Scholastic UK

https://www.scholastic.co.uk · 44/92 checks passed · publishers

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 28/37 (9 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 6/16
Provenance 1/2
Security 6/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement among its listed policies (Accessibility, Cookie, Privacy, etc.).
    Fix: Publish a dedicated AI use policy and link it from the footer policy list alongside the Privacy and Cookie policies.
  • scope_clear: Because no AI policy is present, there is no explanation of what AI is used for on the site.
    Fix: Within a new AI policy, clearly describe where and how AI is used (e.g., recommendations, content generation, customer support).

Privacy

Security

  • strict-transport-security: header not set on the response.

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only commercial information about Book Fairs, Book Clubs and publishing activities.
    Fix: Add a clear funding/sponsorship disclosure section on the About page identifying revenue sources and any sponsors or partners.
  • transparent: No funding sources are identified on the page; it only references commercial products and a rewards programme without explaining how the organisation is funded.
    Fix: Explicitly list Scholastic's funding sources (e.g., book sales, publishing revenue, partnerships) in a dedicated, clearly labelled section.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The page lists phone operating hours but does not publish any timeframe for responding to emails or enquiries.
    Fix: Add an explicit response SLA (e.g., 'We respond to emails within 2 business days') next to each contact email.
  • specific: No specific response timeframe in days or hours is given for enquiries—only call-centre opening hours are stated.
    Fix: Publish a concrete, measurable response window (such as '3 working days') for written enquiries and complaints.
  • process_exists: The contact page provides phone numbers, emails and addresses but no documented complaints or feedback process (the 'Dispute resolution' footer link is not described or summarised here).
    Fix: Add a dedicated complaints/feedback section on the contact page that documents how to raise and escalate a complaint, linking to a formal policy.
  • steps_clear: No step-by-step instructions are provided for how to submit or escalate a complaint.
    Fix: List clear numbered steps (e.g., 1) email X, 2) expect acknowledgement in N days, 3) escalate to Y if unresolved) for making a complaint.
  • appeals_exists: The contact page lists customer service contacts but does not document any appeals process; only a generic 'Dispute resolution' footer link is mentioned without content shown.
    Fix: Add a clearly documented appeals process on the contact or dispute resolution page describing how users can formally appeal decisions.
  • independent: No independent or escalation path is described; all contacts route to internal Scholastic customer service channels.
    Fix: Provide an escalation route or reference to an independent ombudsman/third-party dispute body users can contact if internal resolution fails.

AI & Automation

  • detailed_scope: No AI policy is published on this page, so the scope of AI use is not detailed.
    Fix: Add a detailed AI scope section specifying systems, data inputs, and use cases across Scholastic's services.
  • limitations: No acknowledgement of AI limitations appears anywhere on the About page.
    Fix: Include a section in the AI policy acknowledging known limitations such as potential inaccuracies, bias, and age-appropriateness constraints.
  • safeguards: The page does not describe any safeguards or quality controls for AI systems.
    Fix: Document the safeguards (human review, child-safety filters, audits, data protections) applied to any AI features in the AI policy.
  • marking_policy: The About page contains no policy or statement about marking AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted content is labelled and link it from the About page or footer.
  • consistent: Without any marking policy present on the page, consistent application of AI content marking cannot be demonstrated.
    Fix: Apply AI content labels consistently across articles, products, and resources, and document examples in the policy.
  • oversight_exists: The page does not document any human oversight of AI outputs.
    Fix: Add a statement describing how humans review AI outputs before publication, accessible from the About or policies section.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Describe the editorial review workflow (who reviews, what checks are performed, approval steps) in a dedicated AI governance policy.
  • accountability: No accountable person, role, or team for AI-generated content is identified on the page.
    Fix: Name a responsible role (e.g., Editorial Director or AI Governance Lead) accountable for AI-generated content and provide a contact route.

Interoperability

Privacy

  • plain_language: The policy uses legalistic terms like 'controller', 'fair processing notice', 'Aggregated Data', and 'Special Categories of Personal Data' without plain-language explanations.
    Fix: Rewrite legal terms in plain English or include short lay-person definitions alongside each legal concept.
  • plain_language: The policy relies on GDPR jargon such as 'controller', 'Special Categories of Personal Data', and 'Aggregated Data' rather than jargon-free wording.
    Fix: Replace or gloss technical/legal terminology with everyday language (e.g. 'the company in charge of your data' instead of 'controller').
  • necessity: The visible content does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add a clear statement that Scholastic only collects personal data that is necessary for the specified purposes (data minimisation principle).
  • retention_stated: The visible portion of the policy does not mention data retention periods at all.
    Fix: Add a dedicated 'Data Retention' section describing how long each category of personal data is kept.
  • specific: No specific retention durations (e.g. months or years) are provided anywhere in the visible content.
    Fix: State concrete retention periods for each data category (e.g. 'transaction data retained for 7 years for tax purposes').
  • equal_choices: The page displays no visible cookie/consent banner with accept and reject options, so equal prominence cannot be verified on this privacy page.
    Fix: Implement a visible consent banner on the privacy page (and site-wide) with equally prominent 'Accept' and 'Reject' buttons of matching size, color, and styling.
  • ads_labelled: The About page contains promotional content for Book Fairs, Book Clubs, and Scholastic products without any labelling distinguishing promotional/advertising content from editorial content.
    Fix: Clearly label promotional sections or third-party advertising with terms like 'Advertisement' or 'Sponsored' to distinguish them from editorial content.
  • disclosure: There is no disclosure statement on the page explaining commercial relationships, sponsorships, or partnerships with advertisers or publishers referenced in the content.
    Fix: Add an advertising disclosure statement explaining any commercial relationships between Scholastic and the products, publishers, or partners featured on the page.
  • banner_present: No cookie or consent banner is visible in the provided page content; only a footer 'Cookies & Privacy' link is referenced.
    Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or customize cookie preferences.
  • partner_sharing_mentioned: The page content does not disclose any data sharing with third-party partners in a banner or on-page consent copy.
    Fix: Add clear disclosure within the consent banner explaining that data may be shared with named third-party advertising and analytics partners.
  • partner_count_specific: No partner sharing is disclosed, and therefore no specific numeric count of partners is stated on the page.
    Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner and link to the full partner list.

Provenance

Security

Transparency

  • detail: The page provides no meaningful detail on funding—no amounts, percentages, or categories of revenue are disclosed beyond a donated-books figure.
    Fix: Publish a breakdown of funding by category (e.g., retail sales, publishing, education resources) with approximate percentages or amounts.
  • complete: Because no funding disclosure is present, the page cannot be said to cover all major funding streams.
    Fix: Create a comprehensive funding statement covering every material revenue stream (Book Fairs, Book Clubs, publishing, education resources, etc.) and link to it from the About page.
  • governance_exists: The About page describes Scholastic's mission and product lines but does not outline any governance or editorial structure.
    Fix: Add a governance or editorial section describing how the organisation is structured and how editorial decisions are made.
  • roles_clear: No key roles or responsibilities (e.g., leadership, editorial board, oversight) are identified on the page.
    Fix: Publish a list of key leadership and editorial roles with their responsibilities, or link to a dedicated leadership/governance page.
  • algorithm_explained: The About page describes Scholastic's mission and products but makes no mention of any algorithms or their purpose (e.g., the 'book wizard' recommendation tool is named but not explained).
    Fix: Add a section describing any algorithmic tools used on the site (such as the book wizard recommender) and explain their purpose in plain language.
  • impact_clear: The page does not describe how algorithmic decisions affect users, such as how recommendations or rankings influence what children and parents see.
    Fix: Include a clear statement explaining how algorithmic outputs (e.g., recommended books) shape the user experience and what decisions they influence.
  • annual_statement: The page links to a Privacy Policy but provides no evidence on this page of a regular or annual review of data practices.
    Fix: Publish a statement indicating when the privacy/data practices were last reviewed and commit to a regular (e.g., annual) review cycle visible to users.
  • dated: No date or version information for the privacy policy or data practices statement is shown on this About page.
    Fix: Display a 'Last updated' date or version number alongside the Privacy Policy link or statement so users can verify its currency.

Level 3 — Advanced

Accessibility

  • known_issues: The statement only says it is 'partially conformant' with 'some parts of the content' not conforming, without naming any specific known accessibility issues or limitations.
    Fix: Add a section listing the specific known accessibility barriers (e.g., particular pages, components, or non-text content) that currently fail to meet WCAG 2.1 AA.
  • remediation_timeline: The statement expresses a general commitment to 'continually working towards' higher conformity but provides no target dates or timeline for fixing issues.
    Fix: Include specific target dates or milestones for remediating the identified accessibility issues.

Accountability

  • policy_exists: The About page lists various policies but no moderation policy is published or linked.
    Fix: Publish a dedicated moderation policy covering user-generated content on the kids' club and community features and link it in the footer.
  • criteria_clear: No moderation criteria are stated anywhere on the page for content such as user comments, wish lists, or kids' website interactions.
    Fix: Clearly document the criteria used to evaluate and remove content (e.g., prohibited content types, safety rules) within the moderation policy.
  • enforcement: The page does not describe how moderation decisions are enforced or appealed.
    Fix: Add an enforcement section explaining how violations are detected, actioned, and appealed, including timelines and responsible teams.

Interoperability

Security

  • plan_exists: The page and its footer policy links contain no published incident response plan or security policy, listing only items like Privacy Policy and Modern Slavery Statement.
    Fix: Publish a dedicated incident response plan or security policy and link it from the footer alongside the other policies.
  • notification_commitment: Nothing on the page commits to publicly notifying users of significant security incidents or breaches.
    Fix: Add an explicit commitment to notify affected users and the public in the event of a significant security incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of detecting a breach) in the incident response policy.

Transparency

  • criteria_published: No criteria used by any algorithmic decision-making (such as book recommendations) are published anywhere on the page.
    Fix: Publish the specific criteria (e.g., age, reading level, popularity, purchase history) used by recommendation or ranking algorithms.
  • weighting: The page gives no information about how criteria are weighted or prioritised in any algorithmic process.
    Fix: Disclose the relative weighting or priority of each criterion used in algorithmic decisions, even if expressed qualitatively.
  • auditable: There is insufficient technical or procedural detail on the page to allow any external audit or independent review of algorithmic systems.
    Fix: Provide an algorithmic transparency document or link describing data inputs, logic, and governance so that external auditors can review the system.
  • open_source: There is no mention of or link to publicly available source code on the about page.
    Fix: Add a link to a public code repository (e.g., GitHub) for any open-source components the site uses or publishes.
  • tech_docs: No technical documentation is published or linked from the page.
    Fix: Publish and link to technical documentation (e.g., API docs, developer resources, or a technology stack overview) from the about or footer area.

Responsibility to the Future

  • specific_metrics: The visible content only makes general commitments about sustainable resources and reducing carbon and waste, without any specific figures for carbon, energy use, or emissions.
    Fix: Publish concrete, quantified metrics (e.g., annual tonnes of CO2 emissions, energy consumption, and waste figures) directly on the page rather than only within a downloadable PDF.
  • hosting_disclosure: The page contains no information about the carbon or energy profile of the website's hosting infrastructure.
    Fix: Add a statement disclosing the hosting provider's carbon/energy profile, such as use of renewable-powered data centres or measured hosting emissions.
  • plan_exists: The About page describes Scholastic's mission, Book Fairs, Book Clubs, and resources, but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan outlining what happens to the service and its stakeholders should the organisation cease operations or exit the market.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add a statement specifying how user data and published content would be preserved, transferred, or securely deleted if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere in the page content.
    Fix: Identify and name a custodian, mirror, or archive partner who would take over stewardship of content and data in a wind-down scenario.
  • policy_exists: The careers page mentions an 'About us' and 'Benefits' section by name but contains no published policy text on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy statement on the careers page and link it clearly.
  • specific_commitments: The visible content offers only a generic welcome message with no specific commitments on pay, hours, mental health, or benefits.
    Fix: Add concrete commitments such as pay standards, working hours, mental health support, and benefit details within the careers content.
  • accountability: There is no named role, team, or oversight mechanism identified as responsible for worker conditions anywhere on the page.
    Fix: Identify a responsible person, department, or oversight body for worker wellbeing and provide contact or reporting details.