Oxford University Press
https://global.oup.com · 33/92 checks passed · publishers
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 21/37 (16 failed) |
| Level 2 — Enhanced | 5/27 (22 failed) |
| Level 3 — Advanced | 1/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 4/8 |
| Interoperability | 3/3 |
| Privacy | 6/16 |
| Provenance | 0/2 |
| Security | 3/11 |
| Transparency | 2/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-valid-attr-value.
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-valid-attr-value.
AI & Automation
-
policy_exists: The page content shows only homepage-style listings with no visible AI use policy or statement at the /ai-policy path.
Fix: Publish a clearly labeled AI policy document at /ai-policy explaining OUP's stance on AI use.
-
scope_clear: No explanation of what AI is used for appears anywhere in the page content.
Fix: Add a section describing the specific applications and contexts in which AI is used (e.g., editorial, research, product features).
Privacy
- 1 third-party cookie domain set cookies: .corp.oup.com.
- 3 inline scripts matched a tracker/ad pattern; first match: ' // Define dataLayer and the gtag function. window.dataLayer = window.dataLa…'.
- No hidden iframes detected.
- Detected 4 data-leaking services across 3 categories: cookie consent saas (cdn-ukwest.onetrust.com); google fonts (fonts.googleapis.com, fonts.gstatic.com); google maps (maps.googleapis.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://global.oup.com
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
actionable: The visible page content does not include any concrete contact methods such as an email address, phone number, postal address, or contact form.
Fix: Add direct contact details (e.g., email, phone, postal address, and/or a contact form) on the /contact page so visitors can actually reach the organisation.
-
purpose_clear: The page showcases products, articles, and resources but never clearly states what the organisation does or its purpose.
Fix: Add a concise statement at the top of the about page explaining that OUP is a publishing arm of the University of Oxford and describing its core activities.
-
disclosure_exists: The page content shows no funding or sponsorship disclosure, only general OUP marketing and editorial content.
Fix: Add a dedicated funding disclosure section at /funding that identifies any sponsors, grants, or financial supporters of the organization's activities.
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly name each funding source (e.g., foundations, government grants, parent organization contributions) on the funding page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only generic links like 'Press Office' and 'Contact us' without identifying a named person or specific role responsible.
Fix: Add the name or role title (e.g., Head of Communications) of the person accountable for enquiries on the contact page.
-
response_timeframe: The page contains no mention of any response timeframe for complaints; it only shows general homepage content like news articles and product highlights.
Fix: Publish an explicit response timeframe for complaints (e.g., 'We will acknowledge your complaint within 5 business days') on the /complaints page.
-
specific: No timeframes, specific or vague, are provided anywhere on the page.
Fix: State specific, measurable timeframes in days (e.g., acknowledgement within 5 business days, resolution within 30 days) rather than vague terms like 'promptly'.
-
process_exists: Despite the /complaints path, the page shows only generic homepage content with no documented complaints or feedback process.
Fix: Add a dedicated complaints procedure section describing how complaints are received, reviewed, escalated, and resolved.
-
steps_clear: No steps for making a complaint are shown—there is only a generic 'Contact us' link in the footer.
Fix: Provide a clear numbered list of steps (how to submit, what to include, who handles it, how you'll be updated, and escalation options) for filing a complaint.
-
appeals_exists: The page content shows no documented appeals process; it contains marketing content, news articles, and footer links without any appeals policy.
Fix: Publish a dedicated appeals page outlining the steps, timelines, and contact details for submitting and handling appeals.
-
independent: No appeals process is described, so there is no indication of independent review or escalation paths.
Fix: Define and disclose an independent or escalated review mechanism (e.g., an external ombudsperson or senior review panel) within the appeals documentation.
AI & Automation
-
detailed_scope: The page contains no detailed description of the scope of AI use, only marketing and news items.
Fix: Include a detailed scope section specifying systems, data, and workflows where AI is or is not applied.
-
limitations: No acknowledgment of AI limitations (e.g., accuracy, bias, hallucinations) is present on the page.
Fix: Add a subsection openly acknowledging known limitations such as potential inaccuracies, bias, and lack of contextual understanding.
-
safeguards: The page does not describe any safeguards, human oversight, or quality controls related to AI.
Fix: Document concrete safeguards such as human review processes, quality assurance checks, and governance oversight for AI outputs.
-
marking_policy: The page contains no AI policy content or any statement about how AI-assisted content is marked or labeled.
Fix: Publish a clear policy at /ai-policy describing how AI-assisted content is labeled (e.g., visible tags or disclosures on affected pages).
-
consistent: No AI content markings are visible on the page, so consistent application cannot be demonstrated.
Fix: Apply standardized AI-content labels across all articles and portfolio items and show examples on the policy page.
-
oversight_exists: The page does not document any human oversight of AI outputs despite being at the /ai-policy path.
Fix: Add an explicit section describing human oversight of AI-generated outputs, including who reviews them and when.
-
review_process: No review or approval workflow for AI content is described anywhere on the page.
Fix: Document the end-to-end review/approval process for AI-assisted content, including editorial checkpoints and sign-off criteria.
-
accountability: No individual, role, or team is named as accountable for AI-generated content on the page.
Fix: Identify an accountable owner (e.g., an editorial or AI governance lead) and provide contact details for AI-related concerns.
Interoperability
Privacy
-
comprehensive: The sections listing what data is collected and how it is shared appear to be empty bullet introductions (e.g., 'This information includes:' with no following list), so the policy fails to actually enumerate data collected or recipients.
Fix: Populate the bulleted lists under 'What information does OUP collect?', 'How does OUP use your information?', and 'How will OUP share your information?' with the specific categories of data, purposes, and third-party recipients.
-
understandable: Because the lists enumerating what data is collected, how it is used, and with whom it is shared are missing, a non-expert cannot actually tell what data is collected or why.
Fix: Add the missing enumerations of data categories, purposes, and recipients in plain language so non-expert readers can understand specifics.
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary; it only says data is kept as long as 'reasonably necessary' for retention purposes.
Fix: Add an explicit data minimization statement affirming that OUP collects only the personal information necessary for the stated purposes.
-
proportionate: There is no statement addressing proportionality of data collection relative to the services provided, and without the enumerated data list proportionality cannot be assessed.
Fix: Include a clear statement that data collected is proportionate to each service, and list the specific data tied to each processing purpose.
-
specific: Retention is described only in vague terms ('as long as is reasonably necessary') without specific time periods or criteria per data category.
Fix: Provide specific retention periods or concrete criteria for each category of personal data (e.g., 'account data retained for 3 years after last activity').
-
equal_choices: The page references a Cookie Policy for consent but does not demonstrate on this page that accept and reject options are equally prominent in the consent mechanism.
Fix: Ensure the cookie consent banner provides a 'Reject All' button with equal visual prominence (same size, color, and placement) as the 'Accept All' button.
-
partner_sharing_mentioned: The banner only mentions OUP's use of cookies to enhance experience and does not disclose data sharing with third-party partners.
Fix: Update the banner copy to explicitly state whether cookies share data with third-party partners and link to a list of those partners.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the banner or linked consent interface.
Provenance
- No author or date metadata found on the page.
-
authorship_clear: The page lists articles and products but does not identify the individual authors or curators of the content.
Fix: Add bylines to articles and name the editorial team or department responsible for curating the about page content.
-
credentials: No author credentials or detailed organisational background are provided on this page beyond the Oxford University Press brand name.
Fix: Include a clear organisational overview of Oxford University Press with its history, mission, and governance, plus credentials for contributing authors.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries—only generic 'Contact us' and 'Press Office' links are shown.
Fix: Identify the responsible individual or team (e.g., 'Customer Services Team, led by Jane Doe') handling contact enquiries.
-
role_clear: The page does not state the role or authority of who handles enquiries beyond ambiguous labels.
Fix: Clearly describe the role and remit of the contact team (e.g., 'Press Office handles media enquiries; Customer Services handles orders').
-
substantive: The page lacks any substantive statement of purpose, offering only promotional snippets and article listings.
Fix: Write a detailed purpose section covering OUP's publishing activities, audiences served, and the value it provides.
-
mission_clear: No mission statement or editorial approach is articulated anywhere on the page.
Fix: Publish a clear mission statement describing OUP's commitment to research, education, and scholarship, along with its editorial standards.
-
detail: The page provides no amounts, percentages, or categories of funding whatsoever.
Fix: Include specific detail such as dollar amounts, percentage breakdowns, or categorized funding streams (e.g., sales revenue, endowments, grants) in the disclosure.
-
complete: Since no funding information is present, the disclosure cannot be said to cover all major funding streams.
Fix: Publish a comprehensive list of every major funding stream supporting OUP's operations, ensuring no significant source is omitted.
-
governance_exists: The page does not describe the governance or editorial structure of Oxford University Press, only mentioning 'Delegates of the Press' as a link without explanation.
Fix: Add a dedicated governance section on the About page explaining the editorial and organizational structure, including the role of the Delegates of the Press.
-
roles_clear: Key roles and responsibilities of leadership, editors, or governing bodies are not identified anywhere on the page.
Fix: Include a leadership/governance subsection that names key roles (e.g., Secretary to the Delegates, Board members, editorial leads) and outlines their responsibilities.
-
algorithm_explained: The page mentions content 'chosen for you' in the Portfolio section, implying algorithmic curation, but does not explain the algorithm's purpose.
Fix: Add a brief explanation describing how and why content is selected/personalized for users in the 'chosen for you' Portfolio feature.
-
impact_clear: There is no description of how algorithmic selection of portfolio highlights or featured content affects what users see or experience.
Fix: Include a statement outlining the impact of algorithmic curation on users, such as what content may be shown or hidden based on automated decisions.
-
annual_statement: The page links to a Privacy Policy and Annual Report in the footer but shows no evidence on this page of a regular or annual data practices review.
Fix: Add a brief statement (or link) indicating when the privacy/data practices were last reviewed and commit to an annual review cadence.
-
dated: No date or version information is visible for the privacy policy or data practices statement on this page.
Fix: Display a 'last updated' date or version number alongside the Privacy Policy link in the footer.
Level 3 — Advanced
Accessibility
-
statement_exists: Although the page path is /accessibility-statement, the visible content is generic OUP homepage material with no actual accessibility statement text present.
Fix: Publish a dedicated accessibility statement at this URL describing the site's conformance level (e.g., WCAG 2.1 AA) and commitment to accessibility.
-
known_issues: The page contains no acknowledgement of any known accessibility issues or limitations.
Fix: Add a section listing known accessibility barriers and any content that is not yet fully accessible.
-
remediation_timeline: There is no timeline or commitment stated for fixing accessibility issues anywhere on the page.
Fix: Include target dates or a stated commitment for remediating the identified accessibility issues.
-
feedback_channel: The page only offers a generic 'Contact us' link with no accessibility-specific feedback mechanism or response commitment.
Fix: Provide a dedicated accessibility contact (email/phone/form) along with a stated response time commitment.
Accountability
-
policy_exists: The /moderation page contains no moderation policy content, only general OUP homepage-style listings of articles and products.
Fix: Publish a dedicated moderation policy document on this page outlining what content is moderated and under what rules.
-
criteria_clear: No moderation criteria (e.g., prohibited content, standards for acceptable contributions) are stated anywhere on the page.
Fix: Add a clearly labeled section listing specific criteria such as prohibited behaviors, content standards, and examples of violations.
-
enforcement: There is no explanation of how moderation is enforced, who enforces it, or what actions follow violations.
Fix: Include an enforcement section describing the review workflow, responsible team, possible sanctions, and an appeals or contact process.
Interoperability
Security
-
plan_exists: The page is the OUP homepage content with no published incident response plan or policy despite the /incident-response path.
Fix: Publish a dedicated incident response plan or policy document describing how security incidents are detected, managed, and resolved.
-
notification_commitment: There is no statement committing to public notification of significant security incidents anywhere on the page.
Fix: Add an explicit commitment to notify affected users and the public when significant incidents occur.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming an incident).
-
policy_exists: Despite the /bug-bounty path, the page content is Oxford University Press's general homepage with no published responsible-disclosure or bug-bounty policy present.
Fix: Publish a dedicated responsible-disclosure/bug-bounty policy page describing scope, rules, and how vulnerabilities are handled.
-
clear_contact: The page only lists generic 'Contact us' and 'Press Office' links with no security-specific reporting channel such as a security@ email or vulnerability report form.
Fix: Add a dedicated security contact (e.g., security@oup.com or a report form) and consider a security.txt file for vulnerability reporting.
-
safe_harbour_or_reward: There is no mention of safe harbour protections or any reward/bounty structure for security researchers anywhere on the page.
Fix: Include explicit safe-harbour language protecting good-faith researchers and, if applicable, describe any reward or recognition structure.
Transparency
-
criteria_published: No specific criteria are published for how items like the Portfolio highlights or featured articles are selected.
Fix: Publish the specific criteria (e.g., popularity, region, user behavior) used to select algorithmically curated content on the page.
-
weighting: The page provides no information about weighting or prioritization of any selection criteria for featured content.
Fix: Disclose the relative weight or priority given to each selection criterion used in algorithmic curation.
-
auditable: The page lacks any technical or procedural detail sufficient for an external party to audit the algorithmic selection processes.
Fix: Provide documentation such as a transparency report or methodology page with enough detail to enable external audit of algorithmic decisions.
-
open_source: There is no link to source code or any open-source repository on the page.
Fix: If applicable, link to public repositories (e.g., GitHub) for any open-source tools or components used by the site.
-
tech_docs: No technical documentation is referenced or linked from the page.
Fix: Provide a developer or technical documentation section, for example API docs for Oxford services or data feeds.
Responsibility to the Future
-
disclosure_exists: Although the page is at a /sustainability path and one article is tagged 'Sustainability', the content shows only blog and product promotions with no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated environmental/sustainability disclosure or report on this page describing the organization's environmental impact and commitments.
-
specific_metrics: The page contains no specific figures on carbon emissions, energy use, or any other environmental metric.
Fix: Add quantified environmental metrics such as annual carbon emissions (tCO2e), energy consumption, and reduction targets.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or infrastructure.
Fix: Disclose the hosting provider's energy sources or carbon footprint, for example by stating whether servers run on renewable energy.
-
plan_exists: The page shows blog content, portfolio highlights, and corporate links but contains no published plan describing what happens if the organisation fails or exits.
Fix: Publish a continuity or succession plan document outlining what happens to services and operations in the event of organisational failure or exit, and link to it prominently.
-
data_and_content_fate: There is no mention of what would happen to user data or published content should the organisation cease operations, only marketing and editorial material.
Fix: Add a section explaining how user data and published content would be preserved, transferred, or handled if the organisation shuts down.
-
custodians_or_mirrors: The page identifies no custodians, mirror sites, or archive partners responsible for preserving content beyond regional OUP sites and social channels.
Fix: Name a designated archive partner, custodian institution, or mirror repository (e.g., a digital preservation service) tasked with maintaining content long-term.
-
policy_exists: The page is a publishing/content landing page featuring reports, blog posts, and product highlights with no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the 'Working with us' page.
-
specific_commitments: The content contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit, measurable commitments on pay, working hours, mental health support, and benefits within a worker wellbeing policy.
-
accountability: No named role, committee, or oversight body responsible for worker conditions is identified anywhere on the page.
Fix: Name the individual, team, or governance body accountable for worker conditions and describe their oversight responsibilities.