Latest Trending Discover Timelines Categories
All explainers

Technology explainer

How Do Digital Safety Laws Require Messaging Platforms to Protect Users?

Digital safety regimes increasingly require messaging services to assess foreseeable risks, design proportionate safeguards, operate reporting and appeal systems, and cooperate with lawful orders. Exact duties vary by country, service design, audience and whether communication is public, private or end-to-end encrypted.

Quick summary

Modern online-safety laws often regulate the system a messaging platform operates, not only individual posts after they appear. A service may have to understand how its features can facilitate illegal activity, introduce proportionate safeguards, accept reports, explain moderation decisions and preserve routes for appeal. The law does not impose one universal technical design, and requirements differ substantially between jurisdictions.

Which parts of a messaging service matter?

A messaging product may contain private chats, large groups, public channels, recommendation systems, search, file sharing, livestreams and automated accounts. Each feature creates a different pattern of reach and risk. A one-to-one encrypted conversation is operationally different from a public channel that can distribute material to millions, even when both appear inside the same application.

Regulators therefore examine the service’s functions, users, scale and availability in their territory. Legal coverage may also differ between an intermediary, an online platform and a very large platform.

The risk-based compliance cycle

  1. Identify harms: determine how illegal content or conduct, child exploitation, fraud, terrorism, harassment or other covered risks could arise.
  2. Assess exposure: consider likelihood, severity, affected users and features that increase reach or concealment.
  3. Mitigate: introduce measures proportionate to the risk and compatible with applicable rights.
  4. Operate: maintain reporting, moderation, escalation, appeals and emergency response procedures.
  5. Measure and revise: record outcomes, test safeguards and update the assessment when the product changes.

Safety by design

Preventive measures can include safer defaults for minors, rate limits, friction before forwarding, controls over invitations, abuse-resistant discovery, blocking tools and restrictions on automated mass messaging. Public spaces may use classifiers and human review. Private services can also act on user reports, account behaviour, metadata permitted by law and known abusive networks without necessarily reading every message.

The appropriate combination depends on the harm and architecture. A measure useful against spam may be ineffective against grooming or coordinated violence.

Notice, action and due process

Users and trusted organisations may need a clear way to report suspected illegal material. Platforms must distinguish allegations from confirmed illegality, apply the relevant law and communicate decisions where required. Appeals, reasoned notices and independent dispute routes reduce arbitrary removal and help correct errors.

Emergency requests and binding government orders require authenticated channels, trained teams and auditable handling. A vague request from an official is not automatically equivalent to a lawful order.

The encryption conflict

End-to-end encryption keeps message content readable only by communicating endpoints, protecting users against interception, service breaches and surveillance. It also limits server-side inspection. Policy proposals that seek content detection can therefore affect confidentiality, cybersecurity and freedom of expression.

This is not a choice between perfect safety and perfect privacy. Client-side scanning, metadata analysis and other proposed measures each carry limits, bypass risks and potential misuse. A credible framework evaluates necessity, proportionality, technical effectiveness and effects on all users rather than assuming that access can be created only for benevolent actors.

Transparency and accountability

Useful transparency reports distinguish reports received, automated detections, government requests, actions taken, reversals on appeal and response times. Raw removal totals can mislead because platforms differ in size and policy. Independent audits and regulator access to evidence may test whether the risk assessment matches actual operation.

Reality check

“The platform must remove harmful content” is usually an incomplete description. Laws define particular categories, procedures and territorial scope, and some focus on illegal content rather than everything considered harmful. Encryption does not exempt a service from every duty, but a regulator’s risk-assessment power does not automatically authorize unrestricted access to private messages.

How to evaluate a new regulation or enforcement action

Ask which law and jurisdiction apply, what service function is covered, whether the issue concerns illegal content, child safety or a broader systemic risk, and what procedural protections exist. Then examine whether the proposed measure is technically feasible, proportionate and independently testable. A fine or investigation establishes that a regulator acted; it does not by itself prove the underlying allegation until the process is resolved.

First appeared in

Australia Takes Telegram to Court Over Terror Videos It Says Stayed Online

A new version of NewTqnia is ready.