Marks & Spencer

https://www.marksandspencer.com · 36/68 checks passed · retail

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 29/37 (5 failed)
Level 2 — Enhanced 7/27 (14 failed)
Level 3 — Advanced 0/4 (3 failed)

By category

CategoryResult
Accessibility 12/12
Accountability 3/5
AI & Automation 3/8
Interoperability 0/3
Privacy 11/16
Provenance 0/2
Security 4/9
Transparency 3/13

Level 1 — Basic

Accessibility

AI & Automation

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page only references a generic 'Customer Service Team' without naming a specific person or defined role holder responsible for enquiries.
    Fix: Identify a named individual or specific role (e.g., Head of Customer Service) accountable for responding to contact enquiries.

AI & Automation

  • marking_policy: The page lists various policies (terms, reviews, ethical trading) but contains no policy for marking AI-assisted content.
    Fix: Add a clear policy section describing how AI-assisted content is labeled or disclosed on the site.
  • consistent: Without any AI marking policy referenced on the page, consistent application cannot be demonstrated.
    Fix: Publish and enforce uniform AI-content labels across product descriptions, reviews, and editorial content.
  • oversight_exists: The page does not mention any human oversight process for AI-generated outputs.
    Fix: Document a human-in-the-loop oversight policy for AI outputs and link it from the policies section.
  • review_process: No review or approval workflow for AI content is described anywhere on the page.
    Fix: Describe the review/approval steps AI content must pass before publication in a dedicated policy entry.
  • accountability: No role or team is identified as accountable for AI-generated content on this page.
    Fix: Name an accountable owner (e.g., an editorial or AI governance lead) responsible for AI-generated content.

Interoperability

Privacy

  • necessity: The visible policy content does not explicitly state that data collection is limited to what is necessary (data minimisation principle).
    Fix: Add an explicit statement that M&S only collects personal data that is necessary for the stated purposes, reflecting the data minimisation principle.
  • retention_stated: The visible portion of the policy does not mention how long personal data is retained.
    Fix: Add a dedicated 'Data Retention' section explaining how long each category of personal data is kept and the criteria used to determine that period.
  • specific: No specific retention time periods (e.g., months or years) are provided anywhere in the visible policy text.
    Fix: Specify concrete retention periods for each data category (e.g., 'order data retained for 7 years for tax purposes', 'CCTV footage retained for 30 days').
  • equal_choices: The page mentions that users 'can reject all (non-essential) cookies' but does not demonstrate equally prominent accept/reject options on the consent interface itself.
    Fix: Ensure the cookie consent banner presents 'Accept All' and 'Reject All' buttons with equal visual prominence (same size, color, and placement) at the first layer.
  • ads_labelled: The page mentions personalised digital advertising but does not show any labelling conventions for sponsored or advertising content on M&S sites.
    Fix: Add clear 'Ad' or 'Sponsored' labels to any advertising or sponsored content and describe this labelling practice in the privacy or advertising policy.
  • disclosure: While the policy references partners and personalised ads, it does not clearly disclose commercial relationships between editorial/content and advertisers.
    Fix: Include an explicit disclosure statement explaining the relationship between M&S content and any advertisers or commercial partners.
  • banner_present: No cookie or consent banner is visible in the page content; only a 'Cookies' / 'Manage cookies' footer link appears.
    Fix: Display a visible cookie consent banner on first visit that allows users to accept, reject, or manage cookies before non-essential tracking occurs.
  • partner_sharing_mentioned: The page content contains no disclosure about sharing data with third-party partners in any banner or on-page consent copy.
    Fix: Add clear language to the consent banner stating that data may be shared with third-party advertising and analytics partners, with a link to the full list.
  • partner_count_specific: No specific numeric count of partners is stated anywhere on the page since partner sharing is not disclosed.
    Fix: Include an exact number of third-party partners (e.g., 'We share data with 123 partners') in the consent banner and link to a detailed vendor list.

Provenance

Security

Transparency

  • named_person: Only the generic 'Customer Service Team' is mentioned, with no named individual or specifically identified team lead for enquiries.
    Fix: Add the name of a responsible individual or clearly identify the specific team handling enquiries beyond a generic label.
  • algorithm_explained: The page lists policies and account help topics but does not mention or explain any algorithms used by M&S (e.g., for personalization, recommendations, or Sparks rewards).
    Fix: Add a dedicated section or linked policy explaining the purpose of any algorithms used (such as product recommendations, targeted offers, or loyalty personalization).
  • impact_clear: There is no description of how algorithmic decisions affect users, such as what offers they see or how Sparks rewards are tailored.
    Fix: Include a plain-language explanation of how algorithmic decisions impact users' experience, offers, pricing, or recommendations on the site.
  • annual_statement: The visible policy text does not indicate any regular or annual review cycle of data practices.
    Fix: Add a statement specifying that the privacy policy is reviewed at least annually, including the date of the most recent review.
  • dated: The privacy policy content shown has no visible 'last updated' date or version number.
    Fix: Add a clearly visible 'Last updated' date or version identifier to the top or bottom of the privacy policy.

Level 3 — Advanced

Accountability

  • criteria_clear: The page only lists policy titles as links without stating the actual moderation criteria for content or reviews.
    Fix: Include a visible summary of specific moderation criteria (e.g., prohibited content types, language standards) directly on this policies page or in clearly accessible linked content.
  • enforcement: No information about how moderation is enforced, who reviews content, or what actions are taken is provided on the page.
    Fix: Add an enforcement section describing review timelines, removal processes, appeal options, and consequences for policy violations.

Interoperability

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making for personalization, rewards, or reviews.
    Fix: Publish the specific data inputs and criteria (e.g., purchase history, location, engagement) used in any algorithmic decisions affecting users.
  • weighting: No information is provided on how criteria are weighted or prioritized in any algorithmic process.
    Fix: Document the relative weighting or prioritization of criteria used in algorithmic decisions so users understand which factors matter most.
  • auditable: The page provides no technical or procedural detail that would enable an external audit or review of algorithmic processes.
    Fix: Provide an algorithmic transparency report or audit-ready documentation detailing models, data sources, and decision logic accessible to reviewers.