Macmillan Cancer Support

https://www.macmillan.org.uk · 51/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 8/13
Accountability 2/5
AI & Automation 3/8
Interoperability 1/3
Privacy 12/16
Provenance 1/2
Security 4/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

  • autoplay without controls: {'tag': 'audio', 'src': 'data:audio/mpeg;base64,/+MYxAAAAANIAUAAAASEEB/jwOFM/0MM/90b/+RhST//w4NFwOjf///PZu////9lns5GFDv//l9GlUIEEIAAAgIg8Ir/JGq3/+MYxDsLIj5QMYcoAP0dv9HIjUcH//yYSg+CIbkGP//8w0bLVjUP///3Z0x5QCAv/yLjwtGKTEFNRTMuOTeqqqqqqqqqqqqq/+MYxEkNmdJkUYc4AKqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq', 'autoplay': True, 'controls': False}
  • without controls: {'tag': 'audio', 'src': 'data:audio/mpeg;base64,/+MYxAAAAANIAUAAAASEEB/jwOFM/0MM/90b/+RhST//w4NFwOjf///PZu////9lns5GFDv//l9GlUIEEIAAAgIg8Ir/JGq3/+MYxDsLIj5QMYcoAP0dv9HIjUcH//yYSg+CIbkGP//8w0bLVjUP///3Z0x5QCAv/yLjwtGKTEFNRTMuOTeqqqqqqqqqqqqq/+MYxEkNmdJkUYc4AKqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq', 'autoplay': True, 'controls': False}

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
  • scope_clear: Because no AI policy is present, there is no explanation of what AI is used for.
    Fix: Include a clear scope section in the AI policy describing specific use cases such as chat support, content generation, or analytics.

Privacy

Security

Transparency

  • transparent: Funding sources are not clearly identified on this page itself; the user must navigate to annual reports to learn about them.
    Fix: Add a brief summary of primary funding sources (e.g., donations, legacies, corporate partnerships) directly on the About page with a link to the full annual report.

Level 2 — Enhanced

Accessibility

Accountability

  • steps_clear: The section only links to a feedback form without outlining the steps, stages, escalation path, or expected timeframes of the complaints process.
    Fix: Add a clear step-by-step outline of the complaints process (how to submit, who reviews it, response timeframe, and escalation options) either on this page or on the linked feedback page.
  • appeals_exists: The contact page offers a feedback/complaint form but does not document any appeals process for escalating unresolved complaints or decisions.
    Fix: Add a clearly documented appeals process explaining how users can challenge a decision or escalate an unresolved complaint, including steps, timeframes, and contact routes.
  • independent: No mention is made of an independent reviewer or escalation path (e.g., to an ombudsman, regulator, or independent panel) for appeals.
    Fix: Specify an independent escalation route—such as the Fundraising Regulator, Charity Commission, or an internal independent review panel—that users can contact if they are unhappy with the initial response.

AI & Automation

  • detailed_scope: The page contains no AI policy and therefore no detailed scope of AI use.
    Fix: Add an AI policy that enumerates each AI system in use, its purpose, and the data it processes.
  • limitations: No acknowledgement of AI limitations appears on the page.
    Fix: Include a 'Limitations' section in the AI policy noting risks such as inaccuracy, bias, and unsuitability for medical advice.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human review, data protection measures, and escalation paths in a published AI policy.
  • marking_policy: The About page contains no policy or statement regarding the marking or labeling of AI-assisted content.
    Fix: Publish a clear policy on the About or organisation page explaining how any AI-assisted content is labeled or disclosed.
  • consistent: Without a stated marking policy, there is no evidence of consistent application of AI content labeling on the page.
    Fix: Adopt and consistently apply a visible AI-content label (e.g., a tag or disclosure line) across all pages where AI assistance is used.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a section describing how humans review AI outputs before publication, linked from the About or governance area.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Publish the editorial review/approval steps (e.g., subject-matter expert sign-off) that AI-assisted content must pass before going live.
  • accountability: The page does not identify any role, team, or individual accountable for AI-generated content.
    Fix: Name an accountable owner (such as a Head of Digital or editorial lead) responsible for AI-generated content and include contact details.

Interoperability

Privacy

  • necessity: The visible content does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit data minimisation statement affirming that Macmillan only collects personal information necessary for the purposes described.
  • proportionate: There is no explicit statement that the data collected is proportionate to the services provided.
    Fix: Include a clear proportionality statement explaining that the scope of data collected is matched to each service (e.g., support line, donations, events).
  • specific: The visible retention section refers generally to a 'records retention policy' without citing specific time periods for categories of data.
    Fix: Publish concrete retention periods (e.g., 'donor records kept for 7 years after last interaction') or link directly to a retention schedule with specific timeframes.
  • equal_choices: The page text does not show a consent interface with accept/reject options, so equal prominence cannot be verified on this privacy policy page.
    Fix: Ensure the cookie/consent banner (linked via Cookies) presents 'Accept' and 'Reject' buttons with equal visual prominence and reference this directly in the privacy policy.
  • banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' link appears in the footer.
    Fix: Implement a visible cookie consent banner on initial page load that allows users to accept, reject, or customize cookie preferences.
  • partner_sharing_mentioned: No banner or on-page consent copy is present, so data sharing with third-party partners is not disclosed at the consent layer.
    Fix: Add consent banner copy that explicitly discloses data sharing with third-party partners and link to a full cookie/partner list.
  • partner_count_specific: Because no partner sharing disclosure exists on the page, no specific numeric count of partners is stated.
    Fix: Include a specific numeric count of third-party partners (e.g., 'We share data with X partners') within the consent banner or linked preferences center.

Provenance

Security

Transparency

  • detail: The page provides no amounts, percentages, or categories of funding, only a generic pointer to annual reports.
    Fix: Include summary figures or percentage breakdowns of funding sources (e.g., % from individual giving, legacies, corporate partners) on the About page.
  • complete: No funding streams are enumerated on this page, so coverage of major streams cannot be confirmed.
    Fix: List all major funding streams (individual donations, legacies, fundraising events, corporate partnerships, retail/shops, grants) with proportional contributions.
  • governance_exists: The page mentions 'Our organisation' and strategy but does not describe the governance or editorial structure on this page.
    Fix: Add a dedicated governance section or link describing the board of trustees, leadership structure, and editorial oversight.
  • roles_clear: Key roles and responsibilities (e.g., trustees, executives, editorial leads) are not identified on this page.
    Fix: List key leadership roles with names and responsibilities, or link directly to a 'Meet the team' page with clear role descriptions.
  • algorithm_explained: The About page describes the charity's mission and structure but does not mention or explain any algorithms used by the organisation.
    Fix: Add a section or linked page describing any algorithms or automated decision systems used (e.g., for donor targeting, service allocation) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users, supporters, or service recipients anywhere on this page.
    Fix: Include clear statements describing how any algorithmic decisions impact users and what recourse they have.
  • annual_statement: The page links to a privacy policy but provides no evidence on this page of a regular or annual review of data practices.
    Fix: Add a note near the privacy policy link (or on the policy itself) stating when data practices are reviewed, e.g., 'Reviewed annually, last reviewed [date]'.
  • dated: There is no visible date or version number associated with the privacy policy or data practices statement on this page.
    Fix: Display a 'Last updated' date or version number alongside the privacy policy link in the footer.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement says they are 'working to fix' issues but provides no dates, deadlines, or specific timeline for remediation.
    Fix: Add target dates or a projected timeframe for resolving each category of known accessibility issue and a date the statement was last reviewed.
  • feedback_channel: The statement offers a feedback form and email contacts but does not state any commitment to how quickly it will respond to accessibility reports.
    Fix: Add a stated response commitment (e.g., 'we aim to respond within X working days') alongside the feedback form and contact details.

Accountability

  • criteria_clear: The page only lists 'Content standards' as a heading without visible specific criteria describing what content is acceptable or prohibited.
    Fix: Expand the Content Standards section to explicitly enumerate prohibited content types (e.g., harassment, misinformation, spam) and required conduct for submissions.
  • enforcement: There is no visible description of how moderation is enforced, such as review processes, removal actions, or appeals.
    Fix: Add an enforcement subsection explaining how violations are detected, what actions (warnings, removal, suspension) will be taken, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The About page contains no published incident response plan or security policy, only charity information and support content.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site footer or About section.
  • notification_commitment: There is no commitment anywhere on the page to publicly notify users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public when significant incidents occur.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of detection) within the incident response policy.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making processes.
    Fix: Publish the specific decision criteria used by any algorithms on a dedicated transparency page linked from About us.
  • weighting: No information about how criteria are weighted or prioritised in decisions is provided on the page.
    Fix: Document and publish the relative weighting or priority assigned to each criterion used in algorithmic decisions.
  • auditable: The page provides no technical or procedural detail that would enable an external audit of algorithmic systems.
    Fix: Publish an algorithmic transparency record with sufficient detail (data sources, logic, governance) to support independent audit.
  • open_source: There is no mention of or link to publicly available source code on the page.
    Fix: Add a link to a public code repository (e.g., GitHub) for any open source projects Macmillan maintains, or note the site's technical openness policy.
  • tech_docs: No technical documentation is published or linked from this page.
    Fix: Publish and link to technical documentation such as API docs, data schemas, or a developer/technology page.

Responsibility to the Future

  • disclosure_exists: The page contains only charity, governance, and support information with no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact page and link to it from the About us section and footer.
  • specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
    Fix: Include quantified environmental metrics (e.g., annual carbon footprint in tonnes CO2e and energy consumption) in a sustainability report.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the hosting provider's energy profile or renewable-energy status and any green-hosting certifications.
  • plan_exists: The About page describes the charity's mission, strategy, and organisation but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing how services and operations would continue or be transferred if the charity ceases to operate.
  • data_and_content_fate: The page and its footer links (privacy policy, terms) do not describe what would happen to user data or published content in the event of organisational failure.
    Fix: Add a section addressing the fate of user data and published content upon closure, including retention, deletion, or transfer arrangements.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page to preserve content if the organisation exits.
    Fix: Identify and name a designated custodian, archive partner, or mirror that would take over data and content preservation if the charity closes.
  • policy_exists: The careers page references 'Our Benefits' in navigation but contains no published policy text on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it prominently from the careers page.
  • specific_commitments: The page shows only a single salary figure (£48,000) for one role and no explicit commitments on hours, mental health, or benefits.
    Fix: Add specific, measurable commitments covering pay ranges, working hours, mental health support, and benefits under the 'Our Benefits' section.
  • accountability: There is no mention of any person, team, or governance body responsible for overseeing worker conditions on the page.
    Fix: Identify a named role or oversight body (e.g., HR/People team or board committee) accountable for monitoring worker wellbeing and publish this on the page.