National Library of Wales
https://www.library.wales · 49/92 checks passed · libraries
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (10 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 2/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- Focus trap detected with 20 focusable elements.
- Heading hierarchy issues: h1 -> h3 (skipped h2).
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish a clear AI use policy or statement on the site and link to it from the About or Governance sections.
-
scope_clear: Because no AI policy is present, there is no explanation of what AI is used for.
Fix: Include a section in the AI policy that explicitly describes the purposes and contexts in which AI is used at the Library.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: cookies.library.wales.
- 3 inline scripts matched a tracker/ad pattern; first match: ' // pre-google code per civic example at: https://www.civicuk.com/co…'.
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.library.wales
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
steps_clear: The page only mentions emailing complaints(at)library.wales and links to a policy, without listing the actual steps on the contact page itself.
Fix: Summarise the key steps of the complaints procedure (e.g., how to submit, what information to include, expected timeline, escalation options) directly on the contact page alongside the policy link.
-
independent: The page does not indicate any independent review or escalation route (e.g., to an ombudsman or external body) beyond emailing the Library's own complaints address.
Fix: Add information on the contact page about escalating unresolved complaints to an independent body such as the Public Services Ombudsman for Wales, including contact details.
AI & Automation
-
detailed_scope: The page provides no detailed scope of AI use, as no AI policy is referenced anywhere.
Fix: Add a detailed scope section to an AI policy describing specific systems, use cases, and data involved.
-
limitations: No limitations of AI systems are acknowledged on the page.
Fix: Publish an AI policy that transparently acknowledges known limitations such as bias, accuracy, and content coverage gaps.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human oversight, review procedures, and quality assurance measures in a published AI policy.
-
marking_policy: The About page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy stating how AI-assisted content is labelled and link to it from the About or governance section.
-
consistent: Without any marking policy visible on the page, consistent application cannot be demonstrated.
Fix: Adopt a uniform AI-content label (e.g., an 'AI-assisted' tag) and apply it across all relevant pages and publications.
-
oversight_exists: The page makes no mention of human oversight of AI outputs within the Library's governance or operations.
Fix: Add a section under Governance documenting that AI outputs are subject to human oversight and describing the scope of that oversight.
-
review_process: No review or approval process for AI-generated content is described anywhere on the page.
Fix: Publish a short description of the review/approval workflow AI-generated content must pass through before publication.
-
accountability: No individual, role, or committee is identified as accountable for AI-generated content.
Fix: Name a responsible role (e.g., a named officer or the Board of Trustees committee) accountable for AI-generated content and publish their contact point.
Interoperability
Privacy
-
comprehensive: The page focuses almost exclusively on cookies and does not comprehensively cover other personal data collected (e.g., newsletter sign-ups, reader's ticket, enquiries) or the legal basis and rights of users.
Fix: Expand the policy to describe all categories of personal data collected across library services, the purposes, legal basis, sharing, user rights, and contact details for the data controller/DPO.
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
Fix: Add a statement affirming that data collection is limited to what is strictly necessary to deliver the service, in line with data minimisation principles.
-
proportionate: The use of Microsoft Clarity session replay, heatmaps, and advertising cookies for a national library site is not clearly justified as proportionate to the service provided.
Fix: Justify each tracking technology's proportionality or remove non-essential tracking (particularly advertising/session-replay) and rely on privacy-preserving analytics.
-
retention_stated: The policy does not state how long cookies or any collected data are retained.
Fix: Add a retention section specifying how long each cookie and data category is kept before deletion.
-
specific: No specific retention periods (days, months, years) are provided anywhere on the page.
Fix: Publish concrete retention durations (e.g., '_ga: 2 years; PHPSESSID: session only') for each data type listed.
-
no_dark_patterns: The page describes cookie usage but provides no visible consent mechanism, so it's impossible to verify the absence of dark patterns; cookies (including Microsoft Clarity tracking) appear to be set without offering the user a clear choice.
Fix: Implement a transparent cookie consent banner with neutral language that clearly informs users before non-essential cookies are set.
-
equal_choices: No accept/reject controls are presented on the privacy page, meaning users are not offered equally prominent choices to consent or decline tracking cookies like Google Analytics and Microsoft Clarity.
Fix: Add a consent banner that presents 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement).
-
no_forced_consent: The page states analytics and Microsoft Clarity cookies are used without indicating any opt-in mechanism, suggesting consent is assumed or forced rather than freely given for non-essential tracking.
Fix: Require explicit opt-in consent before loading non-essential cookies (analytics, Clarity, advertising) and allow users to refuse without loss of core site functionality.
-
partner_sharing_mentioned: The banner only mentions optimising site functionality and does not disclose any data sharing with third-party partners.
Fix: Update the cookie banner copy to explicitly disclose whether cookie data is shared with third-party partners and link to a detailed partner list.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Add a specific number of third-party partners (e.g., 'We share data with X partners') in the cookie banner or preferences dialog.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
role_clear: While the Enquiries Team is named, their specific role, authority, or scope of responsibility beyond answering general questions is not clearly defined.
Fix: Add a brief description of the Enquiries Team's remit, authority, and the types of questions they handle versus escalation paths to other teams.
-
detail: The page mentions funding categories (government sponsorship, donations, bequests) but provides no amounts, percentages, or budget breakdowns.
Fix: Add a summary of annual funding with specific amounts or percentages for each source (e.g., government grant, donations, commercial income) or link to an annual financial report.
-
complete: The disclosure omits key streams such as commercial services revenue (referenced in site navigation) and any grants beyond Welsh Government sponsorship.
Fix: Expand the disclosure to enumerate all major funding streams including commercial services income, grants, and legal deposit-related funding, ideally linking to the full annual accounts.
-
roles_clear: While a Board of Trustees is mentioned, the page does not identify specific roles, responsibilities, or individual members, instead linking out to another page.
Fix: Add a summary on this page listing key roles (e.g., Chair, Trustees, President, CEO/Librarian) and their responsibilities, or embed the Board membership details directly.
-
algorithm_explained: The About page makes no mention of any algorithms used by the Library or their purpose.
Fix: Add a section (or link to one) disclosing any algorithmic or automated decision systems used by NLW and explaining their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions might affect users of the Library's services.
Fix: Publish a clear statement describing how any automated systems affect users (e.g., search ranking, recommendations, access decisions) and what recourse users have.
-
annual_statement: The page links to a privacy statement in the footer but shows no evidence of a regular or annual review of data practices.
Fix: Add a note to the privacy statement indicating the date of the last review and a commitment to periodic (e.g., annual) reviews.
-
dated: There is no visible date or version number associated with the privacy statement linked from this page.
Fix: Include a 'last updated' date or version number on the privacy statement and reference it where linked.
Level 3 — Advanced
Accessibility
-
feedback_channel: The statement invites feedback via the Enquiries Service but provides no commitment on how quickly it will respond.
Fix: Add a stated response commitment (e.g., 'we will respond within 5 working days') alongside the Enquiries Service contact details.
Accountability
-
policy_exists: The About page makes no mention of any published moderation policy for user-generated content or interactions.
Fix: Publish a clearly linked moderation policy page outlining rules for community interactions, comments, and submissions.
-
criteria_clear: No moderation criteria (e.g., what content is allowed or prohibited) are stated anywhere on this page.
Fix: Add explicit criteria describing acceptable and unacceptable content, such as prohibited categories and standards for participation.
-
enforcement: There is no explanation of how moderation decisions are made, appealed, or enforced on the page.
Fix: Document the enforcement process including who reviews content, timelines, actions taken, and an appeals mechanism.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains general information about the Library and its governance but no published incident response plan or security incident policy.
Fix: Publish an incident response plan or policy and link to it from the About or Governance sections of the site.
-
notification_commitment: There is no statement anywhere on the page committing to public notification of significant security or data incidents.
Fix: Add a clear commitment to notify the public and affected users when significant incidents occur.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of confirming a significant incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
Fix: Publish a documented list of the specific criteria/inputs used by any algorithmic systems on a dedicated transparency page.
-
weighting: No weighting or prioritisation of decision criteria is disclosed anywhere on the page.
Fix: Include the relative weightings or priority order of the criteria used so users can understand how decisions are reached.
-
auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS template) with sufficient detail for independent audit.
-
open_source: The about page contains no links to publicly available source code or any open-source repositories for the site or its services.
Fix: Publish any custom website or catalogue code to a public repository (e.g., GitHub) and link to it from the About or Governance section.
-
tech_docs: No technical documentation about the site's platform, APIs, or data services is linked from the about page.
Fix: Add a 'Developers' or 'Technical documentation' section linking to API docs, data schemas, or platform information for the Library's digital services.
Responsibility to the Future
-
disclosure_exists: The About page describes the Library's mission, contact details, governance, and donation information but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About and footer sections.
-
specific_metrics: The page provides no specific environmental figures such as carbon emissions, energy use, or consumption data.
Fix: Include concrete metrics like annual carbon footprint (tCO2e) and energy consumption (kWh) in a sustainability report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy profile, such as whether servers run on renewable energy, in an environmental or technical statement.
-
plan_exists: The governance page describes corporate documentation, board structure, and legal compliance but contains no published plan for organisational failure or exit.
Fix: Publish a succession or continuity plan outlining what happens to the institution's holdings and services if the Library ceases to operate, and link it from the governance page.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content in the event of the organisation ceasing operations.
Fix: Add a section addressing the fate of user data and published/digital content upon organisational exit, including retention, transfer, or deletion arrangements.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content if the Library fails.
Fix: Identify and name designated custodians, mirror sites, or archive partners (e.g., other national institutions) that would take over stewardship of the collections and digital assets.
-
policy_exists: The page only mentions general jobs and volunteering opportunities without any published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from the jobs or governance section of the About page.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add explicit commitments on fair pay, working hours, mental health support, and employee benefits to the careers or wellbeing content.
-
accountability: While a Board of Trustees is mentioned for overall governance, no accountability or oversight is identified specifically for worker conditions or wellbeing.
Fix: Name the individual, committee, or role responsible for overseeing worker conditions and wellbeing within the governance section.