Northern Ireland Direct

https://www.nidirect.gov.uk · 43/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (7 failed)
Level 2 — Enhanced 5/27 (14 failed)
Level 3 — Advanced 0/10 (4 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 3/8
Interoperability 0/3
Privacy 10/16
Provenance 0/2
Security 6/11
Transparency 0/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The terms and conditions page does not publish any response timeframes for inquiries, permission requests, or feedback.
    Fix: Add a published response timeframe (e.g., within 10 working days) for contact, logo permission, and feedback requests.
  • specific: No specific timeframes in days or weeks are provided anywhere on the page.
    Fix: Specify concrete durations such as 'we respond within 15 working days' rather than omitting timing altogether.
  • steps_clear: On this terms page the complaint steps themselves are not described; only a link is provided without outlining the procedure here.
    Fix: Include or summarise the complaint steps (how to submit, what info is needed, what happens next) directly on or linked prominently from the terms page.
  • appeals_exists: The terms and conditions page does not document any appeals process for users to challenge decisions or content.
    Fix: Add a clearly documented appeals process describing how users can formally challenge decisions, with steps and timelines.
  • independent: No independent or escalated review mechanism is mentioned; the page only references exclusive jurisdiction of Northern Ireland courts for disputes.
    Fix: Describe an independent appeals or escalation route (e.g., to an ombudsman or separate review body) so appeals aren't confined to the original decision-maker.

AI & Automation

  • marking_policy: The terms and conditions page contains no policy on marking or labelling AI-assisted content.
    Fix: Add a clear policy statement describing how AI-assisted or AI-generated content will be identified and labelled on the site.
  • consistent: Without a marking policy present, there is no evidence that AI content marking is applied consistently across the site.
    Fix: Once a marking policy is introduced, document and apply consistent AI-content labels (e.g., a standard tag or notice) across all relevant pages.
  • oversight_exists: The page does not mention any human oversight arrangements for AI outputs.
    Fix: Publish a statement confirming that AI outputs are subject to human oversight, including where this oversight sits within the organisation.
  • review_process: No review or approval process for AI-generated content is described on this terms page.
    Fix: Describe the specific editorial review or approval workflow that AI-assisted content must pass through before publication.
  • accountability: While the Executive Information Service is named as site manager, no party is identified as accountable for AI-generated content specifically.
    Fix: Name a specific role or team (e.g., the Central Editorial Team) as accountable for AI-generated content and provide contact details for queries.

Interoperability

Privacy

  • comprehensive: This hub page itself does not describe what data is collected or why; it only links out to other privacy notices without summarising the data practices.
    Fix: Add a short summary on this page outlining the categories of personal data collected across nidirect services and the purposes for processing, with links to the detailed notices.
  • plain_language: The page does not describe any data practices directly; it only provides a list of links to external privacy notices.
    Fix: Include a plain-language overview of core data practices (collection, use, sharing) on this landing page before directing users to individual notices.
  • understandable: A non-expert visiting this page cannot understand what data is collected or why because no practices are explained on the page itself.
    Fix: Add a brief, user-friendly explanation of what information nidirect collects and why, so users can understand without clicking through to every linked notice.
  • necessity: The page does not state that data collection is limited to what is necessary.
    Fix: Add a statement on this page confirming that nidirect only collects personal data necessary to deliver the relevant government service.
  • proportionate: There is no mention of proportionality of data collection relative to the service provided on this page.
    Fix: Include a clear statement that data collected is proportionate to the purpose of each service, with examples or a link to detail.
  • retention_stated: The page contains no information about how long personal data is retained.
    Fix: Add a retention section (or clear summary) on this page stating how long data is kept, or link prominently to retention details in each service's privacy notice.
  • specific: No specific retention periods are provided anywhere in the visible content.
    Fix: State specific retention durations (e.g. 'records kept for 6 years after case closure') rather than leaving retention unaddressed.
  • partner_count_specific: The banner references third parties with examples (YouTube, Google Maps) but provides no specific numeric count of partners.
    Fix: Update the banner to state the exact number of third-party partners that may set cookies (e.g., 'shared with X partners') and link to a full list.

Provenance

Security

Transparency

  • algorithm_explained: The terms and conditions page makes no mention of any algorithms or their purpose.
    Fix: Add a section (or link to a dedicated page) describing any algorithms used on nidirect and explaining their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users on this page.
    Fix: Include clear statements about how any automated or algorithmic decisions impact users and what outcomes they may produce.
  • annual_statement: The page provides links to privacy notices but shows no evidence of regular or periodic review of data practices.
    Fix: Add a statement indicating when privacy practices were last reviewed and the cadence for future reviews (e.g., annually).
  • dated: There is no visible date or version number on the privacy notices listing page.
    Fix: Include a 'last updated' date or version indicator on the privacy notices page and on the linked privacy notices themselves.

Level 3 — Advanced

Accessibility

Accountability

  • policy_exists: The terms page contains no published moderation policy for user-generated content or submissions.
    Fix: Publish a dedicated moderation policy outlining how user contributions or comments are reviewed and managed.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use standards) are stated anywhere on the page.
    Fix: Add explicit criteria describing what content is permitted or prohibited and the standards used to evaluate it.
  • enforcement: The page does not explain any enforcement process, appeals, or consequences for moderation decisions.
    Fix: Document the enforcement workflow including who reviews content, what actions are taken, and how users can appeal decisions.

Interoperability

Security

Transparency

  • criteria_published: No criteria used in any algorithmic decision-making are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decisions, either on this page or on a linked transparency page.
  • weighting: The page does not describe any weighting or prioritisation of decision criteria.
    Fix: Explain how each criterion is weighted or prioritised when algorithmic decisions are made.
  • auditable: The page provides no technical or procedural detail that would support external audit of algorithms.
    Fix: Provide documentation (such as model cards, data sources, and decision logic) sufficient to allow external audit or independent review.

Responsibility to the Future

  • policy_exists: The page is a public careers guidance resource for citizens and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the organisation's site.
  • specific_commitments: The content covers career guidance and EMA payments but includes no specific commitments on pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering pay, working hours, mental health support, and employee benefits within a wellbeing policy.
  • accountability: The page does not name any person, role, or body responsible for overseeing worker conditions.
    Fix: Identify a named role or oversight body accountable for monitoring and enforcing worker wellbeing standards.