British Library

https://www.bl.uk · 63/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 32/37 (5 failed)
Level 2 — Enhanced 15/27 (12 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 4/5
AI & Automation 3/8
Interoperability 1/3
Privacy 13/16
Provenance 1/2
Security 8/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

  • without controls: {'tag': 'video', 'src': 'https://cdn.sanity.io/files/v5dwkion/production/b741fe29b38293b627aa9419a2346e14c6412c41.mp4/british-library-website-welcome-video-2025-rf26.mp4', 'autoplay': False, 'controls': False}

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
  • scope_clear: Because no AI policy is present, there is no explanation of what AI is used for on the site.
    Fix: Clearly describe in an AI statement which services or features (e.g., search, cataloguing, chat) use AI and for what purposes.

Privacy

Security

Transparency

  • disclosure_exists: The page mentions the Library is a charity and invites donations but provides no funding or sponsorship disclosure.
    Fix: Add a dedicated funding disclosure section or link summarising government grant-in-aid, donations, and commercial income sources.
  • transparent: No funding sources (e.g., DCMS grant-in-aid, sponsors, donors) are identified on the page.
    Fix: Clearly name primary funders such as the Department for Culture, Media and Sport and list major sponsors and donors on the About page.

Level 2 — Enhanced

Accessibility

Accountability

AI & Automation

  • detailed_scope: No AI policy exists on this page, so detailed scope of AI use is not provided.
    Fix: Create an AI policy that specifies the systems, data sources, and use cases where AI is applied across Library services.
  • limitations: The page does not acknowledge any limitations of AI systems since no AI policy is present.
    Fix: Add a section to the AI policy acknowledging known limitations such as bias, inaccuracy, or hallucination risks.
  • safeguards: No safeguards or quality controls for AI are described anywhere on the page.
    Fix: Document human oversight, review processes, and quality assurance measures applied to AI-driven outputs in the AI policy.
  • marking_policy: The About page contains no policy or statement regarding how AI-assisted content is marked or disclosed.
    Fix: Publish a clear policy on the About or Accessibility page describing how AI-assisted content is labelled and disclosed to users.
  • consistent: Without a marking policy present, there is no evidence that AI content marking is applied consistently across the page.
    Fix: Adopt and apply a uniform AI-content labelling convention (e.g., a standard badge or disclosure line) across all pages that include AI-assisted material.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how staff review and supervise any AI-generated outputs before publication.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Document the specific review and approval steps (who checks, what criteria, and sign-off) for AI-generated content in a published governance statement.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name an accountable role or office (e.g., a Head of Digital or AI Ethics lead) with contact details responsible for AI-generated content.

Interoperability

Privacy

  • retention_stated: The abridged policy only alludes to 'record retention policies' as a legal obligation but does not state retention periods on this page.
    Fix: Add a dedicated retention section explaining how long each category of personal data is kept before deletion or anonymisation.
  • specific: No specific time periods (e.g., months or years) for data retention are provided anywhere in the visible policy text.
    Fix: Provide concrete retention durations for key data types (e.g., 'CCTV footage retained for 30 days', 'Reader records retained for X years after last activity').
  • equal_choices: The page does not present any visible accept/reject consent controls, so equal prominence of choices cannot be demonstrated.
    Fix: Provide a consent mechanism (e.g., cookie banner) with accept and reject buttons of equal visual prominence accessible from the privacy page.
  • banner_present: The page content shows no visible cookie or consent banner text.
    Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookies.
  • partner_sharing_mentioned: No on-page consent copy discloses data sharing with third-party partners.
    Fix: Add clear disclosure in the cookie banner stating whether and with which categories of third-party partners user data is shared.
  • partner_count_specific: No numeric count of partners is stated because partner sharing is not disclosed at all.
    Fix: Once partner sharing is disclosed, include the exact number of third-party partners (e.g., 'We share data with X partners') in the banner.

Provenance

Security

Transparency

  • detail: The page provides no amounts, percentages, or categorical breakdown of funding.
    Fix: Include a summary of funding by category with figures or percentages (e.g., public grant, earned income, philanthropy) or link directly to the relevant annual report section.
  • complete: No major funding streams are disclosed, so coverage cannot be considered complete.
    Fix: Publish a comprehensive funding breakdown covering grant-in-aid, self-generated income, donations, and any restricted funds, with links to the full annual accounts.
  • roles_clear: The page does not identify specific key roles or responsibilities (e.g., board members, executives, or departmental leads) on this About page.
    Fix: Add a section or link listing named leadership roles (e.g., Chief Executive, Board of Trustees) with their responsibilities directly on the About page.
  • algorithm_explained: The About page describes the Library's mission and services but makes no mention of any algorithms or their purpose.
    Fix: Add a section disclosing any algorithms used (e.g., for search, recommendations, or captcha) and explain their purpose in plain language.
  • impact_clear: There is no description of how algorithmic decisions affect users such as researchers, visitors, or newsletter subscribers.
    Fix: Include a statement explaining how automated systems influence user experience and outcomes, with a link to a fuller algorithmic transparency notice.
  • annual_statement: The page links to a Privacy Policy but provides no evidence of a regular or annual review of data practices.
    Fix: Add a statement in the privacy policy or about page indicating when data practices are reviewed (e.g., annually) and publish a summary of the most recent review.
  • dated: No date or version information is shown for the privacy policy or data practices statement on this page.
    Fix: Include a 'last updated' date or version number next to the Privacy Policy link and on the policy itself.

Level 3 — Advanced

Accessibility

  • known_issues: The statement claims the site is 'fully compliant' and lists no non-accessible content or known limitations for the main website.
    Fix: Add a section listing any known accessibility issues or non-compliant content (or explicitly state none exist based on the audit), rather than relying solely on a blanket full-compliance claim.
  • remediation_timeline: Because no known issues are acknowledged, there is no timeline or commitment for fixing accessibility problems.
    Fix: For each identified issue, include a target date or timeframe by which it will be remediated.

Accountability

  • enforcement: While the page notes the Library may refuse admission, ask people to leave, or pursue prosecution for damage/theft, it does not explain the moderation/enforcement process itself (e.g., warnings, appeals, escalation steps, or who decides).
    Fix: Add a section describing the enforcement process, including how breaches are assessed, what sanctions apply at each level, and how users can appeal a decision.

Interoperability

Security

  • plan_exists: The page lists a 'Cyber-attack' link in the footer but does not present or link to a published incident response plan or policy on this About page.
    Fix: Publish a dedicated incident response plan or policy and link to it clearly from the About and security-related pages.
  • notification_commitment: The page contains no stated commitment to publicly notify users of significant security incidents.
    Fix: Add an explicit commitment stating that the Library will publicly notify affected users and the public of significant incidents.
  • timeframe: There is no mention of any timeframe for disclosing incidents to affected users anywhere on the page.
    Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making (e.g., the Friendly Captcha anti-robot check) are published on this page.
    Fix: Publish the criteria used by any algorithmic system on the site, either inline or via a linked transparency record.
  • weighting: The page does not explain any weighting or prioritisation logic for algorithmic decisions.
    Fix: Document how each criterion is weighted or prioritised in algorithmic decisions and link to the documentation from this page.
  • auditable: There is insufficient technical or procedural detail for any external party to audit or review algorithmic systems referenced on the site.
    Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS standard) with model details, data sources, and review processes to enable external audit.
  • open_source: The about page contains no links to source code repositories or any mention of open-source projects.
    Fix: Add a link to a public code repository (e.g., GitHub) or an open-source/developer section from the about page.
  • tech_docs: No technical documentation, API references, or developer resources are linked from this page.
    Fix: Publish and link to technical documentation such as API docs, metadata schemas, or a developer portal from the about or services section.

Responsibility to the Future

  • specific_metrics: The page mentions sustainability reports and pay gap reports but provides no specific carbon, energy use, or emissions figures on the page itself.
    Fix: Publish concrete environmental metrics (e.g., annual carbon emissions in tonnes CO2e, energy consumption) directly on or clearly linked from this page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or digital infrastructure anywhere on the page.
    Fix: Add a statement disclosing the carbon or energy profile of the site's hosting infrastructure, such as use of green/renewable-powered data centres.
  • plan_exists: The page describes the Library's mission, services, and strategy to 2030 but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing what would happen to the Library and its collection in the event of organisational failure or closure.
  • data_and_content_fate: While legal deposit and custodianship of the national collection are mentioned, there is no statement addressing the fate of user data or published content should the organisation cease to operate.
    Fix: Add explicit provisions describing how user data and the digital/published collection would be preserved or transferred if the organisation exits.
  • custodians_or_mirrors: The page references partnerships and international collaboration but does not identify any custodians, mirrors, or archive partners who would safeguard the collection in a failure scenario.
    Fix: Name specific custodians, mirror sites, or archive partners that would assume responsibility for the collection and data if the Library ceased operations.
  • accountability: The page describes values and benefits but names no responsible role, team, or governance body accountable for overseeing worker conditions beyond a general recruitment email.
    Fix: Add a statement identifying the department or senior role (e.g., HR/People Director) responsible for monitoring and enforcing worker wellbeing standards, with reporting or oversight arrangements.