Ocado
https://www.ocado.com · 37/92 checks passed · retail
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (6 failed) |
| Level 2 — Enhanced | 4/27 (17 failed) |
| Level 3 — Advanced | 0/10 (4 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 0/3 |
| Privacy | 6/16 |
| Provenance | 0/2 |
| Security | 7/11 |
| Transparency | 3/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
- Not found at any of: /ai-policy, /ai.
Skipped: Target page not found in captured content
Privacy
- 1 inline script matched a tracker/ad pattern; first match: 'window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(argumen…'.
- 1 hidden iframe found: https://orl-prd-ccai-qy9mz6o.ew2.ccaiplatform.com/web-sdk/v3/bridge.html.
- Detected 3 data-leaking services across 2 categories: cookie consent saas (cdn-ukwest.onetrust.com); google fonts (fonts.googleapis.com, fonts.gstatic.com).
Security
- Redirect chain (1 hops): https://www.ocado.com
- x-frame-options: header not set on the response.
Transparency
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page refers generically to 'our team' and 'advisors' with only a chatbot named 'Herbie' mentioned, but no named person or specific responsible role is identified.
Fix: Identify a specific responsible role (e.g., Head of Customer Service) or named individual accountable for customer enquiries on the contact page.
-
process_exists: The page lists general contact channels but does not document a specific complaints or feedback process or link to a complaints procedure.
Fix: Add a dedicated complaints section or link to a formal complaints policy that explains how complaints are handled, escalated, and resolved.
-
steps_clear: No numbered or sequential steps are provided for how to raise or escalate a complaint—only generic contact options are listed.
Fix: Provide a clear step-by-step complaints procedure (e.g., Step 1: contact us via X, Step 2: escalation path, Step 3: external ombudsman) with expected outcomes at each stage.
-
appeals_exists: The contact page lists channels (email, WhatsApp, chat, phone) but does not document any appeals process for disputing decisions.
Fix: Add a clearly labeled appeals procedure explaining how customers can formally challenge decisions, including steps, timelines, and required information.
-
independent: No escalation path or independent review body (e.g., ombudsman or senior review team) is mentioned on the page.
Fix: Document an escalation route to an independent reviewer or external ADR/ombudsman scheme so appeals are not handled solely by the original responders.
AI & Automation
-
marking_policy: The Terms & Conditions page lists various policies but contains no policy for marking AI-assisted content.
Fix: Add a clear AI content labeling policy to the Terms & Conditions or a dedicated AI policy page stating how AI-assisted content is marked.
-
consistent: Without any AI marking policy referenced on the page, consistency of AI content marking cannot be demonstrated.
Fix: Publish and uniformly apply AI content disclosure labels across product descriptions, recipes, and marketing copy, with examples referenced in the terms.
-
oversight_exists: The page makes no mention of human oversight for any AI-generated outputs.
Fix: Add a statement to the Terms or Legal Information describing how humans oversee AI systems used on the site.
-
review_process: No review or approval workflow for AI outputs is described anywhere on the visible page content.
Fix: Document the editorial review and approval steps that AI-generated content undergoes before publication.
-
accountability: No accountable party or role for AI-generated content is named on the page.
Fix: Name a responsible team or role (e.g., an editorial or compliance lead at Ocado Retail Limited) accountable for AI-generated content in the policy.
Skipped: Target page not found in captured content
Interoperability
- No RSS/Atom feeds discovered.
Skipped: Target page not found in captured content
Privacy
-
comprehensive: The visible content only discusses cookies and does not describe the full scope of personal data collected or the purposes for processing it.
Fix: Include or surface the full privacy policy content covering categories of personal data collected, purposes, legal bases, sharing, and user rights.
-
understandable: While cookie use is understandable, the page does not clearly explain what personal data (beyond cookies) is collected and why in a way a non-expert can follow.
Fix: Add a plain-language summary section listing the types of personal data collected (e.g. name, address, payment info) and why each is needed.
-
necessity: The visible content does not state that data collection is limited to what is necessary for the service.
Fix: Add an explicit statement confirming data minimisation — that only data necessary to provide the service is collected.
-
proportionate: There is no statement or evidence on the page addressing proportionality of the data collected to the service.
Fix: Include a proportionality statement explaining how each data category collected corresponds to a specific service need.
-
retention_stated: The visible content does not mention any data retention periods.
Fix: Add a data retention section stating how long each category of personal data is kept.
-
specific: No specific retention timeframes are provided since retention is not addressed at all.
Fix: Specify concrete retention periods (e.g. 'account data retained for 24 months after last activity') rather than vague terms.
-
no_dark_patterns: The page only surfaces a 'Cookie Settings' button without showing the consent dialog language, so manipulative framing or pre-ticked options cannot be ruled out from the visible content.
Fix: Display the full consent banner text on the privacy page or link to it, ensuring neutral wording and no pre-selected non-essential categories.
-
equal_choices: Only a single 'Cookie Settings' button is shown with no visible 'Accept All' or 'Reject All' options of equal prominence.
Fix: Provide clearly visible 'Accept All' and 'Reject All' buttons with identical styling and prominence alongside the 'Cookie Settings' option.
-
ads_labelled: The page lists promotional categories like 'Big Brand Offers' and 'Brands We Love' without any labels indicating whether these are paid placements or sponsored content.
Fix: Clearly label any paid placements or sponsored brand features with explicit 'Sponsored' or 'Ad' tags visible to users.
-
disclosure: There is no disclosure on the page explaining any commercial relationship between featured brands/offers and Ocado as an advertiser.
Fix: Add a visible disclosure statement (e.g., within the privacy/cookie policy or near promotional sections) explaining commercial relationships with featured brands.
-
banner_present: The page content shows no visible cookie or consent banner text anywhere in the captured content.
Fix: Implement a visible cookie/consent banner on the homepage that appears for first-time visitors prior to non-essential cookie loading.
-
partner_sharing_mentioned: No on-page copy discloses data sharing with third-party advertising or analytics partners.
Fix: Add explicit consent copy disclosing that data may be shared with third-party partners for advertising, analytics, and personalization.
-
partner_count_specific: No numeric count of partners is stated anywhere on the page since partner sharing is not disclosed.
Fix: State a specific number of partners (e.g., 'We share data with X partners') within the consent banner and link to the full partner list.
Provenance
- No author or date metadata found on the page.
Skipped: Target page not found in captured content
Security
Transparency
-
named_person: Only generic references to 'our team', 'advisors', and 'social team' are given, with no named individual or specifically identified team responsible for enquiries.
Fix: Name the specific team (e.g., 'Ocado Customer Care Team') or an individual contact owner responsible for handling enquiries.
-
role_clear: The page does not clearly state the role, authority, or remit of the people answering enquiries beyond vague labels like 'advisors' and 'social team'.
Fix: Clearly describe the role and authority of the responders (e.g., 'Customer Service Advisors empowered to resolve orders, refunds, and delivery issues').
-
algorithm_explained: The Terms & Conditions page contains no mention or explanation of any algorithms used on the site (e.g., for recommendations, pricing, or delivery slotting).
Fix: Add a section describing any algorithms used on Ocado.com (such as product recommendations or delivery slot allocation) and explain their purpose in plain language.
-
impact_clear: There is no description on the page of how algorithmic decisions affect users, such as product rankings, pricing, or delivery availability.
Fix: Include a clear statement describing how algorithmic decisions impact the user experience, such as which products they see or what delivery options are offered.
-
annual_statement: The cookie policy excerpt contains no indication of a regular or annual review of data practices.
Fix: Add a statement indicating when the privacy/cookie policy was last reviewed and commit to a periodic (e.g., annual) review cadence.
-
dated: The cookie policy text shown has no visible effective date, last-updated date, or version number.
Fix: Include a 'Last updated' date or version number at the top or bottom of the Privacy & Cookie Policy.
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Level 3 — Advanced
Accessibility
Skipped: Target page not found in captured content
Accountability
-
policy_exists: The Terms & Conditions page lists only purchase-related policies and a Customer Reviews Policy link, but no moderation policy content is visible on the page.
Fix: Publish a dedicated moderation policy (e.g., for reviews, comments, or user-generated content) accessible from the Terms & Conditions page.
-
criteria_clear: No moderation criteria (e.g., what content is allowed or disallowed) are stated anywhere in the visible page content.
Fix: Add a clearly worded section outlining specific moderation criteria such as prohibited content types, language standards, and review eligibility rules.
-
enforcement: The page does not describe any enforcement process, appeals mechanism, or consequences for violating moderation rules.
Fix: Include an enforcement section explaining how violations are detected, what actions are taken (removal, suspension), and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria used in any algorithmic decision-making are published on this page.
Fix: Publish the specific input criteria (e.g., purchase history, location, stock levels) that feed into algorithmic decisions on the site.
-
weighting: The page provides no information about how criteria are weighted or prioritised in algorithmic decisions.
Fix: Add documentation explaining the relative weighting or priority of factors used in algorithmic decisions, even at a high level.
-
auditable: The page contains no technical or methodological detail that would allow an external party to audit or review any algorithmic system.
Fix: Provide an algorithmic transparency report or methodology document with enough detail (data sources, logic, evaluation metrics) to support external audit.
Skipped: Target page not found in captured content
Responsibility to the Future
-
policy_exists: The careers page mentions section headings like 'What we offer' and lists policies such as Modern Slavery and Gender Pay Gap, but no published worker wellbeing or working conditions policy is present in the content shown.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it clearly from the careers page.
-
specific_commitments: The page offers only vague statements about belonging and culture without any specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete, measurable commitments covering pay standards, working hours, mental health support, and benefits.
-
accountability: No individual, team, or governance body is identified as responsible for overseeing worker conditions on this page.
Fix: Name a responsible role or oversight body (e.g., Chief People Officer or a wellbeing committee) accountable for worker conditions.
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content