Cancer Research UK

https://www.cancerresearchuk.org · 46/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 28/37 (9 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 8/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 12/16
Provenance 1/2
Security 5/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement of any kind.
    Fix: Publish an AI use policy or statement and link to it from the About us page and site footer.
  • scope_clear: There is no explanation of what AI is used for anywhere on this page.
    Fix: Include a clear description of the purposes and contexts in which AI is used by the organisation within the AI policy.

Privacy

Security

Transparency

  • actionable: The page only shows a form to manage contact preferences and the registered address, but provides no direct phone number, email address, or actionable contact channel to reach the organisation.
    Fix: Add a visible phone number, email address, or direct link to a contact form so visitors can actually reach the organisation from this page.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page is a contact preferences form and does not name any individual or specific role responsible for handling enquiries or accountability.
    Fix: Add the name or role (e.g., Supporter Services Manager) of the person or team accountable for contact and data preferences on this page.
  • response_timeframe: The page is a contact preferences form and does not publish any response timeframe for inquiries.
    Fix: Add a clear statement indicating how long it will take to receive a response (e.g., 'We aim to respond within 5 business days').
  • specific: No timeframes of any kind (specific or vague) appear on the page.
    Fix: Include a specific response window in days or hours, such as 'within 10 working days', rather than vague terms.
  • process_exists: The page shows a contact preferences form with no documented complaints or feedback process or link to one.
    Fix: Add a dedicated complaints/feedback section or link describing how supporters can raise concerns.
  • steps_clear: Because no complaints process is provided, there are no steps explaining how to make a complaint.
    Fix: Publish a numbered, step-by-step complaints procedure covering how to submit, what happens next, and escalation options.
  • appeals_exists: The page is a contact preferences form and contains no documented appeals process for decisions or complaints.
    Fix: Add a dedicated appeals/complaints section or link describing how users can formally challenge decisions.
  • independent: No escalation path or independent reviewer is mentioned anywhere on the page.
    Fix: Document an independent escalation route (e.g., to an ombudsman, regulator like the Fundraising Regulator/ICO, or an internal independent reviewer).

AI & Automation

  • detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
    Fix: Create an AI policy that itemises specific use cases (e.g., research, communications, fundraising) and systems covered.
  • limitations: No limitations of AI systems are acknowledged on the page.
    Fix: Add a section to the AI policy that transparently acknowledges limitations such as accuracy, bias, and appropriate-use boundaries.
  • safeguards: No safeguards or quality control measures for AI are described.
    Fix: Document safeguards such as human oversight, review processes, data governance, and quality assurance controls in the AI policy.
  • marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy on the About or editorial standards page explaining how AI-assisted content is identified and labelled for users.
  • consistent: No AI content markings are visible on the page, so consistent application cannot be demonstrated.
    Fix: Introduce a standard visual label or disclosure for AI-assisted content and apply it consistently across all pages where such content appears.
  • oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
    Fix: Add a statement to the About or governance section documenting that qualified humans review and oversee any AI-generated content.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Describe the editorial review or approval process for AI-assisted content, including who reviews it and against what criteria.
  • accountability: No individual, team, or role is identified as accountable for AI-generated content.
    Fix: Name a responsible role or team (e.g., editorial lead or governance committee) accountable for AI-generated content and publish their remit.

Interoperability

Privacy

  • necessity: The landing page does not explicitly state that data collection is limited to what is necessary, only that data is used in 'lots of different ways.'
    Fix: Add an explicit statement on this landing page committing to data minimisation, e.g., 'We only collect personal information that is necessary for the purposes described.'
  • proportionate: There is no statement on this page indicating that data collection is proportionate to the service provided.
    Fix: Include a clear proportionality statement explaining that the data collected is limited to what is proportionate to each specific interaction or service.
  • retention_stated: The landing page does not mention data retention periods or link directly to a retention schedule.
    Fix: Add a dedicated retention section (or prominent link) on this page summarising how long different categories of personal data are kept.
  • specific: No specific retention durations (e.g., number of years) are provided anywhere on this landing page.
    Fix: Publish specific retention periods for each data category (e.g., 'donor records kept for 7 years after last donation') rather than leaving retention unspecified.
  • equal_choices: The page does not display any consent interface showing accept and reject options, so equal prominence cannot be verified on this privacy policy page.
    Fix: Provide a visible cookie/consent banner link or summary on the privacy page demonstrating that 'Accept' and 'Reject' options are presented with equal visual prominence.
  • banner_present: The page content shows no visible cookie or consent banner, only a 'Cookies' link in the footer.
    Fix: Implement a visible cookie consent banner on first visit that allows users to accept or reject non-essential cookies.
  • partner_sharing_mentioned: There is no on-page consent copy or banner text disclosing data sharing with third-party partners.
    Fix: Add explicit banner copy disclosing that cookies and data may be shared with third-party advertising and analytics partners, with a link to details.
  • partner_count_specific: No numeric count of partners is stated anywhere on the page since no partner disclosure exists.
    Fix: Include a specific partner count (e.g., 'We share data with X partners') in the consent banner with a link to the full vendor list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team (e.g., Supporter Services) is identified on the page as responsible for enquiries.
    Fix: Identify the specific team (such as Supporter Services) and ideally a contact person responsible for handling preference and enquiry submissions.
  • role_clear: Because no person or team is named, their role and authority over enquiries is also not stated.
    Fix: Once a responsible team is identified, clearly describe their role and authority (e.g., 'Our Supporter Services team manages all contact preference requests and enquiries').
  • detail: The page mentions funding categories broadly but provides no amounts, percentages, or breakdowns of how funds are raised or allocated.
    Fix: Add a summary (e.g., percentage or monetary breakdown) showing how much income comes from donations, shops, legacies, and corporate partners, and how funds are spent.
  • complete: While several fundraising streams are mentioned, there is no comprehensive disclosure covering all major funding sources such as grants, investments, or government income.
    Fix: Include a link to a complete funding transparency page or annual report summary that covers every major income stream the charity receives.
  • roles_clear: While governance bodies are named (Chief Executive, Executive Board, Members, Council Committees), the page does not describe the specific responsibilities of each role.
    Fix: Add a short description under each governance link outlining the specific responsibilities and remit of the Chief Executive, Executive Board, Members, and Council Committees.
  • algorithm_explained: The About page describes the organisation's mission and activities but does not mention any algorithms or explain their purpose.
    Fix: Add a section or link disclosing any algorithmic systems used (e.g., for donations, research, or personalisation) and explaining their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include clear statements describing how any algorithmic decisions impact users, donors, or beneficiaries.
  • annual_statement: The page links to a Privacy policy but provides no evidence of an annual or periodic review of data practices.
    Fix: Add a statement (e.g., on the privacy page linked from the footer) noting when data practices are reviewed and the date of the last review.
  • dated: The footer links to Privacy and Terms but shows no visible date or version for the data practices statement on this page.
    Fix: Display a 'last updated' date or version number alongside the Privacy link or on the privacy statement itself.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement describes ongoing improvement efforts and a past CMS migration but provides no dates or target timeline for fixing the acknowledged issues like keyboard navigation, alt text, or heading hierarchy.
    Fix: Add specific target dates or a remediation schedule for resolving each listed accessibility issue so users know when barriers are expected to be fixed.
  • feedback_channel: The 'Contact us' section invites users to call, email, or chat to report accessibility issues but states no commitment on how quickly they will respond.
    Fix: Add a stated response timeframe (e.g., 'we aim to reply within 5 working days') to the contact/feedback section.

Accountability

  • policy_exists: The page contains terms for SMS donations but does not publish any moderation policy for user-generated content or community interactions.
    Fix: Publish a dedicated moderation policy covering user-generated content and community interactions, and link to it from the terms page.
  • criteria_clear: No moderation criteria are stated on this page; it focuses solely on donation mechanics, limits, refunds, and Gift Aid.
    Fix: Add a clear list of moderation criteria (e.g., prohibited content, acceptable use) so users understand what is and isn't allowed.
  • enforcement: There is no explanation of how moderation decisions are made, escalated, or enforced anywhere on this page.
    Fix: Document the enforcement process, including who reviews content, timelines, possible actions, and how users can appeal moderation decisions.

Interoperability

Security

  • plan_exists: The About us page contains no published incident response plan or security policy, listing only general links like terms, privacy, and accessibility.
    Fix: Publish a clear incident response plan or security policy and link to it from the site footer or a dedicated security page.
  • notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public when significant incidents occur.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making.
    Fix: Publish the specific criteria used by any algorithmic systems in a dedicated transparency page linked from About us.
  • weighting: No weighting or prioritisation of any decision criteria is explained on the page.
    Fix: Document how each criterion is weighted or prioritised in algorithmic decisions and publish it alongside the criteria.
  • auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithms.
    Fix: Provide an algorithmic transparency report with sufficient detail (data sources, models, governance) to support independent audit.
  • open_source: The about page contains no links to source code or any open source repositories.
    Fix: Add a link (e.g., to a GitHub organisation or code repository) on the about page or a developer/tech section disclosing any open source projects the charity maintains.
  • tech_docs: No technical documentation is published or linked from the about page.
    Fix: Publish and link to technical documentation (such as an API reference, data documentation, or developer portal) from the about page or a dedicated technology section.

Responsibility to the Future

  • disclosure_exists: The About us page contains no published environmental impact or sustainability disclosure, only content about cancer research, fundraising, and organisational governance.
    Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About us and footer sections.
  • specific_metrics: The page provides no specific environmental figures such as carbon emissions, energy use, or emissions data.
    Fix: Add quantified environmental metrics (e.g., annual carbon footprint in tonnes CO2e and energy consumption) to a sustainability report.
  • hosting_disclosure: There is no disclosure of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Disclose the hosting provider's energy source and carbon profile, ideally noting use of renewable or green hosting, in a sustainability or technical section.
  • plan_exists: The About us page describes the charity's mission, organisation, and strategy but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or wind-down plan describing what would happen to the organisation's operations and assets in the event of failure or dissolution.
  • data_and_content_fate: The page addresses no scenario for the fate of user data or published content should the organisation cease operations.
    Fix: Add a statement clarifying how user data and published cancer information would be preserved, transferred, or deleted if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name a designated custodian, mirror, or archive partner (e.g., a national web archive or successor charity) responsible for preserving content if the organisation exits.
  • policy_exists: The page only references careers and an executive board but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or Careers section.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the wellbeing policy.
  • accountability: While an Executive Board and Council Committees are mentioned, no accountability or oversight is specifically assigned to worker conditions.
    Fix: Name the board, committee, or role responsible for overseeing worker wellbeing and working conditions.