- Status
- In Force
- Penalty ceiling
- Regulated
Does it bind you?
Business-side roles with duties under this instrument.
Any Person3
Data Controller1
Operator1
Employer1
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Any Person — also bound by 2340 other Acts
Human Medicines Regulations 2012
184 duties
Merchant Shipping Act 1995
144 duties
Insolvency (England and Wales) Rules 2016
104 duties
Communications Act 2003
92 duties
Road Traffic Act 1988
92 duties
Data Controller — also bound by 35 other Acts
UK GDPR (retained EU law)
127 duties
Data Protection Act 2018
46 duties
Operator — also bound by 746 other Acts
Regulation (EU) No 965/2012 (Air Operations)
203 duties
Space Industry Regulations 2021
76 duties
Employer — also bound by 682 other Acts
What it requires
Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
s.003
Reporting duty
Regulated
- Notify NCA of third-party reporting arrangements and foreign agency changesOperator
s.004
Registration with the NCA
Regulated
- Register with the NCA before submitting CSEA content reportsEmployer
s.005
The organisation administrator, deputy organisation administrator, and authorised persons
Regulated
- Appoint a main point of contact for reporting child sexual abuse content to the NCAAny Person
s.006
Making reports to the NCA
Regulated
- Report CSEA content to the National Crime AgencyAny Person
s.008
Retention of data
Regulated
- Retain CSEA report data for specified periodsAny Person
s.009
Data protection requirements
Regulated
- Ensure appropriate security and confidentiality of personal dataData Controller
3 other provisions — procedural and definitional
s.001
Citation, commencement and extent
s.002
Interpretation
s.007
Requests from the NCA
Schedules
Schedules
0 of 8 shown8 other schedules
s.sch001
Contact information about the reporting person— (a) name,
s.sch001
The detected CSEA content.
s.sch001
Information about the detected CSEA content— (a) method by which...
s.sch001
Information about the user who has uploaded, created, shared or...
s.sch001
A declaration that all the available information has been provided....
s.sch002
Dates must be provided in number format as DD/MM/YYYY.
s.sch002
Time must be provided in an international format and the...
s.sch002
IP addresses must be formatted as follows—
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.