Sector

Technology & Digital

Software, IT services, digital products, telecoms and tech startups.

Technology & Digital 152,370 enterprises in the UK

Start here

See all 7

Who regulates you

See all 20

Ofcom (opens in a new tab)

Regulates telecoms, TV, radio, video-on-demand, postal services, and online safety. Issues licences for telecoms providers, manages spectrum. Now enforces Online Safety Act duties for …

Enforces 10 Acts this sector relies on.

ICO (opens in a new tab)

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. All businesses …

Enforces 7 Acts this sector relies on.

Trading Standards (opens in a new tab)

Enforces consumer protection legislation including food labelling, weights and measures, product safety, and fair trading. Part of local authority structure. Investigates food labelling breaches.

Enforces 7 Acts this sector relies on.

CMA (opens in a new tab)

Promotes competitive markets and tackles unfair behaviour. Investigates mergers, enforces competition law, and has specific digital markets powers. Digital Markets Unit (DMU) designates Strategic …

Enforces 6 Acts this sector relies on.

FCA (opens in a new tab)

Regulation of financial services firms and markets. Supervises banks, insurers, investment firms, payment services, and cryptoasset businesses. Issues authorisations and enforces conduct rules.

Enforces 6 Acts this sector relies on.

BBFC (opens in a new tab)

Classifies films, videos, and some video games for age rating. Statutory authority for classifying cinema releases and video works under the Video Recordings Act …

Enforces 4 Acts this sector relies on.

Key legislation

See all 29
Online Safety Act 2023 Cited by 17 of this sector’s guides · 583 provisions Act
Privacy and Electronic Communications Regulations 2003 Cited by 8 of this sector’s guides · 92 provisions SI
Network and Information Systems Regulations 2018 Cited by 8 of this sector’s guides · 40 provisions SI
Communications Act 2003 Cited by 6 of this sector’s guides · 1559 provisions Act
DMCCA 2024 Cited by 4 of this sector’s guides · 835 provisions Act
Financial Services and Markets Act 2000 Cited by 2 of this sector’s guides · 1893 provisions Act
DEA 2017 Cited by 2 of this sector’s guides · 645 provisions Act
Investigatory Powers Act 2016 Cited by 2 of this sector’s guides · 538 provisions Act

What’s changing

See all changes
Guidance_Update

Ofcom publishes categorisation register for Online Safety Act (July 2026)

Enforcement_Change

Ofcom Online Safety Act fee notification deadline (11 April 2026)

General rules

Common requirements that apply across industries. Conditions such as employing people or operating premises are shown only after they are known.

All guidance for technology & digital

Digital & Technology

8

Tech Sector Licensing and Authorisations

Comprehensive guide to licences and regulatory authorisations required for technology businesses - telecommunications, financial services, intellectual property, export controls, and product safety.

Relevant across several parts of this sector.

Tech Sector Compliance Overview

Comprehensive guide to regulatory compliance for technology businesses - UK GDPR, data protection, online safety, cybersecurity, and sector-specific requirements.

Relevant across several parts of this sector.

Cryptoasset Business Regulation

Regulatory requirements for cryptoasset businesses in the UK - how token classification determines whether you need full FCA authorisation or Money Laundering Regulations registration only.

Relevant across several parts of this sector.

E-commerce regulations for online selling

Legal requirements for selling online - including consumer contracts, pre-contract information, cancellation rights, and digital content regulations.

Relevant across several parts of this sector.

Protecting Your Software Intellectual Property

Complete IP protection guide for software businesses - automatic copyright for source code, patent eligibility under the technical contribution test, UK and international patent fees, and trademark registration for software and services.

Relevant across several parts of this sector.

AI Regulation Framework

The UK takes a principles-based, sector-specific approach to AI regulation. There is no single AI law. Instead, existing regulators — including the ICO, FCA, MHRA, CMA, Ofcom, and EHRC — apply five cross-cutting principles within their own domains. The AI Security Institute (formerly AI Safety Institute) provides guidance on frontier models. A comprehensive government AI Bill is expected in the second half of 2026.

Relevant across several parts of this sector.

Consumer rights compliance for digital content sellers

Your legal obligations under the Consumer Rights Act 2015 and Consumer Contracts Regulations 2013 when selling software, apps, games, music, video, e-books, or other digital content to consumers.

Relevant across several parts of this sector.

App store and digital platform regulation

How the Digital Markets Act and CMA regulation affects large digital platforms and app store operators. Covers Strategic Market Status, conduct requirements, and developer rights.

Relevant across several parts of this sector.

Show 28 more

Privacy and Electronic Communications Regulations

PECR sits alongside UK GDPR and gives specific privacy rights relating to electronic communications, including marketing calls, emails, texts, cookies, and traffic data.

Relevant across several parts of this sector.

Software licensing compliance

Understand your legal obligations when using, developing, or distributing software - including open source licensing, commercial agreements, and intellectual property protection.

Relevant across several parts of this sector.

Implement age assurance on your platform

Practical guide to implementing age assurance on your online platform. Covers choosing between age verification and estimation, evaluating providers, privacy-preserving approaches, the specific requirements for pornographic content, and ensuring compliance with both the Online Safety Act and UK GDPR.

Relevant across several parts of this sector.

Computer Misuse Act Compliance

How to comply with the Computer Misuse Act 1990 when conducting security testing, developing security tools, or running bug bounty programmes. Includes the four criminal offences, penalties up to life imprisonment for serious cases, and requirements for legitimate security research.

Relevant across several parts of this sector.

Export Control (Dual-Use Technology)

Export of goods, software, and technology with both civil and military applications requires licensing. Particularly relevant for encryption, advanced computing, AI, and surveillance technologies.

Relevant across several parts of this sector.

Radio Equipment Regulations

Equipment that intentionally transmits or receives radio waves for communication or radio determination must comply with Radio Equipment Regulations, including IoT devices, WiFi equipment, and Bluetooth products.

Relevant across several parts of this sector.

Children's safety duties under the Online Safety Act

Comprehensive guide to the children's safety duties under the Online Safety Act 2023. Covers what triggers the duties, risk assessment by age group, the categories of harmful content affecting children, age assurance requirements, Ofcom's children's codes of practice, and how the OSA intersects with the ICO's Children's Code.

Relevant across several parts of this sector.

Conduct a children's access assessment

Step-by-step guide to assessing whether children are likely to access your online service under the Online Safety Act 2023. Covers the legal test, Ofcom's April 2025 guidance, factors to consider, and what additional duties are triggered if children can access your service.

Relevant across several parts of this sector.

Conduct an illegal content risk assessment

Step-by-step guide to conducting the mandatory illegal content risk assessment under the Online Safety Act 2023. Covers how to identify risks from Schedule 7 priority offences, assess your service's features, document safety measures, and produce the required written record.

Relevant across several parts of this sector.

Online Safety Act compliance checklist

Quick-check verification of your Online Safety Act compliance status. Covers scope assessment, risk assessments, content moderation, terms of service, complaints, age assurance, Ofcom registration, and record-keeping.

Relevant across several parts of this sector.

Online Safety Act penalties and enforcement powers

Quick reference to Ofcom's enforcement powers, penalty calculations, and senior manager criminal liability under the Online Safety Act 2023.

Relevant across several parts of this sector.

Register with Ofcom for Online Safety Act compliance

How to register with Ofcom as a regulated online service and understand fee requirements under the Online Safety Act 2023. Covers scope, the registration portal, qualifying worldwide revenue thresholds, and annual fee obligations.

Relevant across several parts of this sector.

Set up content moderation to meet Online Safety Act requirements

How to build a content moderation system that meets Online Safety Act 2023 duties. Covers automated detection tools, human moderation teams, user reporting mechanisms, content review workflows, removal timelines, record-keeping, and moderator wellbeing.

Relevant across several parts of this sector.

Understanding the Online Safety Act

A strategic overview of the Online Safety Act 2023, explaining what it is, who it affects, how the regulatory framework operates, and where it sits within the broader UK digital regulation landscape. Essential reading for any business operating an online platform or service with user interaction.

Relevant across several parts of this sector.

Write terms of service that meet Online Safety Act requirements

How to draft or update your platform's terms of service to comply with Online Safety Act 2023 duties. Covers required content, prohibited content policies, enforcement, accessibility, and Category 1 additional obligations.

Relevant across several parts of this sector.

Cyber Essentials Certification

Government-backed scheme helping organisations guard against common cyber attacks. Required for many government contracts involving handling of sensitive information.

Relevant across several parts of this sector.

Run a compliant information service business

Whatever information service you run — data processing, hosting, a web portal, a news agency or media monitoring — the same core duties apply. Data protection comes first: you are usually both a controller of your own records and a processor of client data, and unless exempt you must pay the ICO data protection fee. Add the electronic marketing and cookie rules, insure your employees, and keep your workplace safe, fire-safe and free of discrimination.

Relevant to a specific activity in this sector.

Set up and run a safe IT and programming business

Computer programming, consultancy and IT services work is office- and screen-intensive, with display screen equipment, mental health and — in data centres — electrical and environmental risks. This is the universal spine. It takes you through your core workplace health and safety duties, fire safety, employers' liability insurance, equality, data protection and, where it applies, NIS digital service provider duties.

Relevant to a specific activity in this sector.

IT and programming business: compliance checklist

Use this checklist to confirm your IT, programming or consultancy business meets its obligations. Work through the universal workplace items every employer shares, then the data protection and NIS items that bite harder in this sector. If you answer no to any item, follow the linked guide before you proceed.

Relevant to a specific activity in this sector.

Information services compliance checklist

A confirmation checklist for information service businesses. Work through the cross-cutting duties every information service shares, then the section for what you operate — data processing, hosting and web portals, or news agency and other information services.

Relevant to a specific activity in this sector.

Which information service rules apply to your business

Information service businesses — data processing and hosting providers, web portals, news agencies, media-monitoring and other information services — share one defining regime: data protection. Beyond that, what you must do depends on what you operate: cloud, search and marketplace services above a size threshold have network-security duties, services hosting user content have Online Safety Act duties, and news agencies have copyright and press standards to manage. Work out which you are and follow the right guide.

Relevant to a specific activity in this sector.

Data processing, hosting and web portal rules

If you process or host data, run a cloud service, or operate a web portal or search service, two regimes may apply on top of the rules every information service shares — and both scope by what you operate, not by your sector. The NIS Regulations 2018 put security and incident-reporting duties on cloud computing, online search and online marketplace services at or above a size threshold. The Online Safety Act 2023 puts illegal-content and children's-safety duties on services that host user-generated content or provide search.

Relevant to a specific activity in this sector.

Rules for news agencies and information services

If you run a news agency, a media-monitoring or press-clipping service, or another information service, your specific rules centre on copyright — in both directions. You own copyright in the news you create and license to subscribers, and you must license what you copy from other publishers. Most news publishers also join a press self-regulator (IPSO or Impress) voluntarily — there is no statutory press licensing in the UK — and a news agency's own website is generally outside the Online Safety Act.

Relevant to a specific activity in this sector.

Electronic Communications Code

Rights and obligations for communications network operators to install and maintain electronic communications apparatus on public and private land.

Relevant to a specific activity in this sector.

Which IT and programming regulations apply to your business

Computer programming, consultancy and IT service businesses share workplace-safety duties with every employer, then carry data protection duties that bite harder given the volume of personal data you handle, and — if you provide a relevant digital service above the NIS threshold — network and information systems security duties.

Relevant to a specific activity in this sector.

General Authorisation for Electronic Communications Services

Any provider of electronic communications services or networks in the UK operates under a general authorisation regime. No individual licence required, but providers must comply with general conditions.

Relevant to a specific activity in this sector.

Age verification for online services

How to implement age verification to comply with the Online Safety Act and ICO Children's Code. Covers verification methods, pornography requirements, privacy considerations, and gaming/gambling rules.

Relevant across several parts of this sector.

Network and Information Systems (NIS) Regulations

The NIS Regulations 2018 (as amended in 2022) require operators of essential services and relevant digital service providers to implement appropriate security measures, report significant incidents within 72 hours, and cooperate with sector-specific competent authorities. The Cyber Security and Resilience Bill (introduced November 2025) will further expand scope to managed service providers, data centres, and critical suppliers.

Relevant across several parts of this sector.

Sector-Specific

7

E-commerce legal compliance checklist

Quick reference checklist for online retailers to audit their e-commerce legal setup against the Consumer Contracts Regulations 2013 and the Digital Markets, Competition and Consumers Act 2024.

Relevant across several parts of this sector.

Run a compliant publishing business

Whatever you publish, the same core duties apply: respect copyright in the works you publish, protect the personal data you hold, follow the electronic marketing rules for subscriptions and promotions, insure your employees, and keep your workplace safe, fire-safe and free of discrimination. Put these in place before you add the rules for your kind of publishing.

Relevant to a specific activity in this sector.

Print and periodical publishing rules

If you publish books, newspapers, journals or directories — in print or online — three duties apply on top of the rules every publisher shares: you must deposit copies of what you publish with the legal deposit libraries, meet consumer subscription and cancellation rules, and (for directories and mailing lists) handle personal data lawfully.

Relevant to a specific activity in this sector.

Which publishing rules apply to your business

Publishing covers two very different businesses: print and periodical publishers (books, newspapers, journals, directories) and software and video-game publishers. Both share a core of duties — copyright, data protection, electronic-marketing rules and the usual workplace duties — but print publishers also have legal deposit and subscription rules, while game publishers must get age ratings. Work out which you are and follow the right guide.

Relevant to a specific activity in this sector.

Publishing compliance checklist

A confirmation checklist for publishing businesses. Work through the cross-cutting duties every publisher shares, then the section for what you publish — print and periodical, or software and video games.

Relevant to a specific activity in this sector.

Software and video-game publishing rules

If you publish software or video games, the standout duty is age rating: video games that are not exempt must carry a statutory age rating before supply, and supplying an unrated game is a criminal offence. You also need to protect and license your software copyright, and — if your game has chat or user-generated content — consider your Online Safety Act duties.

Relevant to a specific activity in this sector.

Software and AI as medical devices (SaMD/AIaMD)

How MHRA regulates software and AI-powered medical devices. Covers the SaMD definition and boundary guidance, current classification under UK MDR 2002, future reclassification to Class IIa minimum, Good Machine Learning Practice principles, predetermined change control plans, and clinical evidence for AI.

Relevant across several parts of this sector.

All journeys

Subsectors

SIC 2007 divisions covered by this sector.

Publishing

Publishing activities

SIC 58

Telecommunications

Telecommunications

SIC 61

IT & Software

Computer programming, consultancy and related activities

SIC 62

Information Services

Information service activities

SIC 63