eff.org

https://www.eff.org · 54/89 checks passed

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 27/37 (10 failed)
Level 2 — Enhanced 15/27 (12 failed)
Level 3 — Advanced 2/10 (8 failed)

By category

CategoryResult
Accessibility 6/13
Accountability 1/5
AI & Automation 6/8
Interoperability 2/3
Privacy 14/16
Provenance 1/2
Security 6/11
Transparency 8/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

Privacy

  • 1 1×1 third-party tracking pixel: https://anon-stats.eff.org/js/?idsite=1&rec=1&url=https%3A//www.eff.org/&action_name=Electronic%20Frontier%20Foundation%20%7C%20Defending%20your%20rights%20in%20the%20digital%20world&urlref=.

Security

  • strict-transport-security: header not set on the response.

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • appeals_exists: The contact page lists various email and inquiry channels but documents no formal appeals process for challenging decisions.
    Fix: Add a clearly labeled appeals section describing how users can formally contest a decision, including required information and expected timelines.
  • independent: Because no appeals process is documented, there is no evidence of an independent or escalated review path.
    Fix: Establish and document an escalation route where appeals are reviewed by a person or body independent of the original decision-maker.
  • response_timeframe: The page uses vague phrases like "we'll get back to you soon" but publishes no actual response timeframe for any contact method.
    Fix: Add explicit expected response times for each inquiry type (e.g., "we aim to respond within 5 business days").
  • specific: No specific timeframes such as days or hours are stated anywhere; the only temporal reference is the non-specific word "soon."
    Fix: Replace vague terms like "soon" with concrete durations such as "within 3 business days".
  • process_exists: The page lists contact email addresses but documents no dedicated complaints or feedback process beyond an accessibility-feedback email.
    Fix: Publish a clearly labeled complaints/feedback process explaining how issues are submitted, handled, and escalated.
  • steps_clear: There are no defined steps for lodging a complaint, only email addresses and subject-line conventions without a described procedure or follow-up.
    Fix: Add step-by-step instructions describing how to submit a complaint, what happens next, and how it will be resolved.

AI & Automation

  • marking_policy: The page discusses AI as a policy topic but contains no policy for marking or disclosing AI-assisted content on the site itself.
    Fix: Publish a clear editorial policy stating whether and how AI-assisted content is labeled, and link it from content pages.
  • consistent: No AI content markings appear on any of the listed blog posts or articles, so consistent application cannot be demonstrated.
    Fix: Add visible AI-assistance labels to individual posts and apply them uniformly across all content.
  • oversight_exists: The page describes advocacy on AI issues but does not document any human oversight of the site's own AI outputs.
    Fix: Add a statement documenting that humans review any AI-generated or AI-assisted content before publication.
  • review_process: There is no description of a review or approval process for AI-generated content anywhere on the page.
    Fix: Describe the editorial review and approval workflow applied to AI-assisted content, ideally in a linked policy.
  • accountability: While posts list author bylines, no one is identified as accountable specifically for AI-generated content or its accuracy.
    Fix: Designate and name a responsible party or role accountable for AI-generated content and publish this designation.

Interoperability

Privacy

  • banner_present: The page content shows no cookie or consent banner anywhere on the homepage.
    Fix: Implement a visible cookie/consent banner that appears on page load to inform users about cookie usage.
  • partner_sharing_mentioned: There is no banner or on-page consent copy disclosing any data sharing with third-party partners.
    Fix: Add consent copy to the banner that clearly discloses whether and with which third-party partners user data is shared.
  • partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated on the page.
    Fix: If data is shared with partners, state the exact number of partners in the consent disclosure.

Provenance

Security

Transparency

  • annual_statement: The page links to a privacy policy but shows no evidence of a regular or periodic review of data practices.
    Fix: Add a statement to the privacy policy indicating that data practices are reviewed on a defined periodic (e.g., annual) basis.
  • dated: The page only lists a 'PRIVACY POLICY' link with no visible date, version, or last-updated indicator for the data practices statement.
    Fix: Include a clearly visible 'last updated' date or version number on the privacy policy and reference it near the policy link.
  • detail: The page only states EFF is 'donor-funded' without providing amounts, percentages, or breakdowns of funding categories directly on the page.
    Fix: Add a brief funding breakdown on the page (e.g., percentage from individual members vs. corporate sponsors vs. grants) or a summary of key figures pulled from the annual report.
  • complete: The page references donors and corporate giving but does not clearly enumerate all major funding streams such as grants, foundations, or the Shop revenue in one disclosure.
    Fix: Provide a consolidated statement listing all major revenue streams (individual donations, corporate sponsorships, grants/foundations, merchandise) so the disclosure is comprehensive.
  • algorithm_explained: The About page describes EFF's mission and activities but does not mention or explain any algorithms used on the site.
    Fix: If algorithms are used (e.g., for content ranking or personalization), add a section explaining their purpose.
  • impact_clear: There is no description of how any algorithmic decisions affect users on this page.
    Fix: Include a clear statement describing the impact of any algorithmic decisions on visitors, or confirm none are used.

Level 3 — Advanced

Accessibility

  • statement_exists: The About page contains no dedicated accessibility statement or link to one, only organizational and navigational content.
    Fix: Create a dedicated accessibility statement page and link to it in the site footer or About section.
  • known_issues: There is no statement acknowledging any known accessibility issues or limitations anywhere on the page.
    Fix: Add a section to the accessibility statement listing known accessibility limitations and any conformance gaps against WCAG.
  • remediation_timeline: No timeline or commitment for addressing accessibility issues appears on the page.
    Fix: Include a target date or ongoing commitment for remediating identified accessibility barriers in the accessibility statement.
  • feedback_channel: While general Contact links exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Provide a dedicated accessibility contact (email or form) and state a timeframe within which users will receive a response.

Accountability

  • policy_exists: The About page contains organizational, contact, and donation information but no published moderation policy for user-generated content.
    Fix: Publish a dedicated content moderation policy and link to it from the About or site footer navigation.
  • criteria_clear: The page states no criteria describing what content is allowed, disallowed, or subject to moderation.
    Fix: Add a clearly written section listing specific criteria (e.g., prohibited content categories) that govern moderation decisions.
  • enforcement: There is no explanation of how moderation decisions are made, enforced, or appealed anywhere on the page.
    Fix: Document the enforcement process, including who reviews content, what actions are taken, and how users can appeal decisions.

Interoperability

Security

  • notification_commitment: The page addresses how researchers should report and disclose vulnerabilities but never commits EFF itself to publicly notifying users of significant security incidents.
    Fix: Add an explicit statement committing EFF to publicly disclose and notify users when significant security incidents affecting its software or systems occur.
  • timeframe: The only timeframes given are the 90-day pre-disclosure period for researchers and a seven-business-day response commitment to reports, neither of which states when EFF will disclose incidents to affected users.
    Fix: Specify a concrete timeframe (e.g., within X days of confirming an incident) in which EFF will notify affected users of security breaches.

Transparency

  • open_source: The about page mentions supporting open source software and technology development but provides no link to publicly available source code or a code repository.
    Fix: Add a link on the about page to EFF's public code repositories (e.g., its GitHub organization) or a dedicated projects/software page.
  • tech_docs: The page references whitepapers and educational guides in navigation but does not link to any technical documentation for its tools from this about page.
    Fix: Include a direct link to technical documentation for EFF's tools (such as Certbot or Privacy Badger) on the about page.
  • criteria_published: The page publishes no criteria used in any algorithmic decision-making.
    Fix: Publish the specific criteria used in any algorithmic decisions affecting users.
  • weighting: No weighting or priority of decision criteria is explained anywhere on the page.
    Fix: Describe how criteria are weighted or prioritized in any algorithmic process.
  • auditable: The page provides no technical detail that would allow external audit or review of any algorithm.
    Fix: Provide sufficient documentation or a transparency report enabling external audit of any algorithms used.

Responsibility to the Future

  • disclosure_exists: The About page describes EFF's civil liberties mission, financials, and governance but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental or sustainability statement describing the organization's environmental impact and any reduction efforts.
  • specific_metrics: The page provides no specific environmental figures such as carbon footprint, energy use, or emissions.
    Fix: Add quantitative metrics like annual carbon emissions or energy consumption to the sustainability disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Disclose the hosting provider's energy sourcing or carbon profile, ideally noting use of renewable-powered or low-carbon data centers.
  • plan_exists: The About page describes EFF's mission, history, and funding but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing what happens to the organisation and its assets in the event of closure.
  • data_and_content_fate: The page does not address what would happen to user data or EFF's published content if the organisation were to cease operating.
    Fix: Add a section explaining how user data would be handled and how published content would be preserved or transferred upon dissolution.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page to preserve content in the event of an exit.
    Fix: Identify and name archive partners or mirror hosts (e.g., Internet Archive) responsible for preserving EFF's content long-term.
  • policy_exists: The page links to 'Working at EFF', 'Benefits Summary', and 'Diversity & Inclusion' sections but presents no published policy text on worker wellbeing or working conditions on this page.
    Fix: Publish a dedicated, accessible policy statement on worker wellbeing and working conditions linked directly from the About page.
  • specific_commitments: While a 'Benefits Summary' link exists, the page itself contains no specific commitments regarding pay, hours, mental health, or benefits.
    Fix: Add concrete, measurable commitments on compensation, working hours, mental health support, and benefits to the worker wellbeing content.
  • accountability: The page names no individual, team, or oversight body responsible for monitoring or enforcing worker conditions.
    Fix: Identify a named role or committee (e.g., HR or an oversight body) accountable for worker conditions and describe their oversight process.