Penguin Random House UK

https://www.penguin.co.uk · 36/92 checks passed · publishers

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 23/37 (14 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (10 failed)

By category

CategoryResult
Accessibility 8/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 6/16
Provenance 1/2
Security 6/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About Us page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish an AI use policy page and link to it from the footer alongside the privacy and cookies policies.
  • scope_clear: With no AI policy present, there is no explanation of what AI is used for at Penguin.
    Fix: Include a section in the AI policy describing specific use cases (e.g., editorial, marketing, translation) where AI is or is not applied.

Privacy

Security

Transparency

  • actionable: The page content provides no actual contact details such as email, phone number, or form—only a link that opens in a new tab without visible contact methods on this page.
    Fix: Display direct contact methods (e.g., email address, phone number, or embedded contact form) on the /contact page itself rather than only linking out.
  • disclosure_exists: The page content contains no funding or sponsorship disclosure, only book promotions and corporate information.
    Fix: Add a dedicated funding disclosure section identifying the company's revenue sources and any sponsorships or partnerships.
  • transparent: No funding sources are identified anywhere on the page beyond mention of being a Penguin Random House company.
    Fix: Clearly list funding sources such as parent company investment, book sales revenue, and any external sponsorships.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only the corporate entity 'Penguin Books Limited' with no named individual or specific role (e.g., Data Protection Officer, Customer Service Manager) identified as responsible.
    Fix: Add the name or role title of a specific person or team (e.g., 'Head of Customer Care') accountable for enquiries on the contact page.
  • contactable: Although a 'Contact us' link is referenced, the page content provides no direct email, phone number, or contact form details to actually reach the responsible party.
    Fix: Display a direct contact method such as an email address, phone number, or embedded contact form on the contact page itself.
  • response_timeframe: The page content shown contains no complaints procedure details or any published response timeframes.
    Fix: Publish explicit response timeframes (e.g., acknowledgement within 5 working days, full response within 20 working days) on the complaints procedure page.
  • specific: No specific timeframes in days or weeks are stated anywhere on the page.
    Fix: State concrete time periods in days or weeks for each stage of the complaint handling process rather than vague language.
  • process_exists: Despite the URL path /complaints-procedure, the visible content shows only general homepage/marketing material with no documented complaints or feedback process.
    Fix: Add a clearly documented complaints procedure at this URL describing how complaints are received, handled, and escalated.
  • steps_clear: No step-by-step instructions for making a complaint are present on the page.
    Fix: Provide numbered steps (e.g., 1. Contact customer service, 2. Escalate in writing, 3. Appeal to ombudsman) with contact details for each stage.
  • appeals_exists: The page content shown is generic homepage/navigation content with no documented complaints or appeals procedure visible despite the /complaints-procedure path.
    Fix: Publish a clear complaints procedure page outlining how users can submit complaints, expected response times, and the steps of the appeals process.
  • independent: No information is provided about an independent reviewer or escalation path for complaints that cannot be resolved internally.
    Fix: Document an escalation route to an independent body or senior reviewer (e.g., an ombudsman or external regulator) for unresolved complaints.

AI & Automation

  • detailed_scope: The page does not discuss AI at all, so no detailed scope of AI use is provided.
    Fix: Add a detailed AI scope section enumerating which business processes and products involve AI systems.
  • limitations: No acknowledgement of AI system limitations appears on the page.
    Fix: Include a transparency statement acknowledging known AI limitations such as inaccuracies, bias, or hallucination risks.
  • safeguards: There is no description of safeguards, human review, or quality controls related to AI on the page.
    Fix: Document safeguards such as human-in-the-loop review, author consent policies, and quality assurance procedures in the AI policy.
  • marking_policy: The About Us page contains no policy or statement about marking or labeling AI-assisted content.
    Fix: Publish a clear policy (e.g., in editorial guidelines or a dedicated AI disclosure page) stating how AI-assisted content is identified and labeled.
  • consistent: No AI content markings are visible anywhere on the page, so consistency cannot be demonstrated.
    Fix: Apply standardized AI-assistance labels across all relevant pages and content types once a marking policy is established.
  • oversight_exists: The page does not mention any human oversight framework for AI outputs.
    Fix: Add a statement describing human oversight of any AI use in publishing or site operations, linked from the About or Social Impact section.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Document the editorial review and approval steps that AI-assisted outputs must pass through before publication.
  • accountability: No individual or role is identified as accountable for AI-generated content, despite a detailed leadership team listing.
    Fix: Designate and publicly name an accountable owner (e.g., a member of the leadership team) responsible for AI governance and content.

Interoperability

Privacy

  • plain_language: The provided page content shows only a link to the privacy policy, with no actual policy text visible to assess for plain language.
    Fix: Surface the privacy policy content (or a plain-language summary) directly so users can read it without legal jargon.
  • comprehensive: No privacy policy content is shown on this page beyond a brief signup notice mentioning 'personal data we collect and how we use it', so comprehensiveness cannot be confirmed.
    Fix: Ensure the linked privacy policy explicitly details all categories of data collected, purposes, legal bases, sharing, and user rights, and consider summarising these on-page.
  • plain_language: The only data-practice statement on this page is a brief signup line referring users to the Privacy Policy, with no plain-language description of practices shown.
    Fix: Add a short, jargon-free summary of key data practices (what is collected, why, and how it's used) near signup forms and at the top of the privacy policy.
  • understandable: A non-expert reading this page would not learn what data is collected or why, since only a generic reference to the Privacy Policy is provided.
    Fix: Include a clear, concise explanation (e.g. bullet points) of what data is collected at signup and how it will be used, in everyday language.
  • necessity: The visible page content does not include any statement that data collection is limited to what is necessary.
    Fix: Add an explicit data-minimisation statement to the privacy policy and signup notice confirming only necessary data is collected.
  • proportionate: Without details of what data is collected, proportionality to the newsletter/shop service cannot be demonstrated on this page.
    Fix: Specify the exact data fields collected for each service (e.g. email for newsletter) and explain why each is needed to demonstrate proportionality.
  • retention_stated: No data retention information is stated anywhere in the visible page content.
    Fix: Add a clear retention section to the privacy policy and reference it near signup, stating how long different categories of data are kept.
  • specific: Because no retention periods are mentioned, specific timeframes are absent.
    Fix: State concrete retention periods (e.g. 'newsletter email kept until you unsubscribe' or 'order data retained for 7 years for tax purposes').
  • no_dark_patterns: The newsletter sign-up uses pre-framed language ('By signing up, I confirm that I'm over 16') that bundles age confirmation with consent, and the page content provided shows no visible cookie banner text to assess for manipulative framing.
    Fix: Provide a clearly worded, neutral consent interface (for cookies and newsletter) that separates distinct confirmations and avoids coercive or presumptive language.
  • equal_choices: The page shows a prominent 'Sign up' call-to-action and cookie settings links, but there is no visible 'Reject all' option presented with equal prominence to 'Accept' for cookie consent in the provided content.
    Fix: Ensure the cookie banner presents 'Accept all' and 'Reject all' buttons with equal visual weight, size, and placement on the same layer.
  • no_forced_consent: The newsletter sign-up bundles age confirmation and acceptance of data use for recommendations into a single action without granular opt-ins, suggesting forced/bundled consent.
    Fix: Unbundle consents by offering separate, granular opt-in checkboxes for age confirmation, marketing emails, and personalised recommendations, none of which should be pre-ticked.
  • partner_sharing_mentioned: The banner only mentions using cookies to personalise experience and recommend books, with no disclosure of data sharing with third-party partners.
    Fix: Update the cookie banner copy to explicitly disclose whether and with whom (e.g., advertising or analytics partners) user data is shared.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include an exact number of third-party partners (e.g., 'we share data with X partners') within the banner or linked consent preferences.

Provenance

Security

Transparency

  • named_person: No named individual or specific team (such as 'Customer Services Team' with contact details) is identified for handling enquiries on this page.
    Fix: Identify the specific team or individual (e.g., 'Reader Services Team') responsible for answering enquiries, with their contact details clearly listed.
  • role_clear: Because no person or team is named, their role, remit, or authority in handling enquiries is likewise not stated.
    Fix: Clearly describe the role and scope of the contact team (e.g., 'Our Reader Services team handles general enquiries, complaints, and feedback').
  • detail: The page provides no funding details such as amounts, percentages, or categories of income.
    Fix: Publish a breakdown of funding by category (e.g., sales, licensing, partnerships) with approximate percentages or figures.
  • complete: No funding streams are disclosed at all, so the disclosure cannot be considered complete.
    Fix: Provide a comprehensive list of all major funding streams including parent company support, commercial revenue, and partnership income.
  • algorithm_explained: The About Us page describes Penguin's history and publishing operations but does not mention any algorithms or their purpose.
    Fix: Add a section disclosing any algorithms used (e.g., for book recommendations or personalization) and explain their purpose in plain language.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include a statement explaining how algorithmic decisions (such as recommendations or content ranking) impact users' experience on the site.
  • annual_statement: The page links to a Privacy policy but shows no evidence of an annual or periodic review of data practices.
    Fix: Add a note on the Privacy policy (and reference it here) stating the date of the last review and the cadence of periodic reviews.
  • dated: The page references a Privacy policy link but displays no visible date or version for the data practices statement.
    Fix: Display a 'Last updated' date or version number on the Privacy policy and surface it where privacy is referenced.

Level 3 — Advanced

Accessibility

  • statement_exists: Although the page path is /accessibility-statement, the rendered content is the Penguin homepage with only a footer 'Accessibility' link and no actual accessibility statement text present.
    Fix: Publish a dedicated accessibility statement page with substantive content describing the site's accessibility conformance and commitments.
  • known_issues: The page contains no acknowledgement of any known accessibility issues or limitations.
    Fix: Add a section listing known accessibility barriers, such as areas that are not yet fully WCAG 2.1 AA compliant.
  • remediation_timeline: There is no mention of any timeline or commitment for fixing accessibility issues.
    Fix: Include target dates or a stated commitment for when identified accessibility issues will be remediated.
  • feedback_channel: The page provides no accessibility feedback mechanism or response-time commitment, only a general 'Contact us' link in the footer.
    Fix: Provide a dedicated accessibility contact (email or form) along with a stated timeframe for responding to accessibility feedback.

Accountability

  • policy_exists: The page content shown is the Penguin homepage with no visible moderation policy published at /terms.
    Fix: Publish a clearly labelled moderation policy accessible from the terms or help section of the site.
  • criteria_clear: No moderation criteria (e.g., prohibited content, community guidelines) are stated anywhere on the page.
    Fix: Add a section enumerating specific criteria for acceptable and unacceptable user content.
  • enforcement: There is no explanation of how moderation is enforced, who reviews content, or what actions are taken.
    Fix: Document the enforcement workflow, including reporting channels, review timelines, and possible sanctions.

Interoperability

Security

  • plan_exists: The page at /incident-response contains only Penguin's general homepage content (books, shop, newsletter) with no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or policy document describing how the organization detects, manages, and responds to security incidents.
  • notification_commitment: There is no statement anywhere on the page committing to public notification of significant security incidents.
    Fix: Add an explicit commitment to publicly notify users and relevant authorities when significant security incidents occur.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users, as it contains only marketing and navigational content.
    Fix: State a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a breach) for informing affected users.
  • policy_exists: Despite the /bug-bounty path, the page content is the standard Penguin homepage with no responsible-disclosure or bug-bounty policy present.
    Fix: Publish a dedicated responsible-disclosure or bug-bounty policy page describing scope, reporting process, and expectations for researchers.
  • clear_contact: No security contact channel (such as a security@ email or vulnerability reporting form) appears anywhere on the page.
    Fix: Add a clear security contact, such as a security@penguin.co.uk address or a dedicated vulnerability reporting form, and a security.txt file.
  • safe_harbour_or_reward: The page contains no mention of safe harbour terms or any reward/bounty structure for security researchers.
    Fix: Include explicit safe-harbour language protecting good-faith researchers and clearly state any reward or recognition offered.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making.
    Fix: Publish a clear list of the specific criteria (e.g., user history, popularity, genre) used in any algorithmic decisions on a dedicated transparency page.
  • weighting: No information is provided about how criteria are weighted or prioritized in any algorithm.
    Fix: Disclose the relative weighting or priority of each criterion used in algorithmic decision-making.
  • auditable: The page provides no technical detail, documentation, or audit mechanism for any algorithms.
    Fix: Provide sufficient technical documentation or an audit report so external parties can review how algorithms operate.
  • open_source: No source code repository or open-source links are provided on the page.
    Fix: Add a link to a public repository (e.g., GitHub) if any site components are open source, or state the site's open-source policy.
  • tech_docs: No technical documentation about the site or its platform is referenced on the page.
    Fix: Publish and link to basic technical documentation such as an API reference, data feeds, or developer notes from the About section.

Responsibility to the Future

  • disclosure_exists: Although the page path is /sustainability, the content shown contains only book promotions, shop items, and corporate footer links with no environmental impact or sustainability disclosure present.
    Fix: Publish a dedicated sustainability or environmental impact statement on the /sustainability page describing the company's environmental policies and commitments.
  • specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics anywhere in the content.
    Fix: Add quantified environmental data such as annual carbon emissions, energy consumption, and reduction targets with baseline years.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure or use of renewable-powered data centres.
    Fix: Disclose the hosting provider's energy sourcing and the carbon footprint of the site's infrastructure, ideally noting any green hosting certifications.
  • plan_exists: The page contains only marketing, shop, and corporate links with no published plan describing what happens if Penguin fails or exits.
    Fix: Publish a continuity or wind-down plan describing what would happen to the organisation's services and content in the event of failure or exit.
  • data_and_content_fate: The page references a Privacy Policy for data collection but provides no statement on the fate of user data or published content should the organisation cease operating.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name specific custodians, mirror hosts, or archive partners who would take over preservation of content and data upon exit.
  • policy_exists: The page only links to a 'Modern slavery statement' and 'Careers' but contains no published policy text on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing/working conditions policy page and link to it from the 'Work with us' section.
  • specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to a wellbeing policy.
  • accountability: No individual, team, or oversight body responsible for worker conditions is identified anywhere on the page.
    Fix: Name a responsible role or oversight body (e.g., HR/People director or a wellbeing committee) accountable for monitoring worker conditions.