eff.org
https://www.eff.org · 54/89 checks passed
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (10 failed) |
| Level 2 — Enhanced | 15/27 (12 failed) |
| Level 3 — Advanced | 2/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 6/13 |
| Accountability | 1/5 |
| AI & Automation | 6/8 |
| Interoperability | 2/3 |
| Privacy | 14/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 8/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 3 WCAG 2.1 Level A violations reported by axe-core: image-alt, link-in-text-block, link-name.
- 3 WCAG 2.1 Level A violations reported by axe-core: image-alt, link-in-text-block, link-name.
- 1 image missing alt attribute: https://www.eff.org/sites/all/themes/phoenix/images/logo-monogram-white.svg.
- 1 image missing alt attribute: https://www.eff.org/sites/all/themes/phoenix/images/logo-monogram-white.svg.
- Heading hierarchy issues: h1 -> h3 (skipped h2); h3 -> h6 (skipped h4).
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
Privacy
FAIL
No tracking pixels
- 1 1×1 third-party tracking pixel: https://anon-stats.eff.org/js/?idsite=1&rec=1&url=https%3A//www.eff.org/&action_name=Electronic%20Frontier%20Foundation%20%7C%20Defending%20your%20rights%20in%20the%20digital%20world&urlref=.
PASS
Session cookies only
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
appeals_exists: The contact page lists various email and inquiry channels but documents no formal appeals process for challenging decisions.
Fix: Add a clearly labeled appeals section describing how users can formally contest a decision, including required information and expected timelines.
-
independent: Because no appeals process is documented, there is no evidence of an independent or escalated review path.
Fix: Establish and document an escalation route where appeals are reviewed by a person or body independent of the original decision-maker.
-
response_timeframe: The page uses vague phrases like "we'll get back to you soon" but publishes no actual response timeframe for any contact method.
Fix: Add explicit expected response times for each inquiry type (e.g., "we aim to respond within 5 business days").
-
specific: No specific timeframes such as days or hours are stated anywhere; the only temporal reference is the non-specific word "soon."
Fix: Replace vague terms like "soon" with concrete durations such as "within 3 business days".
-
process_exists: The page lists contact email addresses but documents no dedicated complaints or feedback process beyond an accessibility-feedback email.
Fix: Publish a clearly labeled complaints/feedback process explaining how issues are submitted, handled, and escalated.
-
steps_clear: There are no defined steps for lodging a complaint, only email addresses and subject-line conventions without a described procedure or follow-up.
Fix: Add step-by-step instructions describing how to submit a complaint, what happens next, and how it will be resolved.
AI & Automation
-
marking_policy: The page discusses AI as a policy topic but contains no policy for marking or disclosing AI-assisted content on the site itself.
Fix: Publish a clear editorial policy stating whether and how AI-assisted content is labeled, and link it from content pages.
-
consistent: No AI content markings appear on any of the listed blog posts or articles, so consistent application cannot be demonstrated.
Fix: Add visible AI-assistance labels to individual posts and apply them uniformly across all content.
-
oversight_exists: The page describes advocacy on AI issues but does not document any human oversight of the site's own AI outputs.
Fix: Add a statement documenting that humans review any AI-generated or AI-assisted content before publication.
-
review_process: There is no description of a review or approval process for AI-generated content anywhere on the page.
Fix: Describe the editorial review and approval workflow applied to AI-assisted content, ideally in a linked policy.
-
accountability: While posts list author bylines, no one is identified as accountable specifically for AI-generated content or its accuracy.
Fix: Designate and name a responsible party or role accountable for AI-generated content and publish this designation.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
banner_present: The page content shows no cookie or consent banner anywhere on the homepage.
Fix: Implement a visible cookie/consent banner that appears on page load to inform users about cookie usage.
-
partner_sharing_mentioned: There is no banner or on-page consent copy disclosing any data sharing with third-party partners.
Fix: Add consent copy to the banner that clearly discloses whether and with which third-party partners user data is shared.
-
partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated on the page.
Fix: If data is shared with partners, state the exact number of partners in the consent disclosure.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
annual_statement: The page links to a privacy policy but shows no evidence of a regular or periodic review of data practices.
Fix: Add a statement to the privacy policy indicating that data practices are reviewed on a defined periodic (e.g., annual) basis.
-
dated: The page only lists a 'PRIVACY POLICY' link with no visible date, version, or last-updated indicator for the data practices statement.
Fix: Include a clearly visible 'last updated' date or version number on the privacy policy and reference it near the policy link.
-
detail: The page only states EFF is 'donor-funded' without providing amounts, percentages, or breakdowns of funding categories directly on the page.
Fix: Add a brief funding breakdown on the page (e.g., percentage from individual members vs. corporate sponsors vs. grants) or a summary of key figures pulled from the annual report.
-
complete: The page references donors and corporate giving but does not clearly enumerate all major funding streams such as grants, foundations, or the Shop revenue in one disclosure.
Fix: Provide a consolidated statement listing all major revenue streams (individual donations, corporate sponsorships, grants/foundations, merchandise) so the disclosure is comprehensive.
-
algorithm_explained: The About page describes EFF's mission and activities but does not mention or explain any algorithms used on the site.
Fix: If algorithms are used (e.g., for content ranking or personalization), add a section explaining their purpose.
-
impact_clear: There is no description of how any algorithmic decisions affect users on this page.
Fix: Include a clear statement describing the impact of any algorithmic decisions on visitors, or confirm none are used.
Level 3 — Advanced
Accessibility
-
statement_exists: The About page contains no dedicated accessibility statement or link to one, only organizational and navigational content.
Fix: Create a dedicated accessibility statement page and link to it in the site footer or About section.
-
known_issues: There is no statement acknowledging any known accessibility issues or limitations anywhere on the page.
Fix: Add a section to the accessibility statement listing known accessibility limitations and any conformance gaps against WCAG.
-
remediation_timeline: No timeline or commitment for addressing accessibility issues appears on the page.
Fix: Include a target date or ongoing commitment for remediating identified accessibility barriers in the accessibility statement.
-
feedback_channel: While general Contact links exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
Fix: Provide a dedicated accessibility contact (email or form) and state a timeframe within which users will receive a response.
Accountability
-
policy_exists: The About page contains organizational, contact, and donation information but no published moderation policy for user-generated content.
Fix: Publish a dedicated content moderation policy and link to it from the About or site footer navigation.
-
criteria_clear: The page states no criteria describing what content is allowed, disallowed, or subject to moderation.
Fix: Add a clearly written section listing specific criteria (e.g., prohibited content categories) that govern moderation decisions.
-
enforcement: There is no explanation of how moderation decisions are made, enforced, or appealed anywhere on the page.
Fix: Document the enforcement process, including who reviews content, what actions are taken, and how users can appeal decisions.
Interoperability
Security
-
notification_commitment: The page addresses how researchers should report and disclose vulnerabilities but never commits EFF itself to publicly notifying users of significant security incidents.
Fix: Add an explicit statement committing EFF to publicly disclose and notify users when significant security incidents affecting its software or systems occur.
-
timeframe: The only timeframes given are the 90-day pre-disclosure period for researchers and a seven-business-day response commitment to reports, neither of which states when EFF will disclose incidents to affected users.
Fix: Specify a concrete timeframe (e.g., within X days of confirming an incident) in which EFF will notify affected users of security breaches.
Transparency
-
open_source: The about page mentions supporting open source software and technology development but provides no link to publicly available source code or a code repository.
Fix: Add a link on the about page to EFF's public code repositories (e.g., its GitHub organization) or a dedicated projects/software page.
-
tech_docs: The page references whitepapers and educational guides in navigation but does not link to any technical documentation for its tools from this about page.
Fix: Include a direct link to technical documentation for EFF's tools (such as Certbot or Privacy Badger) on the about page.
-
criteria_published: The page publishes no criteria used in any algorithmic decision-making.
Fix: Publish the specific criteria used in any algorithmic decisions affecting users.
-
weighting: No weighting or priority of decision criteria is explained anywhere on the page.
Fix: Describe how criteria are weighted or prioritized in any algorithmic process.
-
auditable: The page provides no technical detail that would allow external audit or review of any algorithm.
Fix: Provide sufficient documentation or a transparency report enabling external audit of any algorithms used.
Responsibility to the Future
-
disclosure_exists: The About page describes EFF's civil liberties mission, financials, and governance but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated environmental or sustainability statement describing the organization's environmental impact and any reduction efforts.
-
specific_metrics: The page provides no specific environmental figures such as carbon footprint, energy use, or emissions.
Fix: Add quantitative metrics like annual carbon emissions or energy consumption to the sustainability disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy sourcing or carbon profile, ideally noting use of renewable-powered or low-carbon data centers.
-
plan_exists: The About page describes EFF's mission, history, and funding but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing what happens to the organisation and its assets in the event of closure.
-
data_and_content_fate: The page does not address what would happen to user data or EFF's published content if the organisation were to cease operating.
Fix: Add a section explaining how user data would be handled and how published content would be preserved or transferred upon dissolution.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page to preserve content in the event of an exit.
Fix: Identify and name archive partners or mirror hosts (e.g., Internet Archive) responsible for preserving EFF's content long-term.
-
policy_exists: The page links to 'Working at EFF', 'Benefits Summary', and 'Diversity & Inclusion' sections but presents no published policy text on worker wellbeing or working conditions on this page.
Fix: Publish a dedicated, accessible policy statement on worker wellbeing and working conditions linked directly from the About page.
-
specific_commitments: While a 'Benefits Summary' link exists, the page itself contains no specific commitments regarding pay, hours, mental health, or benefits.
Fix: Add concrete, measurable commitments on compensation, working hours, mental health support, and benefits to the worker wellbeing content.
-
accountability: The page names no individual, team, or oversight body responsible for monitoring or enforcing worker conditions.
Fix: Identify a named role or committee (e.g., HR or an oversight body) accountable for worker conditions and describe their oversight process.