Ofcom

https://www.ofcom.org.uk · 51/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 2/2
Security 6/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page lists corporate policies and accessibility but contains no visible AI use policy or statement.
    Fix: Publish a dedicated AI use policy or statement under Corporate policies and link it from the About Ofcom page.
  • scope_clear: Without an AI policy on the page, there is no explanation of what AI is used for at Ofcom.
    Fix: Add a clear scope section to the AI policy describing the specific use cases and contexts in which Ofcom uses AI.

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only general descriptions of Ofcom's role and sections.
    Fix: Add a dedicated funding disclosure section on the About page (or link to one) explaining how Ofcom is funded.
  • transparent: No funding sources are identified anywhere on the visible page content.
    Fix: Clearly identify Ofcom's funding sources (e.g., industry fees, grant-in-aid from government) in a visible statement on the About page.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists departments (e.g., Advice and complaints, Spectrum Licensing) but no named individual or specific role holder is identified as responsible.
    Fix: Add the name and title of a responsible officer or team lead (e.g., Head of Consumer Contact) accountable for handling enquiries.
  • response_timeframe: The page content does not mention any response timeframes for handling complaints.
    Fix: Publish explicit response timeframes (e.g., acknowledgment within X days, resolution within Y days) on the complaints landing page.
  • specific: No specific timeframes in days or weeks are given since no timeframes are provided at all.
    Fix: State concrete durations such as '10 working days for acknowledgement' rather than vague terms.
  • appeals_exists: The page lists complaint categories and a 'Complain about Ofcom' link but does not document an appeals process for decisions made.
    Fix: Add a clearly labeled section describing how users can appeal a complaint outcome, including steps, timelines, and required information.
  • independent: No mention of independent review or escalation to an external body is provided on this page.
    Fix: Document an independent or escalated review route (e.g., ombudsman, independent adjudicator, or judicial review) with contact details and eligibility criteria.

AI & Automation

  • detailed_scope: The page contains no AI policy and therefore no detailed scope of AI use is provided.
    Fix: Create an AI policy page that enumerates the systems, departments, and tasks where AI is deployed across Ofcom.
  • limitations: No acknowledgement of AI system limitations appears anywhere on this About page.
    Fix: Include a section in the AI policy that openly discusses known limitations such as bias, accuracy issues, and contexts where AI is not used.
  • safeguards: The page does not describe any safeguards, oversight, or quality controls for AI usage.
    Fix: Document the human oversight, testing, and governance safeguards applied to AI systems within a published AI policy.
  • marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy on the site (e.g., under 'About this website' or 'Corporate policies') explaining how any AI-assisted content is disclosed and labelled.
  • consistent: Without a stated marking policy, there is no evidence that AI content marking is applied consistently across the page or site.
    Fix: Apply a standardised AI-content label across all pages and reference the convention in the site's editorial or accessibility guidelines.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans review AI outputs before publication, ideally within the 'Corporate policies' or 'About this website' section.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Document the editorial review and approval steps that AI-assisted content must pass through before being published.
  • accountability: The page does not name any role, team, or individual accountable for AI-generated content.
    Fix: Identify a specific owner (e.g., an editorial lead or governance committee) responsible for AI-generated content and publish their role on the site.

Interoperability

Privacy

  • comprehensive: The page focuses on cookies only and does not comprehensively cover broader personal data collection, purposes, sharing, or user rights.
    Fix: Expand the page (or link prominently to) a full privacy notice covering categories of personal data collected, purposes, legal basis, sharing, and data subject rights.
  • necessity: The page does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit statement (e.g., data minimisation principle) confirming that collection is restricted to what is necessary for each purpose.
  • proportionate: There is no statement addressing proportionality of the data collected relative to the service provided.
    Fix: Include a clear assertion that data collected is proportionate to the purpose, ideally tied to each processing purpose listed.
  • specific: While most are specific, at least one entry (SLIB_AWS) lists expiration as 'TBC', which is vague.
    Fix: Replace any 'TBC' retention values with a specific time period for every cookie listed.
  • equal_choices: The page only references a cog icon to update preferences and does not show accept/reject options at all, let alone with equal prominence on this policy page.
    Fix: Include or link to a consent banner/preferences center from this page where Accept All and Reject All buttons are presented with equal visual prominence (same size, color, and styling).
  • banner_present: The page content shows no visible cookie or consent banner, only a 'Cookies policy' link in the footer.
    Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookies.
  • partner_sharing_mentioned: No on-page consent copy or banner discloses any data sharing with third-party partners.
    Fix: Add explicit disclosure within the cookie banner stating whether and how user data is shared with third-party partners.
  • partner_count_specific: No partner sharing is disclosed and therefore no specific numeric count of partners is stated.
    Fix: Within the consent banner, state the exact number of third-party partners with whom data is shared (e.g., 'We share data with X partners').

Provenance

Security

Transparency

  • named_person: Only generic department names are listed; no specific individual or named team contact (e.g., a person's name) is provided for enquiries.
    Fix: Identify a named team or individual (such as 'Consumer Contact Team Manager – [Name]') responsible for each category of enquiry.
  • substantive: The main statement is a single sentence tagline, with further detail only available via secondary links like 'What we do'.
    Fix: Expand the About page with substantive on-page detail about Ofcom's remit, responsibilities, and regulated sectors rather than relying on links.
  • mission_clear: The page mentions making communications work for everyone only in passing and does not clearly articulate a mission or editorial approach on the page itself.
    Fix: Add an explicit mission statement section on the About page articulating Ofcom's core objectives and regulatory approach.
  • detail: There is no funding information on the page, so no amounts, percentages, or categories are provided.
    Fix: Include meaningful detail such as the proportion of funding from licence fees, industry levies, and government grants, ideally with figures from the annual report.
  • complete: Since no disclosure is present, it cannot cover any funding streams let alone all major ones.
    Fix: Provide a complete breakdown of all major funding streams (e.g., broadcasting, spectrum, telecoms fees, and grant-in-aid) on the About page or a linked finance page.
  • algorithm_explained: The About page makes no mention of any algorithms used by Ofcom or their purpose.
    Fix: Add a section or link explaining any algorithmic tools Ofcom uses (e.g., in complaints triage or research) and their intended purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users or regulated parties.
    Fix: Include clear statements describing the real-world impact of any algorithmic decisions on users, such as outcomes, recourse, and limitations.
  • annual_statement: The page links to a 'General Privacy Statement' but shows no evidence of a regular or annual review of data practices on this About page.
    Fix: Add a note in the privacy statement (and reference on the About page) indicating when data practices were last reviewed and the cadence of periodic reviews.
  • dated: No date or version information is visible for the privacy or data practices statement on this page.
    Fix: Include a 'Last updated' date or version number on the General Privacy Statement and surface that date where the statement is linked.

Level 3 — Advanced

Accessibility

  • known_issues: The visible content only states a general aspiration for accessibility and does not acknowledge any specific known accessibility issues or limitations.
    Fix: Add a section to the accessibility statement listing specific known non-compliant areas or limitations of the site.
  • remediation_timeline: There is no timeline or commitment for fixing accessibility issues mentioned anywhere on the page.
    Fix: Include a stated timeline or commitment (e.g., target dates) for remediating identified accessibility issues.
  • feedback_channel: While a 'Contact us' link exists, the page provides no accessibility-specific feedback mechanism with a response commitment.
    Fix: Add a dedicated accessibility feedback contact with a stated response timeframe (e.g., we will respond within X working days).

Accountability

  • policy_exists: The terms of use page covers IP, disclaimer, and hyperlinking but does not publish any moderation policy for user content or submissions.
    Fix: Publish a dedicated moderation policy section (or linked page) describing how user-generated content, comments, or submissions are handled.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use standards) are stated anywhere on this page.
    Fix: Add clear criteria listing what content is permitted or prohibited and the standards used to evaluate it.
  • enforcement: The page does not describe any enforcement process, such as takedown, appeals, or escalation steps.
    Fix: Document the enforcement workflow, including who reviews content, actions taken, notification to users, and appeal routes.

Interoperability

Security

  • plan_exists: The About page lists corporate policies and privacy statements but shows no published incident response plan or security incident policy.
    Fix: Publish a dedicated incident response plan or policy and link it from the About or corporate policies section.
  • notification_commitment: There is no statement anywhere on the page committing to public notification of significant security or data incidents.
    Fix: Add an explicit commitment to publicly notify users of significant incidents within the incident response policy.
  • timeframe: The page contains no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of detection) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
    Fix: Publish the specific input criteria and decision factors used by any algorithms, either on this page or via a linked transparency document.
  • weighting: No information is provided about how criteria are weighted or prioritised in any algorithm.
    Fix: Disclose the relative weighting or prioritisation logic applied to algorithmic criteria in an accessible summary.
  • auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
    Fix: Provide sufficient documentation (model cards, data sources, testing methodology) to enable independent audit, or link to an algorithmic transparency register entry.
  • open_source: The page provides no link to source code or any open source repository for the website.
    Fix: Publish any reusable website or tooling source code in a public repository and link to it from the About or About this website section.
  • tech_docs: No technical documentation about the website or its systems is linked from this About page.
    Fix: Add a link to technical documentation (e.g., APIs, data schemas, or website architecture) under 'About this website' or similar section.

Responsibility to the Future

  • disclosure_exists: The About Ofcom page lists corporate policies, diversity, and annual reports but shows no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About Ofcom section and footer.
  • specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere on the page.
    Fix: Add quantified environmental metrics such as annual carbon emissions and energy consumption to the sustainability disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the energy or carbon profile of the website's hosting provider, including any use of renewable-powered data centres.
  • plan_exists: The About page describes Ofcom's roles, reports, and policies but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing how services and responsibilities would be handled if Ofcom were dissolved or restructured.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or retired if the organisation ceased operations.
  • custodians_or_mirrors: The page does not identify any custodians, mirrors, or archive partners for its data or content.
    Fix: Name a designated custodian or archive partner (e.g., The National Archives) and describe mirroring arrangements for preserving the site's content.
  • policy_exists: The page lists corporate policies, diversity/equality, and jobs links but shows no published policy specifically addressing worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing/working conditions policy and link to it prominently from the About or Corporate policies section.
  • specific_commitments: No specific commitments on pay, hours, mental health, or benefits appear anywhere on the page.
    Fix: Add explicit, measurable commitments covering fair pay, working hours, mental health support, and employee benefits within the wellbeing policy.
  • accountability: While the page references the Board and leadership structure, it does not assign any named accountability or oversight for worker conditions or wellbeing.
    Fix: Name the role, committee, or board function responsible for overseeing worker wellbeing and describe how oversight is exercised and reported.