About The Harm Watch
Why this exists
If you find a website today that is scamming people, hosting intimate images shared without consent, pushing self harm content at teenagers, or serving pornography to anyone who clicks past a birthday box, there is no obvious place to say so.
You can report it to the platform hosting it, if there is one and if you can find the form. You can report it to Ofcom, who regulate services rather than chase individual sites. You can report it to Action Fraud, or the police, or the hosting provider, or the registrar, and each of those routes asks for something slightly different and tells you nothing afterwards. Most people, quite reasonably, give up somewhere in the middle and close the tab.
Meanwhile the organisations who could actually do something — the charities monitoring a particular harm, the regulators building a case, the internet service providers, the legal teams acting for people who have been hurt — are all working from their own partial view. Nobody is short of concern. Everybody is short of signal.
The Harm Watch is an attempt to close that gap with something deliberately small. One page where anyone can report a website in under a minute, and a structured, private feed of those reports for the organisations equipped to act on them.
What it does
Someone finds a harmful site. They paste the URL, pick a category or two that describes the harm, and submit. That takes about thirty seconds and requires no account, no email address and no explanation of who they are.
Behind that, we normalise and deduplicate the URL, so the tenth person to report the same site strengthens an existing record rather than creating a new one. Reports are categorised against a taxonomy shaped around the harms the Online Safety Act 2023 is concerned with, and against the priorities Ofcom has set out for its own work, which currently centre on protecting children, countering terrorist and hateful content, and the safety of women and girls online.
Approved organisations can then browse, filter and export that data, or pull it through an API if their work needs a live feed. Access is granted rather than open, and we vet who gets it.
What it deliberately does not do
We are a signal, not a verdict. A submission is an allegation made by a member of the public. It is not a finding, not a legal determination and not evidence that a site has broken any law. Everything in the product, from the wording on the form to the field names in the database, is built to hold that line.
We do not host, mirror, screenshot, cache or crawl the sites people report. We store the address and the classification, nothing else. Building a searchable archive of harmful material in order to fight harmful material would be an act of remarkable self defeat.
We are not a takedown service. We have no power to remove anything, and we do not contact hosts or registrars on your behalf. What we can do is make sure the people who do have that power can see the pattern.
We are not the police, not Ofcom, and not a replacement for either. If someone is in immediate danger, that is a 999 call, not a web form.
And two categories never enter our system at all. Reports of child sexual abuse material go to the Internet Watch Foundation, and reports of terrorist content go to the government's dedicated reporting route. We route you there rather than accepting the report, and we do not record the URL. A queryable, exportable list of those addresses would be worse than useless — it would be dangerous.
Who it is for
The public side is for anyone. You do not need to know which law applies, or whether the site is technically in scope of anything. If it looks wrong, report it and let the classification happen behind the scenes.
The access side is for organisations with a legitimate reason to see the data. In practice that means charities and civil society organisations working on a specific harm, public bodies and regulators, internet service providers and infrastructure companies, and legal practitioners acting for people who have been harmed online. The Online Safety Act's super complaints route gives eligible bodies a formal way to raise systemic problems with Ofcom, and evidence of pattern is exactly what that kind of complaint needs.
Access is reviewed individually. We ask what you intend to do with the data, and we say no when the answer is unconvincing.
How we handle the data
Reporters are anonymous by default. We do not ask who you are, and if you choose to leave an email address so we can follow up, that address is never shared with the organisations receiving the feed.
The list is not public. That is a considered decision rather than a technical limitation. Publishing unverified public allegations against named websites invites brigading, defamation and the weaponisation of the form itself, and it is far easier to open something up later than to unpick the damage from having opened it too early.
Records are never deleted. When a site comes down, it is marked as removed and stays in the list, because the history of what was up, for how long, and how often it was reported is often the most useful thing in the dataset.
The full detail is in our Privacy Notice, and the rules of use are in our Terms of Use.
Who is behind it
The Harm Watch is operated by [LEGAL ENTITY], based in the United Kingdom. It is independent, and it is not affiliated with Ofcom, the Internet Watch Foundation, any police force, or any of the organisations who hold access to the data.
It exists because the reporting infrastructure for online harm was built platform by platform, harm by harm, over twenty odd years, and nobody ever stood back and asked what it looks like from the point of view of the person who just wants to tell someone. This is an attempt at that view.
Get in touch
- General enquiries: hello@harm.watch
- Organisation access: access@harm.watch
- Privacy and data protection: privacy@harm.watch
- If your website appears in our data and you believe it should not: listings@harm.watch
Other reporting routes
External links are listed as plain text — copy and paste into your browser rather than clicking.