Amnesty International UK
https://www.amnesty.org.uk · 56/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 33/37 (4 failed) |
| Level 2 — Enhanced | 8/27 (19 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish an AI use policy page and link to it from the About section or footer.
-
scope_clear: Because no AI policy is present, the scope of AI use is not explained anywhere on the page.
Fix: Add a clear statement describing what AI systems are used for (e.g., content generation, moderation, analytics) on the organisation's website.
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.amnesty.org.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page does not identify a named person or specific role responsible; it only references a generic 'telefundraising team' and a contact form.
Fix: Add the name or role title (e.g., Head of Supporter Services) of the person accountable for contact enquiries.
-
response_timeframe: The page only states 'we will get back to you as soon as we can' without publishing a response timeframe.
Fix: Add a specific response timeframe (e.g., 'we aim to respond within 5 working days') to the contact page.
-
specific: The language 'as soon as we can' is vague and not specific in days or hours.
Fix: Replace vague phrasing with a concrete timeframe such as a number of business days for initial response.
-
process_exists: The contact page shows only a form and phone numbers; no documented complaints or feedback process is visible or linked.
Fix: Add a dedicated complaints/feedback policy page (or link from the contact page) outlining how complaints are handled.
-
steps_clear: No steps for making a complaint are described—only a generic contact form is offered.
Fix: Publish clear step-by-step guidance (how to submit, what information to include, escalation path, expected timelines) for raising a complaint.
-
appeals_exists: The contact page only provides a general contact form and telefundraising numbers, with no documented appeals process.
Fix: Publish a clear appeals policy describing how individuals can formally appeal decisions, including steps, timelines, and contact channels.
-
independent: No appeals process is described, so there is no indication of independent review or escalation pathway.
Fix: Define an escalation route to an independent body or senior reviewer (e.g., trustees, ombudsman, or Fundraising Regulator) within the appeals policy.
AI & Automation
-
detailed_scope: The page does not provide any detail on the scope of AI use within Amnesty UK's operations.
Fix: Create a dedicated AI policy section describing specific use cases, tools, and data involved in AI deployments.
-
limitations: No acknowledgement of AI system limitations appears on this page.
Fix: Include a section in the AI policy that transparently acknowledges limitations such as bias, accuracy risks, and unsuitable use cases.
-
safeguards: The page describes no safeguards or quality controls related to AI systems.
Fix: Document safeguards such as human-in-the-loop review, auditing, and data protection measures in a published AI policy.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy stating if and how AI-assisted content is identified and labelled on the site.
-
consistent: Without any AI content marking policy visible on the page, consistent application cannot be demonstrated.
Fix: Apply visible AI-content labels consistently across pages and reference the labelling standard in the About or editorial policy section.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a statement to the governance or accountability section explaining how humans oversee any AI-generated outputs.
-
review_process: No review or approval workflow for AI content is described anywhere on the page.
Fix: Describe the editorial review and approval steps required before AI-assisted content is published.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content on this page.
Fix: Name a role or team (e.g., Editorial Lead) responsible for AI content and include contact details in the Accountability and Governance area.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The notice does not explicitly state that data collection is limited to what is necessary (data minimisation principle is not articulated).
Fix: Add an explicit statement that Amnesty only collects the minimum personal information necessary for each stated purpose.
-
retention_stated: The visible content references 'How we keep your information safe' and 'Other ways we look after your personal information' as headings but does not include explicit retention period statements in the shown text.
Fix: Add a clearly labelled 'Data retention' section that states how long each category of personal data is kept.
-
specific: No specific time periods for retention are given in the visible policy content.
Fix: Specify concrete retention durations (e.g., '7 years for financial records', '24 months after last interaction for marketing data') for each data category.
-
equal_choices: The page references a separate cookies statement but does not show accept/reject consent options on this privacy notice, so equal prominence cannot be confirmed here.
Fix: Ensure the cookie/consent banner linked from this page presents 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement).
-
banner_present: No cookie or consent banner text is visible on the page; only a footer 'Cookies statement' and 'Cookies settings' link are shown.
Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or customise cookies before non-essential cookies are set.
-
partner_sharing_mentioned: The page content does not disclose any data sharing with third-party partners in banner or on-page consent copy.
Fix: Add explicit disclosure within the cookie banner stating that data may be shared with third-party partners, with a link to the full list.
-
partner_count_specific: No specific numeric count of partners is stated anywhere in the visible page content.
Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner or linked preference centre.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: Only a vague 'telefundraising team' is mentioned; no named individual or clearly identified team lead handles general enquiries.
Fix: Identify the specific team (e.g., Supporter Communications Team) or individual responsible for handling enquiries submitted through the contact form.
-
role_clear: The page does not explain the role, remit, or authority of whoever receives and responds to enquiries.
Fix: Add a short description of the responsible team's role and what types of enquiries they handle and respond to.
-
detail: The page references finances and funding but provides no amounts, percentages, or categorical breakdowns of funding sources on this page.
Fix: Add a summary of funding figures or percentage breakdowns (e.g., % from individual donors, grants, legacies) directly on the About page or in a clearly linked finance summary.
-
complete: The disclosure only mentions independence and supporter reliance without enumerating all major funding streams such as memberships, legacies, grants, or trading income.
Fix: List all major funding streams (memberships, donations, legacies, grants, shop/trading income, etc.) with approximate contributions to give a complete picture.
-
roles_clear: While governance structure is mentioned, the page does not identify specific key roles or responsibilities (e.g., trustees, directors, board members) or their duties.
Fix: Add a summary of key governance roles (e.g., board of trustees, directors, leadership team) with their names and responsibilities directly on the About page or via a clearly linked leadership/governance page.
-
algorithm_explained: The About page does not mention any algorithms or automated decision-making processes or explain their purpose.
Fix: If algorithms are used (e.g., for donor targeting or content personalization), add a section or link describing their purpose on the About page.
-
impact_clear: There is no description of how any algorithmic decisions might affect users on this page.
Fix: Include a clear statement of how any automated systems affect users (e.g., email targeting, recommendations) and link to a fuller explanation.
-
annual_statement: The page links to a privacy notice but provides no evidence of a regular or periodic review of data practices.
Fix: Add a statement indicating when the privacy notice is reviewed (e.g., annually) and publish a changelog or review history.
-
dated: There is no visible date or version indicator for the privacy notice or data practices statement on this page.
Fix: Display a 'last updated' date or version number next to the privacy notice link or within the privacy notice itself.
Level 3 — Advanced
Accessibility
-
statement_exists: The page and its footer links (Terms, Cookies, Privacy, Community rules) contain no dedicated accessibility statement.
Fix: Create a dedicated accessibility statement page and link it from the footer alongside the other policy links.
-
known_issues: No accessibility statement is present, so no known accessibility issues or limitations are acknowledged.
Fix: Include a section in the accessibility statement listing known non-compliant elements and any content that is not yet accessible.
-
remediation_timeline: There is no accessibility statement and therefore no stated timeline or commitment to fix issues.
Fix: Add target dates or a remediation plan for resolving identified accessibility barriers within the statement.
-
feedback_channel: No accessibility-specific feedback mechanism or response commitment is provided on the page.
Fix: Provide a dedicated contact method for accessibility problems with a stated response timeframe in the accessibility statement.
Accountability
-
enforcement: While clause 9.11 mentions termination of registration, the page (as shown) does not fully explain the enforcement process such as reporting, review, appeals, or timelines.
Fix: Add a dedicated enforcement section describing how violations are reported, who reviews them, the actions taken (warning, removal, suspension), and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page contains no published incident response plan or security policy, only general organizational and governance information.
Fix: Publish an incident response plan or security policy and link to it from the site, for example under Accountability and governance or Safeguarding.
-
notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public about significant incidents, ideally within the privacy notice or a dedicated security page.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy or privacy notice.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for algorithmic decisions are published anywhere on this About page.
Fix: Publish the specific criteria used by any algorithmic systems in a dedicated transparency page linked from About.
-
weighting: The page provides no information about weighting or prioritisation of decision criteria.
Fix: Document and publish how criteria are weighted or prioritised in any algorithmic decision processes.
-
auditable: The page lacks any technical or procedural detail that would enable external audit or review of algorithms.
Fix: Provide detailed algorithmic documentation (inputs, logic, outputs, governance) sufficient for independent audit, and link it from the About page.
-
open_source: The page contains no links to source code repositories or any mention of open-source availability for the site or its tools.
Fix: Add a link (e.g., in the footer or a dedicated developer/transparency page) to any public repositories, or publish a statement about the site's source code availability.
-
tech_docs: No technical documentation, API references, or developer resources are referenced anywhere on the about page.
Fix: Publish and link to basic technical documentation (such as an API, data schema, or developer page) from the about or footer area.
Responsibility to the Future
-
disclosure_exists: The page discusses the climate crisis as a human rights issue but contains no published environmental impact or sustainability disclosure about the organization's own operations.
Fix: Publish a dedicated environmental or sustainability disclosure describing the organization's operational footprint and reduction commitments.
-
specific_metrics: The page provides no specific figures on carbon, energy use, or emissions related to the site owner's activities.
Fix: Include concrete metrics such as annual carbon emissions, energy consumption, or measurable reduction targets in the disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy source or the site's carbon footprint, ideally referencing green hosting certifications.
-
plan_exists: The About page describes governance, finances and structure but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing what would happen to the organisation and its operations in the event of closure or exit.
-
data_and_content_fate: There is no mention of what would happen to user data or published content if the organisation ceased to operate.
Fix: Add a section explaining how user data would be handled and how published content would be preserved or transferred should the organisation shut down.
-
custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners to preserve content in the event of failure.
Fix: Name a designated custodian, mirror, or archive partner (e.g. a national archive or Amnesty International global body) responsible for maintaining content after any exit.
-
policy_exists: The page references a 'Work with us' section mentioning policies and vacancies but does not publish or link to any specific worker wellbeing or working conditions policy on this page.
Fix: Publish or directly link to a dedicated worker wellbeing/working conditions policy from the 'Work with us' section.
-
specific_commitments: The page contains no specific commitments on pay, working hours, mental health, or employee benefits.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits to the worker wellbeing content.
-
accountability: While governance and accountability structures are mentioned, none of them are tied to oversight of worker conditions or wellbeing.
Fix: Identify a named role, committee, or governance body responsible for overseeing worker conditions and wellbeing.