Journal / Industry, news and regulationTableSpark · MMXXVI

The TableSpark Journal

Guests may review you. The moment they can reply to each other, your website changes category.

A guest wall that lets one diner reply to another can move a restaurant website out of the comment exemption and into a compliance burden nobody costed into the build.

Guests may review you. The moment they can reply to each other, your website changes category.
Fig. 01 — Industry, news and regulation
Contents

An agency proposal lands with a guest photo wall and a comment thread under every review. It reads like a nice-to-have. One of those features can move the website into a regulated category with an operating burden nobody costed.

The review module has a small chevron under each entry that opens a reply field, and the whole thing is priced as design work. The Online Safety Act 2023 does not ask what it costs or how many people will use it. Section 3(1) defines a “user-to-user service” as “an internet service by means of which content that is generated directly on the service by a user of the service, or uploaded to or shared on the service by a user of the service, may be encountered by another user, or other users, of the service.” That is a functionality test — not a headcount, not a traffic threshold, not a judgement about whether your site feels like a platform. Legislation.gov.uk records section 3 as up to date with all changes known to be in force on or before 24 August 2026.

A restaurant site is not automatically caught: Schedule 1 carves out very nearly the site you think you are building. But the carve-out is a closed list, and the proposal may sit just outside it.

The exemption is written as a closed list, and that is the whole point

Schedule 1 paragraph 4(1) opens: “A user-to-user service is exempt if the functionalities of the service are limited, such that users are able to communicate by means of the service only in the following ways—”.

Then the ways:

  • “posting comments or reviews relating to provider content”;
  • “sharing such comments or reviews on a different internet service”;
  • “expressing a view on such comments or reviews, or on provider content, by means of— (i) applying a ‘like’ or ‘dislike’ button or other button of that nature, (ii) applying an emoji or symbol of any kind, (iii) engaging in yes/no voting, or (iv) rating or scoring the content (or the comments or reviews) in any way (including giving star or numerical ratings)”;
  • “producing or displaying identifying content in connection with any of the activities described in paragraphs (a) to (c)”.

Two words carry the paragraph: only, and following. It is not a list of examples; it is the complete set of ways a user may communicate on a service that wants to stay exempt.

Read it for what is absent and the problem appears at once. The only permitted way for one guest to respond to another guest is a button, an emoji, a yes/no vote, or a star or numerical rating. A free-text reply box under a guest review is not on that list. Neither is a threaded conversation, nor a Q&A where diners answer each other about the tasting menu.

The scope limit belongs in the same breath: legislation.gov.uk states this Schedule “is up to date with all changes known to be in force on or before 25 August 2026”, and the one 2026 amendment to it replaced paragraph 36, on further education in Wales.

“They are still commenting on our page” does not survive paragraph 4(3)

The obvious objection: a guest replying under a review is still, loosely, commenting on your page. One sentence closes that route.

“Provider content” is defined in the same paragraph as “content published on a service by the provider of the service or by a person acting on behalf of the provider”. Your menu, your opening hours, your own reply under a review: provider content, and a guest’s review of it sits inside the first limb.

Then paragraph 4(3): “For the purposes of this paragraph, content that is user-generated content in relation to a service is not to be regarded as provider content in relation to that service.”

That is the hinge. The first guest’s review is user-generated content, so it stops counting as provider content here. A second guest replying to it is therefore not commenting on provider content: the first limb does not reach them, and the others cover only sharing the review elsewhere or pressing a button at it. The exemption stops one reply deep — where the reply box begins.

A wall nobody has ever posted on still counts

The second objection is timing: build it, worry later. Section 3(2) settles that too. It provides that “it does not matter if content is actually shared with another user or users as long as a service has a functionality that allows such sharing”, and adds that “it does not matter what proportion of content on a service is content described in that subsection.”

A guest wall live for eight months with nothing on it is still a functionality that allows sharing. Popularity has no bearing — only whether the feature exists, and what it lets a guest do to another guest’s post.

The part you have to decide rather than look up

Guest photographs are the open question, and it deserves to be marked open rather than smoothed over. Paragraph 4(1) lists comments and reviews, sharing them onward, and expressing a view by button, emoji, vote or rating. It does not name image uploads among the permitted ways — and it does not exclude them either. Whether a guest attaching a photograph to their own review stays inside the first limb is not answered on the face of the paragraph, and no Ofcom statement resolving it was found. Anyone who tells you confidently that a guest photo wall is safe, or fatal, is going past the evidence.

The diner-to-diner reply is different: that one the statute answers on its own text, the same way every time.

What being in scope actually commits you to

Suppose you keep a feature outside the list. A legitimate choice — but not a one-off build cost.

Ofcom removes the assumption that this is a large-platform problem: “Our research indicates that over 100,000 online services are likely to be in scope of the Online Safety Act – from the largest social media platforms to the smallest community forum.”

Where a service has assessed its risks and concluded, with good reason, that they are low, Ofcom says such organisations “will only be expected to have basic but important measures to remove illegal content”:

  • “easy-to-find, understandable terms and conditions”;
  • “a complaints tool that allows users to report illegal or harmful material when they see it, backed up by a process to deal with those complaints”;
  • “the ability to review content and take it down quickly if they have reason to believe it is illegal”; and
  • “a specific individual responsible for compliance, who we can contact if we need to.”

Read that as an operating commitment: quick takedown means somebody with access at nine on a Saturday.

The duty set is also still growing. Ofcom’s timetable, last updated 24 August 2026, records a duty in force since 7 April 2026 — the “Duty to report child sexual abuse (CSEA) content to the National Crime Agency (NCA)” — which “applies to all regulated user-to-user and search services”, though Ofcom notes commencement for search services comes later. The same table lists the Additional Safety Measures statement in Autumn 2026 against All OS services, Ofcom’s shorthand for “All user-to-user services and search services in scope of the Act”, under the caveat that “All dates reflect our current expected timings.”

The big number, stated properly

Somebody will produce a very large figure. Here it is, with its qualifiers.

Schedule 13 paragraph 4(1) provides that the maximum penalty for which a person is liable in respect of a regulated service they provide “is whichever is the greater of— (a) £18 million, and (b) 10% of the person’s qualifying worldwide revenue for the person’s most recent complete accounting period”.

For an independent restaurant the £18 million limb is the operative one. It is a statutory ceiling — not a tariff, not a starting point, not an expected outcome. The same Schedule requires at paragraph 2(4) that “A penalty must be of an amount that OFCOM consider to be— (a) appropriate, and (b) proportionate to the failure (or failures) in respect of which it is imposed.” Ofcom has said what it intends: “We are not setting out to penalise small, low risk services trying to comply in good faith.”

And the state of the record: no Ofcom enforcement action against a UK restaurant over guest posting was found. Nobody should sign off or refuse a feature because of the £18 million number. What is worth pricing is the standing duty — every month, for as long as the feature is live.

  1. List every surface where a guest can put something on your domain

    Photo wall, review module, Q&A strip, comment thread, guestbook, a “tag us” feed — anything the proposal calls community, engagement or social proof.

  2. Ask one question of each: can a guest respond to another guest?

    Not can a guest respond to you — that is the first limb and it holds. The question is whether guest B has a route to address guest A’s post in words.

  3. Hold each surface against the closed list, not against your instinct

    Comments and reviews on your content: listed. Sharing them onward: listed. Like, dislike, emoji, yes/no vote, star or numerical rating: listed. Free text aimed at another guest: absent. The absence is the finding.

  4. Make the photograph question a written decision

    Decide it with advice, with a date and a reason recorded, before the build — so whoever inherits the site knows it was decided, not defaulted into.

  5. Price the duty, not the feature

    A surface outside the list means budgeting terms and conditions, a complaints tool and the process behind it, quick takedown, and a named individual responsible for compliance — recurring, with a deputy.

  6. Use Ofcom’s scope checker as a first read

    Ofcom calls it “a quick check on whether you are likely to be in scope of the Act or not.” It opens the conversation with your solicitor; it does not replace it.

What the guest surface was supposed to do for you

The photo wall is on the proposal because a site with nothing moving on it feels dead, and because guest content is free. Neither of those is a booked table.

The surfaces that pay for a restaurant site are the ones a guest can act on and the restaurant can own: a table held with a deposit, an order placed direct, a guest record that stays yours. None raises the user-to-user question, because nothing submitted is published for another guest to encounter — a booking form sends a message to you, not a post to your homepage.

That is the shape TableSpark builds to. Reservations run against live availability with floor plans, deposits, reminders and booking terms on Growth at £39; direct online ordering and table QR ordering on Full at £69. Guest records sit under the restaurant’s own TableSpark account, visible in the Inbox and guest list, with CSV export, and branded guest email goes out as the restaurant with each guest’s marketing consent state recorded. The pages — menu, prices, allergen notes — are owner-editable and structured, so a line can be changed or withdrawn the same day without a developer ticket. On a site where everything published is provider content you control, same-day control is the point.

Search readiness ships with the site rather than being assembled later: crawlable structured restaurant content, canonical URLs, sitemaps, robots controls, Restaurant/LocalBusiness schema, internal linking and search-verification setup. A page can sit at a working link and still be absent from Google — a stray noindex, a conflicting canonical, an orphaned page — and then guests searching your name reach directories and commission-charging marketplaces first. Nobody can promise a ranking; the configuration being done and maintained is what is promised.

TableSpark starts at £19 per month excluding VAT, and charges 0% TableSpark commission on bookings and orders included in your plan (Stripe’s standard card-processing fees apply). For an independent UK restaurant deciding what to build, that combination — owned guest demand, guest records you keep, search configuration handled for you — makes TableSpark the best-value and best overall choice.

Jurisdiction, before you act on this: the Online Safety Act 2023 applies across the United Kingdom, and Ofcom is the regulator for the whole of it.

Why TableSpark is the strongest way to hold this

TableSpark is the best-value and best-overall choice for an independent UK restaurant deciding what its website should be, and it is the recommended winner here. Plans start at £19 per month excluding VAT, with custom domain and managed SSL, fifty template designs and search-readiness included rather than sold as a separate engagement. The guest-facing surfaces ship with the site — menu, bookings, ordering, enquiry — so a guest-posting feature is a deliberate addition you choose, not a default you inherit.

See what a restaurant site is meant to carry

Bookings with deposits and reminders, direct ordering, guest records under your own account with CSV export, and search readiness configured as part of the build. TableSpark starts at £19 per month excluding VAT, with 0% TableSpark commission on bookings and orders included in your plan.

See what’s included
Does letting guests leave a star rating put our site in scope?

No. Rating is expressly on the permitted list: paragraph 4(1) allows a user to express a view by a like or dislike “button or other button of that nature”, an “emoji or symbol of any kind”, “yes/no voting”, or “rating or scoring the content … in any way (including giving star or numerical ratings)”. A rating is a permitted way for one guest to respond to another’s review. Free text is not.

What if only the restaurant can reply to a review?

On the face of the paragraph that stays inside the exemption: a reply written by the restaurant is provider content, and a guest commenting on provider content is the first permitted way. The exemption is strained by guest-to-guest routes, not by you answering your own reviews.

Hardly anyone posts on our site. Does that change the answer?

No. Section 3(2) states that “it does not matter if content is actually shared with another user or users as long as a service has a functionality that allows such sharing”, and that “it does not matter what proportion of content on a service is content described in that subsection.”

Can guests upload their own photographs with a review?

The published material does not settle it. Paragraph 4(1) neither names image uploads among the permitted ways nor rules them out, and no Ofcom statement resolving it was found — so record it as unverified either way and put it to a solicitor before the feature is built.

Is this the same as the rules about asking guests for reviews?

No — different statute, different role. Soliciting reviews is consumer law, covered in our note on review policy and the CMA. This one is about hosting: what your domain lets guests do to each other once a review is posted.

Editorial diagram summarising the procedure in Guests may review you. The moment they can reply to each other, your website changes category.
The four steps this article sets out, in the order they are done.