Information Commissioner's Office

https://www.ico.org.uk · 54/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 32/37 (4 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 5/8
Interoperability 1/3
Privacy 12/16
Provenance 0/2
Security 4/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only descriptions of the ICO's role, jobs, and news.
    Fix: Add a dedicated funding/financial disclosure section on the About page identifying how the ICO is funded (e.g., data protection fees, grant-in-aid).
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly name the ICO's funding sources (such as registration fees from data controllers and government grant-in-aid) directly on the About page or link prominently to an annual report.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists service categories (press office, advice services) but does not name any specific person or role responsible for responding.
    Fix: Add the name or job title of the individual or team lead responsible for each contact channel (e.g., Head of Press Office).
  • response_timeframe: The page lists complaint categories and helpline hours but does not publish any timeframe for responding to complaints.
    Fix: Add a statement specifying how long complainants should expect to wait for acknowledgement and resolution (e.g. 'We will acknowledge your complaint within 7 days and respond within 30 days').
  • specific: No specific timeframe in days or weeks is provided anywhere on the page.
    Fix: Publish concrete numeric timeframes (in days) for acknowledgement and full response to complaints rather than vague commitments.
  • steps_clear: The page categorises complaint types but does not lay out the step-by-step process for actually making a complaint on this landing page.
    Fix: Add a clear numbered step-by-step guide (e.g. 1. Choose your complaint type, 2. Gather evidence, 3. Submit via form/phone, 4. Await acknowledgement) on this page.
  • independent: The page does not describe an independent review or escalation path beyond ICO staff, noting only that the Commissioner delegates casework to their own staff.
    Fix: Add clear information about escalation to an independent body (e.g., the Parliamentary and Health Service Ombudsman or First-tier Tribunal) if complainants remain dissatisfied with the ICO's internal response.

AI & Automation

  • detailed_scope: While focus areas are listed, the page does not detail how AI is actually used, by whom, or for what specific purposes in depth.
    Fix: Expand the page to describe specific AI use cases, data involved, and intended outcomes for each listed focus area.
  • limitations: The page mentions AI can pose high risk to rights but does not acknowledge specific limitations of AI systems.
    Fix: Add a section explicitly acknowledging known limitations of AI systems such as bias, accuracy issues, and explainability challenges.
  • safeguards: No safeguards, quality controls, or mitigations are described on the page itself beyond referencing guidance links.
    Fix: Include a clear description of safeguards, oversight mechanisms, and quality controls applied to AI, or summarize them directly on this page with links to detailed guidance.
  • marking_policy: The page describes the ICO's AI regulatory work but contains no policy about how AI-assisted content on the site itself is labeled or marked.
    Fix: Publish a clear policy stating whether and how any AI-assisted content on the ICO website will be labeled or disclosed to readers.
  • consistent: Without a marking policy present, there is no evidence that AI content marking is applied consistently across the page or site.
    Fix: Adopt a standard AI-content label (e.g., a visible badge or note) and apply it consistently to any AI-assisted pages, including this one.
  • oversight_exists: The page outlines external AI focus areas but does not document human oversight of AI outputs used in the ICO's own content.
    Fix: Add a statement describing the human oversight applied to any AI-generated or AI-assisted content published by the ICO.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Document the editorial review and approval process for AI-assisted content, including who reviews it and against what criteria.
  • accountability: The page does not identify any role, team, or individual accountable for AI-generated content on the site.
    Fix: Name an accountable owner (e.g., a specific team or editorial lead) responsible for AI-generated content and provide a contact route for concerns.

Interoperability

Privacy

  • necessity: The visible landing content does not explicitly state that data collection is limited to what is necessary.
    Fix: Add a clear statement on the main privacy notice landing page affirming that personal data collection is limited to what is necessary for each stated purpose.
  • proportionate: The landing page does not explicitly address proportionality of data collection relative to the services provided.
    Fix: Include an overarching statement on proportionality, explaining that the data gathered is proportionate to the specific service being delivered.
  • retention_stated: The visible landing content of the privacy notice does not mention data retention periods.
    Fix: Add a clearly linked 'Data retention' section on the privacy notice landing page summarising retention practices across services.
  • specific: No specific retention time periods are provided on the visible page content.
    Fix: Publish specific retention periods (e.g., '3 years for complaint records') for each processing scenario listed in the layered notice.
  • equal_choices: The page does not display a visible consent mechanism with equally prominent accept and reject options for cookies or tracking.
    Fix: Ensure the cookie consent banner presents 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement).
  • partner_count_specific: The banner names Vimeo, YouTube, and Silktide but does not state a specific numeric count of partners.
    Fix: Add an explicit numeric disclosure (e.g., 'We share data with 3 third-party partners: Silktide, Vimeo, and YouTube') in the banner copy.

Provenance

  • credentials: The page lists sections like 'Who we are' and 'What we do' but does not itself provide organisational credentials, statutory basis, or background details on this about landing page.
    Fix: Add a brief summary on the About page describing the ICO's statutory role, regulatory remit, and leadership credentials with links to more detail.

Security

Transparency

  • substantive: The About page content is mostly a tagline ('Empowering people through information') and navigation links rather than substantive descriptive prose.
    Fix: Include several paragraphs on the About page explaining the ICO's role, powers, history, and how it regulates data protection and information rights.
  • mission_clear: The mission is reduced to a short slogan with the strategic plan linked elsewhere rather than articulated on the page itself.
    Fix: Summarise the ICO25 strategic mission and editorial/regulatory approach directly on the About page instead of only linking out.
  • detail: The page provides no amounts, percentages, or categories for any funding streams.
    Fix: Include meaningful detail such as the proportion of income from data protection fees versus grant-in-aid, with monetary figures drawn from the latest annual accounts.
  • complete: Because no funding disclosure exists, major funding streams are not covered at all.
    Fix: Publish a complete breakdown of all funding streams (fees, grant-in-aid, and any other income) on the About page or link to the ICO's published annual report and accounts.
  • roles_clear: The page references the Information Commissioner's Office broadly but does not identify key roles or responsibilities of leadership on this page itself.
    Fix: Add a section or prominent link on the About page listing the Commissioner, executive team, and their specific responsibilities.
  • algorithm_explained: The About page describes the ICO's role and sections but does not mention or explain any algorithms used by the organisation.
    Fix: Add a dedicated section or link describing any algorithms or automated decision-making tools used by the ICO and their purpose.
  • impact_clear: There is no description on the page of how algorithmic decisions might affect users or the public.
    Fix: Include clear information about the impact of any algorithmic processes on individuals, such as outcomes, risks, and safeguards.
  • annual_statement: The About page links to a privacy notice but shows no evidence of a regular or annual review of data practices.
    Fix: Add a visible statement indicating when the privacy notice or data practices were last reviewed, and commit to a periodic (e.g., annual) review cycle.
  • dated: No date, version, or 'last updated' indicator for the data practices/privacy statement is visible on the page.
    Fix: Display a 'last updated' date or version number on the Privacy notice link or footer so users can see when it was last reviewed.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content is the About page and shows no acknowledgment of any known accessibility issues or limitations.
    Fix: Add a section to the linked accessibility statement that explicitly lists known accessibility issues and non-compliant areas of the site.
  • remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on this page.
    Fix: Include target dates or a stated commitment for when identified accessibility issues will be resolved within the accessibility statement.
  • feedback_channel: The page offers a general 'Contact us' link but no accessibility-specific feedback mechanism with a response commitment.
    Fix: Provide a dedicated accessibility feedback contact method and state a specific timeframe within which the ICO will respond to reports.

Accountability

  • policy_exists: The About page does not publish or link to any moderation policy governing user-generated content or community interactions.
    Fix: Publish a dedicated moderation policy page and link to it from the About section or site footer.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use rules) are stated anywhere on the page.
    Fix: Add a clearly written list of moderation criteria describing what content is allowed, disallowed, and subject to removal.
  • enforcement: The page contains no description of how moderation decisions are made, appealed, or enforced.
    Fix: Document the enforcement workflow including who reviews content, timelines, sanctions, and the appeals process.

Interoperability

Security

  • plan_exists: The About page describes the ICO's role, jobs, and consultations but contains no published incident response plan or security policy.
    Fix: Publish an incident response plan or link to a security policy page describing how the organisation handles security incidents.
  • notification_commitment: There is no statement on the page committing to public notification of significant security incidents.
    Fix: Add an explicit commitment to notify the public and affected users when significant incidents occur.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: State a specific disclosure timeframe (for example, notification within 72 hours of discovering an incident).

Transparency

  • criteria_published: No specific criteria for any algorithmic decisions are published or linked on this About page.
    Fix: Publish a transparency page listing the specific criteria used in any algorithmic decision-making processes.
  • weighting: The page provides no information about the weighting or prioritisation of decision criteria.
    Fix: Document and publish how each criterion is weighted or prioritised within algorithmic decision processes.
  • auditable: The page lacks the technical or procedural detail needed for external audit or review of any algorithms.
    Fix: Provide auditable documentation (e.g., model cards, data sources, evaluation methods) or link to an algorithmic transparency record.
  • open_source: There is no link to source code or any public code repository on the page.
    Fix: Add a link to a public code repository (e.g., GitHub) for any open-source components of the ICO website or tools.
  • tech_docs: The page does not reference or link to any technical documentation for the site or its services.
    Fix: Publish and link to technical documentation (e.g., API docs, developer resources, or site technology details) from the About section.

Responsibility to the Future

  • disclosure_exists: The About page lists sections like strategic plan, jobs, and reports but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About section.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Add measurable environmental metrics such as annual carbon emissions and energy consumption to a sustainability disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's carbon or energy profile, including whether renewable energy or green hosting is used.
  • plan_exists: The About page describes who the ICO is, its strategic plan ICO25, jobs, and news but contains no published plan addressing what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing how services, data, and content would be handled if the organisation ceases to operate.
  • data_and_content_fate: The page makes no reference to the fate of user data or published content in the event of organisational failure or wind-down.
    Fix: Add a section specifying how user data would be retained, transferred, or securely destroyed and how published content would be preserved if the organisation exits.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name a designated custodian, archive partner, or mirror (e.g., a national web archive) responsible for maintaining content and data after an exit.
  • policy_exists: The page only offers general 'About the ICO' navigation and job vacancy links, with no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About section.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits.
    Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits.
  • accountability: The page does not identify any person, role, or body responsible for overseeing worker conditions.
    Fix: Name a responsible role or oversight body accountable for monitoring and improving worker conditions.