Save the Children UK
https://www.savethechildren.org.uk · 46/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (9 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- Heading hierarchy issues: h2 -> h4 (skipped h3).
AI & Automation
-
policy_exists: The page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish a clear AI use policy and link to it from the site footer or About section.
-
scope_clear: Because no AI policy exists on the page, there is no explanation of what AI is used for.
Fix: Add a section to the AI policy that explicitly describes what AI technologies are used and for which purposes.
- Not found at any of: /ai-policy, /ai.
Privacy
- Page sent requests to 2 known domains from the block list: connect.facebook.net.
- Page sent requests to 2 known domains from the block list: connect.facebook.net.
- No scripts matched the tracker/ad pattern list.
- No hidden iframes detected.
- Detected 4 data-leaking services across 3 categories: cookie consent saas (cdn-ukwest.onetrust.com); facebook (connect.facebook.net); google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.savethechildren.org.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The page lists phone line hours (9am-5pm Mon-Fri) but does not publish any timeframe for when enquiries or emails will receive a response.
Fix: Add an explicit response timeframe statement such as 'We aim to respond to emails within 5 working days' to the contact page.
-
specific: Because no response timeframe is published at all, there is no specific day/hour commitment provided.
Fix: Publish a concrete, measurable commitment (e.g., 'within 3 business days') rather than vague language.
-
steps_clear: The contact page only links out to a complaints page without outlining the actual steps, channels, or escalation path on the page itself.
Fix: Summarise the key complaint steps (how to submit, what information to include, expected acknowledgement, and escalation options) directly on the contact page or in the linked section.
-
appeals_exists: The page mentions a 'Make a Complaint' link but does not document an appeals process for escalating unresolved complaints.
Fix: Add a clearly documented appeals process on the contact or complaints page explaining how users can escalate a complaint if dissatisfied with the initial response.
-
independent: There is no mention of an independent reviewer or external escalation body (e.g., Fundraising Regulator, Charity Commission) for appeals on this page.
Fix: Include information about independent escalation routes such as the Fundraising Regulator or Charity Commission so complainants can pursue an impartial review.
AI & Automation
-
detailed_scope: No AI policy is present, so the scope of AI use is not detailed on the page.
Fix: Create an AI policy page detailing specific use cases, systems, and data types involved in AI usage.
-
limitations: The page does not acknowledge any limitations of AI systems since no AI policy is provided.
Fix: Include an explicit section acknowledging known limitations, risks, and potential biases of any AI systems used.
-
safeguards: No safeguards or quality controls related to AI are described on the page.
Fix: Document the human oversight, review processes, and quality controls applied to any AI-driven activities.
-
marking_policy: The page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy describing how AI-assisted content is labelled and link to it from the About or editorial standards page.
-
consistent: No AI content marking is visible anywhere on the page, so consistency cannot be demonstrated.
Fix: Apply standardised AI-content labels across all pages and include visible markers on any content produced with AI assistance.
-
oversight_exists: The page does not document any human oversight of AI outputs.
Fix: Add a statement describing how humans review and oversee any AI-generated or AI-assisted content on the site.
-
review_process: No review or approval process for AI content is described on the page.
Fix: Publish a description of the editorial review/approval workflow for AI outputs, including who signs off before publication.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name a responsible role or contact (e.g., editorial lead or Head of Digital) accountable for AI-generated content governance.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary; instead it describes broad supplementary data collection from public sources and wealth screening.
Fix: Add an explicit statement (data minimisation principle) that Save the Children only collects personal data that is necessary for the specified purposes.
-
proportionate: Practices like profiling supporters using LinkedIn, Companies House, shareholdings, and earnings estimates to assess donation capacity appear broader than needed for basic service provision, and proportionality is not addressed.
Fix: Explain how each category of collected data (especially wealth screening inputs) is proportionate to the specific purpose, and offer supporters a clear opt-out from profiling.
-
retention_stated: The visible content does not state how long personal data is retained, other than a 3-month cookie consent cookie.
Fix: Add a dedicated 'How long do we keep your information?' section stating retention periods for each category of personal data.
-
specific: Apart from the 3-month cookie consent, no specific retention periods (e.g., years after last donation) are given for supporter or transactional data.
Fix: Provide specific retention durations, such as 'we retain donation records for 7 years to comply with HMRC Gift Aid requirements', for each data category.
-
no_dark_patterns: The policy states that merely 'by using our website' users are deemed to agree to cookies unless they reconfigure their browser, which is a manipulative implied-consent pattern.
Fix: Replace implied browser-setting consent with an explicit opt-in consent mechanism presented in clear, neutral language.
-
equal_choices: No reject option is described on this page—consent is assumed by default use of the site, with no equally prominent refusal choice.
Fix: Provide a cookie banner with 'Accept' and 'Reject' buttons of equal visual prominence before any non-essential cookies are set.
-
no_forced_consent: Consent is bundled and forced because using the website, subscribing, donating or shopping is treated as blanket agreement to cookie placement.
Fix: Unbundle consent by category (e.g., analytics, advertising) and allow users to access the site and services without being required to accept non-essential cookies.
-
partner_sharing_mentioned: The banner mentions tailored content and marketing but does not disclose that data is shared with third-party partners.
Fix: Update the cookie banner text to explicitly state that cookie data is shared with third-party advertising and analytics partners.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner copy.
Fix: Include a specific number of third-party partners (e.g., 'shared with X partners') in the banner, linking to a full list in the cookie preferences.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
role_clear: While the team is named and its limitations (what it won't handle) are listed, its positive scope of authority and responsibilities are not clearly defined.
Fix: Add a brief description of the Supporter Care team's role and the types of enquiries they are authorised to handle.
-
complete: The page only highlights three featured partnerships and does not disclose all major funding streams (e.g., individual donations, government grants, total income breakdown).
Fix: Add a summary of all major funding streams with percentages or link prominently to the Annual Report's income breakdown directly from this page.
-
governance_exists: The page describes partnership activities and examples but does not describe the organisation's governance or editorial structure.
Fix: Add a section (or link to one) outlining Save the Children's governance structure, such as trustees, board oversight, and editorial policies.
-
roles_clear: Apart from a single partner quote from an Arsenal Foundation director, no key roles or responsibilities within Save the Children's governance are identified.
Fix: Include named leadership roles (e.g., CEO, trustees, Corporate Advisory Board members) with clear descriptions of their responsibilities.
-
algorithm_explained: The page describes partnership programs but does not mention or explain any algorithms used on the site or in decision-making.
Fix: Add a section or link disclosing any algorithms used (e.g., for personalisation, donation routing, or recommendations) and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users or partners on this page.
Fix: Publish a clear statement describing how any algorithmic decisions impact users, donors, or beneficiaries.
-
annual_statement: The page shows 'Page last updated October 2024' but makes no reference to a regular or annual review of data/privacy practices.
Fix: Add a statement on the Privacy page indicating that data practices are reviewed annually (or on a defined cadence) and link to it from the footer.
-
dated: While the page itself is dated October 2024, there is no visible date or version on the linked Privacy/data practices statement from this page.
Fix: Ensure the Privacy policy linked in the footer displays an explicit 'last updated' date or version number near the top.
Level 3 — Advanced
Accessibility
-
statement_exists: The page only shows an 'Accessibility' link in the footer quick links but no dedicated accessibility statement content is present on this page.
Fix: Publish a dedicated accessibility statement page and ensure it is reachable and clearly labeled from the footer 'Accessibility' link.
-
known_issues: No content on this page acknowledges any known accessibility issues or limitations.
Fix: Include a section in the accessibility statement that lists known non-conformances and inaccessible content areas.
-
remediation_timeline: There is no stated timeline or commitment for resolving accessibility issues anywhere on the page.
Fix: Add target dates or a remediation plan describing when known accessibility issues will be fixed.
-
feedback_channel: The page offers general 'Contact Us' and 'Get in touch' links but no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility contact (email/phone/form) and state a timeframe within which feedback will be answered.
Accountability
-
enforcement: While Section 8(e) says Save the Children may remove non-compliant content, the page does not explain the review/enforcement process, timelines, notification, or appeals.
Fix: Add a section describing how flagged contributions are reviewed, who makes decisions, expected response times, user notification, and any appeal or redress mechanism.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is a corporate partnerships page with no published incident response plan or security policy.
Fix: Publish a dedicated incident response plan or security policy and link to it from the site footer.
-
notification_commitment: The page contains no commitment to publicly notify users of significant security incidents.
Fix: Add an explicit statement committing to notify affected users and the public when significant incidents occur.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of detecting a significant incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decisions are published on this page.
Fix: Publish the specific criteria used in any algorithmic decision-making processes on an accessible transparency page.
-
weighting: The page does not disclose the weighting or prioritisation of any decision criteria.
Fix: Document and publish the relative weighting or priority given to each criterion used in algorithmic decisions.
-
auditable: There is insufficient detail provided to enable any external audit or review of algorithmic processes.
Fix: Provide documentation (methodology, data inputs, criteria, and contact for audit requests) sufficient to enable independent review.
-
open_source: There is no mention or link to publicly available source code for the website or its digital tools.
Fix: Publish and link to a public code repository (e.g., GitHub) for the website or any open-source components used by the charity.
-
tech_docs: No technical documentation is published or linked from the page.
Fix: Provide a developer or technical documentation section describing the site's technology stack, APIs, or data schemas.
Responsibility to the Future
-
disclosure_exists: The partnerships page contains no published environmental impact or sustainability disclosure, focusing solely on corporate partnership benefits.
Fix: Publish a dedicated environmental impact or sustainability statement and link to it from the site's footer or about section.
-
specific_metrics: The page provides no specific environmental figures such as carbon emissions, energy use, or emissions data.
Fix: Add quantified environmental metrics (e.g., annual carbon emissions in tonnes CO2e and energy consumption) to a sustainability disclosure.
-
hosting_disclosure: There is no disclosure of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy profile or green-hosting credentials, including whether servers run on renewable energy.
-
plan_exists: The page is a corporate partnerships and about page with no published plan describing what would happen if the organisation fails or exits.
Fix: Publish a wind-down or continuity plan explaining what would happen to the organisation's operations, services, and digital assets in the event of closure.
-
data_and_content_fate: There is no mention of what happens to user data or published content should the organisation cease operations, only a link to a privacy policy.
Fix: Add explicit provisions describing how user data would be deleted or transferred and how published content would be preserved or archived if the organisation exits.
-
custodians_or_mirrors: The page does not identify any custodians, mirrors, or archive partners for the site's data or content.
Fix: Name a designated custodian, mirror, or archive partner responsible for preserving critical data and content in the event of organisational failure.
-
policy_exists: The careers page references a 'What We Offer & Benefits' section and mentions wellbeing in a job-category label, but no published worker wellbeing or working conditions policy appears on this page.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it prominently from the careers page.
-
specific_commitments: The page contains no specific commitments on pay, hours, mental health, or benefits, only a navigation link titled 'What We Offer & Benefits' with no detail shown.
Fix: Add concrete details about pay, working hours, mental health support, and benefits within the accessible page content.
-
accountability: The page names a 'HR, Wellbeing, Safeguarding, Diversity & Inclusion' job category but does not identify any accountable body or oversight mechanism for worker conditions.
Fix: Clearly state which team, role, or governance body is responsible for overseeing and enforcing worker conditions and wellbeing.