Leeds Libraries

https://www.leeds.gov.uk/libraries · 47/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 28/37 (9 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 4/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 0/2
Security 6/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page content contains no AI use policy or statement anywhere in the visible text or linked policies.
    Fix: Publish an AI use policy (e.g., under 'Our Policies') that clearly states the council's position on AI use across library services.
  • scope_clear: No AI-related content is present, so there is no explanation of what AI is used for.
    Fix: Include a section in the AI policy describing specific use cases such as chatbots, search, recommendations, or back-office automation.

Privacy

Security

Transparency

  • purpose_clear: The visible content contains no descriptive text explaining what the libraries service does.
    Fix: Add introductory text on the About page summarising the purpose and services of Leeds Libraries.
  • disclosure_exists: The page contains no funding or sponsorship disclosure, only navigation, contact, and policy links.
    Fix: Add a funding disclosure section or link on the About page identifying how the libraries service is funded.
  • transparent: No funding sources are identified anywhere on the page content shown.
    Fix: Clearly name funding sources (e.g., council tax, government grants, donations) in a dedicated funding statement.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page only refers generically to 'us' and 'Leeds City Council' without naming a specific person or role responsible for contact.
    Fix: Identify a named officer, team, or role (e.g., 'Customer Services Manager') accountable for handling enquiries on the contact page.

AI & Automation

  • detailed_scope: The page lacks any AI policy, so no detailed scope of AI use is provided.
    Fix: Add a detailed scope section enumerating systems, data inputs, and decisions where AI is applied in library services.
  • limitations: There is no acknowledgement of AI limitations because no AI policy is present on the page.
    Fix: Include a 'Limitations' subsection that acknowledges risks such as inaccuracy, bias, and inappropriate contexts for AI use.
  • safeguards: No safeguards or quality controls are described since the page contains no AI-related content.
    Fix: Document safeguards such as human review, data protection measures, audit processes, and escalation routes for AI outputs.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or disclosed.
    Fix: Publish a clear policy (e.g., in Our Policies) describing how AI-assisted content is identified and labelled on the site.
  • consistent: With no visible AI marking policy, there is no evidence of consistent labelling of AI-generated content on the page.
    Fix: Adopt a consistent visual or textual label for AI-assisted content and apply it uniformly across all pages.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how staff review and oversee any AI-generated content before publication.
  • review_process: No review or approval process for AI content is described on the page.
    Fix: Document the review/approval workflow for AI content within the site's policies section.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name a responsible role or team (e.g., editorial lead) accountable for AI content and include their contact details.

Interoperability

Privacy

  • understandable: The visible page only provides section headings and summaries; the actual explanation of what data is collected and why is not present on this page.
    Fix: Include a brief plain-language summary on the main privacy page explaining the categories of data collected and the purposes, before linking to detailed sub-pages.
  • necessity: The visible content does not state that data collection is limited to what is necessary.
    Fix: Add an explicit statement on the main privacy page that the council only collects personal data that is necessary for the specified purposes.
  • proportionate: There is no statement on this page indicating that data collected is proportionate to the service provided.
    Fix: Include a clear principle-level statement that data collection is proportionate to each service's purpose, ideally aligned with UK GDPR data minimisation.
  • retention_stated: The visible page does not mention data retention periods at all.
    Fix: Add a dedicated retention section (or link) on the main privacy page stating how long personal data is kept for each processing purpose.
  • specific: No specific retention timeframes are provided on the page.
    Fix: Publish a retention schedule with concrete periods (e.g., 'council tax records kept for 7 years') rather than vague commitments.
  • equal_choices: The page content shown does not display any consent interface with visible accept and reject options to evaluate for equal prominence.
    Fix: Ensure the cookie consent banner presents 'Accept' and 'Reject' buttons with equal visual weight, size, color, and placement.
  • partner_sharing_mentioned: The banner only mentions storing cookies for site navigation, usage analysis, and marketing efforts, with no disclosure of data sharing with third-party partners.
    Fix: Update the cookie banner copy to explicitly disclose whether data is shared with third-party partners (e.g., analytics or advertising vendors) and link to a detailed cookie/partner list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the banner along with a link to the full partner list.

Provenance

  • credentials: No background information on Leeds City Council or the libraries service is provided on this page to establish credentials.
    Fix: Add a brief organisational background section describing Leeds City Council's role and the libraries service's remit and expertise.

Security

Transparency

  • named_person: No named individual or specific team is identified for enquiries—the page only references the generic 'Leeds City Council'.
    Fix: Add the name of the specific team (e.g., 'Contact Centre' or 'Customer Services Team') and, where possible, a named lead responsible for enquiries.
  • role_clear: Because no person or team is named, their role or authority to handle enquiries is not stated on the page.
    Fix: Alongside the named team, clearly describe their role and authority (e.g., 'Our Customer Services Team handles all general enquiries and routes them to the appropriate department').
  • substantive: There is no substantive statement of purpose visible, only navigation and contact details.
    Fix: Write a detailed About section describing the mission, services, and values of Leeds Libraries.
  • mission_clear: No mission or editorial approach is articulated anywhere on the page.
    Fix: Add a clearly labelled mission statement describing the aims and guiding principles of the library service.
  • detail: There are no amounts, percentages, or categories of funding described on the page.
    Fix: Publish a breakdown of funding with categories and approximate percentages or amounts for each source.
  • complete: With no disclosure present, there is no coverage of any funding streams, let alone all major ones.
    Fix: Provide a complete disclosure covering all major streams such as council budget allocations, grants, donations, and any sponsorships.
  • governance_exists: The page only shows navigation links and contact details with no description of governance or editorial structure for the libraries service.
    Fix: Add a dedicated governance section on the About page describing how the library service is managed, overseen, and how editorial decisions are made.
  • roles_clear: No key roles, staff positions, or responsibilities are identified anywhere in the visible page content.
    Fix: List key roles (e.g., Head of Libraries, editorial leads, board members) with their responsibilities on the About page.
  • algorithm_explained: The page contains only navigation and contact information with no mention of any algorithms or their purpose.
    Fix: Add a dedicated section or page explaining any algorithms used by library services (e.g., recommendations, catalogue search ranking) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect library users on this page.
    Fix: Publish a clear statement describing how algorithmic outputs influence user experiences such as search results or recommendations.
  • annual_statement: The page only links to a generic Privacy page in the footer with no visible evidence of an annual or periodic review of data practices.
    Fix: Add a statement on the Privacy page indicating when data practices were last reviewed and committing to a regular (e.g. annual) review cycle.
  • dated: No date or version number is shown for any privacy or data practices statement on this page.
    Fix: Display a 'last updated' date or version number on the Privacy/data practices statement and surface it from linked pages.

Level 3 — Advanced

Accessibility

  • feedback_channel: The statement provides a feedback email (webmaster@leeds.gov.uk) but states no timeframe for when users can expect a response.
    Fix: Add an explicit response-time commitment, such as a stated number of working days within which the council will respond to accessibility feedback.

Accountability

Interoperability

Security

  • plan_exists: The page shows only general navigation and contact links with no published incident response plan or security policy.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the site's policy or accessibility section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add explicit language committing to notify the public and affected users when significant incidents occur.
  • timeframe: The page contains no stated timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notify affected users within 72 hours of confirming a breach) in the incident response policy.

Transparency

  • criteria_published: No criteria for any algorithmic decision-making are published on the page.
    Fix: Publish the specific input criteria used by any algorithmic systems on a transparency or policy page.
  • weighting: The page does not explain weighting or priority of any decision criteria.
    Fix: Document and publish how different criteria are weighted or prioritised in any algorithmic decisions.
  • auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithms.
    Fix: Publish an algorithm register or technical documentation sufficient for independent review and audit.
  • open_source: The page does not link to any public source code repository.
    Fix: If appropriate, publish and link to source code (e.g., a GitHub repository) for any in-house developed components.
  • tech_docs: No technical documentation is referenced or linked from this page.
    Fix: Publish technical documentation (such as APIs or data standards used) and link it from the About or Policies section.

Responsibility to the Future

  • hosting_disclosure: The page discusses operational and city-wide emissions but says nothing about the carbon or energy profile of its website hosting infrastructure.
    Fix: Add a statement disclosing the website's hosting energy source or carbon footprint, for example whether the site is hosted on renewable-powered or green data centres.
  • plan_exists: The page shows only general navigation and policy links with no published succession or exit plan for organisational failure.
    Fix: Publish a clearly linked succession/continuity plan describing what happens if the library service or its digital operation ceases.
  • data_and_content_fate: Nothing on the page addresses the fate of user data or published content in the event of service closure.
    Fix: Add a documented statement explaining how user data and published content would be preserved, transferred, or deleted if the service ends.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere in the visible content.
    Fix: Name specific custodians, mirror sites, or archive partners (e.g., a national or local archive) responsible for content continuity.
  • policy_exists: The page shows only general navigation links such as 'Our Policies' and 'Sustainability' but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it clearly from the About us or Our Policies section.
  • specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add concrete, measurable commitments on pay, working hours, mental health support, and employee benefits within a worker wellbeing policy.
  • accountability: The page identifies no person, role, or body responsible for overseeing worker conditions.
    Fix: Name a responsible role or oversight body and provide contact details for accountability on worker wellbeing matters.