National Gallery
https://www.nationalgallery.org.uk · 45/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (10 failed) |
| Level 2 — Enhanced | 8/27 (19 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page content shows no mention of an AI use policy or statement anywhere in the About/FAQ content or footer links.
Fix: Publish a dedicated AI use policy page and link to it from the footer under User information.
-
scope_clear: Since no AI policy is present, there is no explanation of what AI is used for on the site.
Fix: Include a clear scope section in the AI policy describing specific uses such as search, recommendations, or content generation.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: .vimeo.com.
- 1 inline script matched a tracker/ad pattern; first match: ' window.dataLayer = window.dataLayer || []; function gtag() { da…'.
- 2 hidden iframes found: https://player.vimeo.com/video/1163953602?loop=1&background=1&app_id=122963, https://consentcdn.cookiebot.com/sdk/bc-v4.min.html.
- Detected 11 data-leaking services across 3 categories: cookie consent saas (consent.cookiebot.com, consentcdn.cookiebot.com); google fonts (fonts.googleapis.com, fonts.gstatic.com); vimeo embed (arclight.vimeo.com, f.vimeocdn.com, i.vimeocdn.com, lensflare.vimeo.com, player.vimeo.com, skyfire.vimeocdn.com, vimeo.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.nationalgallery.org.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
about_exists: Although the URL is /about and the footer lists 'About us', the visible content is an FAQ/contact page rather than an actual about page.
Fix: Populate the /about page with genuine 'About us' content describing the organisation instead of FAQ links.
-
purpose_clear: The page does not state what the National Gallery does or its purpose as an organisation.
Fix: Add a clear introductory statement explaining that the National Gallery is a public art museum and what it does.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only generic subject categories (e.g., Access, Press, Membership) without naming any individual or specific role responsible for enquiries.
Fix: Add the name or job title of the person or team head responsible for each enquiry category (e.g., 'Head of Visitor Services').
-
response_timeframe: The contact page provides a form and email address but does not publish any response timeframe for inquiries.
Fix: Add a statement on the contact page indicating how quickly users can expect a response (e.g., 'We aim to respond within 5 business days').
-
specific: Since no timeframe is published at all, there is no specific duration stated.
Fix: Specify a concrete timeframe in days (e.g., 'within 5 working days') rather than vague language.
-
process_exists: The page offers a generic contact form with subject categories but no documented complaints or feedback process.
Fix: Publish a dedicated complaints/feedback procedure page linked from Contact us, outlining how complaints are received, handled, and escalated.
-
steps_clear: No complaints steps are described—only a subject dropdown and message field are shown.
Fix: Provide numbered steps explaining how to submit a complaint, what information to include, who reviews it, and how escalation works.
-
appeals_exists: The contact page only offers a generic enquiry form with no documented appeals process for decisions or complaints.
Fix: Publish a clear appeals/complaints procedure describing how users can formally challenge decisions, including required information and expected timelines.
-
independent: No escalation path or independent review body is mentioned on the contact page.
Fix: Document an escalation route to an independent reviewer or external ombudsman if the initial response is unsatisfactory.
AI & Automation
-
detailed_scope: No AI policy exists on the page, so detailed scope of AI use is not provided.
Fix: Add a detailed scope section enumerating each AI system, its purpose, and where it is deployed across the Gallery's digital services.
-
limitations: There is no acknowledgement of AI limitations because no AI policy content appears on the page.
Fix: Include a limitations section noting potential inaccuracies, biases, and boundaries of AI-generated outputs.
-
safeguards: No safeguards or quality controls for AI are described since the page contains no AI-related content.
Fix: Describe safeguards such as human review, testing, and escalation paths in a published AI governance statement.
-
marking_policy: The page contains no policy or statement regarding how AI-assisted content is marked or labelled.
Fix: Publish a clear policy describing how AI-assisted content is identified and labelled on the site.
-
consistent: Without a marking policy, there is no evidence of consistent application of AI content labelling on this page.
Fix: Implement and consistently apply visible AI-content labels across all relevant pages once a marking policy is in place.
-
oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
Fix: Add a statement documenting that AI outputs undergo human oversight, with details on scope.
-
review_process: No review or approval process for AI-generated content is described anywhere on this page.
Fix: Describe the review and approval workflow for AI-generated content in a published governance or editorial policy.
-
accountability: No individual, role, or team is named as accountable for AI-generated content.
Fix: Identify a named role or team (e.g., Digital Editor) publicly accountable for AI-generated content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible content of the notice does not explicitly state that data collection is limited to what is necessary.
Fix: Add an explicit statement that the Gallery only collects personal data that is necessary for the stated purposes (data minimisation principle).
-
proportionate: There is no visible statement that the data collected is proportionate to the services provided.
Fix: Include a clear proportionality statement explaining that data collected is limited and proportionate to each specific purpose such as memberships, visits, or mailings.
-
retention_stated: The page lists a 'How long do we keep your information?' section heading but the visible content does not provide retention details.
Fix: Publish the retention content inline or ensure the linked section clearly states how long each category of personal data is kept.
-
specific: No specific retention periods (e.g., number of months or years) are visible on this page.
Fix: State specific retention periods per data category (e.g., 'subscriber emails retained for 24 months after last interaction') rather than vague references.
-
equal_choices: The page shows no visible cookie/consent banner with accept and reject options, so equal prominence cannot be verified; only a 'Change cookie settings' footer link is shown.
Fix: Display a consent banner with 'Accept' and 'Reject' buttons rendered with equal visual weight (same size, color, and placement).
Provenance
-
authorship_clear: The page does not identify who creates or curates the content beyond a generic 'The National Gallery' copyright notice.
Fix: Add a section identifying the editorial or curatorial team responsible for the site's content.
-
credentials: No credentials, organisational background, or history of the National Gallery are provided on this page.
Fix: Include a brief organisational background section describing the Gallery's history, governance, and expertise.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified; the page only offers a generic subject dropdown and a shared 'hello@' inbox.
Fix: Identify the responsible team (e.g., 'Visitor Experience Team') or named contact for each enquiry subject on the contact page.
-
role_clear: While subject categories exist, there is no description of who handles each category or their authority/role within the organisation.
Fix: Add a short description under each subject option explaining which department handles it and what their remit covers.
-
substantive: There is no statement of purpose on the page at all, substantive or otherwise.
Fix: Write a detailed statement of purpose describing the Gallery's role, collection, and public mission.
-
mission_clear: No mission statement or editorial approach is articulated anywhere on the visible page.
Fix: Include a clearly articulated mission statement explaining the Gallery's values and approach to its collection and audiences.
-
detail: The page gives only a broad '50% self-generated' figure and general categories without specific amounts, percentages per source, or detailed breakdowns.
Fix: Publish a detailed funding breakdown (e.g., percentages or amounts attributable to government grant-in-aid, memberships, corporate partners, trusts, and individual donors) or link to the annual report from this page.
-
complete: The disclosure omits major funding streams such as government grant-in-aid, trading/commercial income, and investment income, focusing only on philanthropic support.
Fix: Expand the disclosure to cover all major revenue streams including public funding, commercial/trading income, and investment returns, ideally with links to audited financial statements.
-
governance_exists: The page contains FAQ categories and contact details but does not describe any governance or editorial structure of the National Gallery.
Fix: Add a dedicated section (or link to one) describing the Gallery's governance structure, such as its Board of Trustees, executive leadership, and editorial oversight.
-
roles_clear: No specific roles or responsibilities (e.g., Director, Trustees, editorial leads) are identified anywhere on the page.
Fix: List key roles such as Director, Trustees, and departmental heads along with their responsibilities, or link to an 'Organisation' page that details them.
-
algorithm_explained: The page contains no mention of algorithms or their purpose, only general contact and FAQ information.
Fix: Add a dedicated section describing any algorithms used on the site (e.g., search ranking or recommendations) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include a clear statement explaining how any algorithmic decisions influence user experience, such as search results or content suggestions.
-
annual_statement: The page links to a privacy notice but shows no evidence of a regular or periodic review of data practices.
Fix: Add a visible note in the privacy notice indicating when it was last reviewed and that it is reviewed on an annual or periodic basis.
-
dated: The privacy notice link shown in the footer has no visible date or version indicator on this page.
Fix: Display a 'Last updated' date or version number alongside the privacy notice link or within the notice itself.
Level 3 — Advanced
Accessibility
-
known_issues: The statement describes accessibility features but never acknowledges any known accessibility issues, limitations, or non-conforming content.
Fix: Add a section listing known accessibility issues or areas of non-compliance (e.g., against WCAG 2.1 AA) so users know what to expect.
-
remediation_timeline: There is no timeline or dated commitment for addressing accessibility problems, only a vague promise to act 'as soon as we can.'
Fix: Include target dates or a stated timeframe for resolving known issues along with a review/update date for the statement.
-
feedback_channel: A feedback email and feedback page are provided, but the page explicitly states 'We cannot reply to all emails,' offering no clear response commitment.
Fix: State a specific response commitment, such as acknowledging feedback within a defined number of working days.
Accountability
-
policy_exists: The terms page lists sections like 'Your use of the Website' and 'Notice and takedown' but does not publish a visible moderation policy for user-contributed content.
Fix: Publish a clear moderation policy section on the terms page (or a dedicated page) outlining rules for user-generated content and community interactions.
-
criteria_clear: No moderation criteria (e.g., what content is prohibited or subject to removal) are stated in the visible content of this page.
Fix: Add explicit moderation criteria listing prohibited content types (e.g., hate speech, spam, infringement) and the standards used to evaluate submissions.
-
enforcement: The page references a 'Notice and takedown' heading but provides no explanation of how moderation decisions are enforced, appealed, or communicated.
Fix: Document the enforcement workflow, including who reviews content, timelines, user notification, and an appeals process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains only FAQ links, contact details, and standard footer navigation with no published incident response plan or policy.
Fix: Publish a dedicated incident response plan or security policy and link to it from the site (e.g., in the footer's user information section).
-
notification_commitment: There is no statement anywhere on the page committing to public notification of significant security or data incidents.
Fix: Add an explicit commitment to notify the public and affected users in the event of a significant security incident within the security or privacy documentation.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published on the page.
Fix: Publish the specific criteria used by any algorithms (e.g., search or recommendation factors) in a transparency or policy page.
-
weighting: The page does not explain any weighting or prioritisation of algorithmic criteria.
Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions.
-
auditable: The page provides no technical detail that would support external audit or review of algorithms.
Fix: Provide sufficient methodological detail, documentation, or an audit contact to allow independent review of algorithmic systems.
-
open_source: There is no link to source code or any indication that the site's code is publicly available.
Fix: Link to a public repository (e.g., GitHub) for any open-source components of the website.
-
tech_docs: No technical documentation is published or linked from this page.
Fix: Provide or link to technical documentation such as API docs or a developer page for the Gallery's digital services.
Responsibility to the Future
-
disclosure_exists: The page contains only contact/FAQ and footer navigation content with no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact page and link to it from the footer or About section.
-
specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
Fix: Include quantified metrics like annual carbon footprint (tCO2e) and energy consumption in a published disclosure.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
Fix: Disclose the hosting provider's energy sources or the website's per-page carbon footprint, ideally referencing green hosting certification.
-
plan_exists: The page contains only contact information, FAQs, and standard footer links, with no published plan describing what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan describing what happens to the Gallery's digital assets and services in the event of organisational failure or exit.
-
data_and_content_fate: There is no mention of what would happen to user data or published content should the organisation cease operating.
Fix: Add a section specifying how user data and published content (such as the collection and picture library) would be preserved, transferred, or archived in a wind-down scenario.
-
custodians_or_mirrors: The page names no custodians, mirrors, or archive partners responsible for preserving content or data if the organisation exits.
Fix: Identify named custodians, mirror sites, or archive partners (e.g., a national archive or trust) that would take stewardship of the content and data.
-
policy_exists: The page only shows a collection search interface and footer links (e.g., 'Work with us', 'Jobs', 'Modern Slavery Statement') with no published worker wellbeing or working conditions policy visible.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the footer's 'Work with us' or 'About us' section.
-
specific_commitments: No content on the page mentions specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the wellbeing policy.
-
accountability: The page identifies no individual, team, or governance body responsible for overseeing worker conditions.
Fix: Name a responsible role or oversight body (e.g., HR director or board committee) accountable for worker conditions within the published policy.