British Heart Foundation
https://www.bhf.org.uk · 49/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (9 failed) |
| Level 2 — Enhanced | 10/27 (17 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-hidden-focus.
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-hidden-focus.
- without controls: {'tag': 'video', 'src': 'https://www.bhf.org.uk/-/media/images/keep-us-beating/keep-us-beating-banner-video-16x9-compressed.mp4?rev=d7304a16f0b54e58a3e53833acd96771', 'autoplay': False, 'controls': False}
AI & Automation
-
policy_exists: The page contains no AI use policy or statement anywhere in its content or policy links.
Fix: Publish an AI use policy and link it from the site footer alongside Privacy and Terms & conditions.
-
scope_clear: There is no mention of AI at all, so the scope of any AI use is not explained.
Fix: Add a clear statement describing where and how AI is used (e.g., on-site search, chat, content generation) within a dedicated AI policy page.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' !function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod? n.cal…'.
- No requests matched the tracker/ad domain list.
- 1 inline script matched a tracker/ad pattern; first match: ' !function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod? n.cal…'.
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.bhf.org.uk
- x-frame-options: header not set on the response.
- TLS certificate expires in 30 days.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The page only states hours of operation (Mon-Fri, 9am-5pm) and says emails will be answered 'as soon as possible' without publishing a response timeframe.
Fix: Publish a specific expected response time for each contact channel (e.g., 'we respond to emails within 5 working days').
-
specific: The only timing language provided is vague ('as soon as possible') rather than a specific number of days or hours.
Fix: Replace vague phrases with concrete numeric commitments, such as '3 working days for email' or '10 working days for written correspondence'.
-
steps_clear: The contact page mentions complaints can be made but does not outline the actual steps of the complaints process on this page.
Fix: Add a brief summary of the complaints steps (how to submit, who reviews it, expected timeframe, and escalation options) directly on the contact page or in a clearly linked procedure.
-
appeals_exists: The page mentions feedback and complaints but does not document a formal appeals process for decisions.
Fix: Add a clearly documented appeals process explaining how users can formally appeal decisions, including steps and timelines.
-
independent: There is no indication of an independent reviewer or escalation path beyond the general complaints link.
Fix: Describe an independent or escalated review route (e.g., external ombudsman or senior review panel) for unresolved complaints and appeals.
AI & Automation
-
detailed_scope: No AI policy is present on the page, so detailed scope of AI use is not provided.
Fix: Create an AI policy that itemises each AI system in use, its purpose, data inputs, and decision areas it supports.
-
limitations: The page does not acknowledge any limitations of AI systems since no AI policy exists.
Fix: Include a 'Limitations' section in the AI policy explaining accuracy constraints, potential biases, and situations where AI output should not be relied upon (e.g., medical advice).
-
safeguards: No safeguards or quality controls for AI are described anywhere on the page.
Fix: Document safeguards such as human review, clinical oversight for health content, data protection measures, and user opt-out options in the AI policy.
-
marking_policy: The page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy describing how AI-assisted content will be labeled or disclosed on the site.
-
consistent: Without any visible AI marking policy, consistency of application cannot be demonstrated on this page.
Fix: Once a marking policy is established, apply visible AI-content labels consistently across all pages and link to the policy.
-
oversight_exists: There is no documentation of human oversight for AI outputs anywhere on the page.
Fix: Add a statement (e.g., in the policies footer) confirming that human reviewers oversee any AI-generated content.
-
review_process: The page does not describe any review or approval workflow for AI-generated content.
Fix: Document the review/approval steps AI content goes through before publication and link to it from the policies section.
-
accountability: No role, team, or individual is named as accountable for AI-generated content on the site.
Fix: Name a responsible team or role (e.g., Editorial/Digital lead) accountable for AI-generated content and publish contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible content does not contain an explicit statement that data collection is limited to what is necessary.
Fix: Add an explicit data minimisation statement confirming that the BHF only collects personal information necessary for the stated purposes.
-
proportionate: There is no visible wording explaining that the data collected is proportionate to the services or purposes provided.
Fix: Include a clear proportionality statement explaining that data collected is limited to what is proportionate to each service (e.g., donations, volunteering, shopping).
-
retention_stated: Although the table of contents references 'Keeping your personal information', no retention details are visible in the provided content.
Fix: Surface explicit retention information in the main body of the policy rather than only linking to a collapsible section.
-
specific: No specific retention timeframes (e.g., years or triggers) are visible on the page as provided.
Fix: State concrete retention periods for each data category (e.g., 'donor records kept for 7 years for tax purposes').
-
equal_choices: The page content shown provides no visible cookie banner with accept/reject options, so equal prominence of choices cannot be confirmed on this privacy page.
Fix: Ensure the cookie settings interface (linked in the footer) presents 'Accept' and 'Reject' options with equal visual prominence (same size, color, and placement).
-
banner_present: The page content shows no visible cookie or consent banner, only a 'Cookie settings' link in the footer policies section.
Fix: Implement a visible cookie consent banner that appears on page load to inform users about cookie use and obtain consent.
-
partner_sharing_mentioned: No banner or on-page consent copy is present, so third-party partner data sharing is not disclosed at the point of consent.
Fix: Add consent banner copy that explicitly discloses data sharing with third-party advertising and analytics partners.
-
partner_count_specific: Because no partner sharing is disclosed on the page, no specific numeric count of partners is stated.
Fix: Include a specific number of third-party partners (e.g., 'we share data with X partners') in the consent banner or linked preferences panel.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
complete: While many donation streams are listed, the page does not provide a complete breakdown of all major funding streams (e.g., retail shop income, government grants, investment income) with proportions.
Fix: Add a summary or link to an annual report breakdown showing the percentage contribution of each major income stream (individual giving, retail, corporate, legacies, lottery, investments, etc.).
-
governance_exists: The page describes mission and strategy but does not outline the governance or editorial structure (e.g., board of trustees, editorial oversight).
Fix: Add a governance section or link describing the board of trustees, executive leadership, and editorial oversight structure.
-
roles_clear: While 'Our people' and 'Working with us' are mentioned, key governance roles and their responsibilities are not identified on this page.
Fix: List named leadership roles (e.g., CEO, Chair of Trustees) with their responsibilities, or link directly to a page detailing them.
-
algorithm_explained: The page contains no mention of any algorithms or automated decision-making systems used by the organisation.
Fix: Add a section or linked page disclosing any algorithms used (e.g., for donor targeting, research prioritisation, or site personalisation) and explaining their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users, supporters, or beneficiaries.
Fix: Publish a clear statement describing how any algorithmic decisions impact users and what recourse they have.
-
annual_statement: The page links to a Privacy policy but provides no evidence on this page of a regular or annual review of data practices.
Fix: Add a note on the About or Privacy page stating when data practices were last reviewed and commit to a periodic (e.g., annual) review cadence.
-
dated: No date or version indicator is shown for the privacy/data practices statement on this page.
Fix: Display a 'last updated' date or version number next to the Privacy policy link and on the policy page itself.
Level 3 — Advanced
Accessibility
-
statement_exists: The page only shows an 'Accessibility' link in the footer policies list but no dedicated accessibility statement content is present on this about page.
Fix: Provide or link to a dedicated accessibility statement page and ensure its content is accessible from this page.
-
known_issues: No acknowledgment of any known accessibility issues or limitations appears anywhere in the page content.
Fix: Add a section to the accessibility statement listing known accessibility issues and non-compliant areas of the site.
-
remediation_timeline: The page contains no timeline or commitment for fixing accessibility issues.
Fix: Include target dates or a commitment describing when known accessibility issues will be resolved.
-
feedback_channel: While general contact details exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
Fix: Add a dedicated accessibility feedback channel and state a clear timeframe for responding to reports.
Accountability
-
policy_exists: The terms and conditions cover website use but do not publish a specific moderation policy for user-generated content.
Fix: Publish a dedicated moderation policy describing how user-submitted content is reviewed and moderated.
-
criteria_clear: While section 4 prohibits unlawful, harassing, defamatory, or offensive material, it does not lay out clear moderation criteria or thresholds for what will be removed.
Fix: Add explicit moderation criteria listing the categories of content that will be removed or actioned and the standards applied.
-
enforcement: The page mentions cancelling registrations and reporting criminal breaches, but does not explain a moderation enforcement process such as review, appeal, or takedown steps.
Fix: Document the enforcement workflow including how violations are reported, reviewed, actioned, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is an 'about us' overview with no published incident response plan or security policy, listing only privacy, cookies, and terms links.
Fix: Publish a dedicated incident response plan or security policy and link it in the site's policies footer section.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify the public and affected users when a significant incident occurs.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: State a specific disclosure timeframe (e.g., notifying affected users within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are published on the page.
Fix: Publish the explicit criteria (inputs, rules, data sources) used in any algorithmic decisions on an accessible transparency page.
-
weighting: The page does not describe any weighting or prioritisation logic for algorithmic criteria.
Fix: Document the relative weighting or priority assigned to each decision criterion so users can understand how outcomes are produced.
-
auditable: The page provides no technical or procedural detail that would enable an external audit of algorithmic systems.
Fix: Provide sufficient documentation (model cards, data sources, governance processes) to enable independent external review or audit.
-
open_source: There is no mention of source code availability or links to any public code repositories on the page.
Fix: Add a link to a public code repository (e.g., GitHub) or a statement about open source policy if any BHF digital tools are open-sourced.
-
tech_docs: No technical documentation is published or linked from the about page.
Fix: Publish or link to technical documentation describing the platform, APIs, or data formats used by BHF's digital services.
Responsibility to the Future
-
specific_metrics: The page only makes general statements about sustainability goals without any specific carbon, energy, or emissions figures.
Fix: Publish concrete metrics such as annual carbon emissions, energy consumption, and reduction targets with measured progress.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's carbon or energy profile, such as whether servers run on renewable energy.
-
plan_exists: The page describes the charity's mission, strategy, and sustainability goals but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing organisational continuity and closure procedures, and link to it from the About or policies section.
-
data_and_content_fate: There is no mention of what would happen to user data or published content in the event the organisation ceases to operate.
Fix: Add a statement (e.g. in the privacy policy or a dedicated continuity plan) detailing how user data and site content would be handled, transferred, or deleted upon organisational exit.
-
custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners who would preserve content or data if the organisation shut down.
Fix: Name specific custodians, mirror hosts, or archive partners (such as a national archive) responsible for preserving content and data, and document these arrangements publicly.
-
specific_commitments: The page only mentions 'competitive salaries' and a benefits 'package' in general terms without specifying pay levels, hours, mental health support, or concrete benefits.
Fix: Publish a dedicated wellbeing statement detailing specific commitments such as pay approach, working hours, mental health provisions, and the benefits offered.
-
accountability: The page does not identify any role, team, or oversight body responsible for worker conditions and wellbeing.
Fix: Name the department or senior role accountable for worker wellbeing and describe how working conditions are monitored and reviewed.