RSPB
https://www.rspb.org.uk · 41/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 22/37 (15 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 1/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 5/13 |
| Accountability | 0/5 |
| AI & Automation | 4/8 |
| Interoperability | 2/3 |
| Privacy | 11/16 |
| Provenance | 0/2 |
| Security | 6/11 |
| Transparency | 2/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: link-name.
- 1 WCAG 2.1 Level A violation reported by axe-core: link-name.
- Heading hierarchy issues: h1 -> h3 (skipped h2); h2 -> h5 (skipped h3).
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
- autoplay without controls: {'tag': 'video', 'src': 'https://base-prod.rspb-prod.magnolia-platform.com/dam/jcr:744a7a50-dd74-4574-b2c0-6303276a7bdf/RSPB_6s_H264_web%20banner_2500x1071_4.mp4', 'autoplay': True, 'controls': False}
- without controls: {'tag': 'video', 'src': 'https://base-prod.rspb-prod.magnolia-platform.com/dam/jcr:744a7a50-dd74-4574-b2c0-6303276a7bdf/RSPB_6s_H264_web%20banner_2500x1071_4.mp4', 'autoplay': True, 'controls': False}
AI & Automation
-
policy_exists: The /ai-policy URL returns a 404 'Page not found' error, meaning no AI policy is published at this location.
Fix: Publish an AI use policy at the /ai-policy URL describing the organisation's approach to AI.
-
scope_clear: With the page missing, there is no explanation of what AI is used for.
Fix: Include a clear section in the AI policy describing the specific use cases and purposes of AI within RSPB's operations.
Privacy
- Detected 2 data-leaking services across 1 category: adobe fonts (p.typekit.net, use.typekit.net).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.rspb.org.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
contact_exists: The /contact page returns a 404 'Page not found' error with no contact information present.
Fix: Restore the contact page at /contact with proper contact details rather than serving a 404 error.
-
findable: Although a 'Contact us' link appears in the Quick links footer, the primary /contact URL is broken, making contact info hard to find.
Fix: Fix the broken /contact URL and ensure the 'Contact us' footer link resolves to a working contact page.
-
actionable: The page provides no phone number, email address, postal address, or contact form to actually reach the organisation.
Fix: Add concrete contact methods such as a phone number, email address, postal address, and/or contact form on the contact page.
-
about_exists: The /about path returns a 'Page not found' 404 error rather than an actual about page.
Fix: Publish a working About page at /about (or redirect /about to the correct URL) so visitors can find information about the organisation.
-
purpose_clear: The 404 page does not state what the organisation does beyond a footer charity registration notice.
Fix: Fix the broken About page so it clearly explains the RSPB's purpose of protecting birds and wildlife.
-
disclosure_exists: The page is a 404 error page with no funding or sponsorship disclosure content present.
Fix: Publish a dedicated funding page at /funding that discloses sources of income and sponsorships, or redirect this URL to an existing funding/annual report page.
-
transparent: No funding sources are identified because the page returns a 'Page not found' error.
Fix: Restore or create the funding page with a clear list of funders, partners, and income sources identified by name.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page is a 404 error page and identifies no named person or role responsible for the site or its content.
Fix: Add a named individual or specific role (e.g., 'Head of Digital') responsible for the site on the contact page.
-
contactable: No contact details such as email, phone, or form are provided on this 404 page, only a link back to the homepage.
Fix: Provide direct contact methods (email, phone, or a working contact form) so users can reach the responsible team.
-
response_timeframe: The page is a 404 error and contains no response timeframe information.
Fix: Publish a complaints page that states specific response timeframes (e.g., acknowledgement within 5 working days, full response within 20 working days).
-
specific: No timeframes of any kind are present on this 404 page.
Fix: Include concrete, numeric timeframes in days or weeks for each stage of the complaints process.
-
process_exists: The /complaints URL returns a 'Page not found' 404 with no documented complaints or feedback process.
Fix: Create and publish a dedicated complaints page at /complaints describing the full complaints and feedback process.
-
steps_clear: No steps for making a complaint are provided because the page does not exist.
Fix: Document clear, numbered steps for submitting, escalating, and resolving complaints, including contact channels at each stage.
-
appeals_exists: The /appeals page returns a 404 'Page not found' error with no documented appeals process.
Fix: Create a dedicated appeals page describing how users can formally appeal decisions, including steps, timelines, and contact points.
-
independent: Since no appeals process is present on the page, there is no indication of independent review or escalation.
Fix: Document an independent or escalated review mechanism (e.g., ombudsman, trustee-level panel, or external reviewer) within the appeals process.
AI & Automation
-
detailed_scope: The 404 page contains no content detailing the scope of AI use.
Fix: Create the AI policy page with detailed scope covering which systems, teams, and activities involve AI.
-
limitations: No limitations of AI systems are acknowledged because the policy page does not exist.
Fix: Add a section acknowledging known limitations, risks, and failure modes of the AI systems used.
-
safeguards: No safeguards or quality controls are described since the page returns a 404 error.
Fix: Document safeguards such as human review, accuracy checks, bias mitigation, and data protection controls on the published AI policy page.
-
marking_policy: The /ai-policy page returns a 404 error, so no AI content marking policy is available.
Fix: Publish an AI policy page describing how AI-assisted content is labelled across the site.
-
consistent: With no accessible AI policy, there is no evidence AI content marking is applied consistently.
Fix: Define and document consistent labelling conventions for AI-assisted content and apply them sitewide.
-
oversight_exists: The AI policy page is missing (404), so human oversight of AI outputs is not documented.
Fix: Create an AI policy page that explicitly documents human oversight of AI-generated outputs.
-
review_process: No review or approval process is described because the AI policy page cannot be found.
Fix: Describe the AI content review/approval workflow (who reviews, when, and against what criteria) on a published AI policy page.
-
accountability: No accountable party for AI-generated content is named, as the policy page is unavailable.
Fix: Name a specific role or team accountable for AI-generated content on the published AI policy page.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible policy text does not explicitly state that data collection is limited to what is necessary (data minimisation principle).
Fix: Add an explicit statement that RSPB only collects personal data that is necessary for the stated purposes, reflecting the GDPR data minimisation principle.
-
retention_stated: The visible portion of the policy does not include a section explicitly stating how long personal data is retained.
Fix: Add a clearly labelled 'Data retention' section explaining how long different categories of personal data are kept.
-
specific: No specific retention periods (e.g. number of years) are provided; references to retention are vague (e.g. 'retained for legal reasons').
Fix: Specify concrete retention durations for each data category (for example, 'financial records retained for 7 years for tax purposes').
-
equal_choices: The page describes how to opt out only via contacting Supporter Services by email, post, or phone, which is more burdensome than the presumably easy opt-in, and no equally prominent reject mechanism is shown.
Fix: Provide a simple, equally prominent self-service mechanism (e.g., an online preference centre link) to withdraw consent with the same ease as giving it.
-
partner_sharing_mentioned: The banner only mentions personalising experience via non-essential cookies and does not disclose data sharing with third-party partners.
Fix: Update the cookie banner copy to explicitly disclose that non-essential cookies may share data with third-party advertising/analytics partners, with a link to the full list.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to view each partner.
Provenance
- No author or date metadata found on the page.
-
authorship_clear: This is a 404 error page with no substantive content identifying who creates or curates material on the site.
Fix: Ensure the /about URL resolves to an actual About page that names the organisation and editorial team responsible for the content.
-
credentials: Beyond a footer note that RSPB is a registered charity and BirdLife International member, no author credentials or organisational background are provided on this 404 page.
Fix: Restore the About page content with details of the RSPB's history, expertise, governance, and staff/scientific credentials.
Security
Transparency
-
named_person: The page shows a 'Page not found' error and does not identify any individual or team handling enquiries.
Fix: Restore or link to a functioning contact page that names the enquiries team or individual responsible.
-
role_clear: Because no person or team is identified, their role or authority is also not stated on this page.
Fix: Clearly state the role and remit (e.g., 'Supporter Services Team handles member enquiries') alongside contact details.
-
substantive: The page contains only a 404 message and navigation links, with no substantive statement of purpose.
Fix: Replace the 404 with a detailed About page describing the RSPB's conservation work, scope, and approach in depth.
-
mission_clear: No mission statement or editorial approach is articulated on this error page.
Fix: Publish the RSPB's mission statement and approach to nature conservation on the About page.
-
detail: There is no funding information on this 404 page, so no amounts, percentages, or categories are provided.
Fix: Add detailed funding breakdowns (e.g., membership fees, grants, legacies) with amounts or percentages, linking to the annual report for full figures.
-
complete: The page contains no disclosure at all and therefore cannot cover any funding streams.
Fix: Create comprehensive funding disclosure content covering all major income streams (donations, grants, government funding, corporate partnerships, retail, memberships).
-
governance_exists: The page is a 404 error page with no description of governance or editorial structure.
Fix: Provide a dedicated About/Governance section describing the RSPB's governance structure, board, and editorial oversight on the About page.
-
roles_clear: No key roles or responsibilities are identified on this 404 page beyond generic navigation links.
Fix: List key leadership roles (e.g., trustees, CEO, editorial leads) with their responsibilities on the About page.
-
algorithm_explained: The page is a 404 error page and contains no explanation of any algorithms used by the site.
Fix: Add a section or dedicated page explaining the purpose of any algorithms used (e.g., for recommendations, personalisation via cookies) and link to it from the About page.
-
impact_clear: No information is provided about how algorithmic decisions affect users, as the page returns a 404 with only navigation links.
Fix: Publish a clear description of how algorithmic decisions (such as cookie-based personalisation) impact users' experience and provide a link from the About section.
-
annual_statement: The page links to a privacy policy but shows no evidence of an annual or periodic review of data practices.
Fix: Publish a statement on the privacy policy page indicating when the data practices were last reviewed and commit to a periodic review cadence.
-
dated: The visible content lists a privacy policy link but shows no date or version for the data practices statement.
Fix: Add a 'Last updated' date or version number to the privacy policy and surface it where the policy is referenced.
Level 3 — Advanced
Accessibility
-
statement_exists: The accessibility-statement URL returns a 404 'Page not found' error with no accessibility statement content present.
Fix: Publish a dedicated accessibility statement at the /accessibility-statement path so the page loads real content instead of a 404 error.
-
known_issues: Since the page is a 404 error, there is no statement acknowledging any known accessibility issues or limitations.
Fix: Include a section in the accessibility statement listing known accessibility issues and non-compliant areas of the site.
-
remediation_timeline: The 404 page contains no timeline or commitment for fixing accessibility issues.
Fix: Add a stated timeline or commitment describing when known accessibility issues will be resolved.
-
feedback_channel: No accessibility-specific feedback mechanism or response commitment is present on the 404 error page.
Fix: Provide a feedback channel (such as an email or form) with a stated response timeframe for accessibility concerns.
Accountability
-
policy_exists: The /moderation page returns a 404 'Page not found' error, so no moderation policy is published at this location.
Fix: Publish a moderation policy document at the /moderation URL outlining rules for user-generated content and community interactions.
-
criteria_clear: Because the page is a 404 error, there are no moderation criteria stated for users to review.
Fix: Add clearly itemized moderation criteria (e.g., prohibited content types, tone expectations) to the moderation page.
-
enforcement: The 404 page contains no information about how moderation decisions are enforced or appealed.
Fix: Document the enforcement process, including warnings, removals, bans, and an appeals mechanism, on the moderation page.
Interoperability
Security
-
plan_exists: The page is a 404 'Page not found' error with no incident response plan or policy content.
Fix: Publish an incident response plan at this URL describing how the organisation detects, manages, and responds to security incidents.
-
notification_commitment: The 404 page contains no commitment to publicly notify affected parties of significant incidents.
Fix: Add explicit language committing to notify affected users and the public when significant incidents occur.
-
timeframe: The error page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g. within 72 hours of discovery) in the published incident response policy.
-
policy_exists: The /bug-bounty page returns a 404 'Page not found' error, so no responsible-disclosure or bug-bounty policy is published at this location.
Fix: Publish a security.txt file and a dedicated vulnerability disclosure policy page describing scope, reporting process, and expectations.
-
clear_contact: The page contains only a generic 404 message and site navigation, with no security or vulnerability reporting contact channel.
Fix: Provide a dedicated security contact such as security@rspb.org.uk or a report form, referenced from the disclosure policy and security.txt.
-
safe_harbour_or_reward: Because the page is a 404 error with no disclosure content, it offers no safe harbour statement or reward structure for researchers.
Fix: Include explicit safe-harbour language protecting good-faith researchers and clarify any reward or recognition arrangements in the published policy.
Transparency
-
criteria_published: No algorithmic decision criteria are published on this 404 page.
Fix: Publish the specific criteria used in any algorithmic decisions on a dedicated transparency or about-our-site page.
-
weighting: There is no mention of weighting or prioritisation of any criteria on this page.
Fix: Document and publish how each criterion is weighted or prioritised in algorithmic decision-making.
-
auditable: The page contains no technical or procedural detail that would allow an external audit or review of algorithms.
Fix: Provide sufficiently detailed documentation (methodology, data inputs, model logic) to enable external audit, and link to it from the site's transparency pages.
-
open_source: No link to source code or any open-source repository is present on the page.
Fix: Add a link to any public code repositories (e.g., GitHub) or a statement about open-source components used by the site.
-
tech_docs: No technical documentation is linked from this page; only legal and cookie policies are shown.
Fix: Publish and link to technical documentation such as API docs, open data resources, or site architecture notes from the About page.
Responsibility to the Future
-
disclosure_exists: The page at /sustainability returns a 404 'Page not found' error with no environmental or sustainability disclosure content present.
Fix: Publish an accessible sustainability or environmental impact disclosure page at the /sustainability URL rather than returning a 404 error.
-
specific_metrics: No specific figures on carbon, energy use, or emissions appear because the page is a 404 error with no disclosure content.
Fix: Include concrete quantitative metrics such as carbon footprint, energy consumption, and emissions figures on the restored sustainability page.
-
hosting_disclosure: The page contains no information about the carbon or energy profile of hosting infrastructure since it is a 404 error page.
Fix: Add a section disclosing the carbon or energy profile of the website's hosting infrastructure, including any green hosting details, to the sustainability page.
-
plan_exists: The page is a 404 'Page not found' error with no published succession or exit plan for the organisation.
Fix: Publish a continuity/succession plan at an accessible URL describing what happens if the RSPB ceases operations.
-
data_and_content_fate: No content on this error page addresses the fate of user data or published content.
Fix: Add a section to a continuity plan specifying how user data and site content would be preserved, transferred, or deleted upon organisational failure.
-
custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners, showing only navigation and a 404 message.
Fix: Name specific custodians, mirror hosts, or archive partners (e.g. BirdLife International or a web archive) responsible for maintaining content if the organisation exits.
-
policy_exists: This is a 404 error page stating the page could not be found, and it contains no published worker wellbeing or working conditions policy content.
Fix: Publish an accessible worker wellbeing policy at a working URL and ensure the /working-with-us page resolves correctly rather than returning a 404.
-
specific_commitments: The page shows only navigation links and a page-not-found message, with no specific commitments on pay, hours, mental health, or benefits.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the working conditions content.
-
accountability: The error page provides no named person, role, or body responsible for oversight of worker conditions.
Fix: Identify a specific role or governance body accountable for monitoring and reporting on worker wellbeing within the published policy.