Pan Macmillan

https://www.panmacmillan.com · 53/92 checks passed · publishers

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 2/5
AI & Automation 3/8
Interoperability 1/3
Privacy 11/16
Provenance 1/2
Security 7/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish a dedicated AI use policy page and link it from the site footer alongside other policies like the Code of Conduct.
  • scope_clear: With no AI policy present, there is no explanation of what AI is used for.
    Fix: Include a clear scope section in the AI policy describing where and how AI is used across editorial, marketing, or operational activities.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic email addresses (e.g., webqueries@macmillan.co.uk, compliance@macmillan.com) and no named individual or specific role/team responsible for enquiries.
    Fix: Identify a specific role or team (e.g., 'Customer Services Team Lead' or a named contact) responsible for handling each category of enquiry.
  • process_exists: The contact page lists various query email addresses but does not document a formal complaints or feedback process.
    Fix: Add a dedicated complaints/feedback procedure section explaining how to lodge a complaint, who handles it, and what to expect.
  • steps_clear: Because no complaints process is defined, there are no clear numbered or sequential steps for making a complaint.
    Fix: Publish clear step-by-step instructions (e.g., step 1 contact X, step 2 escalate to Y, step 3 expected response time) for submitting and escalating complaints.
  • appeals_exists: The contact page lists FAQ topics and email addresses but does not document any formal appeals process for decisions such as rights denials, manuscript rejections, or faults handling.
    Fix: Add a clearly labeled 'Appeals' section describing how users can formally challenge a decision, including required information, submission channel, and expected timeframe.
  • independent: No escalation path or independent reviewer is mentioned; all queries route back to general Pan Macmillan inboxes with no secondary or impartial review body.
    Fix: Define an escalation route to an independent reviewer or senior compliance contact (e.g., compliance@macmillan.com with clear remit) so appeals are not handled solely by the original decision-maker.

AI & Automation

  • detailed_scope: No AI policy exists on the page, so the scope of AI use is not detailed.
    Fix: Add a detailed AI scope statement specifying use cases, data sources, and departments involved in AI-related activities.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Include a section in the AI policy outlining known limitations such as potential inaccuracies, bias, or unsuitability for certain content decisions.
  • safeguards: No safeguards or quality controls for AI use are described on the page.
    Fix: Describe human review processes, approval workflows, and quality assurance measures used to oversee AI outputs in a published AI policy.
  • marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or disclosed.
    Fix: Publish a clear AI content disclosure policy explaining how AI-assisted text, images, or audio are labelled on the site and in publications.
  • consistent: Without any AI marking policy visible on the page, there is no evidence that AI content marking is applied consistently.
    Fix: Adopt a standard AI-content label (e.g., 'AI-assisted') and apply it uniformly across articles, book descriptions, and marketing copy where relevant.
  • oversight_exists: The page does not document any human oversight mechanism for AI outputs.
    Fix: Add a statement to the About or Code of Conduct pages describing how humans review AI-generated or AI-assisted content before publication.
  • review_process: No review or approval process for AI-generated content is described anywhere on the page.
    Fix: Publish a short description of the editorial workflow for AI outputs, including review steps, quality checks, and approval gates.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content on the page.
    Fix: Name an accountable role (e.g., Editorial Director or AI Governance Lead) responsible for AI-generated content and include contact details.

Interoperability

Privacy

  • necessity: The visible content does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit data minimisation statement affirming that only personal information necessary for the described purposes is collected.
  • retention_stated: The visible content does not mention how long personal information is retained.
    Fix: Add a dedicated 'Data retention' section describing how long each category of personal data is kept.
  • specific: No specific retention periods (e.g., months or years) are given anywhere in the visible notice.
    Fix: Specify concrete retention durations per data type, such as 'newsletter subscriber data kept for 24 months of inactivity before deletion'.
  • equal_choices: The page does not display a consent interface showing accept and reject options, so equal prominence of choices cannot be verified on this privacy notice.
    Fix: Ensure the cookie/consent banner (referenced via the Cookies Policy) presents 'Accept' and 'Reject' buttons with equal visual prominence and link to it from this notice.
  • banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' link appears in the footer.
    Fix: Implement a visible cookie consent banner that appears on first visit with clear accept/reject options.
  • partner_sharing_mentioned: No banner or on-page consent copy discloses data sharing with third-party partners.
    Fix: Add explicit disclosure in the consent banner stating that data may be shared with named third-party partners for analytics/advertising.
  • partner_count_specific: No specific numeric count of partners is stated anywhere on the page since partner sharing is not disclosed.
    Fix: Include a specific count of third-party partners (e.g., 'We share data with X partners') with a link to the full partner list in the consent banner.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified; only generic functional mailboxes like webqueries@macmillan.co.uk and faults@macmillan.co.uk are listed.
    Fix: Add the name of the responsible team (e.g., 'Customer Enquiries Team', 'Rights & Permissions Department') or a named contact for each enquiry type.
  • detail: The ownership mention lacks any meaningful detail such as ownership percentages, investment amounts, or revenue categories.
    Fix: Add specifics about the ownership structure (e.g., percentage held by Holtzbrinck, revenue breakdown by imprint or region) to provide meaningful funding detail.
  • complete: The disclosure only references the parent owners and omits other potential funding streams such as book sales revenue, licensing, grants, or partnerships.
    Fix: Expand the disclosure to cover all major funding streams (sales, licensing, partnerships, parent-company investment) for a complete picture.
  • roles_clear: While teams (editors, designers, production, finance) are mentioned in passing, no specific roles, responsibilities, or named leadership positions are identified on this page.
    Fix: Add a section (or link to the Leadership team page) that names key executives and outlines their responsibilities, including editorial governance and decision-making roles.
  • algorithm_explained: The About page describes the company history and mission but makes no mention of any algorithms or their purpose.
    Fix: Add a section (or link to one) describing any algorithms used on the site, such as for book recommendations or search ranking, and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users (e.g., what they see or are recommended) anywhere on this page.
    Fix: Include a clear statement of how algorithmic outputs influence user experience, such as personalized recommendations or content ordering.
  • annual_statement: The page links to a Privacy Notice but provides no evidence of a regular or annual review of data practices.
    Fix: Add a statement to the Privacy Notice indicating that data practices are reviewed on a defined periodic (e.g., annual) basis and note the last review date.
  • dated: The footer links to a Privacy Notice but the visible page shows no date or version for the data practices statement.
    Fix: Include a clearly visible 'Last updated' date or version number on the Privacy Notice and reference it from the About page.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement mentions an initiated project to review and update the backlist catalogue but provides no target date or timeframe for completion.
    Fix: Add a specific timeline or milestone commitment (e.g., target completion year) for the backlist e-book remediation project.
  • feedback_channel: A feedback email (panmac.accessibility@macmillan.com) is provided but there is no stated commitment to respond within a defined timeframe.
    Fix: State a response commitment alongside the feedback email, such as a promise to acknowledge or respond to accessibility feedback within a set number of business days.

Accountability

Interoperability

Security

  • plan_exists: The page is an 'About Us' page describing the publisher's history and mission, with no published incident response plan or security policy anywhere in the content or footer links.
    Fix: Publish a dedicated incident response plan or security policy and link to it from the site footer alongside the other policy documents.
  • notification_commitment: There is no statement anywhere on the page committing to publicly notify users of significant security incidents.
    Fix: Add explicit language to a security/incident policy committing to notify affected users and the public when significant incidents occur.
  • timeframe: The page states no timeframe for disclosing incidents to affected users, as it contains no incident-related content at all.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
    Fix: Publish a list of the specific inputs and criteria (e.g., browsing history, genre, popularity) used by any algorithms on the site.
  • weighting: No information about the weighting or relative priority of any algorithmic criteria is provided.
    Fix: Document how each criterion is weighted or prioritized in algorithmic decisions, even at a high level.
  • auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
    Fix: Provide an algorithmic transparency report or contact route for independent auditors with sufficient methodological detail to enable review.
  • open_source: The page contains no links to any public source code repository for the site.
    Fix: Publish the website's source code (or relevant components) in a public repository such as GitHub and link to it from the about or footer area.
  • tech_docs: No technical documentation about the site's platform, APIs, or data formats is published or linked on the page.
    Fix: Add a developer or technical documentation page describing the site's technology, any APIs, and data feeds, and link it from the footer.

Responsibility to the Future

  • specific_metrics: The page mentions sustainability aspirations but provides no specific figures for carbon, energy use, or emissions.
    Fix: Publish concrete environmental metrics such as annual carbon emissions, energy consumption, and reduction targets with measurable baselines.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing whether the site is hosted on green/renewable-powered infrastructure and its associated carbon or energy footprint.
  • plan_exists: The page describes company history, mission and imprints but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan outlining what happens to the business and its publishing operations in the event of organisational failure or exit.
  • data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased operating.
    Fix: Add a statement specifying how user data and published content would be preserved, transferred, or retired if the company winds down.
  • custodians_or_mirrors: The page names owners and imprints but identifies no custodians, mirrors, or archive partners for content continuity.
    Fix: Name specific custodians, archive partners, or mirror arrangements that would safeguard content should the organisation cease to operate.
  • policy_exists: The page describes workplace culture and wellbeing aspirations in general terms but does not link or reference any published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers page.
  • specific_commitments: The page mentions valuing wellbeing and satisfaction but provides no specific commitments on pay, hours, mental health, or benefits.
    Fix: Add concrete, measurable commitments covering pay standards, working hours, mental health support, and employee benefits.
  • accountability: The page names a sustainability team and Green Group but identifies no accountable owner or oversight body for worker conditions or wellbeing.
    Fix: Name a responsible role, team, or governance body accountable for overseeing worker conditions and reporting on wellbeing outcomes.