What happened

Ofcom's enforcement chief has told peers that most of the fines the regulator has issued under the Online Safety Act remain unpaid. Suzanne Cater, director of enforcement, told the House of Lords Communications and Digital Committee that a further payment had arrived this week, but that "realistically the majority have not been paid." The regulator has fined 11 service providers more than £7 million ($9.4 million) under its Online Safety Act powers so far.

Oliver Griffiths, a group director at Ofcom, said enforcement has so far concentrated on smaller companies in the pornography industry. The largest single penalty, £1.4 million ($1.88 million), went to 8579 LLC in February. He told the committee the picture should improve as the regulator moves on to larger companies, where collection difficulties should be less pronounced.

The gap sits in the regulator's powers rather than its willingness to use them. Ofcom cannot shut a service down worldwide, though it can ask a court to restrict UK access, a power it first used in May against an unnamed suicide forum whose operator had already been fined £950,000 ($1.2 million). Moving operations or infrastructure overseas is not an escape, because courts can order third parties such as internet service providers to block UK access. But business disruption measures require continuing noncompliance and cannot be used purely to recover an unpaid fine. Some services, Griffiths said, complied after being fined and then failed to pay, leaving Ofcom to chase the debt without UK assets to pursue.

Why this is a GRC story

An enforcement regime is only as strong as its collection rate. Most compliance programmes model regulatory risk as the fine plus the remediation cost. That model assumes the fine gets paid. Where penalties go unpaid and uncollected, the practical deterrent weakens, and the risk picture becomes uneven between companies that can be reached and companies that cannot.

There is a governance lesson for anyone running a compliance function. Ofcom says it would rather secure compliance before opening an investigation than litigate a debt afterwards, and that it is beginning to use its power to hold senior managers personally liable in certain circumstances. Both are early signals of a regulator working out which levers actually change behaviour. Read alongside the Online Safety Act's risk assessment and transparency duties, the message is that evidence of the work is the defence, not a promise to do better.

For compliance teams outside media and tech, the transferable point is structural. The services Ofcom struggles to collect from are often the ones with no UK assets and no appetite to stay in the market.

What to watch

Watch whether Ofcom starts publishing the outstanding balance and the number of unpaid penalties. Regulators rarely name non-payers by accident, and naming changes behaviour.

Watch how the judgment debt route performs against offshore operators. If registering a fine as a judgment debt does not produce payment, the next step is likely pressure on payment intermediaries, app stores and advertisers rather than on the service itself.

Watch the first large-platform cases. If they pay, Ofcom's current explanation holds. If they are contested for years, the argument that size solves collection will look weaker than it does today.

Attribution: Analysis based on The Register and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News