Oxfam GB
https://www.oxfam.org.uk · 50/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (9 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-required-children, aria-required-parent, list.
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-required-children, aria-required-parent, list.
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement anywhere in the visible content or footer links.
Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for on the page.
Fix: Clearly describe the specific use cases for AI (e.g., chatbots, analytics, content generation) within a published AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
- Page sent requests to 1 known domain from the block list: scontent-fra5-1.xx.fbcdn.net.
- No scripts matched the tracker/ad pattern list.
- Detected 4 data-leaking services across 3 categories: facebook (scontent-fra5-1.xx.fbcdn.net); google fonts (fonts.googleapis.com, fonts.gstatic.com); linkedin (media.licdn.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.oxfam.org.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only a link to 'Plans, reports and policies' without any funding information on this page.
Fix: Add a funding disclosure section on the About page summarizing income sources (e.g., donations, government grants, trading) with a link to full financial reports.
-
transparent: No funding sources are identified anywhere on the page content provided.
Fix: Clearly name major funding sources such as individual donors, institutional grants, and retail operations directly on the About page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page does not publish any response timeframes for inquiries from the Supporter Care team or other contact channels.
Fix: Add a clear statement on the contact page indicating how quickly supporters can expect a response (e.g., 'We aim to respond within 5 working days').
-
specific: No specific timeframes in days or hours are given anywhere on the page; update promises like 'as soon as possible' are vague.
Fix: Replace vague phrases like 'as soon as possible' with specific durations such as 'within 10 business days' for updates and replies.
-
steps_clear: The page only links to the complaints policy without outlining the actual steps a user needs to follow to submit a complaint on this page.
Fix: Include a brief summary on the contact page listing the steps to make a complaint (e.g., 1. Contact Supporter Care, 2. Escalate in writing, 3. Appeal to the ombudsman) alongside the link.
-
independent: The page mentions a complaints policy but does not indicate any independent review body or escalation path (e.g., to the Fundraising Regulator or Charity Commission) for unresolved appeals.
Fix: Add explicit guidance on the contact page indicating how complainants can escalate unresolved issues to an independent body such as the Fundraising Regulator or Charity Commission.
AI & Automation
-
detailed_scope: The page does not detail any scope of AI use since no AI policy is referenced.
Fix: Add a detailed scope section to an AI policy outlining each system, its purpose, and the data it processes.
-
limitations: No acknowledgement of AI system limitations appears anywhere on the page.
Fix: Include a section in an AI policy that transparently acknowledges known limitations such as bias, accuracy, and hallucination risks.
-
safeguards: The page describes no safeguards or quality controls for AI systems.
Fix: Document safeguards such as human oversight, review processes, and quality assurance measures in a published AI policy.
-
marking_policy: The About page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy describing how AI-assisted content will be labelled or disclosed on Oxfam's website.
-
consistent: No AI content markings are visible on the page, so consistency cannot be demonstrated.
Fix: Apply consistent visual labels or disclosures to any AI-generated text, images, or media across all pages.
-
oversight_exists: The page does not document any human oversight of AI outputs.
Fix: Add a statement describing how staff review and oversee any AI-generated content before publication.
-
review_process: No review or approval workflow for AI content is described on the page.
Fix: Document the specific review/approval steps AI content must pass through prior to being published.
-
accountability: No individual, role, or team is named as accountable for AI-generated content.
Fix: Identify a named role or team (e.g., Editorial Lead or Digital Governance Officer) responsible for AI-generated content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: This short version only lists section headings (e.g. 'What details we ask for and why') without actually describing what data is collected or why on this page.
Fix: Include at least a brief summary on this page describing the categories of data collected and the purposes, or inline the key content from the full policy rather than only linking out.
-
plain_language: The visible page does not actually describe any data practices—it only provides headings and a link to the full policy, so plain-language practice descriptions cannot be assessed as present.
Fix: Add plain-language summaries of each listed topic (e.g. what details are collected, how they are used) directly on the short version page.
-
understandable: A non-expert reading this page would not learn what data is collected or why, since only section titles are shown without explanatory content.
Fix: Provide short, user-friendly explanations under each heading so readers understand data collection and purposes without clicking through.
-
necessity: The page does not state that data collection is limited to what is necessary.
Fix: Add an explicit statement that Oxfam only collects personal data that is necessary for the stated purposes.
-
proportionate: There is no statement or evidence on this page that data collected is proportionate to the service provided.
Fix: Include a clear commitment that data collection is proportionate and minimal relative to the purpose for which it is processed.
-
retention_stated: The page contains no mention of data retention periods.
Fix: Add a data retention section stating how long different categories of personal data are kept.
-
specific: Since no retention periods are stated, specific durations are necessarily absent.
Fix: Specify concrete retention periods (e.g. 'supporter records kept for 7 years after last activity') rather than vague terms.
-
no_dark_patterns: The short privacy page provides no visible consent interface, so it cannot be verified that consent is gathered without manipulative language or dark patterns.
Fix: Display the consent mechanism (e.g., cookie banner) on this page or link to it clearly, using neutral, non-manipulative language.
-
equal_choices: No accept/reject controls are present on this page, so equal prominence of choices cannot be confirmed.
Fix: Include or surface a consent banner with 'Accept' and 'Reject' buttons of equal size, color, and prominence.
-
no_forced_consent: The page does not show any consent options, making it impossible to verify that consent is not bundled or forced.
Fix: Provide granular, unbundled consent toggles (e.g., separate options for analytics, marketing) with no pre-ticked boxes and no requirement to accept to use the site.
-
banner_present: The provided page content shows no visible cookie or consent banner text anywhere on the homepage.
Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or customize cookie preferences.
-
partner_sharing_mentioned: There is no on-page consent copy disclosing data sharing with third-party partners.
Fix: Add clear disclosure in the cookie banner stating that data may be shared with third-party advertising/analytics partners, with a link to the full list.
-
partner_count_specific: No specific numeric count of partners is stated anywhere on the page since no banner or partner disclosure exists.
Fix: Include a specific numeric count of third-party partners (e.g., 'We share data with X partners') in the cookie banner along with a link to view them.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
detail: No amounts, percentages, or funding categories are provided on the page.
Fix: Include a breakdown of income (e.g., percentage from public donations, grants, and shops) with figures from the latest annual report.
-
complete: Since no funding disclosure exists on the page, no funding streams are covered.
Fix: Provide a complete summary covering all major income streams (public donations, legacies, government/institutional funding, trading income) on the About page.
-
algorithm_explained: The About page contains no mention of any algorithms or their purpose.
Fix: Add a section or link describing any algorithms used by Oxfam (e.g., for donation processing, beneficiary selection, or site personalization) and their intended purpose.
-
impact_clear: The page does not describe how any algorithmic decisions affect users, supporters, or beneficiaries.
Fix: Include a clear statement outlining the real-world impact of any algorithmic decisions on users and the communities Oxfam serves.
-
annual_statement: The page links to 'Privacy & cookies' but provides no evidence on this page of an annual or periodic review of data practices.
Fix: Add a statement (or visible link) indicating when the privacy/data practices policy was last reviewed and the review cadence, e.g., 'Reviewed annually — last reviewed [date]'.
-
dated: No date or version is shown for any data practices statement on this page; only a generic 'Privacy & cookies' link appears in the footer.
Fix: Display a 'Last updated' date or version number alongside the Privacy & cookies link or within the linked policy summary.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement describes ongoing improvement efforts but gives no specific dates or target deadlines for resolving the acknowledged issues.
Fix: Add concrete target dates or a remediation schedule stating when each known accessibility issue is expected to be fixed.
-
feedback_channel: A contact email (heretohelp@oxfam.org.uk) is provided, but no commitment to a response time is stated.
Fix: Add a stated response commitment, such as a target timeframe for replying to accessibility-related enquiries.
Accountability
-
criteria_clear: The policy refers vaguely to 'offensive, inappropriate or objectionable content' and 'disruptive behaviour' without defining what these terms mean or providing examples.
Fix: Add a clear list of prohibited content categories (e.g., hate speech, harassment, spam, defamatory material) with concrete examples so users understand what is not allowed.
-
enforcement: The page only states Oxfam 'may use your personal information to stop such behaviour' and inform third parties, but does not explain the actual moderation/enforcement process, appeals, or consequences such as content removal or account suspension.
Fix: Document the enforcement workflow, including how content is reviewed, what sanctions apply (e.g., removal, ban), how users are notified, and how they can appeal a decision.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page lists policies like safeguarding and Modern Slavery Act statement but contains no published incident response plan or policy for security/data incidents.
Fix: Publish a dedicated incident response plan or policy and link it from the About or Privacy & cookies section.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify affected users and the public in the event of a significant incident.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming an incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decision-making are published on this page.
Fix: Publish the specific criteria used in any algorithmic decisions, either on this page or via a linked transparency/policy document.
-
weighting: There is no information about how criteria are weighted or prioritized in any decision process.
Fix: Document and disclose the relative weights or priority given to each criterion used in algorithmic decisions.
-
auditable: The page provides no technical or procedural detail sufficient to allow external audit of any algorithm.
Fix: Provide detailed documentation (methodology, data sources, review processes) and an audit contact so external reviewers can assess algorithmic systems.
-
open_source: The page does not link to any public source code repository for the website or related tools.
Fix: Add a link to a public code repository (e.g., GitHub) for any open-source components of the site or Oxfam's digital tools.
-
tech_docs: No technical documentation is published or linked from the about page.
Fix: Publish and link to technical documentation describing the site's architecture, APIs, or data specifications in a developer/technical section.
Responsibility to the Future
-
disclosure_exists: The page focuses on donations and fundraising with no published environmental impact or sustainability disclosure despite covering climate change as an issue.
Fix: Publish a dedicated sustainability or environmental impact report and link to it prominently from the climate page.
-
specific_metrics: The only figures present relate to how donation money is spent, with no specific carbon, energy use, or emissions metrics disclosed.
Fix: Add quantified environmental metrics such as annual carbon emissions and energy consumption to the disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy sourcing and the site's carbon footprint, ideally citing a green hosting certification.
-
plan_exists: The page describes Oxfam's mission, history, and governance but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity or wind-down plan describing what happens to the organisation and its services if it ceases operations, and link it from the About or Plans, reports and policies section.
-
data_and_content_fate: There is no mention of what would happen to user data or published content in the event of the organisation's closure or exit.
Fix: Add a statement addressing how user data would be handled and how published content would be preserved or removed if the organisation shuts down.
-
custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners who would take over content or data if the organisation ceases to exist.
Fix: Name a custodian, archive partner, or mirror arrangement responsible for maintaining critical content and data after any organisational exit.
-
policy_exists: The page references 'Working at Oxfam' and 'Plans, reports and policies' but does not present any published policy specifically on worker wellbeing or working conditions.
Fix: Publish and link to a dedicated worker wellbeing or working conditions policy from the About page.
-
specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add concrete commitments on pay, working hours, mental health support, and benefits within an accessible worker wellbeing policy.
-
accountability: While the page names a Leadership team and Trustees for overall governance, it does not identify any specific accountability or oversight for worker conditions.
Fix: Clearly designate a role or body (e.g., HR director or a trustee committee) responsible for overseeing worker wellbeing and state this on the site.