Royal Museums Greenwich
https://www.rmg.co.uk · 51/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (9 failed) |
| Level 2 — Enhanced | 12/27 (15 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement anywhere in its content or navigation.
Fix: Publish an AI use policy page and link to it from the About section or footer.
-
scope_clear: No AI-related content is present, so the scope of AI use is not explained.
Fix: Add a clear statement describing what AI technologies are used and for what purposes across the museum's services.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: 'window.dataLayer = window.dataLayer || []; function gtag() { dataL…'.
- 1 hidden iframe found: https://consentcdn.cookiebot.com/sdk/bc-v4.min.html.
- Detected 3 data-leaking services across 2 categories: cookie consent saas (consent.cookiebot.com, consentcdn.cookiebot.com); google fonts (fonts.googleapis.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.rmg.co.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The page solicits donations and lists ways to give but contains no disclosure of existing funding or sponsorship sources.
Fix: Add a section identifying current funders, sponsors, and supporters (e.g., a 'Our funders' or 'Thanks to our supporters' list) on the Support Us page.
-
transparent: No funding sources are named on the page—corporate partners, patrons, and trusts are referenced only generically.
Fix: Publish a clearly labeled list of named corporate partners, patrons, trusts, and major donors with links to further detail.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The page lists office hours and phone availability but does not state how long it will take to receive a response to enquiries.
Fix: Add explicit response time commitments (e.g., 'we respond to email enquiries within 5 working days') for each contact channel.
-
specific: Because no response timeframes are published, there are no specific day/hour commitments to evaluate.
Fix: Publish concrete numeric timeframes (e.g., '3 business days for general enquiries, 10 working days for research enquiries') alongside each contact email.
-
process_exists: The contact page provides enquiry routes but does not reference or link to a documented complaints or feedback process.
Fix: Add a dedicated 'Complaints and feedback' section on the contact page linking to a published complaints policy with submission instructions.
-
steps_clear: Without a complaints process on the page, no steps for making a complaint are described.
Fix: Outline clear numbered steps (how to submit, who reviews it, expected acknowledgement time, escalation route) for raising a complaint.
-
appeals_exists: The contact page lists numerous department contacts but does not document any appeals process for decisions or complaints.
Fix: Add a dedicated complaints and appeals section outlining how users can formally challenge a decision, including steps and timelines.
-
independent: No appeals process is described, so there is no indication of independent review or escalation path.
Fix: Define an escalation route to an independent reviewer or senior body (e.g., trustees or an ombudsman) for unresolved complaints.
AI & Automation
-
detailed_scope: The page does not mention AI at all, so no detailed scope is provided.
Fix: Create an AI policy that enumerates specific AI use cases (e.g., collections cataloguing, chatbots, image tagging).
-
limitations: No acknowledgement of AI limitations is present since AI is not discussed.
Fix: Include a section explicitly acknowledging limitations such as bias, inaccuracies, and the need for human oversight.
-
safeguards: No safeguards or quality controls are described because there is no AI content.
Fix: Document safeguards like human review, data protection measures, and accuracy checks in a published AI policy.
-
marking_policy: The About page contains no policy or statement regarding the marking or labelling of AI-assisted content.
Fix: Publish a clear policy within the Museum policies or How we work section describing how AI-assisted content will be disclosed and labelled.
-
consistent: No AI content markings are visible anywhere on the page, so consistent application cannot be demonstrated.
Fix: Adopt a standard AI disclosure label and apply it uniformly across all pages and content that involve AI assistance.
-
oversight_exists: The page does not document any human oversight process for AI-generated outputs.
Fix: Add a section under Museum policies documenting how staff review and oversee any AI outputs used by the organisation.
-
review_process: No review or approval workflow for AI content is described on the page.
Fix: Describe the editorial review and approval steps AI-assisted content must pass before publication.
-
accountability: No individual, team, or role is identified as accountable for AI-generated content.
Fix: Name a responsible role (e.g., a director or editorial lead) accountable for AI-generated content and publish it alongside governance information.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to the minimum necessary (data minimisation principle).
Fix: Add an explicit statement that RMG only collects personal data that is necessary for the stated purposes, referencing the data minimisation principle.
-
retention_stated: Retention periods are only stated for CCTV (28 days); no retention periods are given for other data such as customer accounts, bookings, or marketing lists.
Fix: Add a retention schedule specifying how long each category of personal data (e.g., customer accounts, booking records, marketing subscribers) is retained.
-
specific: Only the CCTV retention period is specific (28 days); other retention references are vague or absent (e.g., 'not stored longer than necessary').
Fix: Provide specific timeframes for each data category rather than general statements like 'no longer than necessary'.
-
equal_choices: The page text does not demonstrate that accept and reject options for cookies/marketing are presented with equal prominence, and no reject-equivalent mechanism is described alongside consent.
Fix: Ensure the cookie banner and consent interfaces present a 'Reject All' button with equal visual prominence (size, color, placement) to the 'Accept All' button and document this in the privacy notice.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
detail: The page provides no figures, percentages, or categorical breakdown of funding received.
Fix: Include a breakdown of income sources (e.g., % from grants, donations, commercial activity, government) or link to the annual report with these details.
-
complete: Because no funding streams are disclosed at all, the disclosure cannot be considered complete across major streams like government grants, admissions, retail, or philanthropy.
Fix: Provide a comprehensive funding overview covering all major streams (public funding, earned income, philanthropy, corporate, trusts) with associated amounts.
-
algorithm_explained: The About page describes the museums' mission and governance but makes no mention of any algorithms or their purpose.
Fix: Add a section (or link to one) disclosing any algorithmic systems used by the organisation and explaining their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions might affect users or visitors anywhere on this page.
Fix: Publish a clear statement of how any algorithmic decisions influence users (e.g. recommendations, ticketing, access) and the potential consequences.
-
annual_statement: The page links to a Privacy Notice but provides no evidence of a regular or annual review of data practices.
Fix: Add a statement on the Privacy Notice indicating when it is reviewed (e.g., annually) and include a changelog of periodic reviews.
-
dated: The footer links to a Privacy Notice but no last-updated date or version is visible on this page.
Fix: Display a 'last updated' date or version number next to the Privacy Notice link and on the notice itself.
Level 3 — Advanced
Accessibility
-
feedback_channel: The statement provides feedback contacts (webcontent@rmg.co.uk and the EHRC/EASS enforcement route) but does not state a commitment to respond within a defined timeframe.
Fix: Add an explicit response commitment near the feedback email, such as stating that the museum aims to respond to accessibility queries within a set number of working days.
Accountability
-
criteria_clear: The page only says contributions deemed 'unsuitable' may be removed without defining what makes content unsuitable.
Fix: Add explicit moderation criteria (e.g., prohibited content types such as hate speech, spam, personal data, or off-topic material) to the terms.
-
enforcement: The page does not describe how moderation is enforced, who reviews contributions, timelines, or appeal/notification processes.
Fix: Document the enforcement workflow, including who reviews content, how users are notified of removals, and how to appeal moderation decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains no published incident response plan or security policy, only general about-us and governance links like museum policies and legal status.
Fix: Publish an incident response plan or link to it from the Museum policies or Legal section of the site.
-
notification_commitment: There is no statement committing to publicly notify users of significant security or data incidents anywhere on the page.
Fix: Add a clear commitment to notify affected users and the public about significant incidents within the incident response policy.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g. within 72 hours of discovery) in the published incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
Fix: Publish the specific input criteria used by any algorithms, ideally in a dedicated transparency or policies section.
-
weighting: No information on weighting or prioritisation of algorithmic criteria appears on the page.
Fix: Document and publish how criteria are weighted or prioritised within any algorithmic processes the museum uses.
-
auditable: The page provides no technical or procedural detail that would enable external audit of any algorithmic system.
Fix: Provide audit-ready documentation (data sources, logic, governance, review cadence) accessible from the About or Policies section.
-
open_source: There is no link to source code or any public code repository on the about page.
Fix: Add a link to a public code repository (e.g., GitHub) if any site components are open source, or publish a statement about the site's technology stack.
-
tech_docs: The page does not link to any technical documentation about the website or its systems.
Fix: Publish and link to technical documentation such as API docs, collections data schemas, or a developer/technology page.
Responsibility to the Future
-
specific_metrics: The page only references sustainability generally and provides no specific figures for carbon, energy use, or emissions.
Fix: Publish concrete environmental metrics (e.g., annual carbon emissions, energy consumption, and reduction targets) on the sustainability page.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy sourcing or the website's carbon footprint, ideally including whether green/renewable hosting is used.
-
plan_exists: The page describes the museum's structure, legal status, and annual reports but contains no published plan for organisational failure or exit.
Fix: Publish a succession or wind-down plan detailing what would happen to the institution and its assets in the event of failure or closure.
-
data_and_content_fate: There is no mention of what would happen to user data or published content if the organisation ceased operating.
Fix: Add a statement addressing how user data and published digital content would be preserved, transferred, or deleted in an exit scenario.
-
custodians_or_mirrors: The page names venues, directors, and trustees but does not identify any custodians, mirrors, or archive partners for continuity.
Fix: Name specific archive partners or custodians (e.g., a national archive or digital preservation service) responsible for safeguarding collections and content.
-
policy_exists: The page lists jobs, volunteering and 'How we work' links but shows no published policy specifically on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the 'Museum policies' or 'How we work' section.
-
specific_commitments: There is no content on this page mentioning specific commitments around pay, working hours, mental health, or employee benefits.
Fix: Add explicit commitments on fair pay, working hours, mental health support and benefits within a worker wellbeing policy.
-
accountability: While 'Directors and Trustees' are named as responsible for running the venues, no accountability or oversight is identified specifically for worker conditions or wellbeing.
Fix: Name a responsible role or committee (e.g. HR director or trustee subcommittee) tasked with overseeing worker wellbeing and reporting on it.