RSPB

https://www.rspb.org.uk · 41/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 22/37 (15 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 1/10 (9 failed)

By category

CategoryResult
Accessibility 5/13
Accountability 0/5
AI & Automation 4/8
Interoperability 2/3
Privacy 11/16
Provenance 0/2
Security 6/11
Transparency 2/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The /ai-policy URL returns a 404 'Page not found' error, meaning no AI policy is published at this location.
    Fix: Publish an AI use policy at the /ai-policy URL describing the organisation's approach to AI.
  • scope_clear: With the page missing, there is no explanation of what AI is used for.
    Fix: Include a clear section in the AI policy describing the specific use cases and purposes of AI within RSPB's operations.

Privacy

Security

Transparency

  • contact_exists: The /contact page returns a 404 'Page not found' error with no contact information present.
    Fix: Restore the contact page at /contact with proper contact details rather than serving a 404 error.
  • findable: Although a 'Contact us' link appears in the Quick links footer, the primary /contact URL is broken, making contact info hard to find.
    Fix: Fix the broken /contact URL and ensure the 'Contact us' footer link resolves to a working contact page.
  • actionable: The page provides no phone number, email address, postal address, or contact form to actually reach the organisation.
    Fix: Add concrete contact methods such as a phone number, email address, postal address, and/or contact form on the contact page.
  • about_exists: The /about path returns a 'Page not found' 404 error rather than an actual about page.
    Fix: Publish a working About page at /about (or redirect /about to the correct URL) so visitors can find information about the organisation.
  • purpose_clear: The 404 page does not state what the organisation does beyond a footer charity registration notice.
    Fix: Fix the broken About page so it clearly explains the RSPB's purpose of protecting birds and wildlife.
  • disclosure_exists: The page is a 404 error page with no funding or sponsorship disclosure content present.
    Fix: Publish a dedicated funding page at /funding that discloses sources of income and sponsorships, or redirect this URL to an existing funding/annual report page.
  • transparent: No funding sources are identified because the page returns a 'Page not found' error.
    Fix: Restore or create the funding page with a clear list of funders, partners, and income sources identified by name.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page is a 404 error page and identifies no named person or role responsible for the site or its content.
    Fix: Add a named individual or specific role (e.g., 'Head of Digital') responsible for the site on the contact page.
  • contactable: No contact details such as email, phone, or form are provided on this 404 page, only a link back to the homepage.
    Fix: Provide direct contact methods (email, phone, or a working contact form) so users can reach the responsible team.
  • response_timeframe: The page is a 404 error and contains no response timeframe information.
    Fix: Publish a complaints page that states specific response timeframes (e.g., acknowledgement within 5 working days, full response within 20 working days).
  • specific: No timeframes of any kind are present on this 404 page.
    Fix: Include concrete, numeric timeframes in days or weeks for each stage of the complaints process.
  • process_exists: The /complaints URL returns a 'Page not found' 404 with no documented complaints or feedback process.
    Fix: Create and publish a dedicated complaints page at /complaints describing the full complaints and feedback process.
  • steps_clear: No steps for making a complaint are provided because the page does not exist.
    Fix: Document clear, numbered steps for submitting, escalating, and resolving complaints, including contact channels at each stage.
  • appeals_exists: The /appeals page returns a 404 'Page not found' error with no documented appeals process.
    Fix: Create a dedicated appeals page describing how users can formally appeal decisions, including steps, timelines, and contact points.
  • independent: Since no appeals process is present on the page, there is no indication of independent review or escalation.
    Fix: Document an independent or escalated review mechanism (e.g., ombudsman, trustee-level panel, or external reviewer) within the appeals process.

AI & Automation

  • detailed_scope: The 404 page contains no content detailing the scope of AI use.
    Fix: Create the AI policy page with detailed scope covering which systems, teams, and activities involve AI.
  • limitations: No limitations of AI systems are acknowledged because the policy page does not exist.
    Fix: Add a section acknowledging known limitations, risks, and failure modes of the AI systems used.
  • safeguards: No safeguards or quality controls are described since the page returns a 404 error.
    Fix: Document safeguards such as human review, accuracy checks, bias mitigation, and data protection controls on the published AI policy page.
  • marking_policy: The /ai-policy page returns a 404 error, so no AI content marking policy is available.
    Fix: Publish an AI policy page describing how AI-assisted content is labelled across the site.
  • consistent: With no accessible AI policy, there is no evidence AI content marking is applied consistently.
    Fix: Define and document consistent labelling conventions for AI-assisted content and apply them sitewide.
  • oversight_exists: The AI policy page is missing (404), so human oversight of AI outputs is not documented.
    Fix: Create an AI policy page that explicitly documents human oversight of AI-generated outputs.
  • review_process: No review or approval process is described because the AI policy page cannot be found.
    Fix: Describe the AI content review/approval workflow (who reviews, when, and against what criteria) on a published AI policy page.
  • accountability: No accountable party for AI-generated content is named, as the policy page is unavailable.
    Fix: Name a specific role or team accountable for AI-generated content on the published AI policy page.

Interoperability

Privacy

  • necessity: The visible policy text does not explicitly state that data collection is limited to what is necessary (data minimisation principle).
    Fix: Add an explicit statement that RSPB only collects personal data that is necessary for the stated purposes, reflecting the GDPR data minimisation principle.
  • retention_stated: The visible portion of the policy does not include a section explicitly stating how long personal data is retained.
    Fix: Add a clearly labelled 'Data retention' section explaining how long different categories of personal data are kept.
  • specific: No specific retention periods (e.g. number of years) are provided; references to retention are vague (e.g. 'retained for legal reasons').
    Fix: Specify concrete retention durations for each data category (for example, 'financial records retained for 7 years for tax purposes').
  • equal_choices: The page describes how to opt out only via contacting Supporter Services by email, post, or phone, which is more burdensome than the presumably easy opt-in, and no equally prominent reject mechanism is shown.
    Fix: Provide a simple, equally prominent self-service mechanism (e.g., an online preference centre link) to withdraw consent with the same ease as giving it.
  • partner_sharing_mentioned: The banner only mentions personalising experience via non-essential cookies and does not disclose data sharing with third-party partners.
    Fix: Update the cookie banner copy to explicitly disclose that non-essential cookies may share data with third-party advertising/analytics partners, with a link to the full list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to view each partner.

Provenance

  • authorship_clear: This is a 404 error page with no substantive content identifying who creates or curates material on the site.
    Fix: Ensure the /about URL resolves to an actual About page that names the organisation and editorial team responsible for the content.
  • credentials: Beyond a footer note that RSPB is a registered charity and BirdLife International member, no author credentials or organisational background are provided on this 404 page.
    Fix: Restore the About page content with details of the RSPB's history, expertise, governance, and staff/scientific credentials.

Security

Transparency

  • named_person: The page shows a 'Page not found' error and does not identify any individual or team handling enquiries.
    Fix: Restore or link to a functioning contact page that names the enquiries team or individual responsible.
  • role_clear: Because no person or team is identified, their role or authority is also not stated on this page.
    Fix: Clearly state the role and remit (e.g., 'Supporter Services Team handles member enquiries') alongside contact details.
  • substantive: The page contains only a 404 message and navigation links, with no substantive statement of purpose.
    Fix: Replace the 404 with a detailed About page describing the RSPB's conservation work, scope, and approach in depth.
  • mission_clear: No mission statement or editorial approach is articulated on this error page.
    Fix: Publish the RSPB's mission statement and approach to nature conservation on the About page.
  • detail: There is no funding information on this 404 page, so no amounts, percentages, or categories are provided.
    Fix: Add detailed funding breakdowns (e.g., membership fees, grants, legacies) with amounts or percentages, linking to the annual report for full figures.
  • complete: The page contains no disclosure at all and therefore cannot cover any funding streams.
    Fix: Create comprehensive funding disclosure content covering all major income streams (donations, grants, government funding, corporate partnerships, retail, memberships).
  • governance_exists: The page is a 404 error page with no description of governance or editorial structure.
    Fix: Provide a dedicated About/Governance section describing the RSPB's governance structure, board, and editorial oversight on the About page.
  • roles_clear: No key roles or responsibilities are identified on this 404 page beyond generic navigation links.
    Fix: List key leadership roles (e.g., trustees, CEO, editorial leads) with their responsibilities on the About page.
  • algorithm_explained: The page is a 404 error page and contains no explanation of any algorithms used by the site.
    Fix: Add a section or dedicated page explaining the purpose of any algorithms used (e.g., for recommendations, personalisation via cookies) and link to it from the About page.
  • impact_clear: No information is provided about how algorithmic decisions affect users, as the page returns a 404 with only navigation links.
    Fix: Publish a clear description of how algorithmic decisions (such as cookie-based personalisation) impact users' experience and provide a link from the About section.
  • annual_statement: The page links to a privacy policy but shows no evidence of an annual or periodic review of data practices.
    Fix: Publish a statement on the privacy policy page indicating when the data practices were last reviewed and commit to a periodic review cadence.
  • dated: The visible content lists a privacy policy link but shows no date or version for the data practices statement.
    Fix: Add a 'Last updated' date or version number to the privacy policy and surface it where the policy is referenced.

Level 3 — Advanced

Accessibility

  • statement_exists: The accessibility-statement URL returns a 404 'Page not found' error with no accessibility statement content present.
    Fix: Publish a dedicated accessibility statement at the /accessibility-statement path so the page loads real content instead of a 404 error.
  • known_issues: Since the page is a 404 error, there is no statement acknowledging any known accessibility issues or limitations.
    Fix: Include a section in the accessibility statement listing known accessibility issues and non-compliant areas of the site.
  • remediation_timeline: The 404 page contains no timeline or commitment for fixing accessibility issues.
    Fix: Add a stated timeline or commitment describing when known accessibility issues will be resolved.
  • feedback_channel: No accessibility-specific feedback mechanism or response commitment is present on the 404 error page.
    Fix: Provide a feedback channel (such as an email or form) with a stated response timeframe for accessibility concerns.

Accountability

  • policy_exists: The /moderation page returns a 404 'Page not found' error, so no moderation policy is published at this location.
    Fix: Publish a moderation policy document at the /moderation URL outlining rules for user-generated content and community interactions.
  • criteria_clear: Because the page is a 404 error, there are no moderation criteria stated for users to review.
    Fix: Add clearly itemized moderation criteria (e.g., prohibited content types, tone expectations) to the moderation page.
  • enforcement: The 404 page contains no information about how moderation decisions are enforced or appealed.
    Fix: Document the enforcement process, including warnings, removals, bans, and an appeals mechanism, on the moderation page.

Interoperability

Security

  • plan_exists: The page is a 404 'Page not found' error with no incident response plan or policy content.
    Fix: Publish an incident response plan at this URL describing how the organisation detects, manages, and responds to security incidents.
  • notification_commitment: The 404 page contains no commitment to publicly notify affected parties of significant incidents.
    Fix: Add explicit language committing to notify affected users and the public when significant incidents occur.
  • timeframe: The error page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g. within 72 hours of discovery) in the published incident response policy.
  • policy_exists: The /bug-bounty page returns a 404 'Page not found' error, so no responsible-disclosure or bug-bounty policy is published at this location.
    Fix: Publish a security.txt file and a dedicated vulnerability disclosure policy page describing scope, reporting process, and expectations.
  • clear_contact: The page contains only a generic 404 message and site navigation, with no security or vulnerability reporting contact channel.
    Fix: Provide a dedicated security contact such as security@rspb.org.uk or a report form, referenced from the disclosure policy and security.txt.
  • safe_harbour_or_reward: Because the page is a 404 error with no disclosure content, it offers no safe harbour statement or reward structure for researchers.
    Fix: Include explicit safe-harbour language protecting good-faith researchers and clarify any reward or recognition arrangements in the published policy.

Transparency

  • criteria_published: No algorithmic decision criteria are published on this 404 page.
    Fix: Publish the specific criteria used in any algorithmic decisions on a dedicated transparency or about-our-site page.
  • weighting: There is no mention of weighting or prioritisation of any criteria on this page.
    Fix: Document and publish how each criterion is weighted or prioritised in algorithmic decision-making.
  • auditable: The page contains no technical or procedural detail that would allow an external audit or review of algorithms.
    Fix: Provide sufficiently detailed documentation (methodology, data inputs, model logic) to enable external audit, and link to it from the site's transparency pages.
  • open_source: No link to source code or any open-source repository is present on the page.
    Fix: Add a link to any public code repositories (e.g., GitHub) or a statement about open-source components used by the site.
  • tech_docs: No technical documentation is linked from this page; only legal and cookie policies are shown.
    Fix: Publish and link to technical documentation such as API docs, open data resources, or site architecture notes from the About page.

Responsibility to the Future

  • disclosure_exists: The page at /sustainability returns a 404 'Page not found' error with no environmental or sustainability disclosure content present.
    Fix: Publish an accessible sustainability or environmental impact disclosure page at the /sustainability URL rather than returning a 404 error.
  • specific_metrics: No specific figures on carbon, energy use, or emissions appear because the page is a 404 error with no disclosure content.
    Fix: Include concrete quantitative metrics such as carbon footprint, energy consumption, and emissions figures on the restored sustainability page.
  • hosting_disclosure: The page contains no information about the carbon or energy profile of hosting infrastructure since it is a 404 error page.
    Fix: Add a section disclosing the carbon or energy profile of the website's hosting infrastructure, including any green hosting details, to the sustainability page.
  • plan_exists: The page is a 404 'Page not found' error with no published succession or exit plan for the organisation.
    Fix: Publish a continuity/succession plan at an accessible URL describing what happens if the RSPB ceases operations.
  • data_and_content_fate: No content on this error page addresses the fate of user data or published content.
    Fix: Add a section to a continuity plan specifying how user data and site content would be preserved, transferred, or deleted upon organisational failure.
  • custodians_or_mirrors: The page identifies no custodians, mirrors, or archive partners, showing only navigation and a 404 message.
    Fix: Name specific custodians, mirror hosts, or archive partners (e.g. BirdLife International or a web archive) responsible for maintaining content if the organisation exits.
  • policy_exists: This is a 404 error page stating the page could not be found, and it contains no published worker wellbeing or working conditions policy content.
    Fix: Publish an accessible worker wellbeing policy at a working URL and ensure the /working-with-us page resolves correctly rather than returning a 404.
  • specific_commitments: The page shows only navigation links and a page-not-found message, with no specific commitments on pay, hours, mental health, or benefits.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the working conditions content.
  • accountability: The error page provides no named person, role, or body responsible for oversight of worker conditions.
    Fix: Identify a specific role or governance body accountable for monitoring and reporting on worker wellbeing within the published policy.