Quick answer: Online harassment laws criminalize repeated unwanted contact, credible threats, and sharing private data to cause harm. While specific statutes vary across the US, UK, and EU, they generally require a pattern of conduct, intent to distress, and a reasonable person standard. Most jurisdictions do not penalize isolated offensive comments due to free speech protections, focusing instead on severe, persistent abuse.
Online harassment sits in a legal gray zone that most people misunderstand. What feels like harassment is not always illegal, and what is illegal is not always enforceable in practice. Here is the honest map of what the law actually covers in 2026.
The line between offensive and illegal
Most jurisdictions draw the line at a small number of specific behaviors: repeated unwanted contact after being told to stop, credible threats of physical harm, publication of private information intended to enable harm, and content targeting protected characteristics in a way that meets the local definition of harassment. A single rude comment, a negative review, or an angry public post almost never crosses the line on its own - even when it feels like it does.
The legal test in most countries has three parts: a pattern of conduct, an intent to cause distress or fear, and a reasonable person standard for whether the target actually experienced it. All three usually have to be present. Prosecutors and courts are cautious about criminalizing speech, which means the threshold for a criminal case is higher than most victims expect.
United States
Federal law covers cyberstalking under 18 U.S.C. Section 2261A, which makes it a crime to use the internet to cause substantial emotional distress or a reasonable fear of harm across state lines. Every state also has its own harassment or stalking statute, and most have specific provisions for electronic communications. The Interstate Communications Act covers true threats made online. Section 230 of the Communications Decency Act shields platforms from liability for user content, which is why most enforcement focuses on the individual harasser rather than the site hosting the content.
The practical route in the US is usually a combination of platform reporting, a documented pattern of conduct, and either a civil restraining order or a criminal complaint to local law enforcement. Federal charges are rare and reserved for the most serious cases.
United Kingdom
The UK moved further than most countries with the Online Safety Act, which came into full force in 2024 and has been actively enforced through 2025 and 2026. It criminalizes threatening communications, false communications intended to cause harm, and cyberflashing. It also imposes a duty of care on platforms to remove illegal content quickly, with Ofcom empowered to fine companies up to ten percent of global turnover for systemic failures.
The Malicious Communications Act 1988 and the Protection from Harassment Act 1997 remain the workhorses for individual cases. The harassment act specifically requires a "course of conduct" - two or more incidents - which is why isolated posts, however offensive, rarely lead to prosecution.
European Union
The Digital Services Act creates a uniform framework across EU member states for handling illegal online content, including harassment. Very large online platforms must offer clear reporting mechanisms, act on notices quickly, and publish transparency reports on how they handle complaints. National laws still define what counts as harassment - Germany's Network Enforcement Act, France's laws on online abuse, and similar statutes across other member states.
The GDPR also gives victims a right to have personal data removed when publication causes harm, which has become one of the more effective tools for taking down doxxing content, even when the underlying speech is not itself illegal.
What businesses can and cannot do
A business that receives a genuinely harassing review or social media campaign has three practical options. The first is to report the content to the platform under its own community guidelines, which are usually stricter than the law. Most platforms will remove content that targets a business with credible threats, coordinated attacks, or clear factual falsehoods. The second is to send a cease and desist letter through a lawyer, which resolves a surprising number of cases without further action. The third is to pursue civil defamation - not harassment - because businesses are generally not covered by harassment law in the same way individuals are.
What a business cannot do is treat a negative review as harassment. Even a strongly worded, unfair, or emotionally hostile review that stays within the platform's rules is protected speech in every jurisdiction discussed here. The right response to a review of that kind is a professional public reply, a private effort to resolve the underlying issue, and a policy report only if the content genuinely violates a specific rule.
Documenting for a case
Whether you are pursuing a criminal complaint, a civil suit, or a platform escalation, documentation is everything. Screenshots with timestamps and full URLs, a chronological log of every incident, evidence of the impact on the target, and preservation of any account information for the harasser. Most cases that fail in court fail because the documentation was not systematic enough to prove the pattern that harassment law requires.
The honest limit of the law
The uncomfortable truth is that law enforcement in most jurisdictions is under-resourced for online harassment cases that fall short of credible physical threats. Even well-documented cases often result in warnings rather than prosecution. Platform enforcement is faster and more consistent, which is why most experienced practitioners exhaust the platform route before turning to the legal system. The law is a backstop, not a first responder - and understanding that shapes how you spend your time when something goes wrong.
Frequently Asked Questions
What legally constitutes online harassment?
Online harassment typically involves a pattern of unwanted contact, credible threats of physical harm, or the publication of private information intended to cause distress. General rudeness or single negative comments usually do not meet the legal threshold. Laws require proof of intent to harm and a course of conduct rather than isolated incidents to be actionable.
How does the US specifically deal with online harassment?
US law covers cyberstalking under federal statutes like 18 U.S.C. Section 2261A, which addresses causing substantial emotional distress across state lines. Most states also have their own specific laws against electronic harassment or stalking. Platforms are generally protected from liability for user content by Section 230, so enforcement targets the individual harasser.
What is the UK's approach to online harassment, including the Online Safety Act?
The UK's Online Safety Act criminalizes threatening and false communications intended to cause harm, and cyberflashing. It also mandates platforms to remove illegal content efficiently. Existing laws like the Malicious Communications Act and Protection from Harassment Act require a "course of conduct" (two or more incidents) for prosecution, meaning isolated offensive posts are rarely pursued.
Does the EU have unified laws against online harassment?
The EU's Digital Services Act (DSA) creates a framework for very large online platforms to handle illegal content, including harassment, by requiring clear reporting mechanisms and quick action. However, national laws within member states, such as Germany's Network Enforcement Act, still define what constitutes harassment. GDPR can also be used to remove harmful private data.
Can businesses be held responsible for online harassment occurring on their platforms?
The extent of business responsibility varies by jurisdiction. In the US, Section 230 largely shields platforms from liability for user-generated content. However, the UK's Online Safety Act imposes a duty of care on platforms to remove illegal content, with potential for significant fines. The EU's DSA also mandates platforms to address illegal content and provide reporting tools for users.


