London School of Economics

https://www.lse.ac.uk · 50/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (10 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 4/8
Interoperability 0/3
Privacy 10/16
Provenance 1/2
Security 5/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page is a hub for LSE's AI research and activities but does not present an AI use policy or governance statement.
    Fix: Publish a clear AI use policy or statement on this page (or link to one) outlining LSE's principles for using AI.
  • scope_clear: While the page mentions researching responsible, safe, and ethical AI, it does not explain what AI is actually used for at LSE.
    Fix: Add a section that explicitly describes the contexts and purposes for which AI is used at LSE (e.g., teaching, research, administration).

Privacy

Security

Transparency

  • transparent: Funding sources are mentioned only in general terms (e.g., 'external organisations, research councils and governments') without naming specific funders.
    Fix: List the specific external organisations, research councils, and government bodies that provide funding, ideally with links to each source.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic teams like 'Media Relations team' and 'Security' but no named individual or specific role holder is identified as responsible for the contact page or enquiries.
    Fix: Add a named person or specific role (e.g., 'Head of Communications, Jane Smith') accountable for handling general enquiries.
  • response_timeframe: The contact page lists phone numbers and links but does not publish any response timeframe for inquiries.
    Fix: Add a statement on the contact page indicating expected response times for each contact channel (e.g., email, switchboard, admissions).
  • specific: Because no timeframes are published at all, there are no specific day-based commitments.
    Fix: Specify concrete timeframes such as 'we aim to respond within 5 working days' for each enquiry type.
  • process_exists: The page offers general contact details and a 'Report a page' link but does not document a complaints or feedback process.
    Fix: Add a clearly labelled complaints/feedback section or link to a dedicated complaints procedure page.
  • steps_clear: Without a documented complaints process, no steps are provided for making a complaint.
    Fix: Publish step-by-step instructions (who to contact, what information to include, escalation path) for submitting a complaint.

AI & Automation

  • detailed_scope: No AI policy is present, so the scope of AI use is not detailed beyond general research and outreach themes.
    Fix: Create a policy section detailing specific AI applications, departments involved, data types processed, and user groups affected.
  • limitations: The page references topics like AI sentience and bias in linked content but does not acknowledge limitations of AI systems used by LSE itself.
    Fix: Include an explicit statement of known limitations (e.g., accuracy, bias, hallucinations) of any AI systems LSE deploys.
  • safeguards: No safeguards, quality controls, or oversight mechanisms for AI use are described on the page.
    Fix: Document concrete safeguards such as human review, ethics committee oversight, data protection measures, and quality assurance processes.
  • marking_policy: The page discusses AI research and content but does not state any policy for marking or labelling AI-assisted content.
    Fix: Publish a clear policy on the page (or link to one) specifying how AI-assisted or AI-generated content is labelled.
  • consistent: Without a marking policy, there is no evidence that AI content is labelled consistently across articles, podcasts, or videos listed.
    Fix: Apply a uniform AI-content label (e.g., an 'AI-assisted' tag) to all relevant items and document its consistent use.
  • oversight_exists: The page describes AI research themes but does not document any human oversight process for AI outputs published on the site.
    Fix: Add a statement describing how human editors or academics review AI outputs before publication.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Document the review/approval steps (who reviews, criteria, sign-off) for any AI-assisted content.
  • accountability: While the DSI convenes AI work, no individual or role is named as accountable for AI-generated content on the page.
    Fix: Name a specific role or contact (e.g., DSI editorial lead) responsible for AI-generated content and include their contact details.

Interoperability

  • no_proprietary_lock: The Modern Slavery Statement is only linked as a PDF, requiring proprietary/specialised software rather than being offered in open HTML.
    Fix: Publish the Modern Slavery Statement as an HTML page in addition to the PDF version.

Privacy

  • plain_language: The policy uses legalistic references such as 'Data Protection Act 2018', 'GDPR', and formal numbered clauses rather than plain, accessible language.
    Fix: Rewrite sections in plain English with short sentences and everyday terms, and provide a summary at the top explaining key points without statutory citations.
  • plain_language: Phrases like 'strike a fair balance', 'terminal equipment', and references to the 'Act and GDPR' are jargon-heavy rather than plain language.
    Fix: Replace legal and technical jargon with plain-language equivalents and define any necessary technical terms in simple words.
  • necessity: The policy does not explicitly state that data collection is limited to what is necessary (data minimisation principle).
    Fix: Add a clear statement that LSE only collects personal data that is necessary for the stated purposes, reflecting the GDPR data minimisation principle.
  • proportionate: There is no explicit statement that the data collected is proportionate to the service provided.
    Fix: Include a statement explaining that the types and volume of data collected are proportionate to each specific service or purpose described.
  • retention_stated: The policy only says data will be held 'for as long as it is still used for the purpose stated' without clearly defining retention periods.
    Fix: Add a dedicated retention section listing each data category and the specific period it will be retained.
  • specific: The retention statement in 5.3.2 is vague and provides no specific timeframes or criteria for deletion.
    Fix: Specify concrete retention periods (e.g., '12 months for log files', '3 years for enquiry form submissions') for each type of data collected.
  • banner_present: The page content shows only a 'Cookie settings' link in the footer, with no visible cookie or consent banner on the page.
    Fix: Implement a visible cookie consent banner that appears on first visit to inform users about cookie usage and obtain consent.
  • partner_sharing_mentioned: The page content contains no disclosure about data sharing with third-party partners in any banner or on-page consent copy.
    Fix: Add clear language in the cookie banner disclosing that data may be shared with third-party advertising and analytics partners, with a link to details.
  • partner_count_specific: No specific numeric count of third-party partners is stated anywhere on the page since no partner sharing is disclosed.
    Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') in the cookie banner or linked preferences panel.

Provenance

Security

Transparency

  • named_person: Only generic groupings (Admissions, Media Relations team, Security services) are listed without identifying a named individual or specifically designated team lead for enquiries.
    Fix: Identify the specific team or individual responsible for each enquiry type, e.g., 'Enquiries handled by the LSE Student Services Centre, led by [name/role]'.
  • detail: The page provides no amounts, percentages, or concrete categories of funding—only generic references to scholarships and studentships.
    Fix: Add specific figures such as scholarship amounts, number of awards, or percentage breakdowns of funding by category.
  • complete: The disclosure is incomplete, omitting details on major funding streams and leaving users to click through to other pages for substantive information.
    Fix: Provide a consolidated summary on this page covering all major funding streams (LSE taught, LSE research, external, governmental) with key figures for each.
  • governance_exists: The page describes LSE's history, rankings, and achievements but does not outline any governance or editorial structure for the institution or its content.
    Fix: Add a dedicated governance section or link to a page describing LSE's governing bodies (e.g., Council, Court of Governors) and editorial oversight.
  • roles_clear: Only the President and Vice Chancellor is mentioned by name, with no description of other key roles, responsibilities, or decision-making bodies.
    Fix: Include a roles and responsibilities overview listing senior leadership, committees, and their remits, with links to detailed profiles.
  • algorithm_explained: The About page does not mention or explain any algorithms used by LSE in decision-making or services.
    Fix: Add a section or link describing any algorithms used (e.g., in admissions, personalisation, or ranking) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions might impact users (students, applicants, or visitors).
    Fix: Publish a plain-language statement outlining the effects algorithmic decisions have on users and how they can seek redress.
  • annual_statement: The page links to a Privacy policy and Cookie policy but provides no visible evidence of an annual or periodic review of data practices.
    Fix: Publish a clear 'last reviewed' note or periodic review cadence on the Privacy policy and reference it from the site footer.
  • dated: Neither the Privacy policy nor Cookie policy links in the footer show a visible date or version indicator on this page.
    Fix: Add a visible 'Last updated' date or version number to the Privacy policy and Cookie policy and surface it where the policies are linked.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content is a link to the accessibility statement but does not display any acknowledgment of known accessibility issues or limitations.
    Fix: Include a clearly documented list of known accessibility issues and non-compliant elements within the linked accessibility statement.
  • remediation_timeline: No timeline or commitment for fixing accessibility issues is visible on the page.
    Fix: Add a stated timeline or commitment date for remediating known accessibility issues in the accessibility statement.
  • feedback_channel: The page does not present an accessibility-specific feedback mechanism with a response commitment, only a general "Report a page" and contact link.
    Fix: Provide a dedicated accessibility feedback channel (email or form) along with a stated response time commitment in the accessibility statement.

Accountability

  • policy_exists: The terms of use page lists a 'Contributing to the website' section but no moderation policy is visible or detailed in the provided content.
    Fix: Publish a dedicated moderation policy section outlining how user contributions are reviewed and moderated.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use standards) are visible on the page.
    Fix: Add a clear list of criteria describing what content is acceptable and what will be removed or rejected.
  • enforcement: The page does not describe any enforcement process for moderation decisions, appeals, or sanctions.
    Fix: Include an enforcement section explaining how violations are handled, who reviews them, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The page only provides general physical security contact information and crime reporting numbers, with no published incident response plan or policy.
    Fix: Publish a formal incident response plan or policy document describing how security incidents are detected, managed, and resolved.
  • notification_commitment: The page makes no commitment to publicly notifying affected users about significant security incidents.
    Fix: Add a clear statement committing to notify affected individuals and the public in the event of a significant security or data incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a defined timeframe (e.g., within 72 hours of discovery) for disclosing incidents to affected users.
  • policy_exists: The page is about physical campus security services and contains no published responsible-disclosure or bug-bounty policy for reporting software vulnerabilities.
    Fix: Publish a security.txt file and a dedicated responsible-disclosure policy page outlining how researchers can report vulnerabilities.
  • clear_contact: The only contact channels provided are for physical crime reporting (extension 2000 and 666), with no email or web form for reporting security vulnerabilities.
    Fix: Add a dedicated vulnerability-reporting contact such as security@lse.ac.uk or a secure web form clearly labelled for disclosure.
  • safe_harbour_or_reward: The page offers no safe-harbour assurances or reward structure for security researchers.
    Fix: Include explicit safe-harbour language protecting good-faith researchers and, if applicable, describe any reward or recognition program.

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published on this About page.
    Fix: Publish the specific criteria used in any algorithmic decision-making, with links from the About or governance section.
  • weighting: The page provides no information about the weighting or prioritisation of decision criteria.
    Fix: Disclose how each criterion is weighted or prioritised within any algorithmic processes used by LSE.
  • auditable: The page lacks any technical or procedural detail that would enable external audit or review of algorithms.
    Fix: Provide documentation (e.g., model cards, data sources, methodology) sufficient to allow independent auditing of algorithmic systems.
  • open_source: The page does not link to any public source code repository for the website or institutional software.
    Fix: Add a link to a public code repository (e.g., GitHub/GitLab) for any open-source projects or website components LSE maintains.
  • tech_docs: No technical documentation about the site's platform, APIs, or data is linked from the About page.
    Fix: Publish and link to technical documentation such as an API reference, data schemas, or developer notes from the About section.

Responsibility to the Future

  • specific_metrics: The page contains only qualitative statements like 'green campus' and 'top ten for sustainability' with no specific carbon, energy, or emissions figures.
    Fix: Add measurable data such as annual carbon emissions, energy consumption, and reduction targets with year-on-year figures.
  • hosting_disclosure: The page makes no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Publish information on the hosting provider's energy sourcing (e.g., renewable-powered data centres) and the site's associated carbon footprint.
  • plan_exists: The page contains institutional information, news, and rankings but no published plan for what happens if LSE fails or exits.
    Fix: Publish a continuity or wind-down plan describing what would happen to the organisation's operations, services, and digital assets in the event of failure or exit.
  • data_and_content_fate: While a privacy policy is linked, the page provides no statement about what happens to user data and published content should the organisation cease operations.
    Fix: Add a section addressing the fate of user data and published content in a wind-down scenario, including retention, deletion, or transfer arrangements.
  • custodians_or_mirrors: The page names no custodians, mirrors, or archive partners responsible for preserving content if the organisation ceases to operate.
    Fix: Identify and publish designated custodians, mirror sites, or archive partners (e.g. a national web archive) that would preserve content upon exit.
  • policy_exists: The page is a people/experts directory and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the site's HR or about section.
  • specific_commitments: No specific commitments on pay, hours, mental health, or benefits appear anywhere on the page.
    Fix: Include concrete commitments such as fair pay standards, working-hour limits, mental health support, and staff benefits in a wellbeing policy.
  • accountability: The page does not identify any person, office, or body accountable for overseeing worker conditions.
    Fix: Name a responsible office or role (e.g., HR Director or a wellbeing committee) with oversight of worker conditions in the policy.