Office for National Statistics

https://www.ons.gov.uk · 44/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (8 failed)
Level 2 — Enhanced 6/27 (15 failed)
Level 3 — Advanced 0/10 (3 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 0/5
AI & Automation 3/8
Interoperability 0/3
Privacy 11/16
Provenance 0/2
Security 5/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic categories (e.g., 'General and statistical enquiries', 'Social survey enquiries') without naming a specific person or role responsible.
    Fix: Add the name or role title (e.g., Head of Customer Services) of the individual or team lead accountable for each enquiry category.
  • response_timeframe: The page only states 'We are unable to respond to all enquiries' without publishing any response timeframe.
    Fix: Publish an explicit response timeframe (e.g., 'We aim to respond within 20 working days') on the complaints page.
  • specific: No specific timeframe in days or weeks is provided anywhere on the page.
    Fix: Include a specific, measurable response window such as '10 working days' rather than vague language.
  • process_exists: The page only shows a 'Thank you' confirmation and does not document a complaints or feedback process.
    Fix: Add a dedicated complaints policy page describing how complaints are handled, escalated, and resolved.
  • steps_clear: No step-by-step instructions for making a complaint are visible on the page.
    Fix: List clear numbered steps (e.g., submit form, acknowledgement, investigation, outcome, escalation) for making and progressing a complaint.
  • appeals_exists: The page only shows a 'Thank you' confirmation and generic footer links with no documented complaints or appeals process described.
    Fix: Publish a clear complaints and appeals procedure on /complaints outlining how to submit a complaint, expected response times, and escalation steps.
  • independent: No mention of an independent reviewer, ombudsman, or escalation path is present on the page.
    Fix: Document an independent escalation route (e.g., to the UK Statistics Authority, ICO, or Parliamentary Ombudsman) for unresolved complaints.

AI & Automation

  • marking_policy: The terms and conditions page contains no policy addressing how AI-assisted content is marked or labelled.
    Fix: Add a section to the terms or a dedicated policy page stating how AI-assisted content is identified and labelled on the ONS website.
  • consistent: With no marking policy present, there is no evidence of consistent application of AI content labelling on this page.
    Fix: Define a standard AI-content label (e.g., a badge or disclosure statement) and apply it uniformly across all AI-assisted outputs, referencing the policy in the terms.
  • oversight_exists: The page makes no reference to human oversight of AI outputs or any governance of AI-generated content.
    Fix: Publish a statement describing that AI outputs are subject to human oversight, and link to it from the terms and conditions page.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on this page.
    Fix: Document the editorial review and approval steps applied to AI-generated content (e.g., subject-matter expert sign-off) and publish it alongside the terms.
  • accountability: The page does not identify any individual, team, or role accountable for AI-generated content.
    Fix: Name an accountable owner (e.g., a specific ONS team or editorial lead) responsible for AI-generated content and include their contact details in the policy.

Interoperability

Privacy

  • comprehensive: The visible content only covers cookies and does not comprehensively describe what other personal data is collected and why.
    Fix: Expand the privacy page to describe all categories of personal data collected, the purposes, legal bases, and user rights, not just cookies.
  • necessity: The page does not explicitly state that data collection is limited to what is necessary.
    Fix: Add an explicit statement that the ONS only collects data necessary for the stated purposes (data minimisation principle).
  • proportionate: There is no language addressing whether the data collected is proportionate to the service.
    Fix: Include a statement explaining how data collection is proportionate to providing and improving the ONS website services.
  • retention_stated: The visible content does not state any data retention periods for cookies or other personal data.
    Fix: Add explicit retention periods for each cookie and category of personal data on the privacy page.
  • specific: Because retention is not stated at all, no specific time periods are provided.
    Fix: Specify exact retention durations (e.g. 'Google Analytics cookies expire after 24 months') rather than vague descriptions.
  • partner_sharing_mentioned: The banner only mentions essential and additional cookies for settings and site usage, with no disclosure of data sharing with third-party partners.
    Fix: Update the cookie banner copy to explicitly state whether any data is shared with third-party partners and link to a partner list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: If partners receive data, disclose the specific number of partners (e.g., 'we share data with X partners') directly in the banner.

Provenance

Security

Transparency

  • role_clear: While enquiry categories are listed, the authority, remit, or role of each team (e.g., who handles what types of issues and their decision-making authority) is not clearly stated.
    Fix: Add a short description for each contact option clarifying the team's role, scope of authority, and the types of enquiries they are empowered to resolve.
  • algorithm_explained: The terms and conditions page makes no mention of any algorithms used by the ONS website or their purpose.
    Fix: Add a section (or link to one) explaining any algorithms used on the site, such as for search ranking or analytics, and describe their purpose.
  • impact_clear: There is no description of how algorithmic decisions might impact users of the ONS website.
    Fix: Include clear statements describing how any algorithmic processes affect what users see or experience on the site.
  • annual_statement: The cookies/privacy content shown contains no indication of a periodic or annual review of data practices.
    Fix: Add a statement indicating when the privacy/cookies policy was last reviewed and commit to a regular (e.g., annual) review cycle.
  • dated: The visible cookies and privacy content has no last-updated date or version number.
    Fix: Include a clearly visible 'Last updated' date or version identifier on the privacy and cookies statement.

Level 3 — Advanced

Accessibility

Accountability

  • policy_exists: The terms page does not publish any moderation policy for user-generated content or community interactions.
    Fix: Publish a dedicated moderation policy (e.g., for discussion forums or comments) linked from the terms and conditions page.
  • criteria_clear: No moderation criteria describing what content is acceptable or prohibited are stated on the page.
    Fix: Add clear criteria listing prohibited content types (e.g., abusive, off-topic, unlawful) and standards contributors must meet.
  • enforcement: The page does not explain how moderation decisions are made, applied, or appealed; it only mentions reporting attacks to law enforcement.
    Fix: Document the moderation enforcement process, including who reviews content, actions taken (removal, bans), and how users can appeal decisions.

Interoperability

Security

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decisions.
    Fix: Publish a list of the specific inputs and criteria used by any algorithmic systems on the site, ideally in a dedicated transparency page.
  • weighting: No weighting or prioritisation of algorithmic criteria is described anywhere on the page.
    Fix: Document the relative weighting or priority assigned to each criterion used in algorithmic decision-making.
  • auditable: The page provides no technical detail, documentation, or audit mechanism that would enable external review of algorithms.
    Fix: Provide sufficient technical documentation, model cards, or an audit process (e.g., via the Algorithmic Transparency Recording Standard) to enable independent review.

Responsibility to the Future