Information Commissioner's Office
https://www.ico.org.uk · 54/92 checks passed · government
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 32/37 (4 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 5/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 0/2 |
| Security | 4/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (2 hops): https://www.ico.org.uk → https://ico.org.uk/
- x-frame-options: header not set on the response.
- referrer-policy: header not set on the response.
- TLS certificate expires in 14 days.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only descriptions of the ICO's role, jobs, and news.
Fix: Add a dedicated funding/financial disclosure section on the About page identifying how the ICO is funded (e.g., data protection fees, grant-in-aid).
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly name the ICO's funding sources (such as registration fees from data controllers and government grant-in-aid) directly on the About page or link prominently to an annual report.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists service categories (press office, advice services) but does not name any specific person or role responsible for responding.
Fix: Add the name or job title of the individual or team lead responsible for each contact channel (e.g., Head of Press Office).
-
response_timeframe: The page lists complaint categories and helpline hours but does not publish any timeframe for responding to complaints.
Fix: Add a statement specifying how long complainants should expect to wait for acknowledgement and resolution (e.g. 'We will acknowledge your complaint within 7 days and respond within 30 days').
-
specific: No specific timeframe in days or weeks is provided anywhere on the page.
Fix: Publish concrete numeric timeframes (in days) for acknowledgement and full response to complaints rather than vague commitments.
-
steps_clear: The page categorises complaint types but does not lay out the step-by-step process for actually making a complaint on this landing page.
Fix: Add a clear numbered step-by-step guide (e.g. 1. Choose your complaint type, 2. Gather evidence, 3. Submit via form/phone, 4. Await acknowledgement) on this page.
-
independent: The page does not describe an independent review or escalation path beyond ICO staff, noting only that the Commissioner delegates casework to their own staff.
Fix: Add clear information about escalation to an independent body (e.g., the Parliamentary and Health Service Ombudsman or First-tier Tribunal) if complainants remain dissatisfied with the ICO's internal response.
AI & Automation
-
detailed_scope: While focus areas are listed, the page does not detail how AI is actually used, by whom, or for what specific purposes in depth.
Fix: Expand the page to describe specific AI use cases, data involved, and intended outcomes for each listed focus area.
-
limitations: The page mentions AI can pose high risk to rights but does not acknowledge specific limitations of AI systems.
Fix: Add a section explicitly acknowledging known limitations of AI systems such as bias, accuracy issues, and explainability challenges.
-
safeguards: No safeguards, quality controls, or mitigations are described on the page itself beyond referencing guidance links.
Fix: Include a clear description of safeguards, oversight mechanisms, and quality controls applied to AI, or summarize them directly on this page with links to detailed guidance.
-
marking_policy: The page describes the ICO's AI regulatory work but contains no policy about how AI-assisted content on the site itself is labeled or marked.
Fix: Publish a clear policy stating whether and how any AI-assisted content on the ICO website will be labeled or disclosed to readers.
-
consistent: Without a marking policy present, there is no evidence that AI content marking is applied consistently across the page or site.
Fix: Adopt a standard AI-content label (e.g., a visible badge or note) and apply it consistently to any AI-assisted pages, including this one.
-
oversight_exists: The page outlines external AI focus areas but does not document human oversight of AI outputs used in the ICO's own content.
Fix: Add a statement describing the human oversight applied to any AI-generated or AI-assisted content published by the ICO.
-
review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
Fix: Document the editorial review and approval process for AI-assisted content, including who reviews it and against what criteria.
-
accountability: The page does not identify any role, team, or individual accountable for AI-generated content on the site.
Fix: Name an accountable owner (e.g., a specific team or editorial lead) responsible for AI-generated content and provide a contact route for concerns.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible landing content does not explicitly state that data collection is limited to what is necessary.
Fix: Add a clear statement on the main privacy notice landing page affirming that personal data collection is limited to what is necessary for each stated purpose.
-
proportionate: The landing page does not explicitly address proportionality of data collection relative to the services provided.
Fix: Include an overarching statement on proportionality, explaining that the data gathered is proportionate to the specific service being delivered.
-
retention_stated: The visible landing content of the privacy notice does not mention data retention periods.
Fix: Add a clearly linked 'Data retention' section on the privacy notice landing page summarising retention practices across services.
-
specific: No specific retention time periods are provided on the visible page content.
Fix: Publish specific retention periods (e.g., '3 years for complaint records') for each processing scenario listed in the layered notice.
-
equal_choices: The page does not display a visible consent mechanism with equally prominent accept and reject options for cookies or tracking.
Fix: Ensure the cookie consent banner presents 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement).
-
partner_count_specific: The banner names Vimeo, YouTube, and Silktide but does not state a specific numeric count of partners.
Fix: Add an explicit numeric disclosure (e.g., 'We share data with 3 third-party partners: Silktide, Vimeo, and YouTube') in the banner copy.
Provenance
- No author or date metadata found on the page.
-
credentials: The page lists sections like 'Who we are' and 'What we do' but does not itself provide organisational credentials, statutory basis, or background details on this about landing page.
Fix: Add a brief summary on the About page describing the ICO's statutory role, regulatory remit, and leadership credentials with links to more detail.
Security
- security.txt not published.
Transparency
-
substantive: The About page content is mostly a tagline ('Empowering people through information') and navigation links rather than substantive descriptive prose.
Fix: Include several paragraphs on the About page explaining the ICO's role, powers, history, and how it regulates data protection and information rights.
-
mission_clear: The mission is reduced to a short slogan with the strategic plan linked elsewhere rather than articulated on the page itself.
Fix: Summarise the ICO25 strategic mission and editorial/regulatory approach directly on the About page instead of only linking out.
-
detail: The page provides no amounts, percentages, or categories for any funding streams.
Fix: Include meaningful detail such as the proportion of income from data protection fees versus grant-in-aid, with monetary figures drawn from the latest annual accounts.
-
complete: Because no funding disclosure exists, major funding streams are not covered at all.
Fix: Publish a complete breakdown of all funding streams (fees, grant-in-aid, and any other income) on the About page or link to the ICO's published annual report and accounts.
-
roles_clear: The page references the Information Commissioner's Office broadly but does not identify key roles or responsibilities of leadership on this page itself.
Fix: Add a section or prominent link on the About page listing the Commissioner, executive team, and their specific responsibilities.
-
algorithm_explained: The About page describes the ICO's role and sections but does not mention or explain any algorithms used by the organisation.
Fix: Add a dedicated section or link describing any algorithms or automated decision-making tools used by the ICO and their purpose.
-
impact_clear: There is no description on the page of how algorithmic decisions might affect users or the public.
Fix: Include clear information about the impact of any algorithmic processes on individuals, such as outcomes, risks, and safeguards.
-
annual_statement: The About page links to a privacy notice but shows no evidence of a regular or annual review of data practices.
Fix: Add a visible statement indicating when the privacy notice or data practices were last reviewed, and commit to a periodic (e.g., annual) review cycle.
-
dated: No date, version, or 'last updated' indicator for the data practices/privacy statement is visible on the page.
Fix: Display a 'last updated' date or version number on the Privacy notice link or footer so users can see when it was last reviewed.
Level 3 — Advanced
Accessibility
-
known_issues: The provided page content is the About page and shows no acknowledgment of any known accessibility issues or limitations.
Fix: Add a section to the linked accessibility statement that explicitly lists known accessibility issues and non-compliant areas of the site.
-
remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on this page.
Fix: Include target dates or a stated commitment for when identified accessibility issues will be resolved within the accessibility statement.
-
feedback_channel: The page offers a general 'Contact us' link but no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility feedback contact method and state a specific timeframe within which the ICO will respond to reports.
Accountability
-
policy_exists: The About page does not publish or link to any moderation policy governing user-generated content or community interactions.
Fix: Publish a dedicated moderation policy page and link to it from the About section or site footer.
-
criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use rules) are stated anywhere on the page.
Fix: Add a clearly written list of moderation criteria describing what content is allowed, disallowed, and subject to removal.
-
enforcement: The page contains no description of how moderation decisions are made, appealed, or enforced.
Fix: Document the enforcement workflow including who reviews content, timelines, sanctions, and the appeals process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page describes the ICO's role, jobs, and consultations but contains no published incident response plan or security policy.
Fix: Publish an incident response plan or link to a security policy page describing how the organisation handles security incidents.
-
notification_commitment: There is no statement on the page committing to public notification of significant security incidents.
Fix: Add an explicit commitment to notify the public and affected users when significant incidents occur.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: State a specific disclosure timeframe (for example, notification within 72 hours of discovering an incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decisions are published or linked on this About page.
Fix: Publish a transparency page listing the specific criteria used in any algorithmic decision-making processes.
-
weighting: The page provides no information about the weighting or prioritisation of decision criteria.
Fix: Document and publish how each criterion is weighted or prioritised within algorithmic decision processes.
-
auditable: The page lacks the technical or procedural detail needed for external audit or review of any algorithms.
Fix: Provide auditable documentation (e.g., model cards, data sources, evaluation methods) or link to an algorithmic transparency record.
-
open_source: There is no link to source code or any public code repository on the page.
Fix: Add a link to a public code repository (e.g., GitHub) for any open-source components of the ICO website or tools.
-
tech_docs: The page does not reference or link to any technical documentation for the site or its services.
Fix: Publish and link to technical documentation (e.g., API docs, developer resources, or site technology details) from the About section.
Responsibility to the Future
-
disclosure_exists: The About page lists sections like strategic plan, jobs, and reports but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About section.
-
specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
Fix: Add measurable environmental metrics such as annual carbon emissions and energy consumption to a sustainability disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the hosting provider's carbon or energy profile, including whether renewable energy or green hosting is used.
-
plan_exists: The About page describes who the ICO is, its strategic plan ICO25, jobs, and news but contains no published plan addressing what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan describing how services, data, and content would be handled if the organisation ceases to operate.
-
data_and_content_fate: The page makes no reference to the fate of user data or published content in the event of organisational failure or wind-down.
Fix: Add a section specifying how user data would be retained, transferred, or securely destroyed and how published content would be preserved if the organisation exits.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name a designated custodian, archive partner, or mirror (e.g., a national web archive) responsible for maintaining content and data after an exit.
-
policy_exists: The page only offers general 'About the ICO' navigation and job vacancy links, with no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About section.
-
specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits.
-
accountability: The page does not identify any person, role, or body responsible for overseeing worker conditions.
Fix: Name a responsible role or oversight body accountable for monitoring and improving worker conditions.