British Heart Foundation

https://www.bhf.org.uk · 49/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 27/37 (9 failed)
Level 2 — Enhanced 10/27 (17 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 5/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

  • without controls: {'tag': 'video', 'src': 'https://www.bhf.org.uk/-/media/images/keep-us-beating/keep-us-beating-banner-video-16x9-compressed.mp4?rev=d7304a16f0b54e58a3e53833acd96771', 'autoplay': False, 'controls': False}

AI & Automation

  • policy_exists: The page contains no AI use policy or statement anywhere in its content or policy links.
    Fix: Publish an AI use policy and link it from the site footer alongside Privacy and Terms & conditions.
  • scope_clear: There is no mention of AI at all, so the scope of any AI use is not explained.
    Fix: Add a clear statement describing where and how AI is used (e.g., on-site search, chat, content generation) within a dedicated AI policy page.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The page only states hours of operation (Mon-Fri, 9am-5pm) and says emails will be answered 'as soon as possible' without publishing a response timeframe.
    Fix: Publish a specific expected response time for each contact channel (e.g., 'we respond to emails within 5 working days').
  • specific: The only timing language provided is vague ('as soon as possible') rather than a specific number of days or hours.
    Fix: Replace vague phrases with concrete numeric commitments, such as '3 working days for email' or '10 working days for written correspondence'.
  • steps_clear: The contact page mentions complaints can be made but does not outline the actual steps of the complaints process on this page.
    Fix: Add a brief summary of the complaints steps (how to submit, who reviews it, expected timeframe, and escalation options) directly on the contact page or in a clearly linked procedure.
  • appeals_exists: The page mentions feedback and complaints but does not document a formal appeals process for decisions.
    Fix: Add a clearly documented appeals process explaining how users can formally appeal decisions, including steps and timelines.
  • independent: There is no indication of an independent reviewer or escalation path beyond the general complaints link.
    Fix: Describe an independent or escalated review route (e.g., external ombudsman or senior review panel) for unresolved complaints and appeals.

AI & Automation

  • detailed_scope: No AI policy is present on the page, so detailed scope of AI use is not provided.
    Fix: Create an AI policy that itemises each AI system in use, its purpose, data inputs, and decision areas it supports.
  • limitations: The page does not acknowledge any limitations of AI systems since no AI policy exists.
    Fix: Include a 'Limitations' section in the AI policy explaining accuracy constraints, potential biases, and situations where AI output should not be relied upon (e.g., medical advice).
  • safeguards: No safeguards or quality controls for AI are described anywhere on the page.
    Fix: Document safeguards such as human review, clinical oversight for health content, data protection measures, and user opt-out options in the AI policy.
  • marking_policy: The page contains no policy or statement about marking AI-assisted content.
    Fix: Publish a clear policy describing how AI-assisted content will be labeled or disclosed on the site.
  • consistent: Without any visible AI marking policy, consistency of application cannot be demonstrated on this page.
    Fix: Once a marking policy is established, apply visible AI-content labels consistently across all pages and link to the policy.
  • oversight_exists: There is no documentation of human oversight for AI outputs anywhere on the page.
    Fix: Add a statement (e.g., in the policies footer) confirming that human reviewers oversee any AI-generated content.
  • review_process: The page does not describe any review or approval workflow for AI-generated content.
    Fix: Document the review/approval steps AI content goes through before publication and link to it from the policies section.
  • accountability: No role, team, or individual is named as accountable for AI-generated content on the site.
    Fix: Name a responsible team or role (e.g., Editorial/Digital lead) accountable for AI-generated content and publish contact details.

Interoperability

Privacy

  • necessity: The visible content does not contain an explicit statement that data collection is limited to what is necessary.
    Fix: Add an explicit data minimisation statement confirming that the BHF only collects personal information necessary for the stated purposes.
  • proportionate: There is no visible wording explaining that the data collected is proportionate to the services or purposes provided.
    Fix: Include a clear proportionality statement explaining that data collected is limited to what is proportionate to each service (e.g., donations, volunteering, shopping).
  • retention_stated: Although the table of contents references 'Keeping your personal information', no retention details are visible in the provided content.
    Fix: Surface explicit retention information in the main body of the policy rather than only linking to a collapsible section.
  • specific: No specific retention timeframes (e.g., years or triggers) are visible on the page as provided.
    Fix: State concrete retention periods for each data category (e.g., 'donor records kept for 7 years for tax purposes').
  • equal_choices: The page content shown provides no visible cookie banner with accept/reject options, so equal prominence of choices cannot be confirmed on this privacy page.
    Fix: Ensure the cookie settings interface (linked in the footer) presents 'Accept' and 'Reject' options with equal visual prominence (same size, color, and placement).
  • banner_present: The page content shows no visible cookie or consent banner, only a 'Cookie settings' link in the footer policies section.
    Fix: Implement a visible cookie consent banner that appears on page load to inform users about cookie use and obtain consent.
  • partner_sharing_mentioned: No banner or on-page consent copy is present, so third-party partner data sharing is not disclosed at the point of consent.
    Fix: Add consent banner copy that explicitly discloses data sharing with third-party advertising and analytics partners.
  • partner_count_specific: Because no partner sharing is disclosed on the page, no specific numeric count of partners is stated.
    Fix: Include a specific number of third-party partners (e.g., 'we share data with X partners') in the consent banner or linked preferences panel.

Provenance

Security

Transparency

  • complete: While many donation streams are listed, the page does not provide a complete breakdown of all major funding streams (e.g., retail shop income, government grants, investment income) with proportions.
    Fix: Add a summary or link to an annual report breakdown showing the percentage contribution of each major income stream (individual giving, retail, corporate, legacies, lottery, investments, etc.).
  • governance_exists: The page describes mission and strategy but does not outline the governance or editorial structure (e.g., board of trustees, editorial oversight).
    Fix: Add a governance section or link describing the board of trustees, executive leadership, and editorial oversight structure.
  • roles_clear: While 'Our people' and 'Working with us' are mentioned, key governance roles and their responsibilities are not identified on this page.
    Fix: List named leadership roles (e.g., CEO, Chair of Trustees) with their responsibilities, or link directly to a page detailing them.
  • algorithm_explained: The page contains no mention of any algorithms or automated decision-making systems used by the organisation.
    Fix: Add a section or linked page disclosing any algorithms used (e.g., for donor targeting, research prioritisation, or site personalisation) and explaining their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users, supporters, or beneficiaries.
    Fix: Publish a clear statement describing how any algorithmic decisions impact users and what recourse they have.
  • annual_statement: The page links to a Privacy policy but provides no evidence on this page of a regular or annual review of data practices.
    Fix: Add a note on the About or Privacy page stating when data practices were last reviewed and commit to a periodic (e.g., annual) review cadence.
  • dated: No date or version indicator is shown for the privacy/data practices statement on this page.
    Fix: Display a 'last updated' date or version number next to the Privacy policy link and on the policy page itself.

Level 3 — Advanced

Accessibility

  • statement_exists: The page only shows an 'Accessibility' link in the footer policies list but no dedicated accessibility statement content is present on this about page.
    Fix: Provide or link to a dedicated accessibility statement page and ensure its content is accessible from this page.
  • known_issues: No acknowledgment of any known accessibility issues or limitations appears anywhere in the page content.
    Fix: Add a section to the accessibility statement listing known accessibility issues and non-compliant areas of the site.
  • remediation_timeline: The page contains no timeline or commitment for fixing accessibility issues.
    Fix: Include target dates or a commitment describing when known accessibility issues will be resolved.
  • feedback_channel: While general contact details exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Add a dedicated accessibility feedback channel and state a clear timeframe for responding to reports.

Accountability

  • policy_exists: The terms and conditions cover website use but do not publish a specific moderation policy for user-generated content.
    Fix: Publish a dedicated moderation policy describing how user-submitted content is reviewed and moderated.
  • criteria_clear: While section 4 prohibits unlawful, harassing, defamatory, or offensive material, it does not lay out clear moderation criteria or thresholds for what will be removed.
    Fix: Add explicit moderation criteria listing the categories of content that will be removed or actioned and the standards applied.
  • enforcement: The page mentions cancelling registrations and reporting criminal breaches, but does not explain a moderation enforcement process such as review, appeal, or takedown steps.
    Fix: Document the enforcement workflow including how violations are reported, reviewed, actioned, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The page is an 'about us' overview with no published incident response plan or security policy, listing only privacy, cookies, and terms links.
    Fix: Publish a dedicated incident response plan or security policy and link it in the site's policies footer section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected users when a significant incident occurs.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: State a specific disclosure timeframe (e.g., notifying affected users within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on the page.
    Fix: Publish the explicit criteria (inputs, rules, data sources) used in any algorithmic decisions on an accessible transparency page.
  • weighting: The page does not describe any weighting or prioritisation logic for algorithmic criteria.
    Fix: Document the relative weighting or priority assigned to each decision criterion so users can understand how outcomes are produced.
  • auditable: The page provides no technical or procedural detail that would enable an external audit of algorithmic systems.
    Fix: Provide sufficient documentation (model cards, data sources, governance processes) to enable independent external review or audit.
  • open_source: There is no mention of source code availability or links to any public code repositories on the page.
    Fix: Add a link to a public code repository (e.g., GitHub) or a statement about open source policy if any BHF digital tools are open-sourced.
  • tech_docs: No technical documentation is published or linked from the about page.
    Fix: Publish or link to technical documentation describing the platform, APIs, or data formats used by BHF's digital services.

Responsibility to the Future

  • specific_metrics: The page only makes general statements about sustainability goals without any specific carbon, energy, or emissions figures.
    Fix: Publish concrete metrics such as annual carbon emissions, energy consumption, and reduction targets with measured progress.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's carbon or energy profile, such as whether servers run on renewable energy.
  • plan_exists: The page describes the charity's mission, strategy, and sustainability goals but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing organisational continuity and closure procedures, and link to it from the About or policies section.
  • data_and_content_fate: There is no mention of what would happen to user data or published content in the event the organisation ceases to operate.
    Fix: Add a statement (e.g. in the privacy policy or a dedicated continuity plan) detailing how user data and site content would be handled, transferred, or deleted upon organisational exit.
  • custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners who would preserve content or data if the organisation shut down.
    Fix: Name specific custodians, mirror hosts, or archive partners (such as a national archive) responsible for preserving content and data, and document these arrangements publicly.
  • specific_commitments: The page only mentions 'competitive salaries' and a benefits 'package' in general terms without specifying pay levels, hours, mental health support, or concrete benefits.
    Fix: Publish a dedicated wellbeing statement detailing specific commitments such as pay approach, working hours, mental health provisions, and the benefits offered.
  • accountability: The page does not identify any role, team, or oversight body responsible for worker conditions and wellbeing.
    Fix: Name the department or senior role accountable for worker wellbeing and describe how working conditions are monitored and reviewed.