National Library of Scotland
https://www.nls.uk · 57/92 checks passed · libraries
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 34/37 (3 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 0/2 |
| Security | 8/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish an AI use policy or statement on the About page (or link to one) describing the organisation's position on AI.
-
scope_clear: No AI usage is described anywhere on the page, so scope is not explained.
Fix: Add a clear description of what AI tools or systems the Library uses and for which purposes (e.g., cataloguing, transcription, search).
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.nls.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page refers only to generic 'our team' and departmental phone lines without naming any individual or specific role responsible for enquiries.
Fix: Identify a named person or specific role (e.g., Head of Enquiry Services) as the accountable contact on the page.
-
response_timeframe: The page only states enquiries will be responded to 'as quickly as we can' and 'shortly' without publishing an actual timeframe.
Fix: Publish a specific response timeframe (e.g. 'we respond within 5 working days') directly on the contact page.
-
specific: Language such as 'shortly' and 'as quickly as we can' is vague and contains no concrete number of days or hours.
Fix: Replace vague terms with specific time commitments such as 'within 10 working days' for enquiries and complaints.
-
steps_clear: The contact page itself does not outline the steps of the complaints process; it only links out to a separate procedure without summarising what to expect.
Fix: Summarise the key steps of the complaints process (how to submit, acknowledgement, investigation, response, escalation) directly on the contact page alongside the link.
-
independent: The page does not indicate any independent review or escalation path (e.g., to an ombudsman or external body) for unresolved complaints.
Fix: Add information on the contact page about escalating unresolved complaints to an independent body such as the Scottish Public Services Ombudsman.
AI & Automation
-
detailed_scope: There is no AI policy on the page, so no detailed scope is provided.
Fix: Include a detailed scope section in the AI policy listing specific systems, use cases, and data involved.
-
limitations: The page does not acknowledge any AI limitations since no AI policy is present.
Fix: Add a section acknowledging known limitations of AI (e.g., accuracy, bias, hallucination) within a published AI policy.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human review, bias testing, and data governance controls in a published AI policy.
-
marking_policy: The About page contains no policy or statement regarding the marking of AI-assisted content.
Fix: Publish a clear policy under Plans and policies that describes how AI-assisted content is labelled on the site.
-
consistent: No AI content markings are visible on the page, so consistency of application cannot be demonstrated.
Fix: Introduce a standard visual label or disclosure for AI-assisted content and apply it consistently across all pages.
-
oversight_exists: The page does not mention any human oversight of AI outputs.
Fix: Add a statement to the About or policies section describing how humans oversee any AI-generated outputs used by the Library.
-
review_process: No review or approval workflow for AI content is described anywhere on this page.
Fix: Document the editorial review and approval steps for AI-assisted content within a published AI governance policy.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name a responsible role (e.g., a Head of Digital or AI governance lead) accountable for AI outputs in the published policy.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible overview page does not explicitly state that data collection is limited to what is necessary.
Fix: Add a statement on the privacy overview page affirming that data collection is limited to what is strictly necessary for the stated purpose.
-
proportionate: There is no explicit statement on this overview page that data collected is proportionate to the service provided.
Fix: Include a clear proportionality statement on the overview page indicating that data collected is proportionate to the activity/service.
-
retention_stated: The overview page does not mention data retention periods at all.
Fix: Add a retention section (or link to one) on the privacy overview summarising how long each category of personal data is kept.
-
specific: Since retention is not addressed, no specific time periods are provided on this page.
Fix: State concrete retention periods (e.g. 'CCTV footage retained for 30 days', 'enquiry records kept for 2 years') rather than vague language.
-
equal_choices: The page content shown contains no visible consent interface with accept/reject options, so equal prominence cannot be confirmed (only a 'Cookies' footer link is present).
Fix: Provide a consent banner with 'Accept' and 'Reject' buttons rendered with equal visual weight (same size, color, and placement) on first visit.
-
banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' footer link is present.
Fix: Implement a visible cookie consent banner that appears on first visit to inform users and capture their preferences.
-
partner_sharing_mentioned: No on-page consent copy or banner discloses any data sharing with third-party partners.
Fix: Add clear language in the cookie banner disclosing whether data is shared with third-party partners and link to the full cookie policy.
-
partner_count_specific: Because partner sharing is not disclosed at all, no specific numeric count of partners is stated.
Fix: If third-party partners are used, state the exact number of partners (e.g., 'We share data with X partners') in the consent banner.
Provenance
- No author or date metadata found on the page.
-
credentials: While the organisation is named, no detail is given on its credentials, governance, or background on this page itself.
Fix: Add a brief summary of the Library's statutory role, governance, and history (or link directly to such a page) from the About us landing.
Security
Transparency
-
named_person: No named individual or specific team (beyond a vague 'our team') is identified as responsible for handling enquiries.
Fix: Name the responsible team (e.g., 'Enquiries Team' or 'Reader Services') and, ideally, a lead contact person for enquiries.
-
role_clear: The page does not state the role or authority of whoever responds to enquiries, complaints, or feedback.
Fix: Add a brief description of the responsible team's role and authority, such as who handles enquiries, complaints, and media requests.
-
substantive: The description is a short tagline-like sentence with navigational links rather than a substantive explanation of the Library's work.
Fix: Expand the About us page with detailed content describing the Library's activities, collections, and impact directly on the page rather than only linking out.
-
mission_clear: The page references a strategy and mission but does not articulate the mission or editorial approach on the page itself.
Fix: Include the Library's mission and vision statements directly on the About us page instead of requiring users to click through to the strategy page.
-
detail: The page describes funding categories (donations, patrons, legacies, organisations) but provides no amounts, percentages, or breakdown of how funds are used.
Fix: Add figures or percentages showing how much is raised from each stream and how funds are allocated (e.g., digitisation, exhibitions, preservation).
-
complete: The page omits major funding streams typical for a national library such as Scottish Government grant-in-aid, trusts, and commercial income, focusing only on philanthropic giving.
Fix: Include or link to a complete funding overview covering government grant-in-aid, trusts and foundations, commercial/trading income, and philanthropy.
-
governance_exists: The About page mentions 'Plans and policies' and 'Who we are and what we do' as links but does not describe the governance or editorial structure on this page.
Fix: Add a dedicated governance section on the About page summarising the board/trustees and editorial oversight, with links to detailed governance documents.
-
roles_clear: No key roles or responsibilities (e.g., trustees, executive leadership, editorial leads) are identified in the visible page content.
Fix: List key leadership roles and their responsibilities (e.g., Chair, National Librarian, Board members) directly on the About page or link prominently to a leadership/team page.
-
algorithm_explained: The About page makes no mention of any algorithms or automated decision-making systems used by the Library.
Fix: Add a section disclosing any algorithms used (e.g., in search, recommendations, or collection curation) and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users of the Library's services.
Fix: Include a clear statement describing the impact of any algorithmic decisions on users, such as search ranking or access decisions.
-
annual_statement: The page links to a Privacy page but shows no evidence of an annual or periodic review of data practices.
Fix: Publish a note on the Privacy page indicating when data practices were last reviewed and commit to a regular review cadence.
-
dated: There is no visible date or version on the privacy/data practices reference from this page.
Fix: Add a 'Last updated' date or version number to the Privacy statement linked from the footer.
Level 3 — Advanced
Accessibility
-
known_issues: The provided page content is the About page and shows no acknowledgment of any known accessibility issues or limitations.
Fix: Ensure the linked accessibility statement page explicitly lists known non-compliant elements or accessibility limitations of the site.
-
remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on the provided page.
Fix: Add a stated timeline or target dates in the accessibility statement for remediating identified accessibility issues.
-
feedback_channel: The page offers a 'Contact us' link but no feedback mechanism specific to accessibility with a stated response commitment.
Fix: Provide a dedicated accessibility feedback contact in the statement along with a commitment to respond within a defined timeframe.
Accountability
-
policy_exists: The About page does not publish or link to any moderation policies for user-generated content.
Fix: Publish a dedicated moderation policy page and link to it from the About or Plans and policies section.
-
criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use) are stated on the page.
Fix: Add a clearly written list of moderation criteria detailing what content is allowed or removed.
-
enforcement: The page does not describe any enforcement process, appeals, or moderator responsibilities.
Fix: Document the enforcement workflow, including how violations are handled, who reviews them, and how users can appeal.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page only lists general policies and Freedom of Information links but shows no published incident response plan or policy.
Fix: Publish a dedicated incident response plan or policy and link to it from the plans and policies section.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add a clear commitment to notify the public and affected users when a significant incident occurs.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering a significant incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published on this page.
Fix: Publish the specific criteria used in any algorithmic decision-making processes on a dedicated transparency page.
-
weighting: The page does not explain the weighting or prioritisation of any decision criteria.
Fix: Document the relative weighting or priority assigned to each criterion used by algorithms on the site.
-
auditable: The page provides no technical or procedural detail that would support external audit of algorithmic systems.
Fix: Provide auditable documentation such as model cards, data sources, and review processes to enable external scrutiny.
-
open_source: No link to source code or a public code repository is present on the page.
Fix: Add a link to any public code repositories (e.g., GitHub) or a statement about open-source projects maintained by the Library.
-
tech_docs: No technical documentation or developer resources are referenced on the page.
Fix: Provide a link to technical documentation, APIs, or open data resources from the About us page.
Responsibility to the Future
-
disclosure_exists: The About page lists plans, policies, and annual reviews but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link it prominently from the About and Plans and policies sections.
-
specific_metrics: The page provides no specific figures on carbon emissions, energy use, or other environmental metrics.
Fix: Include measurable environmental data such as annual carbon footprint, energy consumption, and emissions figures in a sustainability report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the hosting provider's energy sourcing or carbon profile, e.g. whether servers run on renewable energy, in the site's environmental or technical documentation.
-
plan_exists: The page lists organisational policies and annual reviews generically but shows no published plan for what happens if the Library fails or exits its operations.
Fix: Publish a succession or continuity plan under 'Plans and policies' describing what would happen to the organisation and its collections in the event of closure or transfer.
-
data_and_content_fate: The page references digital resources and collections but does not address what would happen to user data or published content should the organisation cease to exist.
Fix: Add explicit statements about the fate of user data and published/digitised content, including retention, transfer, or deletion arrangements in a wind-down scenario.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving collections if the Library exits.
Fix: Name designated custodians, archive partners, or mirror institutions that would take over stewardship of the collections and digital assets.
-
policy_exists: The page mentions 'Plans and policies' and 'organisational policies' but contains no specific published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it clearly from the About or Jobs sections.
-
specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments on fair pay, working hours, mental health support, and benefits within a wellbeing policy accessible from this page.
-
accountability: The page does not identify any person, team, or governance body responsible for overseeing worker conditions.
Fix: Name a responsible role or committee (e.g., HR director or a wellbeing oversight board) accountable for monitoring and improving worker conditions.