Durham University

https://www.dur.ac.uk · 41/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 24/37 (13 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 6/16
Provenance 2/2
Security 4/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

  • without controls: {'tag': 'video', 'src': '', 'autoplay': True, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}, {'tag': 'video', 'src': '', 'autoplay': False, 'controls': False}

AI & Automation

  • policy_exists: The About page contains no mention of an AI use policy or statement.
    Fix: Publish an AI use policy or statement and link it from the About page's policies section alongside the Disclaimer and Cookie policy.
  • scope_clear: Because no AI policy is present, the page does not explain what AI is used for.
    Fix: Add a clear description of where and how AI is used across university services within the AI policy.

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only links to Annual Reports without direct funding information.
    Fix: Add a dedicated funding/sponsorship disclosure section on the About page summarizing the university's main income sources.
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly list funding sources such as tuition fees, government grants, research councils, and donations with links to supporting documentation.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic departments (Switchboard, Security Office, Communications, etc.) without naming any individual or specific role holder responsible for enquiries.
    Fix: Add the name or job title of a specific person or role (e.g., Head of Communications) accountable for handling contact enquiries.
  • response_timeframe: The contact page lists phone numbers and addresses but does not publish any response timeframes for enquiries or complaints.
    Fix: Add a clear statement indicating how quickly the university will respond to enquiries (e.g., 'We aim to respond within 5 working days').
  • specific: Since no response timeframe is provided at all, there is no specific day-based commitment on the page.
    Fix: Publish a specific numeric response time (e.g., 'within 3 business days') rather than vague language.
  • process_exists: The page only mentions 'Student complaints and non-academic misconduct' as a footer link but does not describe a complaints or feedback process on the contact page itself.
    Fix: Add a dedicated complaints/feedback section on the contact page linking to the full policy and summarising how to submit a complaint.
  • steps_clear: No step-by-step guidance for making a complaint is shown on the contact page.
    Fix: Include a numbered list of steps (e.g., who to contact first, how to escalate, expected outcomes) for submitting a complaint.
  • appeals_exists: The contact page lists phone numbers and addresses but does not document any appeals process.
    Fix: Add a clearly labeled appeals section or link to an official appeals policy outlining how to submit and escalate appeals.
  • independent: No appeals process is described, so there is no indication of independent review or escalation paths.
    Fix: Publish an appeals procedure that specifies an independent reviewer or escalation route (e.g., ombudsperson or external body) for unresolved complaints.

AI & Automation

  • detailed_scope: The page does not detail the scope of any AI use across university activities.
    Fix: Include a dedicated section in the AI policy enumerating specific AI applications (e.g., teaching, admissions, research, web services).
  • limitations: No AI limitations or risks are acknowledged anywhere on the page.
    Fix: Add a 'Limitations' subsection describing known constraints, risks, and uncertainties of AI systems used by the university.
  • safeguards: No safeguards, quality controls, or oversight mechanisms for AI are described on the page.
    Fix: Document safeguards such as human oversight, bias testing, data governance, and review processes in a published AI policy.
  • marking_policy: The About page contains no policy or statement regarding the marking or labeling of AI-assisted content.
    Fix: Publish a clear policy on the site describing how AI-assisted content is labeled or disclosed to users.
  • consistent: Without a marking policy present, there is no evidence of consistent application of AI content labeling on this page.
    Fix: Once a marking policy is established, apply consistent AI-content labels across all pages and link to the policy.
  • oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
    Fix: Add a statement or dedicated page documenting the human oversight process for any AI-generated or AI-assisted content.
  • review_process: No review or approval workflow for AI content is described anywhere on the page.
    Fix: Document and publish the editorial review/approval steps AI-generated content must pass before being published.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name a responsible owner (e.g., a specific office or role) accountable for AI content governance and include their contact details.

Interoperability

Privacy

  • plain_language: The page uses legalistic terminology such as 'data subjects', 'controller', 'profiling', and 'legitimate interests' without plain-language explanations.
    Fix: Rewrite the rights descriptions in plain English and add brief glossary-style definitions for terms like 'data subject' and 'controller'.
  • comprehensive: This landing page only links to various privacy notices and describes rights, but does not itself explain what data is collected and why.
    Fix: Add a summary on this page describing the categories of personal data the University collects and the purposes for processing, or clearly direct users to the General Privacy Notice with a brief overview.
  • plain_language: The content contains jargon such as 'performance of a task in the public interest/exercise of official authority', 'automated processing', and 'legitimate interests' without plain-language equivalents.
    Fix: Simplify wording and replace legal phrases with everyday explanations, or provide plain-language summaries alongside the formal terms.
  • understandable: Because the page focuses on rights and timescales rather than clearly explaining what data is collected and why, a non-expert would not readily understand the University's data practices from this page.
    Fix: Add a concise, user-friendly summary of what personal data is collected, from whom, and for what purposes before linking to the detailed notices.
  • necessity: The page does not contain any statement that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit data minimisation statement confirming that only data necessary for specified purposes is collected.
  • proportionate: There is no discussion on this page of whether the data collected is proportionate to the services provided.
    Fix: Include a statement addressing proportionality, explaining that the data collected is commensurate with the purpose of each processing activity.
  • retention_stated: The page makes no mention of data retention periods, only response timescales for individual rights requests.
    Fix: Add a data retention section (or clearly link to a retention schedule) stating how long each category of personal data is kept.
  • specific: Because no retention periods are given at all, there are no specific timeframes provided.
    Fix: Publish specific retention durations (e.g., 'student records retained for 7 years after graduation') for each relevant data category.
  • equal_choices: The page itself does not present a consent interface with accept/reject options; only a footer 'Cookie notice' link is shown, so equal prominence of choices cannot be verified here.
    Fix: Surface a cookie/consent banner on this page with equally prominent 'Accept' and 'Reject' buttons at the same visual weight and position.
  • banner_present: The page content shows no visible cookie or consent banner; only a footer 'Cookie notice' link is present.
    Fix: Implement a visible cookie/consent banner on page load that allows users to accept, reject, or manage cookies before non-essential cookies are set.
  • partner_sharing_mentioned: There is no banner or on-page consent copy disclosing data sharing with third-party partners.
    Fix: Include clear language in the consent banner disclosing that data may be shared with third-party advertising/analytics partners, with a link to the full list.
  • partner_count_specific: No partner sharing is disclosed and therefore no numeric count of partners is provided on the page.
    Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner or linked preference center.

Provenance

Security

Transparency

  • role_clear: While team names are listed next to phone numbers, their remits or authority (what each team handles) are not explained on the page.
    Fix: Add a brief description next to each listed team explaining the types of enquiries they are responsible for handling.
  • detail: The page provides no amounts, percentages, or categories of funding.
    Fix: Include specific figures or percentage breakdowns of funding streams (e.g., tuition, research grants, philanthropy) directly on the About page or a linked funding page.
  • complete: Because no funding disclosure exists, no major funding streams are covered.
    Fix: Publish a comprehensive funding overview covering all major revenue streams, ideally linked prominently from the About page.
  • roles_clear: The page mentions a 'strong leadership team' but does not identify specific key roles or their responsibilities on this page.
    Fix: Add a summary of key governance roles (e.g., Vice-Chancellor, Council, Senate) with brief descriptions of their responsibilities directly on the About page.
  • algorithm_explained: The About page makes no mention of any algorithms used by the university (e.g., for admissions, rankings display, or personalization), so no purpose is explained.
    Fix: Add a section or link disclosing any algorithmic systems used (such as in admissions or student services) and clearly explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff anywhere on the page.
    Fix: Include plain-language statements describing how any algorithmic decisions impact users and what recourse or human review is available.
  • annual_statement: The page links to privacy notices and a cookie policy but shows no evidence of a regular or annual review of data practices.
    Fix: Publish a statement (e.g., within the privacy notices) indicating when data practices are reviewed and that reviews occur on a defined periodic schedule.
  • dated: The linked privacy/cookie notices are referenced without any visible date or version indicator on this page.
    Fix: Add a 'last updated' date or version number next to the privacy notice and cookie policy links so users can see currency at a glance.

Level 3 — Advanced

Accessibility

  • known_issues: The visible page content only provides links labeled 'Web accessibility' without displaying any acknowledgment of known accessibility issues or limitations.
    Fix: Include or link to a statement section that explicitly lists known accessibility issues and non-compliant areas of the site.
  • remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on the page.
    Fix: Add a stated timeline or commitment date for addressing known accessibility barriers within the accessibility statement.
  • feedback_channel: The page offers general contact links but no accessibility-specific feedback mechanism with a response commitment.
    Fix: Provide a dedicated accessibility feedback contact (email or form) along with a stated timeframe for responding to reports.

Accountability

  • policy_exists: The About page does not publish or link to any moderation policies for user-generated content or community interactions.
    Fix: Publish a moderation policy page and link to it from the About section or site footer.
  • criteria_clear: No moderation criteria (e.g., what content is permitted or prohibited) are stated anywhere on the page.
    Fix: Add a clearly written list of moderation criteria outlining acceptable and prohibited content on university-managed platforms.
  • enforcement: The page does not describe any enforcement process, appeals mechanism, or consequences for policy violations.
    Fix: Document the enforcement workflow, including who reviews content, timelines, sanctions, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The About us page contains no published incident response plan or security policy, only general institutional, governance, and sustainability content.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the About us or policies section.
  • notification_commitment: The page makes no commitment to publicly notify affected users of significant security incidents.
    Fix: Add an explicit statement committing the university to notify affected individuals and the public of significant security incidents.
  • timeframe: No disclosure timeframe for notifying affected users about incidents is stated anywhere on the page.
    Fix: Specify a concrete notification timeframe (e.g., within 72 hours of discovery) in the published incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on the page.
    Fix: Publish a transparency page listing the specific input criteria used by any decision-making algorithms employed by the university.
  • weighting: The page provides no information about how criteria are weighted or prioritized in any algorithmic process.
    Fix: Document and publish the relative weighting or priority given to each criterion in algorithmic decision systems.
  • auditable: The page contains no methodology, documentation, or technical detail sufficient for external audit or review of any algorithm.
    Fix: Provide detailed algorithm documentation (methodology, data sources, validation, governance) or link to an audit report enabling independent review.
  • open_source: No source code repository or open-source links are provided on the About page.
    Fix: Add a link to a public code repository (e.g., GitHub) for any university-maintained open-source projects or website code, if applicable.
  • tech_docs: The page contains no technical documentation about the site's platform, APIs, or data standards.
    Fix: Publish technical documentation or a developer page describing the website's technology, APIs, or data feeds and link to it from the About section.

Responsibility to the Future

  • specific_metrics: The sustainability content is qualitative and cites no specific figures for carbon emissions, energy use, or net-zero targets.
    Fix: Add concrete quantitative figures such as annual carbon emissions (tCO2e), energy consumption, and dated net-zero reduction targets to the sustainability section.
  • hosting_disclosure: The page makes no mention of the carbon or energy profile of its website hosting or digital infrastructure.
    Fix: Publish a statement disclosing the hosting provider's energy source, carbon footprint, or use of green/renewable-powered hosting for the website.
  • plan_exists: The page describes charitable status and the historical Royal Charter but contains no published plan for what happens if the University fails or exits.
    Fix: Publish a succession or wind-down plan describing how the organisation would handle failure or closure, and link it from the governance page.
  • data_and_content_fate: There is no mention of what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add an explicit statement covering the fate of user data and published content upon closure, including retention, transfer, or deletion procedures.
  • custodians_or_mirrors: The page references the University Archives for the Royal Charter hardcopy but names no custodians, mirrors, or archive partners responsible for content continuity if the organisation ceases to operate.
    Fix: Identify designated custodians, mirror sites, or archive partners who would preserve content and data if the University exits.
  • policy_exists: The page is a cultural/museums landing page for Durham University with no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the site's footer or About Us section.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add concrete commitments covering pay, working hours, mental health support, and staff benefits within a documented wellbeing policy.
  • accountability: The page identifies no accountable role, team, or oversight body responsible for worker conditions.
    Fix: Name a responsible officer or oversight committee for worker conditions and provide their contact details on the site.