Closed
Ofcom
Mega, with respect to its service Transfer.it
9 April 2026
17 August 2026
On 17 March 2025, we opened an enforcement programme to assess the measures being taken by providers of file-sharing and file-storage services that present particular risks of harm to UK users from image-based CSAM to ensure users do not encounter, and offenders are not able to disseminate, such content on their services.
Our analysis of Transfer.it raised concerns as to whether the service provider, Mega, was taking appropriate measures to ensure that users in the UK were prevented from encountering and sharing image-based CSAM on the service. In particular, we were concerned whether the provider’s illegal content risk assessment was suitable and sufficient, and whether it had implemented appropriate measures – especially perceptual hash matching technology as recommended in our Illegal Content Code of Practice – to effectively mitigate and manage the risk of the service being used for the storage and dissemination of image-based CSAM on its service.
Sections 9(2), 10(2) and 10(3) of the Online Safety Act 2023.
Background
Ofcom is the UK’s online safety regulator. Under the Online Safety Act, we are responsible for ensuring that services have systems and processes in place to protect UK users from illegal online content and protect child users in the UK from content harmful to children.
On 17 March 2025, we opened an enforcement programme to assess the measures being taken by providers of file-sharing and file-storage services, which present particular risks of harm to UK users from image-based CSAM, to ensure users do not encounter, and offenders are not able to disseminate, such content on their services.
Under our enforcement programme, our taskforce dedicated to driving compliance with small but risky services has identified and contacted relevant services to advise them of their duties under the Online Safety Act. Following this engagement, we opened several investigations into file-sharing and file-storage services to assess whether the providers of these services had failed/were failing to comply with their duties under the Act.
Alongside this formal enforcement action, we also gave a small number of service providers an opportunity to address our compliance concerns through ‘compliance remediation’, in lieu of opening formal investigations.
Our concerns
Our initial assessment of the service Transfer.it raised concerns about whether the provider of this service, Mega, had taken appropriate measures to ensure that users do not encounter, and offenders are not able to disseminate, image-based CSAM on its service.
In particular, we were concerned whether:
- The illegal content risk assessment undertaken by Mega for Transfer.it was suitable and sufficient; and,
- Mega had implemented perceptual hash matching for images and videos on Transfer.it which utilised a hash dataset sourced from one or more persons with expertise in the identification of CSAM.
Following engagement with Mega in order to understand more about the Transfer.it service, and in light of its constructive engagement with Ofcom about our concerns, we offered Mega the opportunity to complete a period of compliance remediation in lieu of an investigation.
Mega’s commitments
Through our compliance remediation process, Mega agreed to review and revise its illegal content risk assessment for Transfer.it. In particular, Mega took steps to reassess the level of risk it had assigned to the likelihood of its service being used for the storage and/or dissemination of image-based CSAM, to better reflect the inherent risk presented by file-storage and file-sharing services, as set out in Ofcom’s Risk Profiles.
We also engaged with Mega about whether it had perceptual hash matching in place on Transfer.it, and whether the hashes used were sourced from one or more persons with expertise in the identification of image-based CSAM (as set out in ICU C9 in our Illegal Content Codes of Practice). We received confirmation from Mega, within the deadlines set for the compliance remediation process, that it had fully implemented appropriate perceptual hash matching solutions for images and videos on Transfer.it.
Our response
We welcome the proactive approach that Mega has taken to engaging with Ofcom and its commitment to making timely and tangible improvements to the design and operation of its service Transfer.it.
Considering Mega’s constructive approach to engaging with Ofcom, its willingness to make improvements to the design and operation of its service to directly address our concerns, and our desire to work productively with providers where possible to drive rapid improvements that increase the safety of UK users, we have decided to close this period of compliance remediation with Mega and take no further action at this time.
We will continue to monitor Transfer.it to assess whether the measures implemented on the service are working effectively.
Our enforcement programme will remain open, and we will continue assessing the measures that other regulated service providers have taken to prevent users from encountering and sharing image-based CSAM.