This is chapter 1 of Regulated Without Representation, a series by internet law solicitor Yair Cohen on how Britain regulates the internet and who pays for it. New here? Start with the introduction.
Picture a telephone exchange in 1935. Rows of young women in headsets, a wall of sockets and cords, and a voice in the ear asking for the number. Britain was moving to automatic dialling, but a great many calls still went through a human being, and some of the humans on the other end were unpleasant about it. Some were rude. Some were considerably worse than rude.
Parliament’s answer was section 10 of the Post Office (Amendment) Act 1935. It made it an offence to send “any message by telephone which is grossly offensive or of an indecent, obscene, or menacing character”. The penalty was a fine of up to ten pounds, or a month in prison, or both. The Law Commission, the body that advises Parliament on tidying up the law, later confirmed what everyone understood at the time: the provision was designed to protect telephone operators from obscene remarks.
That is the whole of the original idea. Do not swear at the switchboard.
Hold on to that image, because ninety years later the same words, “grossly offensive”, are the basis on which British police arrest something like thirty people a day for what they post online. Nobody planned that. It is what happens in a country that never quite throws anything away.
The heirloom
Britain rarely repeals a law. It re-enacts it, the way a family passes down a clock. The 1935 offence was carried into the Post Office Act 1953, then, by way of further Acts in 1969 and 1981, into the Telecommunications Act 1984, where “by telephone” was widened to “a public telecommunication system”. Then, in 2003, it arrived in section 127 of the Communications Act, where that phrase quietly became “a public electronic communications network”.
A public electronic communications network is, among other things, the internet. So far as I can find, nobody in 2003 stood up in Parliament and said: we are about to make it a crime to be grossly offensive on the internet. It was already a crime to be grossly offensive on the telephone, and the wording was simply modernised. The clock was rewound and put back on the mantelpiece.
Three years later the House of Lords, then our highest court, traced this lineage in a case about a man who had left racist messages on his Member of Parliament’s answering machine. Lord Bingham described the purpose of the offence as stopping people using “a service provided and funded by the public for the benefit of the public” for messages that “contravene the basic standards of our society”. Read that again with the internet in mind. The basic standards of our society, decided by a single magistrate without a jury, applied to a medium the drafters of 1935 could not have imagined.
The switchboard rule has a younger sibling. The Malicious Communications Act 1988 came out of a Law Commission report on poison-pen letters, the anonymous notes pushed through letterboxes in village dramas, and it makes it an offence to send a message that is “indecent or grossly offensive” with the purpose of causing “distress or anxiety”. Parliament was told in 1988 that the sending of poison-pen letters “was a common occurrence”. Two laws, then: one for the switchboard, one for the letterbox. Between them they are the workhorses of British speech policing to this day.
For American readers there is one thing to notice about the “grossly offensive” limb of these laws, and it is what it does not require. It does not require a threat. It does not require a target who was actually frightened. It does not require any likelihood of violence, imminent or otherwise. Your Supreme Court has said since 1969 that speech may only be punished as incitement where it is directed to “imminent lawless action“, and since 2023 that a “true threat” needs at least recklessness about how the words will land. Britain has no equivalent test. The question is whether the words were grossly offensive, and grossly offensive is in the eye of the beholder.
The man who threatened an airport
In January 2010 snow closed Robin Hood Airport, a small regional airfield near Doncaster in the north of England. A young trainee accountant called Paul Chambers had a flight booked to see a woman he had met online. He tweeted, to his few hundred followers: “Crap! Robin Hood Airport is closed. You’ve got a week and a bit to get your shit together otherwise I’m blowing the airport sky high!!”
An off-duty airport manager found the tweet some days later while searching the internet. He passed it to the police. Chambers was arrested at work, prosecuted under section 127, convicted, and lost his job. It took two years and a hearing before the Lord Chief Justice, the head of the judiciary of England and Wales, to put it right.
The judgment, in 2012, is one of the best pieces of writing about free speech in English law, and I recommend it to anyone who believes Britain has no tradition here. Lord Judge wrote that the 2003 Act “did not create some newly minted interference with the first of President Roosevelt’s essential freedoms”, freedom of speech and expression, and that “satirical, or iconoclastic, or rude comment, the expression of unpopular or unfashionable opinion about serious or trivial matters, banter or humour, even if distasteful to some or painful to those subjected to it should and no doubt will continue at their customary level, quite undiminished by this legislation”. A message that nobody could sensibly take as a threat, he said, “lacks menace”, and ordinary readers would “brush it aside as a silly joke, or a joke in bad taste, or empty bombastic or ridiculous banter”.
It was a fine judgment, and it changed almost nothing. The offence stayed on the statute book. The police kept using it. By 2023 the number of arrests under section 127 and the Malicious Communications Act had reached about 12,000 a year, roughly 33 a day. I will show you what those arrests look like in chapter 4. For now, keep the shape of the thing in mind: a rule for the switchboard, applied to the timeline, at industrial scale.
The second story: the platforms
So far this has been about what individuals say. The other half of the tale is about the companies that carry it, and that half is much newer.
For most of the internet’s life, Britain’s approach to platforms was borrowed and modest. The Defamation Act 1996 protected those who merely distributed other people’s words. A European directive protected hosts who took content down when told about it. The Defamation Act 2013 added a defence for website operators who helped a complainant find the author of a post. The idea was simple: platforms are not publishers, but they have to help when something goes wrong. It was, roughly, the British cousin of your Section 230.
Then, in April 2019, the Government published the Online Harms White Paper. A white paper is a statement of intended policy, and this one proposed “a new duty of care towards users, which will be overseen by an independent regulator”. A duty of care is an idea from the law of negligence: a company should take reasonable steps to prevent foreseeable harm. Applied to speech, it means a platform has to think in advance about what its users might say and design its systems to stop the harmful parts. Nobody has ever quite explained how you owe a duty of care to millions of strangers about what other strangers might type, but the phrase sounded responsible, and it stuck.
The Bill was introduced in March 2022 as “world-first online safety laws“. The Culture Secretary of the day, the minister responsible for media policy, said tech firms “haven’t been held to account when harm, abuse and criminal behaviour have run riot on their platforms”. The Bill then outlived three Prime Ministers, survived a great many amendments, and received Royal Assent, the formal step by which a Bill becomes law, on 26 October 2023. The Online Safety Act 2023 has 241 sections and 17 schedules. The official print runs to 303 pages.
It also did something none of the earlier laws had done. Section 4 says the Act applies to any service that “has links with the United Kingdom”, and a service has such links if it “has a significant number of United Kingdom users” or if British users “form one of the target markets for the service”. A third route catches a service that can be used here and poses a material risk of significant harm to people in Britain. Incorporation, location, staff, assets: none of it matters. If enough British people use your service, you are in.
The regulator grows to fit the law
A law this size needs a body to run it, and the body Parliament chose was Ofcom, a regulator built for broadcasting licences and telephone masts. It has grown to fit. In 2019/20, the year the White Paper was published, Ofcom employed an average of 937 people and had a budget of £124 million. In the year just ended it employed 1,665 and spent £223 million. This year’s budget is £233 million. Its chief executive told MPs in May 2025 that about 450 staff worked on online safety. The Commons Public Accounts Committee, which follows public money, was told in 2024 that Ofcom’s set-up costs alone could reach £169 million by the end of 2024/25.
And the number of services it is meant to supervise? Ofcom’s own figure is more than 100,000, “from the largest social media platforms to the smallest community forum”. The Public Accounts Committee was told most would be small businesses, based overseas, or both. Oliver Griffiths, Ofcom’s online safety director, repeated the figure to a House of Lords committee on 15 September 2026: “The Act is extraordinarily broad. It applies to more than 100,000 services.”
Why the history matters
Two things happened in Britain, and they came from different centuries.
The tools for prosecuting individuals for what they say were never modern tools. They are a 1935 telephone rule and a 1988 letterbox rule, re-enacted, broadened, and used at a scale nobody intended. The Law Commission said in 2021 that they should go. The Government agreed. I will tell you in chapter 4 what happened next, because it is the part of this story I find hardest to forgive.
The tool for regulating platforms, by contrast, is brand new, enormous, extraterritorial by design, and comes with a regulator that has nearly doubled in size to run it. Britain had left the European Union, so it did not adopt Europe’s Digital Services Act. It built its own, and it built it bigger.
A country with an old habit of policing speech and a new machine for policing platforms was always going to look for someone to pay for the machine. The next chapter is about who it found.
For the serious reader
Two separate bodies of British law now touch a US operator. The criminal offences apply to what your users write, and British police send data requests to American platforms on that basis; a post that is plainly lawful in Texas can be an offence in Tyneside. The Online Safety Act applies to you as a company, on the “links with the United Kingdom” test in section 4, wherever you are incorporated. Neither depends on your having a British office.
If you are British: the offence most likely to be used against you for something you post was written for the telephone exchange. The Law Commission recommended its replacement in 2021. It is still there.
Next: Chapter 2, Taxation without representation, 2026 edition. The Stamp Act asked the American colonies to pay for the army that policed them. The Online Safety Act asks American platforms to pay for the regulator that fines them. In both cases, nobody asked the people paying.
Sources for this chapter
- Post Office (Amendment) Act 1935, section 10 (as enacted): https://www.legislation.gov.uk/ukpga/Geo5/25-26/15/pdfs/ukpga_19350015_en.pdf
- Post Office Act 1953, section 66 (as enacted): https://www.legislation.gov.uk/ukpga/Eliz2/1-2/36/section/66/enacted
- Telecommunications Act 1984, section 43 (as enacted): https://www.legislation.gov.uk/ukpga/1984/12/section/43/enacted
- Communications Act 2003, section 127: https://www.legislation.gov.uk/ukpga/2003/21/section/127
- DPP v Collins [2006] UKHL 40: https://publications.parliament.uk/pa/ld200506/ldjudgmt/jd060719/collin-1.htm
- Malicious Communications Act 1988, section 1: https://www.legislation.gov.uk/ukpga/1988/27/section/1
- Malicious Communications Bill, second reading, 12 February 1988: https://api.parliament.uk/historic-hansard/commons/1988/feb/12/malicious-communications-bill
- Law Commission, Modernising Communications Offences, Law Com No 399 (2021): https://assets.publishing.service.gov.uk/media/61ba022ad3bf7f05539de6f5/Modernising-Communications-Offences-2021-Law-Com-No-399.pdf
- Chambers v DPP [2012] EWHC 2157 (Admin): https://www.judiciary.uk/wp-content/uploads/JCO/Documents/Judgments/chambers-v-dpp.pdf
- Brandenburg v Ohio, 395 U.S. 444 (1969): https://supreme.justia.com/cases/federal/us/395/444/
- Counterman v Colorado (2023): https://www.supremecourt.gov/opinions/22pdf/22-138_43j7.pdf
- House of Lords Library, Select communications offences and concerns over free speech: https://lordslibrary.parliament.uk/select-communications-offences-and-concerns-over-free-speech/
- Defamation Act 2013, section 5: https://www.legislation.gov.uk/ukpga/2013/26/section/5
- 47 U.S.C. § 230: https://www.law.cornell.edu/uscode/text/47/230
- Online Harms White Paper (8 April 2019): https://www.gov.uk/government/consultations/online-harms-white-paper
- Gov.uk, World-first online safety laws introduced in Parliament (17 March 2022): https://www.gov.uk/government/news/world-first-online-safety-laws-introduced-in-parliament
- Online Safety Bill, stages: https://bills.parliament.uk/bills/3137/stages
- Online Safety Act 2023, contents: https://www.legislation.gov.uk/ukpga/2023/50/contents
- Online Safety Act 2023, section 4: https://www.legislation.gov.uk/ukpga/2023/50/section/4
- Ofcom Annual Report and Accounts 2019/20: https://assets.publishing.service.gov.uk/media/5f184d3f3a6f407274d891d9/ofcom-annual-report-and-accounts-2019-20.pdf
- Ofcom Annual Report and Accounts 2025/26: https://assets.publishing.service.gov.uk/media/6a4e92bb43f694ee291df854/Ofcom_Annual_Report_and_Accounts_2025-2026_optimised_A.pdf
- Ofcom Tariff Tables 2026/27: https://www.ofcom.org.uk/siteassets/resources/documents/about-ofcom/how-ofcom-is-run/annual-reports/plans-and-financial-reporting/tariff-tables/ofcom-tariff-tables-2026-27.pdf
- Science, Innovation and Technology Committee, oral evidence, 20 May 2025: https://committees.parliament.uk/oralevidence/15938/html/
- Public Accounts Committee, Preparedness for online safety regulation (February 2024): https://publications.parliament.uk/pa/cm5804/cmselect/cmpubacc/73/report.html
- Ofcom, Helping small services navigate the Online Safety Act (January 2025): https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/helping-small-services-navigate-the-online-safety-act
- Lords Communications and Digital Committee, oral evidence, 15 September 2026: https://committees.parliament.uk/oralevidence/18091/pdf/

