RSPCA

https://www.rspca.org.uk · 48/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 27/37 (10 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 6/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page contains no AI use policy or statement about artificial intelligence.
    Fix: Publish a clear AI use policy or statement, linked from the footer or About section, describing whether and how the organisation uses AI.
  • scope_clear: Because no AI policy is present, the scope of AI use is not explained anywhere on the page.
    Fix: Include a section within the AI policy that explicitly states what activities or services use AI (e.g., chatbots, content generation, analytics).

Privacy

Security

Transparency

  • disclosure_exists: The page mentions donations, fundraising, and lottery/raffle links but contains no funding or sponsorship disclosure statement.
    Fix: Add a dedicated funding disclosure section or link on the About page summarising the charity's income sources.
  • transparent: No funding sources are clearly identified on this About page beyond generic references to donations and local branch fundraising.
    Fix: Clearly list funding sources (e.g. donations, legacies, grants, trading income) with a link to the annual report or financial statements.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page refers only to generic groups like 'RSPCA Animal Advice Team' and 'media centre' without naming a specific individual or clearly defined responsible role.
    Fix: Identify a named individual or specific role (e.g., Head of Customer Engagement) as the accountable owner for enquiries and complaints.
  • response_timeframe: The page lists phone line opening hours but does not publish any timeframe for responding to enquiries or complaints.
    Fix: Add a clear statement of expected response times (e.g., 'We will respond to written enquiries within 10 working days') on the contact page.
  • specific: Because no response timeframes are published, there are no specific day/hour commitments for replies to enquiries or complaints.
    Fix: Publish specific, measurable response targets in days or hours for each contact channel (email, post, complaint).
  • steps_clear: While complaints are mentioned as an option, the page does not lay out the steps of the complaints process (e.g., stages, escalation, what to include, expected outcome).
    Fix: Provide a clear step-by-step description of the complaints process, including how to submit, what information to include, escalation routes, and expected timescales.
  • appeals_exists: The contact page mentions a 'Feedback or complaint' option but does not document an appeals process for decisions or outcomes.
    Fix: Publish a clear appeals procedure (with steps, timelines, and contact route) alongside the complaints information on the contact page.
  • independent: No mention is made of an independent reviewer or escalation path (e.g., to an ombudsman or independent panel) if a complainant is dissatisfied.
    Fix: Document an escalation route to an independent body such as the Fundraising Regulator or Charity Commission, and link to it from the complaints section.

AI & Automation

  • detailed_scope: The page does not mention AI at all, so no detailed scope of AI use is provided.
    Fix: Add a detailed scope section to an AI policy describing specific systems, use cases, and data involved in AI processing.
  • limitations: No acknowledgement of AI system limitations appears on this page.
    Fix: Include a limitations section in the AI policy that acknowledges risks such as inaccuracy, bias, and edge cases.
  • safeguards: The page does not describe any safeguards or quality controls related to AI.
    Fix: Document safeguards such as human oversight, review processes, and accuracy checks applied to any AI-assisted outputs.
  • marking_policy: The About page contains no policy or statement regarding the marking of AI-assisted content.
    Fix: Publish a clear policy explaining how AI-assisted content is labelled on the site, and link to it from the About or Help pages.
  • consistent: Without a marking policy visible on this page, there is no evidence that AI content marking is applied consistently.
    Fix: Adopt a standard label or badge for AI-assisted content and apply it uniformly across all pages, referencing the policy.
  • oversight_exists: The page makes no mention of human oversight over AI outputs.
    Fix: Add a statement to the About or governance section describing how humans oversee any AI-generated or AI-assisted outputs.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Document the editorial review and approval process for AI outputs, including who checks content before publication.
  • accountability: The page does not identify any role or person accountable for AI-generated content.
    Fix: Name an accountable role (e.g., editorial lead or digital governance owner) responsible for AI-generated content and publish their remit.

Interoperability

Privacy

  • understandable: The visible page only provides brief one-line summaries for each topic (e.g., 'We may collect personal information about you') without specifics on what data or why, and the detail apparently lives in a PDF last updated 16.05.2023.
    Fix: Expand each section on the web page itself to concretely list the categories of data collected and the specific purposes, rather than relying on a downloadable PDF for the substantive detail.
  • necessity: The visible notice does not state that data collection is limited to what is necessary; it only says sensitive data isn't usually collected 'unless there is a clear reason'.
    Fix: Add an explicit data minimisation statement confirming that personal information is only collected where necessary for the stated purposes.
  • proportionate: There is no statement on the page indicating that the data collected is proportionate to the services provided.
    Fix: Include a clear proportionality statement explaining that the amount and type of data collected is limited to what is proportionate to each service or interaction.
  • retention_stated: The 'How long we keep your information' section only refers vaguely to 'a specified amount of time as set out in our internal data retention policy' without stating the periods on the page.
    Fix: Publish the actual retention periods (or a retention schedule) directly in the notice rather than referring users to an internal policy.
  • specific: No specific time periods are given; retention is described only as 'a specified amount of time' per an internal policy.
    Fix: Provide concrete retention durations for each category of data (e.g., 'supporter donation records: 7 years') within the public privacy notice.
  • partner_count_specific: The banner references 'trusted digital partners' but does not state a specific numeric count of partners.
    Fix: Disclose the exact number of third-party partners in the banner copy (e.g., 'our 27 trusted digital partners') and/or link to a list of named partners.

Provenance

Security

Transparency

  • role_clear: While team names are listed, their specific roles, authority, and scope of responsibility are not clearly explained beyond brief labels like 'Already a supporter?' or 'We can't do it without you.'
    Fix: Add a short description under each team explaining what matters they handle and their decision-making authority so users know whom to contact for what.
  • detail: The page provides no amounts, percentages, or categorical breakdown of funding streams.
    Fix: Publish a financial breakdown showing percentages or amounts for each major income category, such as legacies, donations, and retail.
  • complete: There is no disclosure on the page that covers any, let alone all, major funding streams.
    Fix: Include a comprehensive funding overview covering legacies, individual donations, lottery, retail, grants, and any corporate partnerships.
  • algorithm_explained: The About page describes the RSPCA's mission and operations but does not mention or explain any algorithms used on the site or in decision-making.
    Fix: Add a section or link disclosing any algorithms used (e.g., for pet matching, content personalization, or advertising) and explaining their purpose.
  • impact_clear: There is no description of how any algorithmic decisions affect users, donors, or adopters on this page.
    Fix: Include clear statements about how algorithmic outputs influence user experience (e.g., recommendations, targeted content) and what that means for users.
  • annual_statement: The page links to a National Privacy Notice but provides no evidence of a regular or annual data practices review.
    Fix: Publish a statement (e.g., in the privacy notice or About page) indicating the data practices are reviewed on an annual or periodic basis.
  • dated: No last-updated date or version is shown for any data practices statement on this page.
    Fix: Add a visible 'last updated' date or version number to the privacy notice and link it clearly from this page.

Level 3 — Advanced

Accessibility

  • statement_exists: The page only shows an 'Accessibility' link in the footer, with no dedicated accessibility statement content present on the reviewed page.
    Fix: Publish a dedicated accessibility statement page and ensure its content is accessible and clearly linked from the footer.
  • known_issues: No accessibility statement content is visible, so no known accessibility issues or limitations are acknowledged.
    Fix: Include a section in the accessibility statement listing known issues and non-compliant areas of the site.
  • remediation_timeline: There is no visible content committing to a timeline for fixing accessibility issues.
    Fix: Add specific dates or a remediation schedule for addressing identified accessibility barriers.
  • feedback_channel: The page provides general 'Contact Us' links but no accessibility-specific feedback mechanism with a response commitment.
    Fix: Provide a dedicated accessibility feedback contact (email or form) and state a commitment to respond within a defined timeframe.

Accountability

  • policy_exists: The Terms page covers site use disclaimers and liability but does not publish any moderation policy for user content or community interactions.
    Fix: Publish a dedicated moderation policy outlining what user-generated content is permitted and how it is reviewed.
  • criteria_clear: Beyond a vague requirement to use the site 'for lawful purposes,' the page does not state specific criteria for what content or behaviour will be moderated or removed.
    Fix: Add explicit moderation criteria (e.g., prohibited content categories such as harassment, hate speech, spam) so users know what standards apply.
  • enforcement: The page only reserves a general right to deny access without notice and does not describe any enforcement process, appeals, or escalation steps.
    Fix: Document the enforcement workflow, including how violations are reported, reviewed, actioned, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The page is an 'About Us' overview of the RSPCA's mission and activities and contains no published incident response plan or security policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site footer.
  • notification_commitment: The page makes no commitment to publicly notify users of significant security incidents.
    Fix: Add a clear statement committing to public notification of affected users in the event of a significant security or data incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on the page.
    Fix: Publish the specific inputs and criteria used in any algorithmic systems on a dedicated transparency or algorithm page.
  • weighting: The page does not explain how any criteria are weighted or prioritized in algorithmic decisions.
    Fix: Document and publish the relative weighting or priority of each criterion used in algorithmic decisions.
  • auditable: The page provides no technical or procedural detail that would allow external audit or review of any algorithm.
    Fix: Provide an algorithm transparency report or audit documentation with sufficient detail (data sources, logic, testing) for external review.
  • open_source: There is no link to source code or any public repository on the about page or in the footer.
    Fix: Add a link (e.g., in the footer or a developer/tech page) to a public repository such as GitHub if any RSPCA code is open-sourced, or publish a statement on technology openness.
  • tech_docs: No technical documentation is published or linked from the page; only policy and governance links appear.
    Fix: Publish a technical/developer documentation page (e.g., API docs, data schemas, or platform overview) and link to it from the site footer.

Responsibility to the Future

  • disclosure_exists: The page describes the RSPCA's mission and animal welfare work but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement covering the organisation's operations and digital footprint.
  • specific_metrics: No specific figures such as carbon emissions, energy use, or environmental metrics appear anywhere on the page.
    Fix: Include quantified metrics (e.g., annual carbon emissions in tonnes CO2e and energy consumption) in a published environmental report.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy source or carbon profile, such as confirming use of a green/renewable-powered host.
  • plan_exists: The governance page describes the Board of Trustees, trustee elections, and reports but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a wind-down or continuity plan describing how the charity would handle dissolution, exit, or transfer of operations.
  • data_and_content_fate: There is no mention of what happens to user data or published content in the event of organisational failure or closure.
    Fix: Add a section detailing the fate of user data and website content on closure, including retention, deletion, or transfer commitments.
  • custodians_or_mirrors: The page does not name any custodians, mirrors, or archive partners for preserving data or content.
    Fix: Identify and document custodians, mirror hosts, or archive partners (e.g., a national web archive) responsible for preserving content if the organisation ceases operations.
  • accountability: The page describes benefits and policies but does not name any person, team, or governance body responsible for overseeing worker conditions or wellbeing.
    Fix: Add a statement identifying the department or role (e.g., HR/People team or a named executive) accountable for monitoring and upholding worker wellbeing and working conditions.