms enforcement deadline, indicating that the deployed age checks drove the response. Users primarily frame this response around privacy, surveillance, and distrust of age-verification intermediaries rather than access-seeking, with near-zero genuine pro-OSA sentiment across two independent classifiers. Several users noted that those least able to pay for reputable VPNs are most likely to turn to free services that monetise their data. Search attention increases across all disclosed privacy-risk categories, with no evidence of a shift toward higher-risk VPN providers. Crucially, after a full year, this attention is still elevated, arguing against a temporary news-cycle reaction. Thus, online safety regulation may create secondary privacy costs without disproportionately directing attention toward higher-risk VPNs.

Explore related subjects

Keep this discovery

BibTeXRIS

Dhyey Mehta, Eldar Jalilzade, Maksim Kalameyets, Rebecca Owens, Marc Juarez, Stergios Aidinlis, Lei Shi, Tuğrulcan Elmas. 2026-08-31. Online Safety Regulation Increases Attention to VPNs: Privacy Implications of the UK Online Safety Act. https://arxiv.org/abs/2606.05273

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

Security Science (SecSci), Basic Concepts and Mathematical Foundations

This textbook compiles the lecture notes from security courses taught at Oxford in the 2000s, at Royal Holloway in the 2010s, and currently in Hawaii. The early chapters are suitable for a first course in security. The middle chapters have been used in advanced courses. Towards the end there are also some research problems.

cs.CR

The Five Safes as a Privacy Context

The Five Safes is a framework used by national statistical offices (NSO) for assessing and managing the disclosure risk of data sharing. It can be understood as a specialization of a broader concept--contextual integrity--to the situation of statistical dissemination by an NSO. We demonstrate this by mapping the five parameters of contextual integrity onto the five dimensions of the Five Safes. We also discuss how each of these two theories can address weaknesses in the other, thereby strengthening them both.

cs.CR

Effective Interventions Against AI-Enhanced Scams

In 2025, scams were responsible for an estimated $442 billion in direct losses globally. In the United States, reported losses increased by nearly 400% between 2020 and 2025. Though AI in scamming is a relatively new phenomenon, its use significantly changes the economics of scams as well as the bottlenecks in scam operations. In this paper I investigate what interventions will remain effective under this new AI-driven scamming regime. I develop a simple model of scam profits to understand how different interventions asymptotically affect scam operations. I find that three levers--reporting rate, centralization of reporting, and report accuracy--multiply in their effect on expected victims per scam channel, reducing revenue per scam channel while increasing costs. Because effects multiply, interventions affecting all three could have a significant effect on the profitability of the scam business model. My analysis suggests that even modest reporting rates against high-value scam infrastructure could have significant impacts on scam profitability.

cs.CR