Evening Standard

https://www.standard.co.uk · 38/92 checks passed · media

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 25/37 (10 failed)
Level 2 — Enhanced 7/27 (15 failed)
Level 3 — Advanced 0/10 (4 failed)

By category

CategoryResult
Accessibility 8/13
Accountability 1/5
AI & Automation 4/8
Interoperability 1/3
Privacy 9/16
Provenance 0/2
Security 5/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page lists AI-related articles but contains no visible AI use policy or statement about the publication's own AI practices.
    Fix: Publish a clearly linked AI use policy or editorial statement describing how the outlet uses AI in its content production.
  • scope_clear: No policy is present, so there is no explanation of what AI is used for on the site.
    Fix: Include a section in the AI policy that specifies the scope of AI use, such as drafting, summarization, translation, or image generation.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists emails and phone numbers but does not publish any response timeframe for inquiries.
    Fix: Add a clearly stated response timeframe (e.g., 'We respond to inquiries within 5 business days') on the contact page.
  • specific: Because no timeframe is published at all, there is no specific duration such as days or hours stated.
    Fix: Specify concrete durations in days or hours for different query types rather than vague terms like 'promptly' or omitting timeframes entirely.
  • steps_clear: The page only links out to the complaints procedure without summarizing the steps, so the steps are not clear on this contact page itself.
    Fix: Summarize the key steps for making a complaint (e.g., who to contact first, what information to include, escalation path) directly on the contact page with the link.
  • independent: The page does not indicate that the complaints/appeals process is independent or escalated to an external body such as IPSO.
    Fix: Explicitly state on the contact page that unresolved complaints can be escalated to an independent regulator (e.g., IPSO) and provide a direct link and contact details.

AI & Automation

  • detailed_scope: The page shows only article headlines and navigation links, with no AI policy detailing scope.
    Fix: Create a dedicated AI policy page detailing each specific use case of AI across editorial, commercial, and operational functions.
  • limitations: No acknowledgement of AI limitations appears anywhere on the page content provided.
    Fix: Add a section to the AI policy that explicitly acknowledges limitations such as hallucinations, bias, and factual errors.
  • safeguards: The page does not describe any safeguards, human review, or quality controls related to AI use.
    Fix: Document safeguards such as mandatory human editorial review, fact-checking, and disclosure labels for AI-assisted content.
  • marking_policy: The page lists AI-related articles and footer links but contains no visible policy describing how AI-assisted content is marked or labelled.
    Fix: Publish and link a clear editorial policy explaining how AI-assisted content is disclosed and labelled on articles.
  • consistent: None of the listed AI-topic articles show any visible AI-assistance label or disclosure, so consistent marking cannot be demonstrated.
    Fix: Apply a standard, visible AI-disclosure tag or byline note to every article that uses AI assistance across the site.
  • oversight_exists: The page contains no statement or link documenting human oversight of AI outputs.
    Fix: Add a dedicated AI governance or editorial standards page describing how humans oversee AI-generated or AI-assisted outputs.
  • review_process: No review or approval workflow for AI content is described anywhere on the visible page or linked footer items.
    Fix: Document the editorial review and approval steps for AI-assisted content and link it from the footer alongside the Code of conduct.
  • accountability: No named role, editor, or team is identified as accountable for AI-generated content on the page.
    Fix: Identify a specific editor or role responsible for AI content oversight and publish their accountability statement in the editorial or code of conduct section.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit data minimisation statement confirming that only data necessary for the specified purposes is collected.
  • proportionate: Extensive third-party data enrichment from Experian, Eyeota, Bombora, Quantcast, etc. for profiling appears to go beyond what is strictly proportionate to delivering news content.
    Fix: Justify and narrow third-party data enrichment and profiling, or clearly explain how each enrichment is proportionate to the service provided.
  • retention_stated: The visible content does not state any data retention periods.
    Fix: Add a dedicated 'Data Retention' section describing how long each category of personal data is kept.
  • specific: No specific retention timeframes (e.g., months or years) are provided anywhere in the notice.
    Fix: Specify concrete retention periods for each data category (e.g., 'account data retained for 24 months after last activity').
  • equal_choices: The privacy notice describes consent but does not demonstrate that accept and reject options are presented with equal prominence in the consent interface.
    Fix: Ensure the cookie/consent banner displays a 'Reject All' button with the same size, color, and placement as the 'Accept All' button, and reference this equal prominence in the notice.
  • no_forced_consent: The notice states consent is the legal basis for advertising, personalisation, analytics, and profiling bundled together, suggesting consent may be obtained in a non-granular manner.
    Fix: Provide granular, unbundled consent toggles for each processing purpose (advertising, analytics, profiling, personalisation) so users can accept or reject each independently without being forced into a single combined consent.
  • ads_labelled: The privacy notice discusses personalised advertising but does not state that ads or sponsored content on the site are labelled as such.
    Fix: Add a statement (and on-site practice) confirming that all advertising and sponsored/branded content is clearly labelled with terms like 'Ad' or 'Sponsored'.
  • banner_present: The provided page content contains no visible cookie or consent banner text.
    Fix: Implement a visible cookie consent banner on the homepage that appears on first visit.
  • partner_sharing_mentioned: No on-page consent copy disclosing data sharing with third-party partners is present in the content.
    Fix: Add explicit disclosure in the consent banner stating that user data is shared with third-party advertising and analytics partners.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the page content.
    Fix: Include a precise number of third-party partners (e.g., 'We share data with 150 partners') in the consent banner with a link to the full list.

Provenance

Security

Transparency

  • algorithm_explained: The page only lists navigation links and footer items like Terms, Privacy Notice, and Cookie Policy with no explanation of any algorithms used by the site.
    Fix: Add a dedicated section (or link from the Terms page) describing any algorithms used for content recommendation, personalization, or ad targeting and their purpose.
  • impact_clear: There is no description on the page of how algorithmic decisions affect users' experience, content visibility, or data handling.
    Fix: Publish a clear explanation of how algorithmic outputs affect users (e.g., what content they see, how ads are targeted) within the Terms or Privacy documentation.
  • annual_statement: The privacy notice contains no mention of any periodic or annual review of its data practices.
    Fix: Add a sentence stating that the privacy notice and underlying data practices are reviewed at least annually.
  • dated: The visible privacy notice has no last-updated date or version number indicated.
    Fix: Add a clearly visible 'Last updated' date or version number at the top or bottom of the privacy notice.

Level 3 — Advanced

Accessibility

Accountability

  • policy_exists: The page only lists navigation links like 'Code of conduct and complaints' and 'Terms of use' without displaying any actual moderation policy content.
    Fix: Publish a dedicated moderation policy page and link to it clearly from the terms or footer.
  • criteria_clear: No moderation criteria (e.g., prohibited content, community standards) are stated on the visible page content.
    Fix: Add a clearly labeled section listing the specific criteria used to moderate user content and comments.
  • enforcement: The page does not describe any enforcement process, appeals, or actions taken against violations.
    Fix: Include an enforcement section outlining escalation steps, sanctions, and the appeals process for moderation decisions.

Interoperability

Security

Transparency

  • criteria_published: The visible page content contains no published criteria used in any algorithmic decision-making.
    Fix: Publish the specific input signals and criteria (e.g., user interests, location, browsing history) that drive algorithmic decisions in an accessible policy page.
  • weighting: No information is provided about the weighting or priority given to any algorithmic criteria.
    Fix: Include a summary explaining the relative weight or priority of key factors used by the algorithm in ranking or recommending content.
  • auditable: The page provides no technical or procedural detail that would enable external auditing or review of any algorithm.
    Fix: Provide an algorithmic transparency report or audit documentation with sufficient methodological detail to enable independent review.

Responsibility to the Future

  • policy_exists: The culture landing page shows only entertainment articles and footer links (Terms of use, Privacy Notice, Code of conduct) with no published worker wellbeing or working conditions policy.
    Fix: Publish a dedicated worker wellbeing policy and link to it from the site footer or an accessible corporate/about section.
  • specific_commitments: There is no content on the page addressing pay, hours, mental health, or benefits for workers.
    Fix: Add specific, measurable commitments on pay, working hours, mental health support, and benefits within the worker wellbeing policy.
  • accountability: The page names no individual, team, or oversight mechanism responsible for worker conditions.
    Fix: Designate and publicly name a responsible person or oversight body accountable for monitoring and improving worker conditions.