Pan Macmillan
https://www.panmacmillan.com · 53/92 checks passed · publishers
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 31/37 (6 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 1/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 2/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 11/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-hidden-focus, list, nested-interactive.
- 3 WCAG 2.1 Level A violations reported by axe-core: aria-hidden-focus, list, nested-interactive.
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish a dedicated AI use policy page and link it from the site footer alongside other policies like the Code of Conduct.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for.
Fix: Include a clear scope section in the AI policy describing where and how AI is used across editorial, marketing, or operational activities.
- Not found at any of: /ai-policy, /ai.
Privacy
- Detected 2 data-leaking services across 1 category: adobe fonts (p.typekit.net, use.typekit.net).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.panmacmillan.com
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only generic email addresses (e.g., webqueries@macmillan.co.uk, compliance@macmillan.com) and no named individual or specific role/team responsible for enquiries.
Fix: Identify a specific role or team (e.g., 'Customer Services Team Lead' or a named contact) responsible for handling each category of enquiry.
-
process_exists: The contact page lists various query email addresses but does not document a formal complaints or feedback process.
Fix: Add a dedicated complaints/feedback procedure section explaining how to lodge a complaint, who handles it, and what to expect.
-
steps_clear: Because no complaints process is defined, there are no clear numbered or sequential steps for making a complaint.
Fix: Publish clear step-by-step instructions (e.g., step 1 contact X, step 2 escalate to Y, step 3 expected response time) for submitting and escalating complaints.
-
appeals_exists: The contact page lists FAQ topics and email addresses but does not document any formal appeals process for decisions such as rights denials, manuscript rejections, or faults handling.
Fix: Add a clearly labeled 'Appeals' section describing how users can formally challenge a decision, including required information, submission channel, and expected timeframe.
-
independent: No escalation path or independent reviewer is mentioned; all queries route back to general Pan Macmillan inboxes with no secondary or impartial review body.
Fix: Define an escalation route to an independent reviewer or senior compliance contact (e.g., compliance@macmillan.com with clear remit) so appeals are not handled solely by the original decision-maker.
AI & Automation
-
detailed_scope: No AI policy exists on the page, so the scope of AI use is not detailed.
Fix: Add a detailed AI scope statement specifying use cases, data sources, and departments involved in AI-related activities.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include a section in the AI policy outlining known limitations such as potential inaccuracies, bias, or unsuitability for certain content decisions.
-
safeguards: No safeguards or quality controls for AI use are described on the page.
Fix: Describe human review processes, approval workflows, and quality assurance measures used to oversee AI outputs in a published AI policy.
-
marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or disclosed.
Fix: Publish a clear AI content disclosure policy explaining how AI-assisted text, images, or audio are labelled on the site and in publications.
-
consistent: Without any AI marking policy visible on the page, there is no evidence that AI content marking is applied consistently.
Fix: Adopt a standard AI-content label (e.g., 'AI-assisted') and apply it uniformly across articles, book descriptions, and marketing copy where relevant.
-
oversight_exists: The page does not document any human oversight mechanism for AI outputs.
Fix: Add a statement to the About or Code of Conduct pages describing how humans review AI-generated or AI-assisted content before publication.
-
review_process: No review or approval process for AI-generated content is described anywhere on the page.
Fix: Publish a short description of the editorial workflow for AI outputs, including review steps, quality checks, and approval gates.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content on the page.
Fix: Name an accountable role (e.g., Editorial Director or AI Governance Lead) responsible for AI-generated content and include contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible content does not explicitly state that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit data minimisation statement affirming that only personal information necessary for the described purposes is collected.
-
retention_stated: The visible content does not mention how long personal information is retained.
Fix: Add a dedicated 'Data retention' section describing how long each category of personal data is kept.
-
specific: No specific retention periods (e.g., months or years) are given anywhere in the visible notice.
Fix: Specify concrete retention durations per data type, such as 'newsletter subscriber data kept for 24 months of inactivity before deletion'.
-
equal_choices: The page does not display a consent interface showing accept and reject options, so equal prominence of choices cannot be verified on this privacy notice.
Fix: Ensure the cookie/consent banner (referenced via the Cookies Policy) presents 'Accept' and 'Reject' buttons with equal visual prominence and link to it from this notice.
-
banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' link appears in the footer.
Fix: Implement a visible cookie consent banner that appears on first visit with clear accept/reject options.
-
partner_sharing_mentioned: No banner or on-page consent copy discloses data sharing with third-party partners.
Fix: Add explicit disclosure in the consent banner stating that data may be shared with named third-party partners for analytics/advertising.
-
partner_count_specific: No specific numeric count of partners is stated anywhere on the page since partner sharing is not disclosed.
Fix: Include a specific count of third-party partners (e.g., 'We share data with X partners') with a link to the full partner list in the consent banner.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified; only generic functional mailboxes like webqueries@macmillan.co.uk and faults@macmillan.co.uk are listed.
Fix: Add the name of the responsible team (e.g., 'Customer Enquiries Team', 'Rights & Permissions Department') or a named contact for each enquiry type.
-
detail: The ownership mention lacks any meaningful detail such as ownership percentages, investment amounts, or revenue categories.
Fix: Add specifics about the ownership structure (e.g., percentage held by Holtzbrinck, revenue breakdown by imprint or region) to provide meaningful funding detail.
-
complete: The disclosure only references the parent owners and omits other potential funding streams such as book sales revenue, licensing, grants, or partnerships.
Fix: Expand the disclosure to cover all major funding streams (sales, licensing, partnerships, parent-company investment) for a complete picture.
-
roles_clear: While teams (editors, designers, production, finance) are mentioned in passing, no specific roles, responsibilities, or named leadership positions are identified on this page.
Fix: Add a section (or link to the Leadership team page) that names key executives and outlines their responsibilities, including editorial governance and decision-making roles.
-
algorithm_explained: The About page describes the company history and mission but makes no mention of any algorithms or their purpose.
Fix: Add a section (or link to one) describing any algorithms used on the site, such as for book recommendations or search ranking, and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users (e.g., what they see or are recommended) anywhere on this page.
Fix: Include a clear statement of how algorithmic outputs influence user experience, such as personalized recommendations or content ordering.
-
annual_statement: The page links to a Privacy Notice but provides no evidence of a regular or annual review of data practices.
Fix: Add a statement to the Privacy Notice indicating that data practices are reviewed on a defined periodic (e.g., annual) basis and note the last review date.
-
dated: The footer links to a Privacy Notice but the visible page shows no date or version for the data practices statement.
Fix: Include a clearly visible 'Last updated' date or version number on the Privacy Notice and reference it from the About page.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement mentions an initiated project to review and update the backlist catalogue but provides no target date or timeframe for completion.
Fix: Add a specific timeline or milestone commitment (e.g., target completion year) for the backlist e-book remediation project.
-
feedback_channel: A feedback email (panmac.accessibility@macmillan.com) is provided but there is no stated commitment to respond within a defined timeframe.
Fix: State a response commitment alongside the feedback email, such as a promise to acknowledge or respond to accessibility feedback within a set number of business days.
Accountability
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is an 'About Us' page describing the publisher's history and mission, with no published incident response plan or security policy anywhere in the content or footer links.
Fix: Publish a dedicated incident response plan or security policy and link to it from the site footer alongside the other policy documents.
-
notification_commitment: There is no statement anywhere on the page committing to publicly notify users of significant security incidents.
Fix: Add explicit language to a security/incident policy committing to notify affected users and the public when significant incidents occur.
-
timeframe: The page states no timeframe for disclosing incidents to affected users, as it contains no incident-related content at all.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
Fix: Publish a list of the specific inputs and criteria (e.g., browsing history, genre, popularity) used by any algorithms on the site.
-
weighting: No information about the weighting or relative priority of any algorithmic criteria is provided.
Fix: Document how each criterion is weighted or prioritized in algorithmic decisions, even at a high level.
-
auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
Fix: Provide an algorithmic transparency report or contact route for independent auditors with sufficient methodological detail to enable review.
-
open_source: The page contains no links to any public source code repository for the site.
Fix: Publish the website's source code (or relevant components) in a public repository such as GitHub and link to it from the about or footer area.
-
tech_docs: No technical documentation about the site's platform, APIs, or data formats is published or linked on the page.
Fix: Add a developer or technical documentation page describing the site's technology, any APIs, and data feeds, and link it from the footer.
Responsibility to the Future
-
specific_metrics: The page mentions sustainability aspirations but provides no specific figures for carbon, energy use, or emissions.
Fix: Publish concrete environmental metrics such as annual carbon emissions, energy consumption, and reduction targets with measurable baselines.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing whether the site is hosted on green/renewable-powered infrastructure and its associated carbon or energy footprint.
-
plan_exists: The page describes company history, mission and imprints but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan outlining what happens to the business and its publishing operations in the event of organisational failure or exit.
-
data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased operating.
Fix: Add a statement specifying how user data and published content would be preserved, transferred, or retired if the company winds down.
-
custodians_or_mirrors: The page names owners and imprints but identifies no custodians, mirrors, or archive partners for content continuity.
Fix: Name specific custodians, archive partners, or mirror arrangements that would safeguard content should the organisation cease to operate.
-
policy_exists: The page describes workplace culture and wellbeing aspirations in general terms but does not link or reference any published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers page.
-
specific_commitments: The page mentions valuing wellbeing and satisfaction but provides no specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete, measurable commitments covering pay standards, working hours, mental health support, and employee benefits.
-
accountability: The page names a sustainability team and Green Group but identifies no accountable owner or oversight body for worker conditions or wellbeing.
Fix: Name a responsible role, team, or governance body accountable for overseeing worker conditions and reporting on wellbeing outcomes.