Bodleian Library
https://www.bodleian.ox.ac.uk · 44/92 checks passed · libraries
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 26/37 (11 failed) |
| Level 2 — Enhanced | 8/27 (19 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 0/2 |
| Security | 5/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- Heading hierarchy issues: h1 -> h3 (skipped h2).
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
-
scope_clear: No AI-related content appears on the page, so the scope of AI use is not explained.
Fix: Add a clear section describing where and how AI is (or is not) used across the Bodleian's services and collections.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: .youtube.com.
- 1 hidden iframe found: https://eu.libraryh3lp.com/chat/bodleian-livechat@chat.eu.libraryh3lp.com?identity=Bodleian+Libraries&skin=14009.
- Detected 3 data-leaking services across 2 categories: google fonts (fonts.googleapis.com, fonts.gstatic.com); youtube embed (www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.bodleian.ox.ac.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
purpose_clear: The page shows only navigation tiles (History, Careers, Business services) and does not state in prose what the Bodleian Libraries do.
Fix: Include an introductory paragraph at the top of /about explaining the Bodleian Libraries' purpose, scope, and services.
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only navigation links and general library information.
Fix: Add a dedicated funding/sponsorship section on the About page listing the organisation's funders and supporters.
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly name each funding body, donor, or sponsor supporting the Bodleian Libraries on this page or a linked disclosure page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page lists various contact routes but does not state any response timeframe for enquiries.
Fix: Add an expected response time (e.g. 'We aim to reply within 5 working days') next to each contact channel.
-
specific: Since no timeframes are given at all, there are no specific day/hour commitments published.
Fix: Publish concrete response windows in business days or hours for each enquiry type rather than vague language.
-
process_exists: The page offers enquiry contacts and a 'Website feedback' link but does not describe a documented complaints or feedback process.
Fix: Add a dedicated complaints/feedback section or link to a complaints policy explaining how issues are handled.
-
steps_clear: No step-by-step instructions are provided for submitting or escalating a complaint.
Fix: Document clear steps (how to submit, who reviews, escalation path, and outcome notification) for raising a complaint.
-
appeals_exists: The contact page lists various enquiry routes but does not document any appeals process for decisions or complaints.
Fix: Add a clearly labeled appeals or complaints procedure section explaining how users can formally challenge decisions.
-
independent: No appeals process is described, so there is no indication of independent review or escalation path.
Fix: Document an escalation path to an independent body or senior officer (e.g., University Proctors or an ombudsperson) for unresolved appeals.
AI & Automation
-
detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
Fix: Create an AI policy that enumerates specific AI applications (e.g., cataloguing, digitisation, search) and the systems involved.
-
limitations: The page does not acknowledge any AI system limitations since no AI policy exists.
Fix: Include a section in the AI policy that openly discusses known limitations such as bias, inaccuracy, and hallucinations.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human review, validation processes, and governance oversight within a published AI policy.
-
marking_policy: The About page contains no mention of any policy for marking AI-assisted content.
Fix: Publish a clear policy statement indicating how AI-assisted content is labeled or disclosed on the site.
-
consistent: Without a marking policy present, there is no evidence of consistent application of AI content labeling on the page.
Fix: Apply consistent AI content labels across all pages and reference the labeling convention in a public policy.
-
oversight_exists: The page does not document any human oversight of AI outputs.
Fix: Add a statement describing how humans oversee any AI-generated content used by the Bodleian.
-
review_process: No review or approval process for AI-generated content is described on the page.
Fix: Document the editorial review and approval workflow for AI-assisted material in an accessible policy page.
-
accountability: No individual or team is identified as accountable for AI-generated content.
Fix: Name a responsible role or team (e.g., a digital editor or governance lead) accountable for AI output quality and compliance.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary, only mentioning minimisation in the context of third-party sharing (Section H).
Fix: Add an explicit data minimisation statement affirming that only data necessary for stated purposes is collected.
-
specific: Section K provides only a vague statement ('as long as we need it') without specific time periods or retention schedules for different data categories.
Fix: Publish a retention schedule specifying concrete time periods (e.g., months/years) for each category of data collected.
-
no_dark_patterns: The policy states 'By visiting our site you are accepting and consenting to the practices described in this policy,' which is implied consent via browsing — a recognized dark pattern.
Fix: Replace implied browse-wrap consent with an explicit opt-in consent mechanism that requires an affirmative user action before cookies/tracking are set.
-
equal_choices: The page describes consent to cookies and Microsoft Clarity tracking but provides no visible reject option equally prominent to accept, only a vague reference to cookie consent.
Fix: Provide a cookie banner with 'Accept' and 'Reject' buttons presented with equal visual prominence (same size, color, and placement).
-
no_forced_consent: Consent appears bundled — visiting the site is treated as consent to all described practices including Microsoft Clarity behavioural tracking, session replay, and advertising cookies.
Fix: Unbundle consent by allowing users to granularly accept or reject each category (analytics, advertising, session replay) independently rather than treating site visits as blanket consent.
-
partner_sharing_mentioned: The banner copy describes essential, analytical, and functional cookies but does not disclose any data sharing with third-party partners.
Fix: Add explicit language in the banner naming third-party recipients (e.g., analytics providers) and linking to a list of partners with whom data is shared.
-
partner_count_specific: No specific numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: State an exact number of third-party partners (e.g., 'We share data with X partners') in the banner and link to the full list.
Provenance
- No author or date metadata found on the page.
-
credentials: The about page offers navigation tiles but no substantive background on the organisation's credentials or governance on this page itself.
Fix: Add a short paragraph (or visible summary) on the About page describing the Bodleian's role, governance, and institutional credentials with links to more detail.
Security
- security.txt not published.
Transparency
-
substantive: The page contains only short tile captions and no substantive statement of purpose.
Fix: Add a detailed statement of purpose describing the libraries' mission, collections, and public role beyond tagline-style captions.
-
mission_clear: No mission statement or editorial approach is articulated on the page.
Fix: Publish a clear mission statement on the About page describing the libraries' goals, values, and approach to collections and access.
-
detail: The page provides no financial detail such as amounts, percentages, or funding categories.
Fix: Publish a breakdown of funding by source (e.g., grants, donations, public funding) with amounts or percentages.
-
complete: No funding streams are disclosed, so coverage of major funding sources cannot be considered complete.
Fix: Provide a comprehensive funding statement covering all major income streams including public funds, grants, philanthropy, and commercial revenue.
-
governance_exists: The About page lists sections like History, Careers, and Business services but does not describe any governance or editorial structure for the libraries.
Fix: Add a governance section on the About page outlining the library's leadership, editorial oversight, and decision-making bodies.
-
roles_clear: No key roles or responsibilities (e.g., director, trustees, editorial leads) are identified anywhere on the page.
Fix: Publish a list of named leadership roles with their responsibilities, or link to a dedicated 'Our team/leadership' page from the About section.
-
algorithm_explained: The About page contains no mention of any algorithms or automated decision-making systems used by the Bodleian Libraries.
Fix: Add a section or link describing any algorithms used (e.g., in search, recommendations, or access decisions) and their purpose.
-
impact_clear: The page does not describe how any algorithmic decisions might affect users or library patrons.
Fix: Include a clear explanation of how algorithmic decisions impact users, such as effects on search results, resource access, or service delivery.
-
annual_statement: The page links to a privacy policy but shows no evidence of regular or annual review of data practices.
Fix: Add a note to the privacy policy indicating when it was last reviewed and commit to a periodic (e.g., annual) review cycle.
-
dated: The privacy policy link in the footer is not accompanied by any date or version indicator on this page.
Fix: Display a 'last updated' date or version number next to the privacy policy link or within the policy itself.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement says it is 'working hard' and 'it will take some time' but provides no specific dates or target timeline for fixing the known issues.
Fix: Add concrete target dates or milestones for remediating each category of known accessibility issue.
Accountability
-
policy_exists: The terms page only references the University's Ownership, Liability and Use policy and does not publish any moderation policy.
Fix: Publish a dedicated moderation policy on the terms page or link to a specific moderation policy document.
-
criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on the page.
Fix: Add a clearly written section listing specific criteria for acceptable content and grounds for moderation.
-
enforcement: The page does not describe any enforcement process, appeals, or actions taken against violators.
Fix: Include an explanation of the enforcement workflow, including reporting channels, review steps, sanctions, and appeal procedures.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains only navigation links, library service information, and general policy links with no published incident response plan or security policy.
Fix: Publish a dedicated incident response plan or security policy page describing how security incidents are detected, managed, and resolved.
-
notification_commitment: The page includes no statement committing to publicly notifying users of significant security incidents.
Fix: Add an explicit commitment to notify affected users and the public when a significant security or data incident occurs.
-
timeframe: There is no mention of any timeframe for disclosing incidents to affected users anywhere on the page.
Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of discovering a significant incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published or referenced on the About page.
Fix: Publish the specific criteria used in any algorithmic processes, for example on a dedicated transparency or algorithmic accountability page.
-
weighting: The page does not mention any weighting or prioritisation of criteria in algorithmic decisions.
Fix: Document how criteria are weighted or prioritised in any algorithmic systems used by the libraries.
-
auditable: There is no technical or procedural detail provided that would allow external audit or review of any algorithms.
Fix: Provide sufficient documentation (methodology, data sources, decision logic) to enable independent audit, or link to an algorithmic transparency register.
-
open_source: There is no link to source code or any open-source repository on the page.
Fix: If the Bodleian maintains any open-source projects, link to the relevant repository (e.g., GitHub) from the About or developer section.
-
tech_docs: No technical documentation or developer resources are linked from this page.
Fix: Provide or link to technical documentation (e.g., APIs for Digital Bodleian/ORA) from the About page or a dedicated developer page.
Responsibility to the Future
-
disclosure_exists: The About page and footer contain no published environmental impact or sustainability disclosure, only navigation, news, and standard legal links.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About page or footer.
-
specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
Fix: Include concrete metrics such as annual carbon emissions or energy consumption within a published sustainability report.
-
hosting_disclosure: There is no disclosure of the carbon or energy profile of the hosting infrastructure, only a 'powered by Oxford Mosaic' note with no environmental data.
Fix: Add information about the hosting provider's energy sources or carbon footprint, ideally referencing green or renewable-powered hosting.
-
plan_exists: The About page contains institutional history, careers, and business service links but no published plan for organisational failure or exit.
Fix: Publish a succession or continuity plan describing what happens to the libraries' digital services if the organisation ceases to operate.
-
data_and_content_fate: The page references resources like Digital Bodleian and ORA but does not state what would happen to user data or published content in a shutdown scenario.
Fix: Add a statement outlining how user data and published collections would be preserved, transferred, or handled if services end.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content in the event of closure.
Fix: Name specific custodians, mirror sites, or archival partners responsible for maintaining collections and data long-term.
-
policy_exists: The careers page describes the range of roles and mentions benefits via an external link but publishes no policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers page.
-
specific_commitments: The page only vaguely references discovering 'the benefits of working for the University of Oxford' without any specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete commitments detailing pay standards, working hours, mental health support, and staff benefits directly on the page.
-
accountability: No individual, team, or governance body is identified as responsible for overseeing worker conditions on this page.
Fix: Name a responsible department or role (e.g., HR or a wellbeing officer) and provide oversight/contact details for worker conditions.