Barnardo's

https://www.barnardos.org.uk · 51/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 6/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page contains no AI use policy or statement; it only describes the charity's mission, history, and organisational information.
    Fix: Publish a dedicated AI use policy or statement and link to it from the About page or site footer.
  • scope_clear: Because no AI policy is present, the page does not explain what AI is used for.
    Fix: Include a clear section in the AI policy describing the specific purposes and contexts in which AI is used by Barnardo's.

Privacy

Security

Transparency

  • transparent: Funding sources are not identified on this page itself; it only links out to the annual report without naming sources.
    Fix: Add a brief summary of key funding sources (e.g., donations, government contracts, retail, grants) directly on the About page with a link to the full report.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page references generic groups like 'Supporter Care Team' but does not name an individual or specific role responsible for contact enquiries.
    Fix: Add the name and job title of the person or specific role (e.g., Head of Supporter Care) accountable for responding to enquiries.
  • process_exists: The page lists 'Complaints' as a topic but does not document a complaints or feedback process on this page.
    Fix: Add a dedicated complaints section (or link to a complaints procedure page) describing how Barnardo's handles feedback and complaints.
  • steps_clear: No step-by-step instructions for making a complaint are provided on this contact page.
    Fix: Include clear numbered steps explaining how to submit a complaint, what information to provide, escalation routes, and expected outcomes.
  • appeals_exists: The contact page lists a complaints category but does not document an appeals process for decisions made by the organisation.
    Fix: Publish a clear appeals procedure describing how users can formally challenge decisions, including steps, timelines, and contact points.
  • independent: No mention is made of an independent reviewer or escalation path (such as to an ombudsman or regulator) for appeals.
    Fix: Document an escalation route to an independent body (e.g., Fundraising Regulator, Charity Commission, or ICO) when internal resolution is unsatisfactory.

AI & Automation

  • detailed_scope: No AI policy or detailed scope of AI use appears anywhere on the page.
    Fix: Add a detailed scope section to the AI policy outlining specific systems, use cases, and data involved.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Include an explicit statement of known AI limitations, such as accuracy, bias, and appropriate-use boundaries.
  • safeguards: No safeguards or quality controls relating to AI are described on the page.
    Fix: Document safeguards such as human oversight, review procedures, and quality assurance measures in the AI policy.
  • marking_policy: The page contains no policy or statement about marking AI-assisted content.
    Fix: Publish a clear policy explaining how AI-assisted content is labelled and link to it from the About page or footer.
  • consistent: Without a marking policy, there is no evidence of consistent AI content labelling on the page.
    Fix: Apply a consistent visible label or disclosure to any AI-assisted content across the site once a policy is in place.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans oversee and validate any AI-generated outputs used by the organisation.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Describe the specific review and approval steps AI-generated content must pass before publication.
  • accountability: No role or individual is identified as accountable for AI-generated content.
    Fix: Name a responsible role (e.g., editorial lead or governance officer) accountable for AI-generated content and publish their remit.

Interoperability

Privacy

  • comprehensive: Only the table of contents and introduction are visible; the actual sections on what data is collected, why, sharing, safety, and rights are not shown on this page content.
    Fix: Ensure the full content of sections 1-5 (data collected, uses, sharing, safety, legal rights) is rendered on the privacy notice page rather than only headings.
  • plain_language: The visible content only lists section headings and legal entity names without describing data practices in plain language.
    Fix: Include the plain-language explanations of each data practice directly on the page under each section heading.
  • understandable: A non-expert cannot determine from the visible content what data is collected or why, as only the structure is shown.
    Fix: Add clear, non-expert explanations under each heading describing what personal data is collected and the purposes for collecting it.
  • necessity: The visible content does not state that data collection is limited to what is necessary.
    Fix: Add an explicit statement that Barnardo's only collects personal data that is necessary for the stated purposes.
  • proportionate: There is no visible statement about proportionality of data collected relative to services provided.
    Fix: Include a statement confirming data collection is proportionate to the services offered, with examples tied to each service.
  • retention_stated: No data retention periods are mentioned anywhere in the visible content.
    Fix: Add a dedicated 'Data Retention' section specifying how long each category of personal data is kept.
  • specific: Since no retention information is present, no specific time periods are provided.
    Fix: Provide specific retention durations (e.g., '7 years for donation records', '2 years for enquiry emails') rather than vague language.
  • partner_sharing_mentioned: The banner mentions cookies for advertising, marketing, and analytics but does not explicitly disclose data sharing with third-party partners.
    Fix: Update the banner copy to explicitly state that data may be shared with third-party advertising, marketing, and analytics partners, and link to a partner list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Add a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full partner list.

Provenance

Security

Transparency

  • named_person: Only a generic 'Supporter Care Team' is mentioned; no named individual or clearly identified team lead is provided for enquiries.
    Fix: Identify a named individual or explicitly named team with contact details as the responsible point of contact for enquiries.
  • detail: The page provides no amounts, percentages, or categories of funding, only a pointer to the annual report.
    Fix: Include a short breakdown on-page showing funding categories with percentages or figures drawn from the latest annual report.
  • complete: No funding streams are enumerated on the page, so coverage of major streams cannot be confirmed.
    Fix: List all major income streams (individual giving, legacies, statutory/government income, retail, corporate partnerships, investments) with their relative contributions.
  • roles_clear: While roles like CEO and Trustees are named, their specific responsibilities and decision-making remits are not described on this page.
    Fix: Add a short description next to each governance role explaining their responsibilities and how they contribute to organisational decision-making.
  • algorithm_explained: The about page makes no mention of any algorithms or automated decision-making used by Barnardo's.
    Fix: Add a section describing any algorithms or automated tools used (e.g., in service delivery or analytics) and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users, beneficiaries, or site visitors.
    Fix: Include clear statements about the impact of any algorithmic decisions on children, families, and service users, including any consequences and safeguards.
  • annual_statement: The page links to a privacy notice and cookie notice but provides no evidence of a regular or periodic review of data practices.
    Fix: Add a statement to the privacy notice indicating when it was last reviewed and commit to a regular (e.g., annual) review cycle.
  • dated: There is no visible date or version indicator for the privacy notice or cookie notice referenced on the page.
    Fix: Display a 'last updated' date or version number on the privacy notice and cookie notice.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement commits to fixing issues 'continuously' and 'where possible' but provides no concrete dates or target timeline for remediation.
    Fix: Add specific target dates or a timeframe (e.g., 'we aim to fix the remaining issues by Q4 2025') for resolving the listed non-accessible content.
  • feedback_channel: The statement invites users to 'contact us' to report problems but does not state any commitment to respond within a defined timeframe.
    Fix: Include a stated response commitment, such as 'we will respond to accessibility feedback within 5 working days,' alongside the contact link.

Accountability

  • enforcement: While Barnardo's reserves the right to edit, delete, or terminate access, the page does not explain the actual enforcement process, review steps, or appeals.
    Fix: Add a section describing how moderation decisions are made, who reviews reported content, expected timelines, and how users can appeal enforcement actions.

Interoperability

Security

  • plan_exists: The about page contains no published incident response plan or security policy, only organizational and charity information.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the site footer.
  • notification_commitment: There is no commitment to publicly notify users of significant security incidents anywhere on the page.
    Fix: Add a clear statement committing to notify affected users and the public in the event of a significant data or security incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in your incident response or privacy documentation.

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published on the page.
    Fix: Publish the specific criteria used in any algorithmic decisions, such as eligibility rules or data inputs, in a dedicated transparency page.
  • weighting: The page provides no information on how criteria are weighted or prioritised in any decisions.
    Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions so users understand how outcomes are reached.
  • auditable: The page contains no technical or procedural detail that would allow external audit or review of algorithms.
    Fix: Provide enough methodological detail (models, data sources, review processes) for independent auditors to assess algorithmic systems.
  • open_source: There is no mention of or link to publicly available source code for the site on the about page.
    Fix: Publish any in-house website or service code to a public repository (e.g., GitHub) and link to it from the about or accessibility page.
  • tech_docs: No technical documentation about the website's platform, APIs, or data is published or linked from this page.
    Fix: Provide a technical documentation page or developer section describing the site's technology stack, APIs, or open data resources.

Responsibility to the Future

  • disclosure_exists: The About page covers history, EDI, policy work, and governance but contains no environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About page and footer.
  • specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
    Fix: Add quantified environmental metrics (e.g., annual carbon footprint in tonnes CO2e and energy consumption) to the sustainability disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy source or carbon profile, ideally noting use of renewable-powered or green hosting.
  • plan_exists: The page describes Barnardo's mission, history, and governance but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan outlining how services, obligations, and digital assets would be handled if the organisation ceased operating.
  • data_and_content_fate: The page links to a privacy notice but does not address what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add a section (or extend the privacy notice) specifying how user data and published content would be preserved, transferred, or deleted upon organisational closure.
  • custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners responsible for maintaining content or data if the organisation exits.
    Fix: Name a designated custodian, archive partner, or mirror arrangement to ensure content and records remain accessible after any organisational exit.
  • policy_exists: The page describes Barnardo's mission, history, and EDI work but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the about page or footer.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere in the page content.
    Fix: Add explicit commitments on staff pay, working hours, mental health support, and benefits to a dedicated wellbeing policy.
  • accountability: While the page mentions a CEO and Board of Trustees, it does not identify any accountability or oversight specifically for worker conditions or wellbeing.
    Fix: Name the body or role responsible for overseeing worker conditions and describe how they are held accountable.