Contents
A guest reviews wall, a photo competition and a public message board are three different legal animals, and only one of them sits safely outside the Online Safety Act. The risk is that the exemption is lost for the whole website rather than the feature that broke it, and there is nobody at the regulator who will confirm it either way. A restaurant switches on a guest reviews wall one quiet afternoon, or a comments box under the blog, or a share-your-photo-and-win-a-table upload gallery, and nothing about it feels like a regulatory act. The Online Safety Act 2023 classifies websites not by industry, size or intent but by functionality, and on the face of its definition a public wall on a restaurant site is a user-to-user service. Wrong in one direction, that means an illegal content risk assessment, a children's access assessment, reporting and complaints procedures and a written record, on a clock starting the day the feature goes live rather than the day anybody notices, against a maximum penalty of the greater of £18 million or ten per cent of qualifying worldwide revenue. Wrong in the other, the commoner error, an owner buys a compliance file nobody needed or strips a working feature off the site. Both come from one gap: the scope test is easy to fail on a first reading, and the answer sits in a schedule most explainers never open.
The definition is functional, and it catches a great deal

The definition, in section 3(1):
In this Act “user-to-user service” means an internet service by means of which content that is generated directly on the service by a user of the service, or uploaded to or shared on the service by a user of the service, may be encountered by another user, or other users, of the service.
Section 3(2) closes the escape route: it does not matter whether content is actually shared, as long as the service has a functionality that allows such sharing, and it does not matter what proportion of the content is of that kind. An empty comments box counts as much as a busy one. Section 4(2) makes such a service regulated if it has links with the United Kingdom and is not either a service of a description exempt as provided for by Schedule 1 or a service of a kind described in Schedule 2. Section 4(5) concedes that limb for a UK restaurant: links exist where a service has a significant number of United Kingdom users, or where they form one of its target markets, or the only one. Schedule 1 is the whole question.
The exemption most explainers never open
Schedule 1 paragraph 4, limited functionality services, is exhaustive — the operative word is "only" — so it is set out here whole:
A user-to-user service is exempt if the functionalities of the service are limited, such that users are able to communicate by means of the service only in the following ways—(a)posting comments or reviews relating to provider content;(b)sharing such comments or reviews on a different internet service;(c)expressing a view on such comments or reviews, or on provider content, by means of—(i)applying a “like” or “dislike” button or other button of that nature,(ii)applying an emoji or symbol of any kind,(iii)engaging in yes/no voting, or(iv)rating or scoring the content (or the comments or reviews) in any way (including giving star or numerical ratings);(d)producing or displaying identifying content in connection with any of the activities described in paragraphs (a) to (c).
Star ratings and written reviews of the restaurant's own food, under its own menu pages, sit inside that list, as do a below-the-line thread on its blog posts, like buttons, emoji and display names. Read against paragraph 4(1), the ordinary restaurant reviews wall is not a regulated user-to-user service at all, and none of Part 3 reaches it.
Paragraph 4(2) anchors it: provider content is what the provider publishes on the service, or what someone publishes on the provider's behalf, including where publication is controlled by software or an automated tool the provider applies or makes available — menu pages, dish photographs, event listings, blog posts. Paragraph 4(3) stops that anchor being bootstrapped:
For the purposes of this paragraph, content that is user-generated content in relation to a service is not to be regarded as provider content in relation to that service.
A guest's own review is not provider content. The chain has to begin at something the restaurant published.
The regulator's own worked example
Ofcom says the same, at paragraph 1.17 of Overview of regulated services, read on 30 August 2026:
A U2U service is exempt if the only way users can communicate on it is by posting comments or reviews on the service provider’s own content (as distinct from another user’s content).
and in the sentence that follows:
For example, this would exempt services where users can only write ‘below the line’ comments or reviews on media articles, or only post reviews on goods and/or services offered directly by the provider of the platform.
That is precisely a restaurant publishing reviews of its own food. The Act's Explanatory Notes gloss the same point at note 63:
This exempts services where the only user interaction is, for example, ‘below the line’ content on media articles, or user reviews of directly provided goods and services. Any services that also have additional user-to-user functionalities will remain in regulatory scope.
They are not part of the Act and were not endorsed by Parliament, so they are intent rather than authority. The second sentence is the one to write down: the loss is service-wide, not feature-scoped.
Three seams an ordinary restaurant site crosses
The guest photo-upload gallery. Section 236(1) defines content for the whole Act to include photographs, videos and visual images, so an upload gallery lets a user put content on the service. Whether uploading a picture of a plate is posting a comment or review relating to provider content, within paragraph 4(1)(a), the Act does not say, and no Ofcom statement or court decision found for this article does either.
The free-standing message board. A public "leave a message for the chef" wall is not attached to anything the restaurant published, and paragraph 4(1)(a) requires the comment or review to relate to provider content. That such a board falls outside it is an inference from the statutory words; no regulator or court has said it.
Guests replying to one another. The sharpest seam, and the least settled. Section 55(6), defining comments and reviews on provider content, reads:
“Comments and reviews on provider content”, in relation to a user-to-user service, means content present on the service consisting of comments or reviews relating to provider content (together with any further comments on such comments or reviews).
Parliament wrote an express extension to threaded replies — together with any further comments on such comments or reviews — into section 55(6). It wrote none into Schedule 1 paragraph 4(1), and paragraph 4(3) says a user's own content is not provider content. Whether a guest's reply to another guest's review keeps a service inside the exemption is unresolved: no Ofcom statement, explanatory note or reported decision resolves the asymmetry, and no case law applies Schedule 1 paragraph 4 at all.
The dates, because a duty that has not commenced is not a duty
Scope and duties commenced separately.
- Extent.
Section 239(1) provides that, subject to the following provisions of that section, the Act extends to England and Wales, Scotland and Northern Ireland: UK-wide.
- Scope.
Sections 2, 3 and 4 and Schedule 1 sit in Parts 1 and 2, which section 240(4)(a) brought into force on the day the Act was passed, 26 October 2023.
- Duties.
The Online Safety Act 2023 (Commencement No. 2) Regulations 2023, S.I. 2023/1420, regulation 2, commenced sections 7 to 13 — section 7 except subsection (5)(f) — on 10 January 2024.
- Illegal content.
Ofcom's guidance and first codes appeared on 16 December 2024, risk assessments were due by 16 March 2025, and the safety duties bit from 17 March 2025.
- Children.
Ofcom's statement and the first Protection of Children Codes were published on 24 April 2025, children's risk assessments were due by 24 July 2025, and the safety measures applied from 25 July 2025.
None of those is the live date for a restaurant. It is rolling, and Schedule 3 paragraph 3(2) sets it:
If, on the first day, illegal content risk assessment guidance and CAA guidance are both available, both of the following must be completed within the period of three months beginning with that day—(a)the first illegal content risk assessment of the service, and(b)the first CAA of the service.
The exposure is created on the afternoon a feature is switched on. Nor is the exemption permanent: section 220(9) lets the Secretary of State amend paragraph 4 of Schedule 1 by regulations, subject to subsection (10), where the risk of harm presented by a service described in that paragraph makes that appropriate. That power is prospective. As read on 30 August 2026, the only textual amendment annotated in Schedule 1 attaches to paragraph 36, in Part 2; paragraphs 1 to 8 carry none. Every provision here is dated by the day it was read, not by the site's currency banner.
There is nobody to ask
The uncomfortable part of a favourable answer is that it is the restaurant's own. Ofcom's Online Safety Act Explained Q&A, at page 3:
Regulated services cannot apply for an exemption. All user-to-user and search services that fall within scope of the Act must assess their risks and implement appropriate safety measures.
No application, no registration, no ruling. Section 226(2) decides who carries the judgement: the entity that has control over who can use the user-to-user part of the service, and that entity alone — not the web designer, not the hosting company. The cost of losing the exemption is the assessments, the records, and the section 10(3) duty to minimise how long priority illegal content is present and to take it down swiftly once alerted or otherwise aware.
The exemption is only from this Act
This is where a general explainer stops: what follows is a different Act and a different regulator. Since 6 April 2025, by S.I. 2025/272, paragraph 13 of Schedule 20 to the Digital Markets, Competition and Consumers Act 2024 has listed among the commercial practices banned in all circumstances:
Publishing consumer reviews, or consumer review information, without taking such reasonable and proportionate steps as are necessary for the purposes of—(a)preventing the publication of—(i)fake consumer reviews,(ii)consumer reviews that conceal the fact they have been incentivised, or(iii)consumer review information that is false or misleading, and(b)removing any such reviews or information from publication.
That reaches the restaurant's own reviews wall directly, and it is UK-wide. The Competition and Markets Authority's guidance CMA208 says at paragraph 8.5 that all publishers need a clear policy on the prevention and removal of banned reviews and false or misleading review information, and in addition an assessment of the risks of such material appearing on their media, with further reasonable and proportionate proactive steps. A policy and a risk assessment: very nearly the paperwork the exemption spares them, from a different direction. That policy is the review rules a UK operator writes to in 2026, and the incentive limb runs into what the star-rating guidelines withdraw from a page.
Defamation is narrower in extent: section 5 of the Defamation Act 2013 is marked E+W, England and Wales. Section 5(3) defeats the operator's defence where the claimant shows the poster could not be identified, that a notice of complaint was given, and that the operator failed to respond in accordance with regulations — the Defamation (Operators of Websites) Regulations 2013:
Where the operator has no means of contacting the poster paragraph 2 does not apply and the operator must, within 48 hours of receiving a notice of complaint, remove the statement from the locations on the website which were specified in the notice of complaint.
A reviews form that captures no contact address is a 48-hour removal clock, decided when the form is designed rather than when a complaint arrives. Whether an address is asked for is the same decision as the one behind the wifi list that is not a marketing list.
Practically, that means writing down every way a visitor can put words or pictures on the site, anchoring each to something the restaurant published, and keeping a dated note of what the site could do that day. Nobody issues a clearance, so the record is the defence. The exemption is a configuration to be maintained, not a status granted: a widget added by whoever touches the website next can move a site across the line without anybody deciding to.
What this is worth to an independent restaurant
The exposure follows from which features exist and how they are anchored, so the decision belongs with whoever controls the website — which is the case for TableSpark, the best-value and best overall choice for an independent UK restaurant. Starter is £19 a month excluding VAT and carries the AI menu scan and website setup, a live QR-ready menu, enquiry and newsletter forms, an Inbox for every lead with CSV export, and guest records under the restaurant's own account, exportable as CSV. The reviews block sits on Growth, at £39 a month excluding VAT, alongside on-site reservations at 0% TableSpark commission, live availability and table inventory, floor plans, deposits, reminders, email campaigns to consented guest segments, and a custom domain with managed SSL. Full, at £69 a month excluding VAT, adds online ordering and table QR ordering at 0% TableSpark commission, and up to five sites under one login. Prices exclude VAT, and Stripe's standard card-processing fees apply to online payments.
The compliance work underneath any public wall is handled in the platform: UK GDPR done properly, where decline means off; consent-gated embeds; data rights built in, meaning erasure, export and deletion; legal pages generated; secure by default, with bot protection, roles, 2FA and SSL. When UK rules move, TableSpark publishes plain-English updates linked to the official source. Whether a given set of switched-on features falls inside or outside Schedule 1 is a judgement for the restaurant and its own advisers; no such promise is made here.
Two decisions at the same keyboard have the same shape: scripts nobody chose can read the card fields on a checkout page, the payment-page script problem, and the guest list a reviews form feeds is only as private as the logins that still open it, what happens to guest records when staff leave.
A reviews block, and the guest list it feeds
Whether a statute reaches a restaurant’s own wall is a judgement the restaurant has to form and defend; what a platform settles is what the wall is and where its output goes. A reviews block comes with Growth at £39 per month excluding VAT, alongside direct reservations at 0% TableSpark commission, email campaigns to consented guest segments and a custom domain with managed SSL. Guest records sit under the restaurant’s own account in one Inbox, exportable as CSV, on every plan from Starter at £19 per month excluding VAT, and consent-gated embeds load nothing until a guest agrees. Which functionality a restaurant chooses to switch on remains its own decision; no such promise is made here.
Sources
- The definition a restaurant trips over. It is functional, not sectoral: nothing in it turns on the size of the business, whether the site sells anything, or whe — UK Government (checked 2026-08-31)
- The two-part gate. Being a user-to-user service is not enough to attract duties: the service must also have UK links AND not fall inside Schedule 1. For a UK re — UK Government (checked 2026-08-31)
- THE central provision, quoted whole. This is the limited-functionality exemption and it is exhaustive: the word is 'only'. A restaurant reviews wall, a below-th — UK Government (checked 2026-08-31)
- The parallel Part 3 carve-out, and the one place the Act expressly addresses replies to reviews. Note the words 'together with any further comments on such comm — UK Government (checked 2026-08-31)
- Why a guest photo-upload competition is a different animal from a reviews wall. 'Content' expressly includes photographs, videos and visual images, so an upload — UK Government (checked 2026-08-31)
- Who carries the duty if the exemption is lost. Not the web designer and not the hosting company: the provider is whoever controls who can use the user-to-user p — UK Government (checked 2026-08-31)
- The exemption is not permanent, and this is the clock a restaurant should watch. The Secretary of State can amend the limited-functionality paragraph by regulat — UK Government (checked 2026-08-31)
- EXTENT. The Act extends to England and Wales, Scotland and Northern Ireland, subject to a short list of exceptions in the same section — none of which concerns — UK Government (checked 2026-08-31)
- The Government's plain-English statement of exactly what puts a site back IN scope. One sentence, and it is the operative test for a restaurant: add any additio — UK Government (checked 2026-08-31)
- COMMENCEMENT of the scope test itself. Parts 1 and 2 — which contain sections 2, 3 and 4 and Schedule 1 — came into force on the day the Act was passed, 26 Octo — UK Government (checked 2026-08-31)
- COMMENCEMENT of the duties. The illegal content risk assessment and safety duties for user-to-user services were commenced by statutory instrument on 10 January — UK Government (checked 2026-08-31)
- Duty 1 if the exemption is lost. Not a form to file with Ofcom — an assessment the provider must carry out and be able to defend, at a time fixed by Schedule 3. — UK Government (checked 2026-08-31)
- Duty 2 if the exemption is lost, and the one that changes daily operations. 'Swiftly take down' is an operational standard for a business whose staff are on a s — UK Government (checked 2026-08-31)
- Duty 3 if the exemption is lost. A restaurant site is exactly the kind of place children are likely to reach, so the children's limb is not hypothetical once th — UK Government (checked 2026-08-31)
- THE DEADLINE for a restaurant that switches a feature on today. Three months from the first day the site is a Part 3 service — the clock starts when the functio — UK Government (checked 2026-08-31)
- The consequence, stated in the statute rather than in a headline. Note sub-paragraph (2): a provider with no accounting period is exposed to the £18 million fig — UK Government (checked 2026-08-31)
- THE REGULATOR'S OWN EXAMPLE, and the closest thing to an on-point statement that a restaurant reviews wall is exempt. Ofcom's worked example is reviews of goods — Ofcom (checked 2026-08-31)
- Closes off the 'we'll just ask Ofcom to let us off' route. Schedule 1 is a description you either fit or do not; there is no application, no registration and no — Ofcom (checked 2026-08-31)
- The regulator's own statement of the rolling deadline, in the plainest possible words. This is the sentence to put in front of an owner who is about to add a fo — Ofcom (checked 2026-08-31)
- PHASE 1 IN FORCE. Ofcom's own announcement on the day the illegal content safety duties began to bite: risk assessments were due 16 March 2025, and the safety d — Ofcom (checked 2026-08-31)
- PHASE 2 DATED FROM THE SOURCE. Both children’s-phase dates in one sentence, published the day the guidance and Codes came out: children’s risk assessments due 2 — Ofcom (checked 2026-08-31)
- THE POINT MOST EXPLAINERS MISS. Being outside the Online Safety Act does not mean being outside the law. Publishing consumer reviews without taking reasonable a — UK Government (checked 2026-08-31)
- What that duty means in practice for a small trader publishing reviews on its own website, in the regulator's words. Note that a policy is required of ALL publi — UK Government (checked 2026-08-31)
- The other law that reaches an exempt reviews wall: defamation. A restaurant that hosts a review defaming a supplier, a former employee or a rival keeps the sect — UK Government (checked 2026-08-31)
- The 48-hour clock nobody tells restaurants about. If the reviews wall takes anonymous submissions with no email address captured, the operator has no means of c — UK Government (checked 2026-08-31)
- TableSpark pricing — TableSpark (checked 2026-08-31)
- The platform-side compliance list and the plain-English updates commitment used in the close. — TableSpark (checked 2026-08-31)
