Penguin Random House UK
https://www.penguin.co.uk · 36/92 checks passed · publishers
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 23/37 (14 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (10 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 8/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 6/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: image-alt.
- 1 WCAG 2.1 Level A violation reported by axe-core: image-alt.
- 2 images missing alt attribute: https://www.penguin.co.uk/_next/image?url=https%3A%2F%2Fwp.penguin.co.uk%2Fwp-content%2Fuploads%2F2025%2F01%2Fquiz-classics-768x512.png&w=3840&q=100, https://www.penguin.co.uk/_next/image?url=https%3A%2F%2Fwp.penguin.co.uk%2Fwp-content%2Fuploads%2F2022%2F08%2FBook-club-books-2026-Penguin-2-768x512.jpg&w=3840&q=100.
- 2 images missing alt attribute: https://www.penguin.co.uk/_next/image?url=https%3A%2F%2Fwp.penguin.co.uk%2Fwp-content%2Fuploads%2F2025%2F01%2Fquiz-classics-768x512.png&w=3840&q=100, https://www.penguin.co.uk/_next/image?url=https%3A%2F%2Fwp.penguin.co.uk%2Fwp-content%2Fuploads%2F2022%2F08%2FBook-club-books-2026-Penguin-2-768x512.jpg&w=3840&q=100.
AI & Automation
-
policy_exists: The About Us page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish an AI use policy page and link to it from the footer alongside the privacy and cookies policies.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for at Penguin.
Fix: Include a section in the AI policy describing specific use cases (e.g., editorial, marketing, translation) where AI is or is not applied.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 third-party cookie domain set cookies: .wp.penguin.co.uk.
- No hidden iframes detected.
FAIL
No tracking pixels
- 1 1×1 third-party tracking pixel: https://wp.penguin.co.uk/wp-content/uploads/2022/05/Frame-1-e1738153284717.png?w=98&q=100.
- Detected 1 data-leaking service across 1 category: cookie consent saas (cdn-ukwest.onetrust.com).
PASS
Session cookies only
Security
- Redirect chain (1 hops): https://www.penguin.co.uk
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
actionable: The page content provides no actual contact details such as email, phone number, or form—only a link that opens in a new tab without visible contact methods on this page.
Fix: Display direct contact methods (e.g., email address, phone number, or embedded contact form) on the /contact page itself rather than only linking out.
-
disclosure_exists: The page content contains no funding or sponsorship disclosure, only book promotions and corporate information.
Fix: Add a dedicated funding disclosure section identifying the company's revenue sources and any sponsorships or partnerships.
-
transparent: No funding sources are identified anywhere on the page beyond mention of being a Penguin Random House company.
Fix: Clearly list funding sources such as parent company investment, book sales revenue, and any external sponsorships.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only the corporate entity 'Penguin Books Limited' with no named individual or specific role (e.g., Data Protection Officer, Customer Service Manager) identified as responsible.
Fix: Add the name or role title of a specific person or team (e.g., 'Head of Customer Care') accountable for enquiries on the contact page.
-
contactable: Although a 'Contact us' link is referenced, the page content provides no direct email, phone number, or contact form details to actually reach the responsible party.
Fix: Display a direct contact method such as an email address, phone number, or embedded contact form on the contact page itself.
-
response_timeframe: The page content shown contains no complaints procedure details or any published response timeframes.
Fix: Publish explicit response timeframes (e.g., acknowledgement within 5 working days, full response within 20 working days) on the complaints procedure page.
-
specific: No specific timeframes in days or weeks are stated anywhere on the page.
Fix: State concrete time periods in days or weeks for each stage of the complaint handling process rather than vague language.
-
process_exists: Despite the URL path /complaints-procedure, the visible content shows only general homepage/marketing material with no documented complaints or feedback process.
Fix: Add a clearly documented complaints procedure at this URL describing how complaints are received, handled, and escalated.
-
steps_clear: No step-by-step instructions for making a complaint are present on the page.
Fix: Provide numbered steps (e.g., 1. Contact customer service, 2. Escalate in writing, 3. Appeal to ombudsman) with contact details for each stage.
-
appeals_exists: The page content shown is generic homepage/navigation content with no documented complaints or appeals procedure visible despite the /complaints-procedure path.
Fix: Publish a clear complaints procedure page outlining how users can submit complaints, expected response times, and the steps of the appeals process.
-
independent: No information is provided about an independent reviewer or escalation path for complaints that cannot be resolved internally.
Fix: Document an escalation route to an independent body or senior reviewer (e.g., an ombudsman or external regulator) for unresolved complaints.
AI & Automation
-
detailed_scope: The page does not discuss AI at all, so no detailed scope of AI use is provided.
Fix: Add a detailed AI scope section enumerating which business processes and products involve AI systems.
-
limitations: No acknowledgement of AI system limitations appears on the page.
Fix: Include a transparency statement acknowledging known AI limitations such as inaccuracies, bias, or hallucination risks.
-
safeguards: There is no description of safeguards, human review, or quality controls related to AI on the page.
Fix: Document safeguards such as human-in-the-loop review, author consent policies, and quality assurance procedures in the AI policy.
-
marking_policy: The About Us page contains no policy or statement about marking or labeling AI-assisted content.
Fix: Publish a clear policy (e.g., in editorial guidelines or a dedicated AI disclosure page) stating how AI-assisted content is identified and labeled.
-
consistent: No AI content markings are visible anywhere on the page, so consistency cannot be demonstrated.
Fix: Apply standardized AI-assistance labels across all relevant pages and content types once a marking policy is established.
-
oversight_exists: The page does not mention any human oversight framework for AI outputs.
Fix: Add a statement describing human oversight of any AI use in publishing or site operations, linked from the About or Social Impact section.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Document the editorial review and approval steps that AI-assisted outputs must pass through before publication.
-
accountability: No individual or role is identified as accountable for AI-generated content, despite a detailed leadership team listing.
Fix: Designate and publicly name an accountable owner (e.g., a member of the leadership team) responsible for AI governance and content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
plain_language: The provided page content shows only a link to the privacy policy, with no actual policy text visible to assess for plain language.
Fix: Surface the privacy policy content (or a plain-language summary) directly so users can read it without legal jargon.
-
comprehensive: No privacy policy content is shown on this page beyond a brief signup notice mentioning 'personal data we collect and how we use it', so comprehensiveness cannot be confirmed.
Fix: Ensure the linked privacy policy explicitly details all categories of data collected, purposes, legal bases, sharing, and user rights, and consider summarising these on-page.
-
plain_language: The only data-practice statement on this page is a brief signup line referring users to the Privacy Policy, with no plain-language description of practices shown.
Fix: Add a short, jargon-free summary of key data practices (what is collected, why, and how it's used) near signup forms and at the top of the privacy policy.
-
understandable: A non-expert reading this page would not learn what data is collected or why, since only a generic reference to the Privacy Policy is provided.
Fix: Include a clear, concise explanation (e.g. bullet points) of what data is collected at signup and how it will be used, in everyday language.
-
necessity: The visible page content does not include any statement that data collection is limited to what is necessary.
Fix: Add an explicit data-minimisation statement to the privacy policy and signup notice confirming only necessary data is collected.
-
proportionate: Without details of what data is collected, proportionality to the newsletter/shop service cannot be demonstrated on this page.
Fix: Specify the exact data fields collected for each service (e.g. email for newsletter) and explain why each is needed to demonstrate proportionality.
-
retention_stated: No data retention information is stated anywhere in the visible page content.
Fix: Add a clear retention section to the privacy policy and reference it near signup, stating how long different categories of data are kept.
-
specific: Because no retention periods are mentioned, specific timeframes are absent.
Fix: State concrete retention periods (e.g. 'newsletter email kept until you unsubscribe' or 'order data retained for 7 years for tax purposes').
-
no_dark_patterns: The newsletter sign-up uses pre-framed language ('By signing up, I confirm that I'm over 16') that bundles age confirmation with consent, and the page content provided shows no visible cookie banner text to assess for manipulative framing.
Fix: Provide a clearly worded, neutral consent interface (for cookies and newsletter) that separates distinct confirmations and avoids coercive or presumptive language.
-
equal_choices: The page shows a prominent 'Sign up' call-to-action and cookie settings links, but there is no visible 'Reject all' option presented with equal prominence to 'Accept' for cookie consent in the provided content.
Fix: Ensure the cookie banner presents 'Accept all' and 'Reject all' buttons with equal visual weight, size, and placement on the same layer.
-
no_forced_consent: The newsletter sign-up bundles age confirmation and acceptance of data use for recommendations into a single action without granular opt-ins, suggesting forced/bundled consent.
Fix: Unbundle consents by offering separate, granular opt-in checkboxes for age confirmation, marketing emails, and personalised recommendations, none of which should be pre-ticked.
-
partner_sharing_mentioned: The banner only mentions using cookies to personalise experience and recommend books, with no disclosure of data sharing with third-party partners.
Fix: Update the cookie banner copy to explicitly disclose whether and with whom (e.g., advertising or analytics partners) user data is shared.
-
partner_count_specific: No specific numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Include an exact number of third-party partners (e.g., 'we share data with X partners') within the banner or linked consent preferences.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team (such as 'Customer Services Team' with contact details) is identified for handling enquiries on this page.
Fix: Identify the specific team or individual (e.g., 'Reader Services Team') responsible for answering enquiries, with their contact details clearly listed.
-
role_clear: Because no person or team is named, their role, remit, or authority in handling enquiries is likewise not stated.
Fix: Clearly describe the role and scope of the contact team (e.g., 'Our Reader Services team handles general enquiries, complaints, and feedback').
-
detail: The page provides no funding details such as amounts, percentages, or categories of income.
Fix: Publish a breakdown of funding by category (e.g., sales, licensing, partnerships) with approximate percentages or figures.
-
complete: No funding streams are disclosed at all, so the disclosure cannot be considered complete.
Fix: Provide a comprehensive list of all major funding streams including parent company support, commercial revenue, and partnership income.
-
algorithm_explained: The About Us page describes Penguin's history and publishing operations but does not mention any algorithms or their purpose.
Fix: Add a section disclosing any algorithms used (e.g., for book recommendations or personalization) and explain their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include a statement explaining how algorithmic decisions (such as recommendations or content ranking) impact users' experience on the site.
-
annual_statement: The page links to a Privacy policy but shows no evidence of an annual or periodic review of data practices.
Fix: Add a note on the Privacy policy (and reference it here) stating the date of the last review and the cadence of periodic reviews.
-
dated: The page references a Privacy policy link but displays no visible date or version for the data practices statement.
Fix: Display a 'Last updated' date or version number on the Privacy policy and surface it where privacy is referenced.
Level 3 — Advanced
Accessibility
-
statement_exists: Although the page path is /accessibility-statement, the rendered content is the Penguin homepage with only a footer 'Accessibility' link and no actual accessibility statement text present.
Fix: Publish a dedicated accessibility statement page with substantive content describing the site's accessibility conformance and commitments.
-
known_issues: The page contains no acknowledgement of any known accessibility issues or limitations.
Fix: Add a section listing known accessibility barriers, such as areas that are not yet fully WCAG 2.1 AA compliant.
-
remediation_timeline: There is no mention of any timeline or commitment for fixing accessibility issues.
Fix: Include target dates or a stated commitment for when identified accessibility issues will be remediated.
-
feedback_channel: The page provides no accessibility feedback mechanism or response-time commitment, only a general 'Contact us' link in the footer.
Fix: Provide a dedicated accessibility contact (email or form) along with a stated timeframe for responding to accessibility feedback.
Accountability
-
policy_exists: The page content shown is the Penguin homepage with no visible moderation policy published at /terms.
Fix: Publish a clearly labelled moderation policy accessible from the terms or help section of the site.
-
criteria_clear: No moderation criteria (e.g., prohibited content, community guidelines) are stated anywhere on the page.
Fix: Add a section enumerating specific criteria for acceptable and unacceptable user content.
-
enforcement: There is no explanation of how moderation is enforced, who reviews content, or what actions are taken.
Fix: Document the enforcement workflow, including reporting channels, review timelines, and possible sanctions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page at /incident-response contains only Penguin's general homepage content (books, shop, newsletter) with no published incident response plan or policy.
Fix: Publish a dedicated incident response plan or policy document describing how the organization detects, manages, and responds to security incidents.
-
notification_commitment: There is no statement anywhere on the page committing to public notification of significant security incidents.
Fix: Add an explicit commitment to publicly notify users and relevant authorities when significant security incidents occur.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users, as it contains only marketing and navigational content.
Fix: State a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a breach) for informing affected users.
-
policy_exists: Despite the /bug-bounty path, the page content is the standard Penguin homepage with no responsible-disclosure or bug-bounty policy present.
Fix: Publish a dedicated responsible-disclosure or bug-bounty policy page describing scope, reporting process, and expectations for researchers.
-
clear_contact: No security contact channel (such as a security@ email or vulnerability reporting form) appears anywhere on the page.
Fix: Add a clear security contact, such as a security@penguin.co.uk address or a dedicated vulnerability reporting form, and a security.txt file.
-
safe_harbour_or_reward: The page contains no mention of safe harbour terms or any reward/bounty structure for security researchers.
Fix: Include explicit safe-harbour language protecting good-faith researchers and clearly state any reward or recognition offered.
Transparency
-
criteria_published: The page does not publish any criteria used in algorithmic decision-making.
Fix: Publish a clear list of the specific criteria (e.g., user history, popularity, genre) used in any algorithmic decisions on a dedicated transparency page.
-
weighting: No information is provided about how criteria are weighted or prioritized in any algorithm.
Fix: Disclose the relative weighting or priority of each criterion used in algorithmic decision-making.
-
auditable: The page provides no technical detail, documentation, or audit mechanism for any algorithms.
Fix: Provide sufficient technical documentation or an audit report so external parties can review how algorithms operate.
-
open_source: No source code repository or open-source links are provided on the page.
Fix: Add a link to a public repository (e.g., GitHub) if any site components are open source, or state the site's open-source policy.
-
tech_docs: No technical documentation about the site or its platform is referenced on the page.
Fix: Publish and link to basic technical documentation such as an API reference, data feeds, or developer notes from the About section.
Responsibility to the Future
-
disclosure_exists: Although the page path is /sustainability, the content shown contains only book promotions, shop items, and corporate footer links with no environmental impact or sustainability disclosure present.
Fix: Publish a dedicated sustainability or environmental impact statement on the /sustainability page describing the company's environmental policies and commitments.
-
specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics anywhere in the content.
Fix: Add quantified environmental data such as annual carbon emissions, energy consumption, and reduction targets with baseline years.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure or use of renewable-powered data centres.
Fix: Disclose the hosting provider's energy sourcing and the carbon footprint of the site's infrastructure, ideally noting any green hosting certifications.
-
plan_exists: The page contains only marketing, shop, and corporate links with no published plan describing what happens if Penguin fails or exits.
Fix: Publish a continuity or wind-down plan describing what would happen to the organisation's services and content in the event of failure or exit.
-
data_and_content_fate: The page references a Privacy Policy for data collection but provides no statement on the fate of user data or published content should the organisation cease operating.
Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted if the organisation shuts down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name specific custodians, mirror hosts, or archive partners who would take over preservation of content and data upon exit.
-
policy_exists: The page only links to a 'Modern slavery statement' and 'Careers' but contains no published policy text on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing/working conditions policy page and link to it from the 'Work with us' section.
-
specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to a wellbeing policy.
-
accountability: No individual, team, or oversight body responsible for worker conditions is identified anywhere on the page.
Fix: Name a responsible role or oversight body (e.g., HR/People director or a wellbeing committee) accountable for monitoring worker conditions.