HarperCollins UK

https://www.harpercollins.co.uk · 37/92 checks passed · publishers

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 21/37 (16 failed)
Level 2 — Enhanced 6/27 (21 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 5/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 8/16
Provenance 1/2
Security 6/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

  • Heading hierarchy issues: h1 -> h5 (skipped h2); h2 -> h5 (skipped h3); h2 -> h5 (skipped h3); h2 -> h5 (skipped h3); h2 -> h4 (skipped h3).

AI & Automation

  • policy_exists: The page contains office location information with no mention of an AI use policy or statement.
    Fix: Publish a dedicated AI use policy page and link to it from the About/Reports and Policies section.
  • scope_clear: No AI policy is present, so the scope of AI use is not explained anywhere on the page.
    Fix: Add a clear description of what AI tools are used for (e.g., editorial, marketing, translation) in a published AI policy.

Privacy

Security

Transparency

  • actionable: The page lists contact section headings but provides no actual phone numbers, email addresses, or contact form to reach the organisation.
    Fix: Add concrete contact details such as a customer service email, phone number, contact form, or office addresses directly on the contact page.
  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only office locations and corporate information.
    Fix: Add a dedicated funding/ownership disclosure section identifying HarperCollins's parent company (News Corp) and any other revenue or sponsorship sources.
  • transparent: No funding sources are identified anywhere on the page, though News Corp is mentioned only incidentally as a building co-tenant.
    Fix: Clearly state ownership and funding sources (e.g., 'HarperCollins is a subsidiary of News Corp') in a visible disclosure block.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The contact page lists generic categories like 'Customer Service' and 'Publicity Contacts' but names no individual or specific role as responsible.
    Fix: Add the name or job title of a specific person or team lead (e.g., Head of Customer Service) accountable for each contact area.
  • contactable: No email addresses, phone numbers, or contact forms are visible on the page—only navigation labels like 'How to Contact Us' appear without actual contact details.
    Fix: Publish direct contact details (email, phone, or a contact form) on the page so users can actually reach the responsible team.
  • response_timeframe: The contact page lists options like 'How to Contact Us' and 'Customer Service' but shows no published response timeframe for inquiries.
    Fix: Publish an expected response time (e.g., 'We respond within 5 business days') alongside the customer service contact information.
  • specific: No specific timeframe in days or hours is provided anywhere on the visible contact page.
    Fix: State a concrete timeframe such as '2 business days for email inquiries' rather than vague language.
  • process_exists: The page links to 'Customer Service' and 'How to Contact Us' but does not display a documented complaints or feedback process.
    Fix: Add a dedicated complaints/feedback procedure page describing how to submit a complaint and how it will be handled.
  • steps_clear: No step-by-step instructions for lodging a complaint are visible on the page content provided.
    Fix: Include numbered steps (e.g., 1. Contact customer service, 2. Escalation path, 3. External ombudsman) so users know exactly how to proceed.
  • appeals_exists: The contact page lists customer service and office info but contains no documented appeals process.
    Fix: Add a clearly labeled appeals procedure describing how users can formally challenge decisions, including required information and timelines.
  • independent: No escalation path or independent review body is mentioned anywhere on the page.
    Fix: Document an independent or escalated review step (e.g., ombudsman, senior review panel, or external arbiter) for unresolved appeals.

AI & Automation

  • detailed_scope: The page makes no reference to AI, so detailed scope of AI use is absent.
    Fix: Create a policy section detailing specific AI use cases, systems, and contexts across HarperCollins operations.
  • limitations: There is no acknowledgement of AI system limitations on this page.
    Fix: Include a section in the AI policy that openly acknowledges limitations such as bias, hallucination, and accuracy constraints.
  • safeguards: No safeguards or quality control measures for AI use are described on the page.
    Fix: Document human review, data protection, and quality assurance safeguards applied to any AI-assisted workflows.
  • marking_policy: The About page contains no policy or statement regarding how AI-assisted content is marked or labeled.
    Fix: Publish a clear AI content labeling policy describing how AI-assisted material is identified and disclosed on the site.
  • consistent: Without any visible AI marking policy or examples on the page, consistent application cannot be demonstrated.
    Fix: Apply standardized AI-content labels across all pages and document this consistent approach in a published policy.
  • oversight_exists: The page makes no mention of human oversight of AI outputs or any AI governance practices.
    Fix: Add a statement or policy page describing how humans oversee and validate any AI-generated outputs used by HarperCollins.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the About page.
    Fix: Document the review and approval steps that AI outputs must pass through before publication and link to it from relevant pages.
  • accountability: No individual, team, or role is identified as accountable for AI-generated content on this page.
    Fix: Name a responsible role or team (e.g., an editorial AI lead) accountable for AI outputs and list their contact in the Reports and Policies section.

Interoperability

Privacy

  • plain_language: The notice uses legalistic phrasing and defined terms like 'Personal Data', 'legitimate interest', and references to GDPR without plain-language explanation.
    Fix: Rewrite key sections in plain English with short sentences and define or avoid legal/technical jargon such as 'legitimate interest' and 'web beacons'.
  • plain_language: Sections describing automated collection use technical jargon like 'HTTP, HTML5 and Flash cookies', 'web beacons', 'clear GIF', and 'JavaScript' without simple explanations.
    Fix: Simplify the cookies/automated means section using layperson wording and provide brief plain definitions or a glossary for technical terms.
  • understandable: A non-expert would struggle with phrases like 'De-identify Personal Data to provide third parties with aggregated data reports' and 'Associate your browser and/or device with other browsers...for the purpose of providing relevant...advertising across browsers and devices'.
    Fix: Add a concise summary table or plain-language overview at the top explaining in everyday terms what data is collected and why.
  • necessity: The policy does not state that data collection is limited to what is necessary; instead it describes broad collection including from publicly available sources and partners.
    Fix: Add an explicit data minimisation statement committing to collect only the personal data necessary for the stated purposes.
  • proportionate: Collection appears broad (supplementing data from public/commercial sources, cross-device tracking, social media profile data) without a proportionality justification tied to each service.
    Fix: Map each category of data collected to the specific service purpose it supports and remove or justify any collection that exceeds what the service requires.
  • retention_stated: The visible content mentions a section titled 'HOW WE PROTECT AND RETAIN PERSONAL DATA' but does not actually state any retention periods in the provided text.
    Fix: Include explicit retention periods for each category of personal data within the retention section of the policy.
  • specific: No specific timeframes (e.g., months or years) for data retention are provided anywhere on the page.
    Fix: Specify concrete retention durations (e.g., 'account data retained for 24 months after account closure') for each data category.
  • banner_present: The page content only shows a 'Cookie Settings' link in the footer; no active cookie or consent banner is visible.
    Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or customize cookie preferences before non-essential cookies are set.
  • partner_sharing_mentioned: The page does not disclose any sharing of data with third-party partners in the visible consent copy or banner area.
    Fix: Add clear language in the cookie banner disclosing that data may be shared with third-party advertising/analytics partners, with a link to the full list.
  • partner_count_specific: No partner sharing is disclosed and no numeric count of third-party partners is stated anywhere on the page.
    Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the cookie banner or linked preferences center.

Provenance

Security

Transparency

  • named_person: The page references teams such as 'Customer Service' and 'Publicity Contacts' but identifies no named individual or specifically named team responsible for enquiries.
    Fix: Identify a specific named contact or team (e.g., 'UK Customer Service Team, led by [Name]') for each enquiry category.
  • role_clear: While broad category labels exist, the page does not clearly describe the role, authority, or remit of who handles which type of enquiry.
    Fix: Add a short description under each contact heading explaining the team's role, scope of authority, and which enquiries they handle.
  • mission_clear: The page describes operations and locations but does not clearly articulate an editorial mission or overarching publishing philosophy.
    Fix: Add a dedicated mission statement section explaining HarperCollins' editorial values, publishing philosophy, and purpose beyond operational descriptions.
  • detail: The page provides no amounts, percentages, or categories describing funding streams.
    Fix: Include meaningful detail such as revenue categories (e.g., book sales, third-party distribution percentages, rights income) in a financial transparency section.
  • complete: No funding streams are disclosed, so coverage of major streams cannot be established.
    Fix: Publish a complete breakdown of major revenue streams (publishing, distribution services, rights, etc.) to ensure comprehensive disclosure.
  • governance_exists: The page describes office locations and facilities but does not outline any governance or editorial structure of the organization.
    Fix: Add a dedicated section describing the company's governance framework, editorial oversight, and decision-making structure.
  • roles_clear: The page mentions divisions and teams in general terms but does not identify key roles, leadership, or their responsibilities.
    Fix: Include a leadership or org-chart section naming key executives and editorial leads along with their specific responsibilities.
  • algorithm_explained: The page describes office locations and distribution operations but does not mention or explain any algorithms in use.
    Fix: Add a section describing any algorithms used (e.g., for personalization, recommendations, or ad targeting referenced in the cookie notice) and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users, despite the cookie banner mentioning personalized ads and analytics.
    Fix: Clearly describe how algorithm-driven features (like personalized content or ads) impact user experience and what outcomes users can expect.
  • annual_statement: The page only references a Cookie Policy link without any evidence of annual or periodic review of data practices.
    Fix: Publish a statement (e.g., in the Cookie/Privacy Policy) confirming that data practices are reviewed on a regular, periodic basis and note the last review date.
  • dated: The cookie banner and referenced Cookie Policy are not shown with any date or version identifier on this page.
    Fix: Add a 'Last updated' date or version number to the Cookie/Privacy Policy and surface it near the consent banner or policy link.

Level 3 — Advanced

Accessibility

  • statement_exists: The page is an 'About Our Offices' page with no dedicated accessibility statement present anywhere in the content.
    Fix: Create a dedicated accessibility statement page (e.g., /accessibility) and link to it from the site footer and navigation.
  • known_issues: There is no accessibility statement, so no known accessibility issues or limitations are acknowledged.
    Fix: Within an accessibility statement, list any known barriers (e.g., non-conforming PDFs or unlabeled controls) discovered through an audit against WCAG 2.1 AA.
  • remediation_timeline: No accessibility statement exists, so there is no timeline or commitment for fixing known issues.
    Fix: Add a remediation section committing to target dates for resolving each identified accessibility barrier.
  • feedback_channel: The page offers office phone numbers and generic email links but no accessibility-specific feedback mechanism with a response commitment.
    Fix: Provide a dedicated accessibility contact (email/phone/form) and state a specific response time commitment for accessibility feedback.

Accountability

  • policy_exists: The terms page covers sales, digital product usage, and account rules but does not publish any moderation policy for user-generated content.
    Fix: Publish a dedicated moderation or community guidelines policy covering reviews, comments, or other user submissions.
  • criteria_clear: No moderation criteria (e.g., prohibited content categories, acceptable use standards) are stated anywhere on the page.
    Fix: Add explicit criteria describing what content is prohibited and what standards submissions must meet.
  • enforcement: The page does not describe any enforcement process, such as how violations are reviewed, removed, or appealed.
    Fix: Document the enforcement workflow including how content is reviewed, actions taken (removal, suspension), and an appeals process.

Interoperability

Security

  • plan_exists: The page is an 'About Our Offices' page listing office locations and contact details, with no published incident response plan or security policy present.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the site's Reports and Policies section.
  • notification_commitment: The page contains no commitment to publicly notify users of significant security incidents.
    Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant security incident.
  • timeframe: No timeframe for disclosing incidents to affected users is mentioned anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page contains no published criteria for any algorithmic decision-making.
    Fix: Publish the specific inputs and criteria used in any algorithmic decisions (e.g., personalization or ad-serving logic) on a dedicated transparency page.
  • weighting: No information is provided about how criteria are weighted or prioritized in algorithmic decisions.
    Fix: Document and disclose the relative weighting or priority of factors used by algorithms that affect users.
  • auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
    Fix: Provide sufficient documentation—such as model descriptions, data sources, and decision logic—to allow independent third-party audit.
  • open_source: There is no mention of or link to any open source code repositories on the page.
    Fix: Add a link to a public code repository (e.g., GitHub) if any of the organisation's software is open source, or note technology transparency in a dedicated section.
  • tech_docs: No technical documentation is linked or referenced on the page beyond brief mentions of logistics vendors like KNAPP and Jungheinrich.
    Fix: Publish or link to technical documentation describing the site's platforms, APIs, or data standards used for publishing and distribution.

Responsibility to the Future

  • disclosure_exists: The page at /sustainability contains only navigation links, cookie notices, and a footer with no actual environmental or sustainability disclosure content.
    Fix: Publish substantive sustainability disclosure content on the page describing the company's environmental policies, goals, and performance.
  • specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
    Fix: Add quantified metrics such as annual carbon emissions (tCO2e), energy consumption, and year-over-year reduction targets.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Disclose whether hosting uses renewable energy or green data centers and provide the associated carbon/energy figures.
  • plan_exists: The About Us page describes offices, distribution and archives but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or contingency plan describing how operations, data, and content would be handled in the event of business failure, closure, or acquisition.
  • data_and_content_fate: The page discusses book storage and archives but never addresses what would happen to user data or published content in a wind-down scenario.
    Fix: Add a section specifying the fate of user data and published/digital content on exit, including retention, transfer, or deletion arrangements.
  • custodians_or_mirrors: Although the page mentions a physical archive of historical materials, it names no custodians, mirrors, or archive partners responsible for preserving data or content should the organisation cease operating.
    Fix: Identify and name specific custodians, mirror sites, or archive partners who would take responsibility for preserving content and data if the organisation exits.
  • policy_exists: The page is an office locations overview and contains no published policy on worker wellbeing or working conditions, only mentions of a 'People and Culture' and 'People' team.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this page (e.g., under 'People and Culture').
  • specific_commitments: The content includes no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add explicit commitments covering pay, working hours, mental health support, and employee benefits.
  • accountability: The page names a 'People' team in Glasgow but does not identify any accountability or oversight structure for worker conditions.
    Fix: Name a responsible role, committee, or governance body accountable for overseeing worker wellbeing and working conditions.