Hachette UK
https://www.hachette.co.uk · 42/92 checks passed · publishers
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 25/37 (12 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 4/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-allowed-attr, aria-prohibited-attr, aria-valid-attr-value.
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-allowed-attr, aria-prohibited-attr, aria-valid-attr-value.
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish a clear AI use policy or statement, linked from the About page or footer, describing the organisation's stance on AI.
-
scope_clear: There is no content on the page explaining what AI is used for within Hachette's operations.
Fix: Add a section describing specific AI use cases (e.g. editorial, marketing, operations) so readers understand the scope of AI application.
- Not found at any of: /ai-policy, /ai.
Privacy
- No hidden iframes detected.
- Detected 3 data-leaking services across 2 categories: google fonts (fonts.googleapis.com, fonts.gstatic.com); twitter x (pbs.twimg.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.hachette.co.uk
- x-frame-options: SAMEORIGIN
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure of any kind.
Fix: Add a dedicated funding/ownership disclosure section identifying the parent company and any sponsorship or financial backers.
-
transparent: No funding sources are identified anywhere on the page, so transparency cannot be established.
Fix: Clearly name all funding sources (e.g., parent company Hachette Livre/Lagardère, any grants or sponsors) in a visible disclosure.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists divisions and departments (e.g., Rights, Head Office) but no named individual or specific role title is identified as responsible for enquiries.
Fix: Add the name or job title of a specific person or role (e.g., 'Head of Communications – Jane Smith') responsible for handling each category of enquiry.
-
process_exists: The page provides contact details and submission/permissions processes but no documented complaints or feedback process.
Fix: Add a dedicated complaints/feedback section explaining how customers or stakeholders can raise concerns and what to expect in response.
-
steps_clear: Because no complaints process is documented, there are no clear steps for making a complaint.
Fix: Publish a numbered step-by-step complaints procedure (e.g., who to contact, how to submit, escalation path, and expected response time).
-
appeals_exists: The contact page lists contact details and permissions/submissions processes but does not document any appeals process for decisions.
Fix: Add a dedicated 'Appeals' section describing how users can formally appeal decisions (e.g., permissions denials, submission rejections) with required steps and timelines.
-
independent: No appeals mechanism is described, so there is no indication of independent review or escalation path.
Fix: Define an escalation route to an independent reviewer or senior body (e.g., an ombudsperson or a review committee separate from the original decision-maker) and publish it on the contact page.
AI & Automation
-
detailed_scope: No AI policy is present, so detailed scope of AI use is not provided.
Fix: Create an AI policy page detailing where and how AI is deployed across divisions, products, and workflows.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include an explicit section on AI limitations such as bias, inaccuracy, and copyright considerations in a published AI policy.
-
safeguards: No safeguards or quality controls relating to AI are described on the page.
Fix: Document safeguards such as human review, data protection measures, and quality-assurance processes within an AI policy statement.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is labeled or marked.
Fix: Publish a clear policy describing how AI-assisted content (text, images, summaries) is disclosed and labeled on the site.
-
consistent: Without any marking policy visible, there is no evidence that AI content marking is applied consistently across the page or site.
Fix: Adopt and enforce a consistent labeling convention (e.g., a standard 'AI-assisted' tag) and apply it uniformly wherever AI tools contribute to content.
-
oversight_exists: The page does not mention any human oversight or governance process for AI outputs.
Fix: Add a statement to the About or ethics section documenting that AI outputs are subject to human review before publication.
-
review_process: No review or approval workflow for AI-generated material is described anywhere on the page.
Fix: Describe the editorial review steps (who reviews, against what criteria, and when) that AI-assisted content must pass before being published.
-
accountability: Although leadership is listed, no individual or role is identified as accountable for AI-generated content.
Fix: Name a responsible owner (e.g., a named executive, editorial director, or AI governance lead) accountable for AI content decisions and outcomes.
Interoperability
Privacy
-
plain_language: The visible page content only shows links to separate privacy notices with no actual policy text to evaluate for plain language.
Fix: Surface a plain-language summary of the privacy notice directly on the /privacy page or ensure the linked notices use clear, non-legal wording accessible from this index.
-
comprehensive: The page content provided shows only navigation links and headings without describing what data is collected or why.
Fix: Include a comprehensive overview on the privacy page itself outlining categories of data collected, purposes, and legal bases, or provide accessible summaries alongside each linked notice.
-
plain_language: No description of data practices appears on the visible page—only links to separate notices—so plain-language handling cannot be confirmed.
Fix: Add a concise, jargon-free summary of the company's data practices to the main privacy landing page.
-
understandable: Without any descriptive content on the page itself, a non-expert cannot determine what data is collected or why.
Fix: Include an at-a-glance explanation of what personal data is collected and the reasons for collection that is understandable to a general audience.
-
necessity: The visible page content contains no statement that data collection is limited to what is necessary.
Fix: Add an explicit data minimisation statement confirming only necessary personal data is collected for specified purposes.
-
proportionate: The page provides no information demonstrating that the data collected is proportionate to the services offered.
Fix: Describe each processing purpose alongside the specific data required to show collection is proportionate to the service.
-
retention_stated: No data retention information is present in the visible page content.
Fix: State data retention periods for each category of personal data directly within the privacy notice.
-
specific: Because no retention periods are disclosed on the page, specificity cannot be established.
Fix: Provide specific retention durations (e.g., '12 months after account closure') rather than vague phrases like 'as long as necessary'.
-
no_dark_patterns: The visible page content shows only a list of privacy notice links with no consent mechanism displayed, so it cannot be verified that consent is gathered without dark patterns.
Fix: Surface the consent interface on the privacy page and ensure it uses neutral, non-manipulative language for all options.
-
equal_choices: No accept/reject controls are visible in the page content, so equal prominence of choices cannot be confirmed.
Fix: Provide clearly visible Accept and Reject buttons with identical styling, size, and placement on the consent banner.
-
no_forced_consent: The page content does not demonstrate a granular, unbundled consent mechanism, leaving it unclear whether consent is forced or bundled.
Fix: Offer granular toggles for each processing purpose (analytics, marketing, etc.) with no pre-ticked boxes and no requirement to accept in order to access the site.
-
partner_sharing_mentioned: The banner mentions analytics, personalization, and targeted advertising purposes but does not disclose that data is shared with third-party partners.
Fix: Update the banner copy to explicitly state that data is shared with third-party advertising, analytics, and personalization partners, with a link to the partner list.
-
partner_count_specific: No specific numeric count of third-party partners is stated anywhere in the banner or on-page consent copy.
Fix: Include the exact number of third-party partners (e.g., 'We share data with X partners') in the banner along with a link to the full vendor list.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team (beyond generic 'Rights department' or division names) is identified as responsible for enquiries.
Fix: Identify the responsible team or contact person by name for each enquiry type, such as 'Permissions Team Lead' or 'Rights Manager – [Name]'.
-
role_clear: While enquiry categories (submissions, permissions, rights) are described, the role or authority of the person/team handling each is not explicitly stated.
Fix: Clearly state the role and decision-making authority of each contact point, e.g., 'The Rights Department is authorised to approve translation licences.'
-
detail: The page provides no amounts, percentages, or categories describing how the organization is funded.
Fix: Include meaningful financial detail such as revenue categories, ownership percentages, or a breakdown of funding streams.
-
complete: Because no funding information is disclosed, the disclosure cannot be considered complete across major funding streams.
Fix: Publish a comprehensive disclosure covering all major revenue and funding streams, including ownership, sponsorships, and any external financial support.
-
algorithm_explained: The About page describes the company's mission, leadership, and locations but makes no mention of any algorithms or their purpose.
Fix: Add a section (or link to a dedicated page) disclosing any algorithmic systems used and explaining their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions might affect users, customers, or authors anywhere on the page.
Fix: Include a clear explanation of the user-facing impacts of any algorithmic decisions, such as recommendations, pricing, or content moderation.
-
annual_statement: The page links to 'Privacy notices' in the footer but provides no evidence on this page of a regular or annual review of data practices.
Fix: Add a note (or link) indicating when privacy/data practices were last reviewed and commit to a periodic review cadence.
-
dated: There is no visible date, 'last updated' timestamp, or version on the page or next to the privacy notices link.
Fix: Display a 'last updated' date or version number on the privacy notice and reference it from corporate pages like About us.
Level 3 — Advanced
Accessibility
-
statement_exists: The page only shows an 'Accessibility' link and 'Accessibility tools' in navigation, with no dedicated accessibility statement content visible on this About page.
Fix: Publish a dedicated accessibility statement page and link to it clearly, ensuring its content is accessible from this page.
-
known_issues: No accessibility statement content is present, so known accessibility issues or limitations are not acknowledged anywhere on this page.
Fix: Add a section to the accessibility statement that lists known accessibility limitations and areas of partial compliance.
-
remediation_timeline: There is no accessibility statement content, and therefore no timeline or commitment for fixing known issues is provided.
Fix: Include target dates or a stated commitment for resolving identified accessibility issues in the accessibility statement.
-
feedback_channel: No accessibility feedback mechanism or response commitment is shown on this page beyond a generic 'Contact Us' link.
Fix: Provide a dedicated accessibility feedback channel (e.g., email or form) with a stated response timeframe within the accessibility statement.
Accountability
-
enforcement: While clause 11 mentions the right to remove access and report to law enforcement, the page does not explain the actual review/enforcement process, timelines, or appeal mechanism.
Fix: Add a section describing how moderation decisions are made, timelines for review of reported content, notification to users, and any appeal or redress process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The about page contains only corporate and mission content with no published incident response plan or security policy.
Fix: Publish an incident response plan or security policy and link to it from the site footer or a dedicated security page.
-
notification_commitment: The page makes no commitment to publicly notify users of significant security incidents.
Fix: Add an explicit commitment to notify affected users and the public of significant incidents within the incident response policy.
-
timeframe: No disclosure timeframe for reporting incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of detecting a significant incident) in the published policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decision-making are published on this About page.
Fix: Publish the specific inputs and criteria that feed into any algorithmic decisions on a transparency or policy page.
-
weighting: The page provides no information about how any decision criteria are weighted or prioritised.
Fix: Document the relative weighting or priority order of the criteria used in algorithmic decisions.
-
auditable: The page offers no technical detail, methodology, or contact channel that would enable external audit or review of any algorithm.
Fix: Provide sufficient methodology details and an audit/contact mechanism so external parties can meaningfully review the algorithms.
-
open_source: There is no mention of or link to any publicly available source code on the about page.
Fix: Add a link to a public code repository (e.g., GitHub) for any open-source components of the site, or state the organisation's open-source policy.
-
tech_docs: No technical documentation is referenced or linked from the page.
Fix: Publish and link to technical documentation (e.g., API docs, accessibility conformance reports, or platform specifications) from the about or footer area.
Responsibility to the Future
-
specific_metrics: The sustainability text speaks generally about working towards targets but provides no specific carbon, energy, or emissions figures.
Fix: Publish concrete metrics such as annual carbon emissions, energy consumption, and measurable reduction targets with baseline years.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or IT infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy sourcing (e.g., renewable-powered data centres) and the digital carbon footprint of the site.
-
plan_exists: The About page describes the company's history, mission, sustainability, and leadership but contains no published plan for organisational failure or exit.
Fix: Publish a succession or continuity plan describing what happens to the organisation's operations, sites, and services in the event of failure or wind-down.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content if the organisation ceased operating.
Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted should the organisation shut down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name a designated custodian, mirror, or archive partner (e.g., a digital preservation organisation) responsible for maintaining content after any exit.
-
policy_exists: The careers page mentions AI guidelines, a fraud notice, and a Disability Confident scheme, but does not publish any policy addressing worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers or culture pages.
-
specific_commitments: The page contains no specific commitments regarding pay, hours, mental health support, or employee benefits.
Fix: Add concrete, measurable commitments covering fair pay, working hours, mental health provision, and benefits to the site.
-
accountability: No individual, team, or oversight body is identified as accountable for worker conditions on the page.
Fix: Name a responsible person, department, or governance body overseeing worker wellbeing and describe how concerns can be raised.