Cancer Research UK
https://www.cancerresearchuk.org · 46/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (9 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 8/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: label.
- 1 WCAG 2.1 Level A violation reported by axe-core: label.
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish an AI use policy or statement and link to it from the About us page and site footer.
-
scope_clear: There is no explanation of what AI is used for anywhere on this page.
Fix: Include a clear description of the purposes and contexts in which AI is used by the organisation within the AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.cancerresearchuk.org
- x-frame-options: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
actionable: The page only shows a form to manage contact preferences and the registered address, but provides no direct phone number, email address, or actionable contact channel to reach the organisation.
Fix: Add a visible phone number, email address, or direct link to a contact form so visitors can actually reach the organisation from this page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
- 1 form-label violation reported by axe-core.
Accountability
-
named_person: The page is a contact preferences form and does not name any individual or specific role responsible for handling enquiries or accountability.
Fix: Add the name or role (e.g., Supporter Services Manager) of the person or team accountable for contact and data preferences on this page.
-
response_timeframe: The page is a contact preferences form and does not publish any response timeframe for inquiries.
Fix: Add a clear statement indicating how long it will take to receive a response (e.g., 'We aim to respond within 5 business days').
-
specific: No timeframes of any kind (specific or vague) appear on the page.
Fix: Include a specific response window in days or hours, such as 'within 10 working days', rather than vague terms.
-
process_exists: The page shows a contact preferences form with no documented complaints or feedback process or link to one.
Fix: Add a dedicated complaints/feedback section or link describing how supporters can raise concerns.
-
steps_clear: Because no complaints process is provided, there are no steps explaining how to make a complaint.
Fix: Publish a numbered, step-by-step complaints procedure covering how to submit, what happens next, and escalation options.
-
appeals_exists: The page is a contact preferences form and contains no documented appeals process for decisions or complaints.
Fix: Add a dedicated appeals/complaints section or link describing how users can formally challenge decisions.
-
independent: No escalation path or independent reviewer is mentioned anywhere on the page.
Fix: Document an independent escalation route (e.g., to an ombudsman, regulator like the Fundraising Regulator/ICO, or an internal independent reviewer).
AI & Automation
-
detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
Fix: Create an AI policy that itemises specific use cases (e.g., research, communications, fundraising) and systems covered.
-
limitations: No limitations of AI systems are acknowledged on the page.
Fix: Add a section to the AI policy that transparently acknowledges limitations such as accuracy, bias, and appropriate-use boundaries.
-
safeguards: No safeguards or quality control measures for AI are described.
Fix: Document safeguards such as human oversight, review processes, data governance, and quality assurance controls in the AI policy.
-
marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or labelled.
Fix: Publish a clear policy on the About or editorial standards page explaining how AI-assisted content is identified and labelled for users.
-
consistent: No AI content markings are visible on the page, so consistent application cannot be demonstrated.
Fix: Introduce a standard visual label or disclosure for AI-assisted content and apply it consistently across all pages where such content appears.
-
oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
Fix: Add a statement to the About or governance section documenting that qualified humans review and oversee any AI-generated content.
-
review_process: No review or approval workflow for AI content is described on the page.
Fix: Describe the editorial review or approval process for AI-assisted content, including who reviews it and against what criteria.
-
accountability: No individual, team, or role is identified as accountable for AI-generated content.
Fix: Name a responsible role or team (e.g., editorial lead or governance committee) accountable for AI-generated content and publish their remit.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The landing page does not explicitly state that data collection is limited to what is necessary, only that data is used in 'lots of different ways.'
Fix: Add an explicit statement on this landing page committing to data minimisation, e.g., 'We only collect personal information that is necessary for the purposes described.'
-
proportionate: There is no statement on this page indicating that data collection is proportionate to the service provided.
Fix: Include a clear proportionality statement explaining that the data collected is limited to what is proportionate to each specific interaction or service.
-
retention_stated: The landing page does not mention data retention periods or link directly to a retention schedule.
Fix: Add a dedicated retention section (or prominent link) on this page summarising how long different categories of personal data are kept.
-
specific: No specific retention durations (e.g., number of years) are provided anywhere on this landing page.
Fix: Publish specific retention periods for each data category (e.g., 'donor records kept for 7 years after last donation') rather than leaving retention unspecified.
-
equal_choices: The page does not display any consent interface showing accept and reject options, so equal prominence cannot be verified on this privacy policy page.
Fix: Provide a visible cookie/consent banner link or summary on the privacy page demonstrating that 'Accept' and 'Reject' options are presented with equal visual prominence.
-
banner_present: The page content shows no visible cookie or consent banner, only a 'Cookies' link in the footer.
Fix: Implement a visible cookie consent banner on first visit that allows users to accept or reject non-essential cookies.
-
partner_sharing_mentioned: There is no on-page consent copy or banner text disclosing data sharing with third-party partners.
Fix: Add explicit banner copy disclosing that cookies and data may be shared with third-party advertising and analytics partners, with a link to details.
-
partner_count_specific: No numeric count of partners is stated anywhere on the page since no partner disclosure exists.
Fix: Include a specific partner count (e.g., 'We share data with X partners') in the consent banner with a link to the full vendor list.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team (e.g., Supporter Services) is identified on the page as responsible for enquiries.
Fix: Identify the specific team (such as Supporter Services) and ideally a contact person responsible for handling preference and enquiry submissions.
-
role_clear: Because no person or team is named, their role and authority over enquiries is also not stated.
Fix: Once a responsible team is identified, clearly describe their role and authority (e.g., 'Our Supporter Services team manages all contact preference requests and enquiries').
-
detail: The page mentions funding categories broadly but provides no amounts, percentages, or breakdowns of how funds are raised or allocated.
Fix: Add a summary (e.g., percentage or monetary breakdown) showing how much income comes from donations, shops, legacies, and corporate partners, and how funds are spent.
-
complete: While several fundraising streams are mentioned, there is no comprehensive disclosure covering all major funding sources such as grants, investments, or government income.
Fix: Include a link to a complete funding transparency page or annual report summary that covers every major income stream the charity receives.
-
roles_clear: While governance bodies are named (Chief Executive, Executive Board, Members, Council Committees), the page does not describe the specific responsibilities of each role.
Fix: Add a short description under each governance link outlining the specific responsibilities and remit of the Chief Executive, Executive Board, Members, and Council Committees.
-
algorithm_explained: The About page describes the organisation's mission and activities but does not mention any algorithms or explain their purpose.
Fix: Add a section or link disclosing any algorithmic systems used (e.g., for donations, research, or personalisation) and explaining their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include clear statements describing how any algorithmic decisions impact users, donors, or beneficiaries.
-
annual_statement: The page links to a Privacy policy but provides no evidence of an annual or periodic review of data practices.
Fix: Add a statement (e.g., on the privacy page linked from the footer) noting when data practices are reviewed and the date of the last review.
-
dated: The footer links to Privacy and Terms but shows no visible date or version for the data practices statement on this page.
Fix: Display a 'last updated' date or version number alongside the Privacy link or on the privacy statement itself.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement describes ongoing improvement efforts and a past CMS migration but provides no dates or target timeline for fixing the acknowledged issues like keyboard navigation, alt text, or heading hierarchy.
Fix: Add specific target dates or a remediation schedule for resolving each listed accessibility issue so users know when barriers are expected to be fixed.
-
feedback_channel: The 'Contact us' section invites users to call, email, or chat to report accessibility issues but states no commitment on how quickly they will respond.
Fix: Add a stated response timeframe (e.g., 'we aim to reply within 5 working days') to the contact/feedback section.
Accountability
-
policy_exists: The page contains terms for SMS donations but does not publish any moderation policy for user-generated content or community interactions.
Fix: Publish a dedicated moderation policy covering user-generated content and community interactions, and link to it from the terms page.
-
criteria_clear: No moderation criteria are stated on this page; it focuses solely on donation mechanics, limits, refunds, and Gift Aid.
Fix: Add a clear list of moderation criteria (e.g., prohibited content, acceptable use) so users understand what is and isn't allowed.
-
enforcement: There is no explanation of how moderation decisions are made, escalated, or enforced anywhere on this page.
Fix: Document the enforcement process, including who reviews content, timelines, possible actions, and how users can appeal moderation decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About us page contains no published incident response plan or security policy, listing only general links like terms, privacy, and accessibility.
Fix: Publish a clear incident response plan or security policy and link to it from the site footer or a dedicated security page.
-
notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public when significant incidents occur.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any criteria used in algorithmic decision-making.
Fix: Publish the specific criteria used by any algorithmic systems in a dedicated transparency page linked from About us.
-
weighting: No weighting or prioritisation of any decision criteria is explained on the page.
Fix: Document how each criterion is weighted or prioritised in algorithmic decisions and publish it alongside the criteria.
-
auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithms.
Fix: Provide an algorithmic transparency report with sufficient detail (data sources, models, governance) to support independent audit.
-
open_source: The about page contains no links to source code or any open source repositories.
Fix: Add a link (e.g., to a GitHub organisation or code repository) on the about page or a developer/tech section disclosing any open source projects the charity maintains.
-
tech_docs: No technical documentation is published or linked from the about page.
Fix: Publish and link to technical documentation (such as an API reference, data documentation, or developer portal) from the about page or a dedicated technology section.
Responsibility to the Future
-
disclosure_exists: The About us page contains no published environmental impact or sustainability disclosure, only content about cancer research, fundraising, and organisational governance.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About us and footer sections.
-
specific_metrics: The page provides no specific environmental figures such as carbon emissions, energy use, or emissions data.
Fix: Add quantified environmental metrics (e.g., annual carbon footprint in tonnes CO2e and energy consumption) to a sustainability report.
-
hosting_disclosure: There is no disclosure of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy source and carbon profile, ideally noting use of renewable or green hosting, in a sustainability or technical section.
-
plan_exists: The About us page describes the charity's mission, organisation, and strategy but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity or wind-down plan describing what would happen to the organisation's operations and assets in the event of failure or dissolution.
-
data_and_content_fate: The page addresses no scenario for the fate of user data or published content should the organisation cease operations.
Fix: Add a statement clarifying how user data and published cancer information would be preserved, transferred, or deleted if the organisation shuts down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name a designated custodian, mirror, or archive partner (e.g., a national web archive or successor charity) responsible for preserving content if the organisation exits.
-
policy_exists: The page only references careers and an executive board but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or Careers section.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the wellbeing policy.
-
accountability: While an Executive Board and Council Committees are mentioned, no accountability or oversight is specifically assigned to worker conditions.
Fix: Name the board, committee, or role responsible for overseeing worker wellbeing and working conditions.