Bodleian Library

https://www.bodleian.ox.ac.uk · 44/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 0/2
Security 5/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement of any kind.
    Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
  • scope_clear: No AI-related content appears on the page, so the scope of AI use is not explained.
    Fix: Add a clear section describing where and how AI is (or is not) used across the Bodleian's services and collections.

Privacy

Security

Transparency

  • purpose_clear: The page shows only navigation tiles (History, Careers, Business services) and does not state in prose what the Bodleian Libraries do.
    Fix: Include an introductory paragraph at the top of /about explaining the Bodleian Libraries' purpose, scope, and services.
  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only navigation links and general library information.
    Fix: Add a dedicated funding/sponsorship section on the About page listing the organisation's funders and supporters.
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly name each funding body, donor, or sponsor supporting the Bodleian Libraries on this page or a linked disclosure page.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists various contact routes but does not state any response timeframe for enquiries.
    Fix: Add an expected response time (e.g. 'We aim to reply within 5 working days') next to each contact channel.
  • specific: Since no timeframes are given at all, there are no specific day/hour commitments published.
    Fix: Publish concrete response windows in business days or hours for each enquiry type rather than vague language.
  • process_exists: The page offers enquiry contacts and a 'Website feedback' link but does not describe a documented complaints or feedback process.
    Fix: Add a dedicated complaints/feedback section or link to a complaints policy explaining how issues are handled.
  • steps_clear: No step-by-step instructions are provided for submitting or escalating a complaint.
    Fix: Document clear steps (how to submit, who reviews, escalation path, and outcome notification) for raising a complaint.
  • appeals_exists: The contact page lists various enquiry routes but does not document any appeals process for decisions or complaints.
    Fix: Add a clearly labeled appeals or complaints procedure section explaining how users can formally challenge decisions.
  • independent: No appeals process is described, so there is no indication of independent review or escalation path.
    Fix: Document an escalation path to an independent body or senior officer (e.g., University Proctors or an ombudsperson) for unresolved appeals.

AI & Automation

  • detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
    Fix: Create an AI policy that enumerates specific AI applications (e.g., cataloguing, digitisation, search) and the systems involved.
  • limitations: The page does not acknowledge any AI system limitations since no AI policy exists.
    Fix: Include a section in the AI policy that openly discusses known limitations such as bias, inaccuracy, and hallucinations.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human review, validation processes, and governance oversight within a published AI policy.
  • marking_policy: The About page contains no mention of any policy for marking AI-assisted content.
    Fix: Publish a clear policy statement indicating how AI-assisted content is labeled or disclosed on the site.
  • consistent: Without a marking policy present, there is no evidence of consistent application of AI content labeling on the page.
    Fix: Apply consistent AI content labels across all pages and reference the labeling convention in a public policy.
  • oversight_exists: The page does not document any human oversight of AI outputs.
    Fix: Add a statement describing how humans oversee any AI-generated content used by the Bodleian.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Document the editorial review and approval workflow for AI-assisted material in an accessible policy page.
  • accountability: No individual or team is identified as accountable for AI-generated content.
    Fix: Name a responsible role or team (e.g., a digital editor or governance lead) accountable for AI output quality and compliance.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to what is necessary, only mentioning minimisation in the context of third-party sharing (Section H).
    Fix: Add an explicit data minimisation statement affirming that only data necessary for stated purposes is collected.
  • specific: Section K provides only a vague statement ('as long as we need it') without specific time periods or retention schedules for different data categories.
    Fix: Publish a retention schedule specifying concrete time periods (e.g., months/years) for each category of data collected.
  • no_dark_patterns: The policy states 'By visiting our site you are accepting and consenting to the practices described in this policy,' which is implied consent via browsing — a recognized dark pattern.
    Fix: Replace implied browse-wrap consent with an explicit opt-in consent mechanism that requires an affirmative user action before cookies/tracking are set.
  • equal_choices: The page describes consent to cookies and Microsoft Clarity tracking but provides no visible reject option equally prominent to accept, only a vague reference to cookie consent.
    Fix: Provide a cookie banner with 'Accept' and 'Reject' buttons presented with equal visual prominence (same size, color, and placement).
  • no_forced_consent: Consent appears bundled — visiting the site is treated as consent to all described practices including Microsoft Clarity behavioural tracking, session replay, and advertising cookies.
    Fix: Unbundle consent by allowing users to granularly accept or reject each category (analytics, advertising, session replay) independently rather than treating site visits as blanket consent.
  • partner_sharing_mentioned: The banner copy describes essential, analytical, and functional cookies but does not disclose any data sharing with third-party partners.
    Fix: Add explicit language in the banner naming third-party recipients (e.g., analytics providers) and linking to a list of partners with whom data is shared.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: State an exact number of third-party partners (e.g., 'We share data with X partners') in the banner and link to the full list.

Provenance

  • credentials: The about page offers navigation tiles but no substantive background on the organisation's credentials or governance on this page itself.
    Fix: Add a short paragraph (or visible summary) on the About page describing the Bodleian's role, governance, and institutional credentials with links to more detail.

Security

Transparency

  • substantive: The page contains only short tile captions and no substantive statement of purpose.
    Fix: Add a detailed statement of purpose describing the libraries' mission, collections, and public role beyond tagline-style captions.
  • mission_clear: No mission statement or editorial approach is articulated on the page.
    Fix: Publish a clear mission statement on the About page describing the libraries' goals, values, and approach to collections and access.
  • detail: The page provides no financial detail such as amounts, percentages, or funding categories.
    Fix: Publish a breakdown of funding by source (e.g., grants, donations, public funding) with amounts or percentages.
  • complete: No funding streams are disclosed, so coverage of major funding sources cannot be considered complete.
    Fix: Provide a comprehensive funding statement covering all major income streams including public funds, grants, philanthropy, and commercial revenue.
  • governance_exists: The About page lists sections like History, Careers, and Business services but does not describe any governance or editorial structure for the libraries.
    Fix: Add a governance section on the About page outlining the library's leadership, editorial oversight, and decision-making bodies.
  • roles_clear: No key roles or responsibilities (e.g., director, trustees, editorial leads) are identified anywhere on the page.
    Fix: Publish a list of named leadership roles with their responsibilities, or link to a dedicated 'Our team/leadership' page from the About section.
  • algorithm_explained: The About page contains no mention of any algorithms or automated decision-making systems used by the Bodleian Libraries.
    Fix: Add a section or link describing any algorithms used (e.g., in search, recommendations, or access decisions) and their purpose.
  • impact_clear: The page does not describe how any algorithmic decisions might affect users or library patrons.
    Fix: Include a clear explanation of how algorithmic decisions impact users, such as effects on search results, resource access, or service delivery.
  • annual_statement: The page links to a privacy policy but shows no evidence of regular or annual review of data practices.
    Fix: Add a note to the privacy policy indicating when it was last reviewed and commit to a periodic (e.g., annual) review cycle.
  • dated: The privacy policy link in the footer is not accompanied by any date or version indicator on this page.
    Fix: Display a 'last updated' date or version number next to the privacy policy link or within the policy itself.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement says it is 'working hard' and 'it will take some time' but provides no specific dates or target timeline for fixing the known issues.
    Fix: Add concrete target dates or milestones for remediating each category of known accessibility issue.

Accountability

  • policy_exists: The terms page only references the University's Ownership, Liability and Use policy and does not publish any moderation policy.
    Fix: Publish a dedicated moderation policy on the terms page or link to a specific moderation policy document.
  • criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on the page.
    Fix: Add a clearly written section listing specific criteria for acceptable content and grounds for moderation.
  • enforcement: The page does not describe any enforcement process, appeals, or actions taken against violators.
    Fix: Include an explanation of the enforcement workflow, including reporting channels, review steps, sanctions, and appeal procedures.

Interoperability

Security

  • plan_exists: The page contains only navigation links, library service information, and general policy links with no published incident response plan or security policy.
    Fix: Publish a dedicated incident response plan or security policy page describing how security incidents are detected, managed, and resolved.
  • notification_commitment: The page includes no statement committing to publicly notifying users of significant security incidents.
    Fix: Add an explicit commitment to notify affected users and the public when a significant security or data incident occurs.
  • timeframe: There is no mention of any timeframe for disclosing incidents to affected users anywhere on the page.
    Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of discovering a significant incident).

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published or referenced on the About page.
    Fix: Publish the specific criteria used in any algorithmic processes, for example on a dedicated transparency or algorithmic accountability page.
  • weighting: The page does not mention any weighting or prioritisation of criteria in algorithmic decisions.
    Fix: Document how criteria are weighted or prioritised in any algorithmic systems used by the libraries.
  • auditable: There is no technical or procedural detail provided that would allow external audit or review of any algorithms.
    Fix: Provide sufficient documentation (methodology, data sources, decision logic) to enable independent audit, or link to an algorithmic transparency register.
  • open_source: There is no link to source code or any open-source repository on the page.
    Fix: If the Bodleian maintains any open-source projects, link to the relevant repository (e.g., GitHub) from the About or developer section.
  • tech_docs: No technical documentation or developer resources are linked from this page.
    Fix: Provide or link to technical documentation (e.g., APIs for Digital Bodleian/ORA) from the About page or a dedicated developer page.

Responsibility to the Future

  • disclosure_exists: The About page and footer contain no published environmental impact or sustainability disclosure, only navigation, news, and standard legal links.
    Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About page or footer.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Include concrete metrics such as annual carbon emissions or energy consumption within a published sustainability report.
  • hosting_disclosure: There is no disclosure of the carbon or energy profile of the hosting infrastructure, only a 'powered by Oxford Mosaic' note with no environmental data.
    Fix: Add information about the hosting provider's energy sources or carbon footprint, ideally referencing green or renewable-powered hosting.
  • plan_exists: The About page contains institutional history, careers, and business service links but no published plan for organisational failure or exit.
    Fix: Publish a succession or continuity plan describing what happens to the libraries' digital services if the organisation ceases to operate.
  • data_and_content_fate: The page references resources like Digital Bodleian and ORA but does not state what would happen to user data or published content in a shutdown scenario.
    Fix: Add a statement outlining how user data and published collections would be preserved, transferred, or handled if services end.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content in the event of closure.
    Fix: Name specific custodians, mirror sites, or archival partners responsible for maintaining collections and data long-term.
  • policy_exists: The careers page describes the range of roles and mentions benefits via an external link but publishes no policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers page.
  • specific_commitments: The page only vaguely references discovering 'the benefits of working for the University of Oxford' without any specific commitments on pay, hours, mental health, or benefits.
    Fix: Add concrete commitments detailing pay standards, working hours, mental health support, and staff benefits directly on the page.
  • accountability: No individual, team, or governance body is identified as responsible for overseeing worker conditions on this page.
    Fix: Name a responsible department or role (e.g., HR or a wellbeing officer) and provide oversight/contact details for worker conditions.