British Red Cross
https://www.redcross.org.uk · 48/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 29/37 (8 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish an AI use policy or statement (e.g., linked from the footer or About section) describing how the British Red Cross uses AI.
-
scope_clear: There is no content on the page explaining what AI is used for.
Fix: Add a clear description of the scope of AI use (e.g., chatbots, data analysis, fundraising) within an AI policy page.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: .youtube.com.
- No hidden iframes detected.
- Detected 5 data-leaking services across 3 categories: cookie consent saas (cdn-ukwest.onetrust.com); google fonts (fonts.gstatic.com); youtube embed (i.ytimg.com, www.youtube-nocookie.com, www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.redcross.org.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The page is a donation appeal and contains no disclosure of the organization's funding or sponsorship sources.
Fix: Add a funding disclosure section that identifies where the British Red Cross's income comes from (e.g., public donations, grants, government contracts).
-
transparent: No funding sources are identified on this page; it only solicits donations without explaining the broader funding mix.
Fix: Clearly list and link to a page identifying all major funding sources, such as individual donations, corporate partners, trusts, and government grants.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page does not identify any named person or specific role responsible for handling enquiries, only the generic 'British Red Cross' organisation.
Fix: Add the name or title of a responsible individual or team (e.g., 'Head of Supporter Care' or 'Supporter Care Team Lead') accountable for enquiries and complaints.
-
response_timeframe: The page only states complaints will be addressed 'as soon as possible' without publishing any response timeframe.
Fix: Publish a specific response timeframe (e.g., 'We respond within 10 working days') on the contact page.
-
specific: The phrase 'as soon as possible' is vague and not specific in days or hours.
Fix: Replace 'as soon as possible' with a concrete duration such as a specified number of working days.
-
steps_clear: The page mentions feedback but does not lay out clear step-by-step instructions for how to make a complaint on this page.
Fix: Add a numbered list of steps describing how to submit a complaint, what information to include, and what happens next.
-
appeals_exists: The contact page mentions feedback and complaints generally but does not document a formal appeals process.
Fix: Add a clearly labeled appeals procedure describing how users can formally challenge decisions, including required steps and timelines.
-
independent: There is no mention of an independent reviewer or escalation path for appeals on this page.
Fix: Specify an independent body or escalation route (e.g., an ombudsman or senior review panel) that handles appeals separately from the original decision-maker.
AI & Automation
-
detailed_scope: The page does not detail any scope of AI use across operations or services.
Fix: Create a dedicated AI policy page that enumerates each AI application area and its purpose.
-
limitations: No acknowledgement of AI system limitations appears on the page.
Fix: Include a section in the AI policy that candidly describes the limitations and risks of the AI systems used.
-
safeguards: The page describes no safeguards or quality controls for AI.
Fix: Document safeguards such as human oversight, accuracy checks, and bias mitigation in a published AI policy.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or disclosed.
Fix: Publish an AI content policy (linked from the About or Transparency section) describing how AI-assisted material is labelled on the site.
-
consistent: Without any visible marking policy or labels, consistent application of AI content marking cannot be demonstrated on this page.
Fix: Adopt a standard label (e.g., 'AI-assisted') and apply it consistently to any AI-generated text, images, or summaries across the site.
-
oversight_exists: The page makes no mention of human oversight of AI outputs anywhere in its governance or 'How we are run' content.
Fix: Add a statement to the governance pages confirming that all AI outputs are subject to human review before publication.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Document the editorial review steps (e.g., staff review, sign-off, fact-checking) that AI-assisted content must pass before going live.
-
accountability: No individual, team, or role is named as accountable for AI-generated content on this page.
Fix: Identify an accountable owner (such as a named team or the Executive Team) responsible for AI content and publish their remit.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
plain_language: Portions discussing the Misconduct Disclosure Scheme and legitimate interests use legalistic phrasing like 'necessary for reasons of substantial public interest' and cite GDPR/DPA/DUAA statutes without plain-language explanation.
Fix: Add short plain-language summaries or a glossary alongside the legal terminology so non-experts can understand lawful bases and schemes referenced.
-
retention_stated: Only one retention period is mentioned (up to 12 months for unsuccessful applicants); retention for donors, service users, volunteers, and employees is not stated on the visible content.
Fix: Add a dedicated retention section listing how long each category of personal data (donors, service users, volunteers, employees, enquirers) is kept.
-
specific: Apart from the 12-month applicant retention, other retention references are vague (e.g., 'in accordance with your employment contract') rather than specifying durations.
Fix: Provide specific time periods (e.g., '7 years after last donation', '6 years after employment ends') for each data category rather than referring generally to policies or contracts.
-
equal_choices: The privacy notice references a cookies policy but does not show the actual consent interface on this page, so equal prominence of accept/reject cannot be verified here.
Fix: Ensure the cookie banner displays 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement) and link to it from the privacy notice for transparency.
-
partner_count_specific: The banner references 'trusted partners' generically but does not state a specific numeric count of partners.
Fix: Update the cookie banner to disclose the exact number of third-party partners (e.g., 'including from our X trusted partners') with a link to the full list.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
named_person: No named individual or specific team (e.g., 'Supporter Care Team') is identified as responsible for enquiries—only the general organisation is referenced.
Fix: Explicitly name the team handling enquiries (such as 'Supporter Care Team' or 'Customer Service Team') on the contact page.
-
role_clear: Because no person or team is named, their role and authority to handle enquiries, complaints, or feedback is not stated.
Fix: After naming the responsible team, describe their role and authority, e.g., 'Our Supporter Care Team is authorised to respond to all general enquiries, complaints, and feedback within X working days.'
-
detail: The page provides no amounts, percentages, or categories describing funding streams—only example uses of donation amounts.
Fix: Include a breakdown (e.g., percentages or figures) of income by source, such as donations, legacies, grants, and trading activities.
-
complete: No funding disclosure is present, so major funding streams are not covered at all.
Fix: Publish a complete funding breakdown covering all major income streams and link to the annual report or financial statements from this page.
-
roles_clear: While Trustees and the Executive Team are mentioned, the page does not identify specific roles, individuals, or their responsibilities in any detail.
Fix: Add a summary or link on this page naming key leadership roles (e.g., Chair, CEO, Trustees) with brief descriptions of their responsibilities.
-
algorithm_explained: The About page does not mention any algorithms or explain their purpose.
Fix: Add a section or link describing any algorithms used (e.g., for case prioritisation or donor targeting) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users or beneficiaries.
Fix: Publish a clear statement describing how any automated decisions impact service users, donors, or volunteers.
-
annual_statement: The page links to a Privacy policy but provides no evidence of a regular or annual review of data practices.
Fix: Add a statement on the Privacy page indicating that data practices are reviewed on a regular (e.g., annual) basis, with the date of the most recent review.
-
dated: There is no visible date or version indicator for the Privacy/data practices statement on this page.
Fix: Include a 'last updated' date or version number adjacent to the Privacy link or at the top of the Privacy policy itself.
Level 3 — Advanced
Accessibility
-
known_issues: The statement only lists aspirational improvement goals and never acknowledges any specific known accessibility issues or limitations of the current site.
Fix: Add a section listing specific non-compliant elements or known barriers (e.g., 'some older PDFs are not accessible') to be transparent about current limitations.
-
remediation_timeline: The statement describes what they 'aim to' do but provides no dates, deadlines, or commitments for when known issues will be fixed.
Fix: Include target dates or a schedule for addressing identified accessibility issues so users know when to expect improvements.
-
feedback_channel: A feedback email (digitalsupport@redcross.org.uk) and Contact Us link are provided, but there is no stated commitment on response time.
Fix: State a response commitment, such as replying to accessibility feedback within a specific number of working days.
Accountability
-
policy_exists: The page is about text-to-donate terms and does not publish any moderation policies for user content.
Fix: Publish a dedicated moderation policy page covering user-generated content and community interactions, and link to it from the site footer.
-
criteria_clear: No moderation criteria (e.g., prohibited content, acceptable behaviour) are stated anywhere on this page.
Fix: Clearly enumerate the criteria used to moderate content, such as prohibited categories and standards of conduct, within the moderation policy.
-
enforcement: The page does not describe any enforcement process for moderation decisions, appeals, or escalation.
Fix: Document the enforcement workflow including who reviews content, actions taken (removal, warnings, bans), and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is a contact/about page with no published incident response plan or policy.
Fix: Publish an incident response plan or policy and link to it from the site.
-
notification_commitment: There is no commitment anywhere on the page to publicly notify users of significant incidents.
Fix: Add a clear commitment to notify affected users and the public of significant security or data incidents.
-
timeframe: No timeframe for disclosing incidents to affected users is stated on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of confirming an incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
Fix: Publish the specific criteria used in any algorithmic decisions, either on this page or via a linked transparency notice.
-
weighting: There is no information about weighting or priority of any decision criteria.
Fix: Document and publish how different criteria are weighted or prioritised in any automated decision process.
-
auditable: The page provides no technical or procedural detail that would support external audit of algorithms.
Fix: Provide an algorithmic transparency report with sufficient detail (data sources, logic, governance) to enable independent audit.
-
open_source: There is no link to any public source code repository for the website on the About page.
Fix: Add a link in the footer or About page to a public code repository (e.g., GitHub) for any open-source components used on the site.
-
tech_docs: No technical documentation about the site's technology, APIs, or data is published or linked from the page.
Fix: Publish and link to technical documentation (e.g., a developer/API page or tech stack description) from the About or footer area.
Responsibility to the Future
-
disclosure_exists: The page is a contact/about page and contains no published environmental impact or sustainability disclosure.
Fix: Publish an environmental or sustainability statement and link it from the footer or About us section.
-
specific_metrics: No specific figures on carbon, energy use, or emissions appear anywhere on the page.
Fix: Include concrete metrics such as annual carbon footprint or energy consumption in a dedicated sustainability disclosure.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
Fix: Disclose the hosting provider's energy sourcing or carbon profile, ideally referencing green/renewable hosting credentials.
-
plan_exists: The page is a contact/about page with no published plan describing what would happen if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing continuity, transfer of activities, or dissolution procedures if the organisation ceases to operate.
-
data_and_content_fate: The page contains no information about the fate of user data or published content in the event of organisational failure.
Fix: Add a section (or link from the privacy policy) explaining what happens to user data and site content if the organisation shuts down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name a custodian, archival partner, or mirror arrangement responsible for preserving data and content if the organisation ceases operations.
-
policy_exists: The page is a donation appeal for the British Red Cross and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from the site.
-
specific_commitments: The page contains no specific commitments on pay, hours, mental health, or benefits, focusing solely on soliciting donations.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits for workers.
-
accountability: The page identifies no person, role, or body responsible for overseeing worker conditions.
Fix: Name a role or oversight body accountable for worker conditions and describe their responsibilities.