Barnardo's
https://www.barnardos.org.uk · 51/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (7 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page contains no AI use policy or statement; it only describes the charity's mission, history, and organisational information.
Fix: Publish a dedicated AI use policy or statement and link to it from the About page or site footer.
-
scope_clear: Because no AI policy is present, the page does not explain what AI is used for.
Fix: Include a clear section in the AI policy describing the specific purposes and contexts in which AI is used by Barnardo's.
- Not found at any of: /ai-policy, /ai.
Privacy
- Detected 2 data-leaking services across 1 category: google maps (maps.googleapis.com, maps.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.barnardos.org.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
transparent: Funding sources are not identified on this page itself; it only links out to the annual report without naming sources.
Fix: Add a brief summary of key funding sources (e.g., donations, government contracts, retail, grants) directly on the About page with a link to the full report.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page references generic groups like 'Supporter Care Team' but does not name an individual or specific role responsible for contact enquiries.
Fix: Add the name and job title of the person or specific role (e.g., Head of Supporter Care) accountable for responding to enquiries.
-
process_exists: The page lists 'Complaints' as a topic but does not document a complaints or feedback process on this page.
Fix: Add a dedicated complaints section (or link to a complaints procedure page) describing how Barnardo's handles feedback and complaints.
-
steps_clear: No step-by-step instructions for making a complaint are provided on this contact page.
Fix: Include clear numbered steps explaining how to submit a complaint, what information to provide, escalation routes, and expected outcomes.
-
appeals_exists: The contact page lists a complaints category but does not document an appeals process for decisions made by the organisation.
Fix: Publish a clear appeals procedure describing how users can formally challenge decisions, including steps, timelines, and contact points.
-
independent: No mention is made of an independent reviewer or escalation path (such as to an ombudsman or regulator) for appeals.
Fix: Document an escalation route to an independent body (e.g., Fundraising Regulator, Charity Commission, or ICO) when internal resolution is unsatisfactory.
AI & Automation
-
detailed_scope: No AI policy or detailed scope of AI use appears anywhere on the page.
Fix: Add a detailed scope section to the AI policy outlining specific systems, use cases, and data involved.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include an explicit statement of known AI limitations, such as accuracy, bias, and appropriate-use boundaries.
-
safeguards: No safeguards or quality controls relating to AI are described on the page.
Fix: Document safeguards such as human oversight, review procedures, and quality assurance measures in the AI policy.
-
marking_policy: The page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy explaining how AI-assisted content is labelled and link to it from the About page or footer.
-
consistent: Without a marking policy, there is no evidence of consistent AI content labelling on the page.
Fix: Apply a consistent visible label or disclosure to any AI-assisted content across the site once a policy is in place.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a statement describing how humans oversee and validate any AI-generated outputs used by the organisation.
-
review_process: No review or approval workflow for AI content is described on the page.
Fix: Describe the specific review and approval steps AI-generated content must pass before publication.
-
accountability: No role or individual is identified as accountable for AI-generated content.
Fix: Name a responsible role (e.g., editorial lead or governance officer) accountable for AI-generated content and publish their remit.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: Only the table of contents and introduction are visible; the actual sections on what data is collected, why, sharing, safety, and rights are not shown on this page content.
Fix: Ensure the full content of sections 1-5 (data collected, uses, sharing, safety, legal rights) is rendered on the privacy notice page rather than only headings.
-
plain_language: The visible content only lists section headings and legal entity names without describing data practices in plain language.
Fix: Include the plain-language explanations of each data practice directly on the page under each section heading.
-
understandable: A non-expert cannot determine from the visible content what data is collected or why, as only the structure is shown.
Fix: Add clear, non-expert explanations under each heading describing what personal data is collected and the purposes for collecting it.
-
necessity: The visible content does not state that data collection is limited to what is necessary.
Fix: Add an explicit statement that Barnardo's only collects personal data that is necessary for the stated purposes.
-
proportionate: There is no visible statement about proportionality of data collected relative to services provided.
Fix: Include a statement confirming data collection is proportionate to the services offered, with examples tied to each service.
-
retention_stated: No data retention periods are mentioned anywhere in the visible content.
Fix: Add a dedicated 'Data Retention' section specifying how long each category of personal data is kept.
-
specific: Since no retention information is present, no specific time periods are provided.
Fix: Provide specific retention durations (e.g., '7 years for donation records', '2 years for enquiry emails') rather than vague language.
-
partner_sharing_mentioned: The banner mentions cookies for advertising, marketing, and analytics but does not explicitly disclose data sharing with third-party partners.
Fix: Update the banner copy to explicitly state that data may be shared with third-party advertising, marketing, and analytics partners, and link to a partner list.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Add a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full partner list.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
named_person: Only a generic 'Supporter Care Team' is mentioned; no named individual or clearly identified team lead is provided for enquiries.
Fix: Identify a named individual or explicitly named team with contact details as the responsible point of contact for enquiries.
-
detail: The page provides no amounts, percentages, or categories of funding, only a pointer to the annual report.
Fix: Include a short breakdown on-page showing funding categories with percentages or figures drawn from the latest annual report.
-
complete: No funding streams are enumerated on the page, so coverage of major streams cannot be confirmed.
Fix: List all major income streams (individual giving, legacies, statutory/government income, retail, corporate partnerships, investments) with their relative contributions.
-
roles_clear: While roles like CEO and Trustees are named, their specific responsibilities and decision-making remits are not described on this page.
Fix: Add a short description next to each governance role explaining their responsibilities and how they contribute to organisational decision-making.
-
algorithm_explained: The about page makes no mention of any algorithms or automated decision-making used by Barnardo's.
Fix: Add a section describing any algorithms or automated tools used (e.g., in service delivery or analytics) and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users, beneficiaries, or site visitors.
Fix: Include clear statements about the impact of any algorithmic decisions on children, families, and service users, including any consequences and safeguards.
-
annual_statement: The page links to a privacy notice and cookie notice but provides no evidence of a regular or periodic review of data practices.
Fix: Add a statement to the privacy notice indicating when it was last reviewed and commit to a regular (e.g., annual) review cycle.
-
dated: There is no visible date or version indicator for the privacy notice or cookie notice referenced on the page.
Fix: Display a 'last updated' date or version number on the privacy notice and cookie notice.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement commits to fixing issues 'continuously' and 'where possible' but provides no concrete dates or target timeline for remediation.
Fix: Add specific target dates or a timeframe (e.g., 'we aim to fix the remaining issues by Q4 2025') for resolving the listed non-accessible content.
-
feedback_channel: The statement invites users to 'contact us' to report problems but does not state any commitment to respond within a defined timeframe.
Fix: Include a stated response commitment, such as 'we will respond to accessibility feedback within 5 working days,' alongside the contact link.
Accountability
-
enforcement: While Barnardo's reserves the right to edit, delete, or terminate access, the page does not explain the actual enforcement process, review steps, or appeals.
Fix: Add a section describing how moderation decisions are made, who reviews reported content, expected timelines, and how users can appeal enforcement actions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The about page contains no published incident response plan or security policy, only organizational and charity information.
Fix: Publish a dedicated incident response plan or security policy and link to it from the site footer.
-
notification_commitment: There is no commitment to publicly notify users of significant security incidents anywhere on the page.
Fix: Add a clear statement committing to notify affected users and the public in the event of a significant data or security incident.
-
timeframe: No timeframe for disclosing incidents to affected users is stated on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in your incident response or privacy documentation.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published on the page.
Fix: Publish the specific criteria used in any algorithmic decisions, such as eligibility rules or data inputs, in a dedicated transparency page.
-
weighting: The page provides no information on how criteria are weighted or prioritised in any decisions.
Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions so users understand how outcomes are reached.
-
auditable: The page contains no technical or procedural detail that would allow external audit or review of algorithms.
Fix: Provide enough methodological detail (models, data sources, review processes) for independent auditors to assess algorithmic systems.
-
open_source: There is no mention of or link to publicly available source code for the site on the about page.
Fix: Publish any in-house website or service code to a public repository (e.g., GitHub) and link to it from the about or accessibility page.
-
tech_docs: No technical documentation about the website's platform, APIs, or data is published or linked from this page.
Fix: Provide a technical documentation page or developer section describing the site's technology stack, APIs, or open data resources.
Responsibility to the Future
-
disclosure_exists: The About page covers history, EDI, policy work, and governance but contains no environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About page and footer.
-
specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
Fix: Add quantified environmental metrics (e.g., annual carbon footprint in tonnes CO2e and energy consumption) to the sustainability disclosure.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the hosting provider's energy source or carbon profile, ideally noting use of renewable-powered or green hosting.
-
plan_exists: The page describes Barnardo's mission, history, and governance but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan outlining how services, obligations, and digital assets would be handled if the organisation ceased operating.
-
data_and_content_fate: The page links to a privacy notice but does not address what would happen to user data or published content in the event of organisational failure or exit.
Fix: Add a section (or extend the privacy notice) specifying how user data and published content would be preserved, transferred, or deleted upon organisational closure.
-
custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners responsible for maintaining content or data if the organisation exits.
Fix: Name a designated custodian, archive partner, or mirror arrangement to ensure content and records remain accessible after any organisational exit.
-
policy_exists: The page describes Barnardo's mission, history, and EDI work but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from the about page or footer.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere in the page content.
Fix: Add explicit commitments on staff pay, working hours, mental health support, and benefits to a dedicated wellbeing policy.
-
accountability: While the page mentions a CEO and Board of Trustees, it does not identify any accountability or oversight specifically for worker conditions or wellbeing.
Fix: Name the body or role responsible for overseeing worker conditions and describe how they are held accountable.