National Gallery

https://www.nationalgallery.org.uk · 45/92 checks passed · archives

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 27/37 (10 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 1/2
Security 5/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page content shows no mention of an AI use policy or statement anywhere in the About/FAQ content or footer links.
    Fix: Publish a dedicated AI use policy page and link to it from the footer under User information.
  • scope_clear: Since no AI policy is present, there is no explanation of what AI is used for on the site.
    Fix: Include a clear scope section in the AI policy describing specific uses such as search, recommendations, or content generation.

Privacy

Security

Transparency

  • about_exists: Although the URL is /about and the footer lists 'About us', the visible content is an FAQ/contact page rather than an actual about page.
    Fix: Populate the /about page with genuine 'About us' content describing the organisation instead of FAQ links.
  • purpose_clear: The page does not state what the National Gallery does or its purpose as an organisation.
    Fix: Add a clear introductory statement explaining that the National Gallery is a public art museum and what it does.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic subject categories (e.g., Access, Press, Membership) without naming any individual or specific role responsible for enquiries.
    Fix: Add the name or job title of the person or team head responsible for each enquiry category (e.g., 'Head of Visitor Services').
  • response_timeframe: The contact page provides a form and email address but does not publish any response timeframe for inquiries.
    Fix: Add a statement on the contact page indicating how quickly users can expect a response (e.g., 'We aim to respond within 5 business days').
  • specific: Since no timeframe is published at all, there is no specific duration stated.
    Fix: Specify a concrete timeframe in days (e.g., 'within 5 working days') rather than vague language.
  • process_exists: The page offers a generic contact form with subject categories but no documented complaints or feedback process.
    Fix: Publish a dedicated complaints/feedback procedure page linked from Contact us, outlining how complaints are received, handled, and escalated.
  • steps_clear: No complaints steps are described—only a subject dropdown and message field are shown.
    Fix: Provide numbered steps explaining how to submit a complaint, what information to include, who reviews it, and how escalation works.
  • appeals_exists: The contact page only offers a generic enquiry form with no documented appeals process for decisions or complaints.
    Fix: Publish a clear appeals/complaints procedure describing how users can formally challenge decisions, including required information and expected timelines.
  • independent: No escalation path or independent review body is mentioned on the contact page.
    Fix: Document an escalation route to an independent reviewer or external ombudsman if the initial response is unsatisfactory.

AI & Automation

  • detailed_scope: No AI policy exists on the page, so detailed scope of AI use is not provided.
    Fix: Add a detailed scope section enumerating each AI system, its purpose, and where it is deployed across the Gallery's digital services.
  • limitations: There is no acknowledgement of AI limitations because no AI policy content appears on the page.
    Fix: Include a limitations section noting potential inaccuracies, biases, and boundaries of AI-generated outputs.
  • safeguards: No safeguards or quality controls for AI are described since the page contains no AI-related content.
    Fix: Describe safeguards such as human review, testing, and escalation paths in a published AI governance statement.
  • marking_policy: The page contains no policy or statement regarding how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy describing how AI-assisted content is identified and labelled on the site.
  • consistent: Without a marking policy, there is no evidence of consistent application of AI content labelling on this page.
    Fix: Implement and consistently apply visible AI-content labels across all relevant pages once a marking policy is in place.
  • oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
    Fix: Add a statement documenting that AI outputs undergo human oversight, with details on scope.
  • review_process: No review or approval process for AI-generated content is described anywhere on this page.
    Fix: Describe the review and approval workflow for AI-generated content in a published governance or editorial policy.
  • accountability: No individual, role, or team is named as accountable for AI-generated content.
    Fix: Identify a named role or team (e.g., Digital Editor) publicly accountable for AI-generated content.

Interoperability

Privacy

  • necessity: The visible content of the notice does not explicitly state that data collection is limited to what is necessary.
    Fix: Add an explicit statement that the Gallery only collects personal data that is necessary for the stated purposes (data minimisation principle).
  • proportionate: There is no visible statement that the data collected is proportionate to the services provided.
    Fix: Include a clear proportionality statement explaining that data collected is limited and proportionate to each specific purpose such as memberships, visits, or mailings.
  • retention_stated: The page lists a 'How long do we keep your information?' section heading but the visible content does not provide retention details.
    Fix: Publish the retention content inline or ensure the linked section clearly states how long each category of personal data is kept.
  • specific: No specific retention periods (e.g., number of months or years) are visible on this page.
    Fix: State specific retention periods per data category (e.g., 'subscriber emails retained for 24 months after last interaction') rather than vague references.
  • equal_choices: The page shows no visible cookie/consent banner with accept and reject options, so equal prominence cannot be verified; only a 'Change cookie settings' footer link is shown.
    Fix: Display a consent banner with 'Accept' and 'Reject' buttons rendered with equal visual weight (same size, color, and placement).

Provenance

  • authorship_clear: The page does not identify who creates or curates the content beyond a generic 'The National Gallery' copyright notice.
    Fix: Add a section identifying the editorial or curatorial team responsible for the site's content.
  • credentials: No credentials, organisational background, or history of the National Gallery are provided on this page.
    Fix: Include a brief organisational background section describing the Gallery's history, governance, and expertise.

Security

Transparency

  • named_person: No named individual or specific team is identified; the page only offers a generic subject dropdown and a shared 'hello@' inbox.
    Fix: Identify the responsible team (e.g., 'Visitor Experience Team') or named contact for each enquiry subject on the contact page.
  • role_clear: While subject categories exist, there is no description of who handles each category or their authority/role within the organisation.
    Fix: Add a short description under each subject option explaining which department handles it and what their remit covers.
  • substantive: There is no statement of purpose on the page at all, substantive or otherwise.
    Fix: Write a detailed statement of purpose describing the Gallery's role, collection, and public mission.
  • mission_clear: No mission statement or editorial approach is articulated anywhere on the visible page.
    Fix: Include a clearly articulated mission statement explaining the Gallery's values and approach to its collection and audiences.
  • detail: The page gives only a broad '50% self-generated' figure and general categories without specific amounts, percentages per source, or detailed breakdowns.
    Fix: Publish a detailed funding breakdown (e.g., percentages or amounts attributable to government grant-in-aid, memberships, corporate partners, trusts, and individual donors) or link to the annual report from this page.
  • complete: The disclosure omits major funding streams such as government grant-in-aid, trading/commercial income, and investment income, focusing only on philanthropic support.
    Fix: Expand the disclosure to cover all major revenue streams including public funding, commercial/trading income, and investment returns, ideally with links to audited financial statements.
  • governance_exists: The page contains FAQ categories and contact details but does not describe any governance or editorial structure of the National Gallery.
    Fix: Add a dedicated section (or link to one) describing the Gallery's governance structure, such as its Board of Trustees, executive leadership, and editorial oversight.
  • roles_clear: No specific roles or responsibilities (e.g., Director, Trustees, editorial leads) are identified anywhere on the page.
    Fix: List key roles such as Director, Trustees, and departmental heads along with their responsibilities, or link to an 'Organisation' page that details them.
  • algorithm_explained: The page contains no mention of algorithms or their purpose, only general contact and FAQ information.
    Fix: Add a dedicated section describing any algorithms used on the site (e.g., search ranking or recommendations) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include a clear statement explaining how any algorithmic decisions influence user experience, such as search results or content suggestions.
  • annual_statement: The page links to a privacy notice but shows no evidence of a regular or periodic review of data practices.
    Fix: Add a visible note in the privacy notice indicating when it was last reviewed and that it is reviewed on an annual or periodic basis.
  • dated: The privacy notice link shown in the footer has no visible date or version indicator on this page.
    Fix: Display a 'Last updated' date or version number alongside the privacy notice link or within the notice itself.

Level 3 — Advanced

Accessibility

  • known_issues: The statement describes accessibility features but never acknowledges any known accessibility issues, limitations, or non-conforming content.
    Fix: Add a section listing known accessibility issues or areas of non-compliance (e.g., against WCAG 2.1 AA) so users know what to expect.
  • remediation_timeline: There is no timeline or dated commitment for addressing accessibility problems, only a vague promise to act 'as soon as we can.'
    Fix: Include target dates or a stated timeframe for resolving known issues along with a review/update date for the statement.
  • feedback_channel: A feedback email and feedback page are provided, but the page explicitly states 'We cannot reply to all emails,' offering no clear response commitment.
    Fix: State a specific response commitment, such as acknowledging feedback within a defined number of working days.

Accountability

  • policy_exists: The terms page lists sections like 'Your use of the Website' and 'Notice and takedown' but does not publish a visible moderation policy for user-contributed content.
    Fix: Publish a clear moderation policy section on the terms page (or a dedicated page) outlining rules for user-generated content and community interactions.
  • criteria_clear: No moderation criteria (e.g., what content is prohibited or subject to removal) are stated in the visible content of this page.
    Fix: Add explicit moderation criteria listing prohibited content types (e.g., hate speech, spam, infringement) and the standards used to evaluate submissions.
  • enforcement: The page references a 'Notice and takedown' heading but provides no explanation of how moderation decisions are enforced, appealed, or communicated.
    Fix: Document the enforcement workflow, including who reviews content, timelines, user notification, and an appeals process.

Interoperability

Security

  • plan_exists: The page contains only FAQ links, contact details, and standard footer navigation with no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the site (e.g., in the footer's user information section).
  • notification_commitment: There is no statement anywhere on the page committing to public notification of significant security or data incidents.
    Fix: Add an explicit commitment to notify the public and affected users in the event of a significant security incident within the security or privacy documentation.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published on the page.
    Fix: Publish the specific criteria used by any algorithms (e.g., search or recommendation factors) in a transparency or policy page.
  • weighting: The page does not explain any weighting or prioritisation of algorithmic criteria.
    Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions.
  • auditable: The page provides no technical detail that would support external audit or review of algorithms.
    Fix: Provide sufficient methodological detail, documentation, or an audit contact to allow independent review of algorithmic systems.
  • open_source: There is no link to source code or any indication that the site's code is publicly available.
    Fix: Link to a public repository (e.g., GitHub) for any open-source components of the website.
  • tech_docs: No technical documentation is published or linked from this page.
    Fix: Provide or link to technical documentation such as API docs or a developer page for the Gallery's digital services.

Responsibility to the Future

  • disclosure_exists: The page contains only contact/FAQ and footer navigation content with no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact page and link to it from the footer or About section.
  • specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
    Fix: Include quantified metrics like annual carbon footprint (tCO2e) and energy consumption in a published disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the hosting provider's energy sources or the website's per-page carbon footprint, ideally referencing green hosting certification.
  • plan_exists: The page contains only contact information, FAQs, and standard footer links, with no published plan describing what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing what happens to the Gallery's digital assets and services in the event of organisational failure or exit.
  • data_and_content_fate: There is no mention of what would happen to user data or published content should the organisation cease operating.
    Fix: Add a section specifying how user data and published content (such as the collection and picture library) would be preserved, transferred, or archived in a wind-down scenario.
  • custodians_or_mirrors: The page names no custodians, mirrors, or archive partners responsible for preserving content or data if the organisation exits.
    Fix: Identify named custodians, mirror sites, or archive partners (e.g., a national archive or trust) that would take stewardship of the content and data.
  • policy_exists: The page only shows a collection search interface and footer links (e.g., 'Work with us', 'Jobs', 'Modern Slavery Statement') with no published worker wellbeing or working conditions policy visible.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the footer's 'Work with us' or 'About us' section.
  • specific_commitments: No content on the page mentions specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the wellbeing policy.
  • accountability: The page identifies no individual, team, or governance body responsible for overseeing worker conditions.
    Fix: Name a responsible role or oversight body (e.g., HR director or board committee) accountable for worker conditions within the published policy.