Royal Museums Greenwich

https://www.rmg.co.uk · 51/92 checks passed · archives

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 28/37 (9 failed)
Level 2 — Enhanced 12/27 (15 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 5/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or navigation.
    Fix: Publish an AI use policy page and link to it from the About section or footer.
  • scope_clear: No AI-related content is present, so the scope of AI use is not explained.
    Fix: Add a clear statement describing what AI technologies are used and for what purposes across the museum's services.

Privacy

Security

Transparency

  • disclosure_exists: The page solicits donations and lists ways to give but contains no disclosure of existing funding or sponsorship sources.
    Fix: Add a section identifying current funders, sponsors, and supporters (e.g., a 'Our funders' or 'Thanks to our supporters' list) on the Support Us page.
  • transparent: No funding sources are named on the page—corporate partners, patrons, and trusts are referenced only generically.
    Fix: Publish a clearly labeled list of named corporate partners, patrons, trusts, and major donors with links to further detail.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The page lists office hours and phone availability but does not state how long it will take to receive a response to enquiries.
    Fix: Add explicit response time commitments (e.g., 'we respond to email enquiries within 5 working days') for each contact channel.
  • specific: Because no response timeframes are published, there are no specific day/hour commitments to evaluate.
    Fix: Publish concrete numeric timeframes (e.g., '3 business days for general enquiries, 10 working days for research enquiries') alongside each contact email.
  • process_exists: The contact page provides enquiry routes but does not reference or link to a documented complaints or feedback process.
    Fix: Add a dedicated 'Complaints and feedback' section on the contact page linking to a published complaints policy with submission instructions.
  • steps_clear: Without a complaints process on the page, no steps for making a complaint are described.
    Fix: Outline clear numbered steps (how to submit, who reviews it, expected acknowledgement time, escalation route) for raising a complaint.
  • appeals_exists: The contact page lists numerous department contacts but does not document any appeals process for decisions or complaints.
    Fix: Add a dedicated complaints and appeals section outlining how users can formally challenge a decision, including steps and timelines.
  • independent: No appeals process is described, so there is no indication of independent review or escalation path.
    Fix: Define an escalation route to an independent reviewer or senior body (e.g., trustees or an ombudsman) for unresolved complaints.

AI & Automation

  • detailed_scope: The page does not mention AI at all, so no detailed scope is provided.
    Fix: Create an AI policy that enumerates specific AI use cases (e.g., collections cataloguing, chatbots, image tagging).
  • limitations: No acknowledgement of AI limitations is present since AI is not discussed.
    Fix: Include a section explicitly acknowledging limitations such as bias, inaccuracies, and the need for human oversight.
  • safeguards: No safeguards or quality controls are described because there is no AI content.
    Fix: Document safeguards like human review, data protection measures, and accuracy checks in a published AI policy.
  • marking_policy: The About page contains no policy or statement regarding the marking or labelling of AI-assisted content.
    Fix: Publish a clear policy within the Museum policies or How we work section describing how AI-assisted content will be disclosed and labelled.
  • consistent: No AI content markings are visible anywhere on the page, so consistent application cannot be demonstrated.
    Fix: Adopt a standard AI disclosure label and apply it uniformly across all pages and content that involve AI assistance.
  • oversight_exists: The page does not document any human oversight process for AI-generated outputs.
    Fix: Add a section under Museum policies documenting how staff review and oversee any AI outputs used by the organisation.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Describe the editorial review and approval steps AI-assisted content must pass before publication.
  • accountability: No individual, team, or role is identified as accountable for AI-generated content.
    Fix: Name a responsible role (e.g., a director or editorial lead) accountable for AI-generated content and publish it alongside governance information.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to the minimum necessary (data minimisation principle).
    Fix: Add an explicit statement that RMG only collects personal data that is necessary for the stated purposes, referencing the data minimisation principle.
  • retention_stated: Retention periods are only stated for CCTV (28 days); no retention periods are given for other data such as customer accounts, bookings, or marketing lists.
    Fix: Add a retention schedule specifying how long each category of personal data (e.g., customer accounts, booking records, marketing subscribers) is retained.
  • specific: Only the CCTV retention period is specific (28 days); other retention references are vague or absent (e.g., 'not stored longer than necessary').
    Fix: Provide specific timeframes for each data category rather than general statements like 'no longer than necessary'.
  • equal_choices: The page text does not demonstrate that accept and reject options for cookies/marketing are presented with equal prominence, and no reject-equivalent mechanism is described alongside consent.
    Fix: Ensure the cookie banner and consent interfaces present a 'Reject All' button with equal visual prominence (size, color, placement) to the 'Accept All' button and document this in the privacy notice.

Provenance

Security

Transparency

  • detail: The page provides no figures, percentages, or categorical breakdown of funding received.
    Fix: Include a breakdown of income sources (e.g., % from grants, donations, commercial activity, government) or link to the annual report with these details.
  • complete: Because no funding streams are disclosed at all, the disclosure cannot be considered complete across major streams like government grants, admissions, retail, or philanthropy.
    Fix: Provide a comprehensive funding overview covering all major streams (public funding, earned income, philanthropy, corporate, trusts) with associated amounts.
  • algorithm_explained: The About page describes the museums' mission and governance but makes no mention of any algorithms or their purpose.
    Fix: Add a section (or link to one) disclosing any algorithmic systems used by the organisation and explaining their purpose in plain language.
  • impact_clear: There is no description of how algorithmic decisions might affect users or visitors anywhere on this page.
    Fix: Publish a clear statement of how any algorithmic decisions influence users (e.g. recommendations, ticketing, access) and the potential consequences.
  • annual_statement: The page links to a Privacy Notice but provides no evidence of a regular or annual review of data practices.
    Fix: Add a statement on the Privacy Notice indicating when it is reviewed (e.g., annually) and include a changelog of periodic reviews.
  • dated: The footer links to a Privacy Notice but no last-updated date or version is visible on this page.
    Fix: Display a 'last updated' date or version number next to the Privacy Notice link and on the notice itself.

Level 3 — Advanced

Accessibility

  • feedback_channel: The statement provides feedback contacts (webcontent@rmg.co.uk and the EHRC/EASS enforcement route) but does not state a commitment to respond within a defined timeframe.
    Fix: Add an explicit response commitment near the feedback email, such as stating that the museum aims to respond to accessibility queries within a set number of working days.

Accountability

  • criteria_clear: The page only says contributions deemed 'unsuitable' may be removed without defining what makes content unsuitable.
    Fix: Add explicit moderation criteria (e.g., prohibited content types such as hate speech, spam, personal data, or off-topic material) to the terms.
  • enforcement: The page does not describe how moderation is enforced, who reviews contributions, timelines, or appeal/notification processes.
    Fix: Document the enforcement workflow, including who reviews content, how users are notified of removals, and how to appeal moderation decisions.

Interoperability

Security

  • plan_exists: The page contains no published incident response plan or security policy, only general about-us and governance links like museum policies and legal status.
    Fix: Publish an incident response plan or link to it from the Museum policies or Legal section of the site.
  • notification_commitment: There is no statement committing to publicly notify users of significant security or data incidents anywhere on the page.
    Fix: Add a clear commitment to notify affected users and the public about significant incidents within the incident response policy.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g. within 72 hours of discovery) in the published incident response policy.

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
    Fix: Publish the specific input criteria used by any algorithms, ideally in a dedicated transparency or policies section.
  • weighting: No information on weighting or prioritisation of algorithmic criteria appears on the page.
    Fix: Document and publish how criteria are weighted or prioritised within any algorithmic processes the museum uses.
  • auditable: The page provides no technical or procedural detail that would enable external audit of any algorithmic system.
    Fix: Provide audit-ready documentation (data sources, logic, governance, review cadence) accessible from the About or Policies section.
  • open_source: There is no link to source code or any public code repository on the about page.
    Fix: Add a link to a public code repository (e.g., GitHub) if any site components are open source, or publish a statement about the site's technology stack.
  • tech_docs: The page does not link to any technical documentation about the website or its systems.
    Fix: Publish and link to technical documentation such as API docs, collections data schemas, or a developer/technology page.

Responsibility to the Future

  • specific_metrics: The page only references sustainability generally and provides no specific figures for carbon, energy use, or emissions.
    Fix: Publish concrete environmental metrics (e.g., annual carbon emissions, energy consumption, and reduction targets) on the sustainability page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy sourcing or the website's carbon footprint, ideally including whether green/renewable hosting is used.
  • plan_exists: The page describes the museum's structure, legal status, and annual reports but contains no published plan for organisational failure or exit.
    Fix: Publish a succession or wind-down plan detailing what would happen to the institution and its assets in the event of failure or closure.
  • data_and_content_fate: There is no mention of what would happen to user data or published content if the organisation ceased operating.
    Fix: Add a statement addressing how user data and published digital content would be preserved, transferred, or deleted in an exit scenario.
  • custodians_or_mirrors: The page names venues, directors, and trustees but does not identify any custodians, mirrors, or archive partners for continuity.
    Fix: Name specific archive partners or custodians (e.g., a national archive or digital preservation service) responsible for safeguarding collections and content.
  • policy_exists: The page lists jobs, volunteering and 'How we work' links but shows no published policy specifically on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the 'Museum policies' or 'How we work' section.
  • specific_commitments: There is no content on this page mentioning specific commitments around pay, working hours, mental health, or employee benefits.
    Fix: Add explicit commitments on fair pay, working hours, mental health support and benefits within a worker wellbeing policy.
  • accountability: While 'Directors and Trustees' are named as responsible for running the venues, no accountability or oversight is identified specifically for worker conditions or wellbeing.
    Fix: Name a responsible role or committee (e.g. HR director or trustee subcommittee) tasked with overseeing worker wellbeing and reporting on it.