HarperCollins UK
https://www.harpercollins.co.uk · 37/92 checks passed · publishers
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 21/37 (16 failed) |
| Level 2 — Enhanced | 6/27 (21 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 5/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 3/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 4 WCAG 2.1 Level A violations reported by axe-core: button-name, image-alt, link-name, list.
- 4 WCAG 2.1 Level A violations reported by axe-core: button-name, image-alt, link-name, list.
- 15 images missing alt attribute: https://harpercollins.co.uk/cdn/shop/files/8_300x.png?v=1768307252, https://harpercollins.co.uk/cdn/shop/t/9/assets/search.svg?v=123853058921949955031593701284, https://harpercollins.co.uk/cdn/shop/t/9/assets/search.svg?v=123853058921949955031593701284, https://harpercollins.co.uk/cdn/shop/t/9/assets/star-solid.svg?v=139440108495545441651593701289, https://harpercollins.co.uk/cdn/shop/t/9/assets/star-solid.svg?v=139440108495545441651593701289 (+10 more).
- 15 images missing alt attribute: https://harpercollins.co.uk/cdn/shop/files/8_300x.png?v=1768307252, https://harpercollins.co.uk/cdn/shop/t/9/assets/search.svg?v=123853058921949955031593701284, https://harpercollins.co.uk/cdn/shop/t/9/assets/search.svg?v=123853058921949955031593701284, https://harpercollins.co.uk/cdn/shop/t/9/assets/star-solid.svg?v=139440108495545441651593701289, https://harpercollins.co.uk/cdn/shop/t/9/assets/star-solid.svg?v=139440108495545441651593701289 (+10 more).
- Heading hierarchy issues: h1 -> h5 (skipped h2); h2 -> h5 (skipped h3); h2 -> h5 (skipped h3); h2 -> h5 (skipped h3); h2 -> h4 (skipped h3).
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
-
policy_exists: The page contains office location information with no mention of an AI use policy or statement.
Fix: Publish a dedicated AI use policy page and link to it from the About/Reports and Policies section.
-
scope_clear: No AI policy is present, so the scope of AI use is not explained anywhere on the page.
Fix: Add a clear description of what AI tools are used for (e.g., editorial, marketing, translation) in a published AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: .shop.app.
FAIL
No tracking pixels
- 5 1×1 third-party tracking pixels: https://harpercollins.co.uk/cdn/shop/files/x500_319109c2-a853-4acd-8e45-c18b35062fd5.jpg?crop=center&height=250&v=1776532498&width=200, https://harpercollins.co.uk/cdn/shop/files/x500_62a04843-27a2-45eb-8fe1-7360bfdeb0e5.jpg?crop=center&height=250&v=1776532773&width=200, https://harpercollins.co.uk/cdn/shop/files/x9780008347239.jpg?crop=center&height=250&v=1776532573&width=200, https://harpercollins.co.uk/cdn/shop/files/9781335534637_980588c9-5922-4350-a58c-58504b1e9c68.jpg?crop=center&height=250&v=1776539276&width=200, https://harpercollins.co.uk/cdn/shop/files/x500_6377c3af-4ef5-4e50-9e24-6ff38a02cd11.jpg?crop=center&height=250&v=1776527213&width=200.
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
Security
- Redirect chain (2 hops): https://www.harpercollins.co.uk → https://harpercollins.co.uk/
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
actionable: The page lists contact section headings but provides no actual phone numbers, email addresses, or contact form to reach the organisation.
Fix: Add concrete contact details such as a customer service email, phone number, contact form, or office addresses directly on the contact page.
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only office locations and corporate information.
Fix: Add a dedicated funding/ownership disclosure section identifying HarperCollins's parent company (News Corp) and any other revenue or sponsorship sources.
-
transparent: No funding sources are identified anywhere on the page, though News Corp is mentioned only incidentally as a building co-tenant.
Fix: Clearly state ownership and funding sources (e.g., 'HarperCollins is a subsidiary of News Corp') in a visible disclosure block.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The contact page lists generic categories like 'Customer Service' and 'Publicity Contacts' but names no individual or specific role as responsible.
Fix: Add the name or job title of a specific person or team lead (e.g., Head of Customer Service) accountable for each contact area.
-
contactable: No email addresses, phone numbers, or contact forms are visible on the page—only navigation labels like 'How to Contact Us' appear without actual contact details.
Fix: Publish direct contact details (email, phone, or a contact form) on the page so users can actually reach the responsible team.
-
response_timeframe: The contact page lists options like 'How to Contact Us' and 'Customer Service' but shows no published response timeframe for inquiries.
Fix: Publish an expected response time (e.g., 'We respond within 5 business days') alongside the customer service contact information.
-
specific: No specific timeframe in days or hours is provided anywhere on the visible contact page.
Fix: State a concrete timeframe such as '2 business days for email inquiries' rather than vague language.
-
process_exists: The page links to 'Customer Service' and 'How to Contact Us' but does not display a documented complaints or feedback process.
Fix: Add a dedicated complaints/feedback procedure page describing how to submit a complaint and how it will be handled.
-
steps_clear: No step-by-step instructions for lodging a complaint are visible on the page content provided.
Fix: Include numbered steps (e.g., 1. Contact customer service, 2. Escalation path, 3. External ombudsman) so users know exactly how to proceed.
-
appeals_exists: The contact page lists customer service and office info but contains no documented appeals process.
Fix: Add a clearly labeled appeals procedure describing how users can formally challenge decisions, including required information and timelines.
-
independent: No escalation path or independent review body is mentioned anywhere on the page.
Fix: Document an independent or escalated review step (e.g., ombudsman, senior review panel, or external arbiter) for unresolved appeals.
AI & Automation
-
detailed_scope: The page makes no reference to AI, so detailed scope of AI use is absent.
Fix: Create a policy section detailing specific AI use cases, systems, and contexts across HarperCollins operations.
-
limitations: There is no acknowledgement of AI system limitations on this page.
Fix: Include a section in the AI policy that openly acknowledges limitations such as bias, hallucination, and accuracy constraints.
-
safeguards: No safeguards or quality control measures for AI use are described on the page.
Fix: Document human review, data protection, and quality assurance safeguards applied to any AI-assisted workflows.
-
marking_policy: The About page contains no policy or statement regarding how AI-assisted content is marked or labeled.
Fix: Publish a clear AI content labeling policy describing how AI-assisted material is identified and disclosed on the site.
-
consistent: Without any visible AI marking policy or examples on the page, consistent application cannot be demonstrated.
Fix: Apply standardized AI-content labels across all pages and document this consistent approach in a published policy.
-
oversight_exists: The page makes no mention of human oversight of AI outputs or any AI governance practices.
Fix: Add a statement or policy page describing how humans oversee and validate any AI-generated outputs used by HarperCollins.
-
review_process: No review or approval workflow for AI-generated content is described anywhere on the About page.
Fix: Document the review and approval steps that AI outputs must pass through before publication and link to it from relevant pages.
-
accountability: No individual, team, or role is identified as accountable for AI-generated content on this page.
Fix: Name a responsible role or team (e.g., an editorial AI lead) accountable for AI outputs and list their contact in the Reports and Policies section.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
plain_language: The notice uses legalistic phrasing and defined terms like 'Personal Data', 'legitimate interest', and references to GDPR without plain-language explanation.
Fix: Rewrite key sections in plain English with short sentences and define or avoid legal/technical jargon such as 'legitimate interest' and 'web beacons'.
-
plain_language: Sections describing automated collection use technical jargon like 'HTTP, HTML5 and Flash cookies', 'web beacons', 'clear GIF', and 'JavaScript' without simple explanations.
Fix: Simplify the cookies/automated means section using layperson wording and provide brief plain definitions or a glossary for technical terms.
-
understandable: A non-expert would struggle with phrases like 'De-identify Personal Data to provide third parties with aggregated data reports' and 'Associate your browser and/or device with other browsers...for the purpose of providing relevant...advertising across browsers and devices'.
Fix: Add a concise summary table or plain-language overview at the top explaining in everyday terms what data is collected and why.
-
necessity: The policy does not state that data collection is limited to what is necessary; instead it describes broad collection including from publicly available sources and partners.
Fix: Add an explicit data minimisation statement committing to collect only the personal data necessary for the stated purposes.
-
proportionate: Collection appears broad (supplementing data from public/commercial sources, cross-device tracking, social media profile data) without a proportionality justification tied to each service.
Fix: Map each category of data collected to the specific service purpose it supports and remove or justify any collection that exceeds what the service requires.
-
retention_stated: The visible content mentions a section titled 'HOW WE PROTECT AND RETAIN PERSONAL DATA' but does not actually state any retention periods in the provided text.
Fix: Include explicit retention periods for each category of personal data within the retention section of the policy.
-
specific: No specific timeframes (e.g., months or years) for data retention are provided anywhere on the page.
Fix: Specify concrete retention durations (e.g., 'account data retained for 24 months after account closure') for each data category.
-
banner_present: The page content only shows a 'Cookie Settings' link in the footer; no active cookie or consent banner is visible.
Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or customize cookie preferences before non-essential cookies are set.
-
partner_sharing_mentioned: The page does not disclose any sharing of data with third-party partners in the visible consent copy or banner area.
Fix: Add clear language in the cookie banner disclosing that data may be shared with third-party advertising/analytics partners, with a link to the full list.
-
partner_count_specific: No partner sharing is disclosed and no numeric count of third-party partners is stated anywhere on the page.
Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the cookie banner or linked preferences center.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: The page references teams such as 'Customer Service' and 'Publicity Contacts' but identifies no named individual or specifically named team responsible for enquiries.
Fix: Identify a specific named contact or team (e.g., 'UK Customer Service Team, led by [Name]') for each enquiry category.
-
role_clear: While broad category labels exist, the page does not clearly describe the role, authority, or remit of who handles which type of enquiry.
Fix: Add a short description under each contact heading explaining the team's role, scope of authority, and which enquiries they handle.
-
mission_clear: The page describes operations and locations but does not clearly articulate an editorial mission or overarching publishing philosophy.
Fix: Add a dedicated mission statement section explaining HarperCollins' editorial values, publishing philosophy, and purpose beyond operational descriptions.
-
detail: The page provides no amounts, percentages, or categories describing funding streams.
Fix: Include meaningful detail such as revenue categories (e.g., book sales, third-party distribution percentages, rights income) in a financial transparency section.
-
complete: No funding streams are disclosed, so coverage of major streams cannot be established.
Fix: Publish a complete breakdown of major revenue streams (publishing, distribution services, rights, etc.) to ensure comprehensive disclosure.
-
governance_exists: The page describes office locations and facilities but does not outline any governance or editorial structure of the organization.
Fix: Add a dedicated section describing the company's governance framework, editorial oversight, and decision-making structure.
-
roles_clear: The page mentions divisions and teams in general terms but does not identify key roles, leadership, or their responsibilities.
Fix: Include a leadership or org-chart section naming key executives and editorial leads along with their specific responsibilities.
-
algorithm_explained: The page describes office locations and distribution operations but does not mention or explain any algorithms in use.
Fix: Add a section describing any algorithms used (e.g., for personalization, recommendations, or ad targeting referenced in the cookie notice) and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users, despite the cookie banner mentioning personalized ads and analytics.
Fix: Clearly describe how algorithm-driven features (like personalized content or ads) impact user experience and what outcomes users can expect.
-
annual_statement: The page only references a Cookie Policy link without any evidence of annual or periodic review of data practices.
Fix: Publish a statement (e.g., in the Cookie/Privacy Policy) confirming that data practices are reviewed on a regular, periodic basis and note the last review date.
-
dated: The cookie banner and referenced Cookie Policy are not shown with any date or version identifier on this page.
Fix: Add a 'Last updated' date or version number to the Cookie/Privacy Policy and surface it near the consent banner or policy link.
Level 3 — Advanced
Accessibility
-
statement_exists: The page is an 'About Our Offices' page with no dedicated accessibility statement present anywhere in the content.
Fix: Create a dedicated accessibility statement page (e.g., /accessibility) and link to it from the site footer and navigation.
-
known_issues: There is no accessibility statement, so no known accessibility issues or limitations are acknowledged.
Fix: Within an accessibility statement, list any known barriers (e.g., non-conforming PDFs or unlabeled controls) discovered through an audit against WCAG 2.1 AA.
-
remediation_timeline: No accessibility statement exists, so there is no timeline or commitment for fixing known issues.
Fix: Add a remediation section committing to target dates for resolving each identified accessibility barrier.
-
feedback_channel: The page offers office phone numbers and generic email links but no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility contact (email/phone/form) and state a specific response time commitment for accessibility feedback.
Accountability
-
policy_exists: The terms page covers sales, digital product usage, and account rules but does not publish any moderation policy for user-generated content.
Fix: Publish a dedicated moderation or community guidelines policy covering reviews, comments, or other user submissions.
-
criteria_clear: No moderation criteria (e.g., prohibited content categories, acceptable use standards) are stated anywhere on the page.
Fix: Add explicit criteria describing what content is prohibited and what standards submissions must meet.
-
enforcement: The page does not describe any enforcement process, such as how violations are reviewed, removed, or appealed.
Fix: Document the enforcement workflow including how content is reviewed, actions taken (removal, suspension), and an appeals process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is an 'About Our Offices' page listing office locations and contact details, with no published incident response plan or security policy present.
Fix: Publish a dedicated incident response plan or security policy and link to it from the site's Reports and Policies section.
-
notification_commitment: The page contains no commitment to publicly notify users of significant security incidents.
Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant security incident.
-
timeframe: No timeframe for disclosing incidents to affected users is mentioned anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page contains no published criteria for any algorithmic decision-making.
Fix: Publish the specific inputs and criteria used in any algorithmic decisions (e.g., personalization or ad-serving logic) on a dedicated transparency page.
-
weighting: No information is provided about how criteria are weighted or prioritized in algorithmic decisions.
Fix: Document and disclose the relative weighting or priority of factors used by algorithms that affect users.
-
auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
Fix: Provide sufficient documentation—such as model descriptions, data sources, and decision logic—to allow independent third-party audit.
-
open_source: There is no mention of or link to any open source code repositories on the page.
Fix: Add a link to a public code repository (e.g., GitHub) if any of the organisation's software is open source, or note technology transparency in a dedicated section.
-
tech_docs: No technical documentation is linked or referenced on the page beyond brief mentions of logistics vendors like KNAPP and Jungheinrich.
Fix: Publish or link to technical documentation describing the site's platforms, APIs, or data standards used for publishing and distribution.
Responsibility to the Future
-
disclosure_exists: The page at /sustainability contains only navigation links, cookie notices, and a footer with no actual environmental or sustainability disclosure content.
Fix: Publish substantive sustainability disclosure content on the page describing the company's environmental policies, goals, and performance.
-
specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
Fix: Add quantified metrics such as annual carbon emissions (tCO2e), energy consumption, and year-over-year reduction targets.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose whether hosting uses renewable energy or green data centers and provide the associated carbon/energy figures.
-
plan_exists: The About Us page describes offices, distribution and archives but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or contingency plan describing how operations, data, and content would be handled in the event of business failure, closure, or acquisition.
-
data_and_content_fate: The page discusses book storage and archives but never addresses what would happen to user data or published content in a wind-down scenario.
Fix: Add a section specifying the fate of user data and published/digital content on exit, including retention, transfer, or deletion arrangements.
-
custodians_or_mirrors: Although the page mentions a physical archive of historical materials, it names no custodians, mirrors, or archive partners responsible for preserving data or content should the organisation cease operating.
Fix: Identify and name specific custodians, mirror sites, or archive partners who would take responsibility for preserving content and data if the organisation exits.
-
policy_exists: The page is an office locations overview and contains no published policy on worker wellbeing or working conditions, only mentions of a 'People and Culture' and 'People' team.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this page (e.g., under 'People and Culture').
-
specific_commitments: The content includes no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add explicit commitments covering pay, working hours, mental health support, and employee benefits.
-
accountability: The page names a 'People' team in Glasgow but does not identify any accountability or oversight structure for worker conditions.
Fix: Name a responsible role, committee, or governance body accountable for overseeing worker wellbeing and working conditions.