Durham University
https://www.dur.ac.uk · 41/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 24/37 (13 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 6/16 |
| Provenance | 2/2 |
| Security | 4/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- autoplay without controls: {'tag': 'video', 'src': '', 'autoplay': True, 'controls': False}
- without controls: {'tag': 'video', 'src': '', 'autoplay': True, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish an AI use policy or statement and link it from the About page's policies section alongside the Disclaimer and Cookie policy.
-
scope_clear: Because no AI policy is present, the page does not explain what AI is used for.
Fix: Add a clear description of where and how AI is used across university services within the AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
- Page sent requests to 3 known domains from the block list: connect.facebook.net.
- 2 third-party cookie domains set cookies: .vimeo.com, .youtube.com.
- Page sent requests to 3 known domains from the block list: connect.facebook.net.
- No scripts matched the tracker/ad pattern list.
- Detected 6 data-leaking services across 4 categories: facebook (connect.facebook.net); google fonts (fonts.gstatic.com); vimeo embed (player.vimeo.com); youtube embed (i.ytimg.com, i3.ytimg.com, www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.dur.ac.uk
- x-frame-options: SAMEORIGIN
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only links to Annual Reports without direct funding information.
Fix: Add a dedicated funding/sponsorship disclosure section on the About page summarizing the university's main income sources.
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly list funding sources such as tuition fees, government grants, research councils, and donations with links to supporting documentation.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only generic departments (Switchboard, Security Office, Communications, etc.) without naming any individual or specific role holder responsible for enquiries.
Fix: Add the name or job title of a specific person or role (e.g., Head of Communications) accountable for handling contact enquiries.
-
response_timeframe: The contact page lists phone numbers and addresses but does not publish any response timeframes for enquiries or complaints.
Fix: Add a clear statement indicating how quickly the university will respond to enquiries (e.g., 'We aim to respond within 5 working days').
-
specific: Since no response timeframe is provided at all, there is no specific day-based commitment on the page.
Fix: Publish a specific numeric response time (e.g., 'within 3 business days') rather than vague language.
-
process_exists: The page only mentions 'Student complaints and non-academic misconduct' as a footer link but does not describe a complaints or feedback process on the contact page itself.
Fix: Add a dedicated complaints/feedback section on the contact page linking to the full policy and summarising how to submit a complaint.
-
steps_clear: No step-by-step guidance for making a complaint is shown on the contact page.
Fix: Include a numbered list of steps (e.g., who to contact first, how to escalate, expected outcomes) for submitting a complaint.
-
appeals_exists: The contact page lists phone numbers and addresses but does not document any appeals process.
Fix: Add a clearly labeled appeals section or link to an official appeals policy outlining how to submit and escalate appeals.
-
independent: No appeals process is described, so there is no indication of independent review or escalation paths.
Fix: Publish an appeals procedure that specifies an independent reviewer or escalation route (e.g., ombudsperson or external body) for unresolved complaints.
AI & Automation
-
detailed_scope: The page does not detail the scope of any AI use across university activities.
Fix: Include a dedicated section in the AI policy enumerating specific AI applications (e.g., teaching, admissions, research, web services).
-
limitations: No AI limitations or risks are acknowledged anywhere on the page.
Fix: Add a 'Limitations' subsection describing known constraints, risks, and uncertainties of AI systems used by the university.
-
safeguards: No safeguards, quality controls, or oversight mechanisms for AI are described on the page.
Fix: Document safeguards such as human oversight, bias testing, data governance, and review processes in a published AI policy.
-
marking_policy: The About page contains no policy or statement regarding the marking or labeling of AI-assisted content.
Fix: Publish a clear policy on the site describing how AI-assisted content is labeled or disclosed to users.
-
consistent: Without a marking policy present, there is no evidence of consistent application of AI content labeling on this page.
Fix: Once a marking policy is established, apply consistent AI-content labels across all pages and link to the policy.
-
oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
Fix: Add a statement or dedicated page documenting the human oversight process for any AI-generated or AI-assisted content.
-
review_process: No review or approval workflow for AI content is described anywhere on the page.
Fix: Document and publish the editorial review/approval steps AI-generated content must pass before being published.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name a responsible owner (e.g., a specific office or role) accountable for AI content governance and include their contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
plain_language: The page uses legalistic terminology such as 'data subjects', 'controller', 'profiling', and 'legitimate interests' without plain-language explanations.
Fix: Rewrite the rights descriptions in plain English and add brief glossary-style definitions for terms like 'data subject' and 'controller'.
-
comprehensive: This landing page only links to various privacy notices and describes rights, but does not itself explain what data is collected and why.
Fix: Add a summary on this page describing the categories of personal data the University collects and the purposes for processing, or clearly direct users to the General Privacy Notice with a brief overview.
-
plain_language: The content contains jargon such as 'performance of a task in the public interest/exercise of official authority', 'automated processing', and 'legitimate interests' without plain-language equivalents.
Fix: Simplify wording and replace legal phrases with everyday explanations, or provide plain-language summaries alongside the formal terms.
-
understandable: Because the page focuses on rights and timescales rather than clearly explaining what data is collected and why, a non-expert would not readily understand the University's data practices from this page.
Fix: Add a concise, user-friendly summary of what personal data is collected, from whom, and for what purposes before linking to the detailed notices.
-
necessity: The page does not contain any statement that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit data minimisation statement confirming that only data necessary for specified purposes is collected.
-
proportionate: There is no discussion on this page of whether the data collected is proportionate to the services provided.
Fix: Include a statement addressing proportionality, explaining that the data collected is commensurate with the purpose of each processing activity.
-
retention_stated: The page makes no mention of data retention periods, only response timescales for individual rights requests.
Fix: Add a data retention section (or clearly link to a retention schedule) stating how long each category of personal data is kept.
-
specific: Because no retention periods are given at all, there are no specific timeframes provided.
Fix: Publish specific retention durations (e.g., 'student records retained for 7 years after graduation') for each relevant data category.
-
equal_choices: The page itself does not present a consent interface with accept/reject options; only a footer 'Cookie notice' link is shown, so equal prominence of choices cannot be verified here.
Fix: Surface a cookie/consent banner on this page with equally prominent 'Accept' and 'Reject' buttons at the same visual weight and position.
-
banner_present: The page content shows no visible cookie or consent banner; only a footer 'Cookie notice' link is present.
Fix: Implement a visible cookie/consent banner on page load that allows users to accept, reject, or manage cookies before non-essential cookies are set.
-
partner_sharing_mentioned: There is no banner or on-page consent copy disclosing data sharing with third-party partners.
Fix: Include clear language in the consent banner disclosing that data may be shared with third-party advertising/analytics partners, with a link to the full list.
-
partner_count_specific: No partner sharing is disclosed and therefore no numeric count of partners is provided on the page.
Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner or linked preference center.
Provenance
Security
- security.txt not published.
Transparency
-
role_clear: While team names are listed next to phone numbers, their remits or authority (what each team handles) are not explained on the page.
Fix: Add a brief description next to each listed team explaining the types of enquiries they are responsible for handling.
-
detail: The page provides no amounts, percentages, or categories of funding.
Fix: Include specific figures or percentage breakdowns of funding streams (e.g., tuition, research grants, philanthropy) directly on the About page or a linked funding page.
-
complete: Because no funding disclosure exists, no major funding streams are covered.
Fix: Publish a comprehensive funding overview covering all major revenue streams, ideally linked prominently from the About page.
-
roles_clear: The page mentions a 'strong leadership team' but does not identify specific key roles or their responsibilities on this page.
Fix: Add a summary of key governance roles (e.g., Vice-Chancellor, Council, Senate) with brief descriptions of their responsibilities directly on the About page.
-
algorithm_explained: The About page makes no mention of any algorithms used by the university (e.g., for admissions, rankings display, or personalization), so no purpose is explained.
Fix: Add a section or link disclosing any algorithmic systems used (such as in admissions or student services) and clearly explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff anywhere on the page.
Fix: Include plain-language statements describing how any algorithmic decisions impact users and what recourse or human review is available.
-
annual_statement: The page links to privacy notices and a cookie policy but shows no evidence of a regular or annual review of data practices.
Fix: Publish a statement (e.g., within the privacy notices) indicating when data practices are reviewed and that reviews occur on a defined periodic schedule.
-
dated: The linked privacy/cookie notices are referenced without any visible date or version indicator on this page.
Fix: Add a 'last updated' date or version number next to the privacy notice and cookie policy links so users can see currency at a glance.
Level 3 — Advanced
Accessibility
-
known_issues: The visible page content only provides links labeled 'Web accessibility' without displaying any acknowledgment of known accessibility issues or limitations.
Fix: Include or link to a statement section that explicitly lists known accessibility issues and non-compliant areas of the site.
-
remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on the page.
Fix: Add a stated timeline or commitment date for addressing known accessibility barriers within the accessibility statement.
-
feedback_channel: The page offers general contact links but no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility feedback contact (email or form) along with a stated timeframe for responding to reports.
Accountability
-
policy_exists: The About page does not publish or link to any moderation policies for user-generated content or community interactions.
Fix: Publish a moderation policy page and link to it from the About section or site footer.
-
criteria_clear: No moderation criteria (e.g., what content is permitted or prohibited) are stated anywhere on the page.
Fix: Add a clearly written list of moderation criteria outlining acceptable and prohibited content on university-managed platforms.
-
enforcement: The page does not describe any enforcement process, appeals mechanism, or consequences for policy violations.
Fix: Document the enforcement workflow, including who reviews content, timelines, sanctions, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About us page contains no published incident response plan or security policy, only general institutional, governance, and sustainability content.
Fix: Publish a dedicated incident response plan or security policy and link to it from the About us or policies section.
-
notification_commitment: The page makes no commitment to publicly notify affected users of significant security incidents.
Fix: Add an explicit statement committing the university to notify affected individuals and the public of significant security incidents.
-
timeframe: No disclosure timeframe for notifying affected users about incidents is stated anywhere on the page.
Fix: Specify a concrete notification timeframe (e.g., within 72 hours of discovery) in the published incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are published on the page.
Fix: Publish a transparency page listing the specific input criteria used by any decision-making algorithms employed by the university.
-
weighting: The page provides no information about how criteria are weighted or prioritized in any algorithmic process.
Fix: Document and publish the relative weighting or priority given to each criterion in algorithmic decision systems.
-
auditable: The page contains no methodology, documentation, or technical detail sufficient for external audit or review of any algorithm.
Fix: Provide detailed algorithm documentation (methodology, data sources, validation, governance) or link to an audit report enabling independent review.
-
open_source: No source code repository or open-source links are provided on the About page.
Fix: Add a link to a public code repository (e.g., GitHub) for any university-maintained open-source projects or website code, if applicable.
-
tech_docs: The page contains no technical documentation about the site's platform, APIs, or data standards.
Fix: Publish technical documentation or a developer page describing the website's technology, APIs, or data feeds and link to it from the About section.
Responsibility to the Future
-
specific_metrics: The sustainability content is qualitative and cites no specific figures for carbon emissions, energy use, or net-zero targets.
Fix: Add concrete quantitative figures such as annual carbon emissions (tCO2e), energy consumption, and dated net-zero reduction targets to the sustainability section.
-
hosting_disclosure: The page makes no mention of the carbon or energy profile of its website hosting or digital infrastructure.
Fix: Publish a statement disclosing the hosting provider's energy source, carbon footprint, or use of green/renewable-powered hosting for the website.
-
plan_exists: The page describes charitable status and the historical Royal Charter but contains no published plan for what happens if the University fails or exits.
Fix: Publish a succession or wind-down plan describing how the organisation would handle failure or closure, and link it from the governance page.
-
data_and_content_fate: There is no mention of what would happen to user data or published content in the event of organisational failure or exit.
Fix: Add an explicit statement covering the fate of user data and published content upon closure, including retention, transfer, or deletion procedures.
-
custodians_or_mirrors: The page references the University Archives for the Royal Charter hardcopy but names no custodians, mirrors, or archive partners responsible for content continuity if the organisation ceases to operate.
Fix: Identify designated custodians, mirror sites, or archive partners who would preserve content and data if the University exits.
-
policy_exists: The page is a cultural/museums landing page for Durham University with no published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from the site's footer or About Us section.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add concrete commitments covering pay, working hours, mental health support, and staff benefits within a documented wellbeing policy.
-
accountability: The page identifies no accountable role, team, or oversight body responsible for worker conditions.
Fix: Name a responsible officer or oversight committee for worker conditions and provide their contact details on the site.