Tate
https://www.tate.org.uk · 47/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 26/37 (11 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 3/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 image missing alt attribute: none.
- 1 image missing alt attribute: none.
- Heading hierarchy issues: h2 -> h5 (skipped h3).
AI & Automation
-
policy_exists: The page is a privacy notice with no mention of an AI use policy or statement.
Fix: Publish a dedicated AI use policy page outlining whether and how AI is used across Tate's digital services.
-
scope_clear: No AI-related content is present, so the scope of AI use is not explained.
Fix: Include a clear section describing which AI tools or features are used (e.g., chatbots, recommendations, content generation) and for what purposes.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 hidden iframe found: https://www.tate.org.uk/.
- Detected 1 data-leaking service across 1 category: google fonts (fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.tate.org.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
purpose_clear: The /about path actually shows a Tate Privacy Notice, which does not clearly state what the organisation does.
Fix: Ensure the /about URL resolves to an actual About page that clearly describes Tate's mission and activities, rather than the privacy notice.
-
disclosure_exists: The page is a privacy notice and contains no funding or sponsorship disclosure beyond a generic mention of 'donors, supporters'.
Fix: Add a dedicated funding/sponsorship disclosure section (or link) identifying Tate's funders and sponsors.
-
transparent: Funding sources are not clearly identified; the page only vaguely references 'donors, supporters, employees, workers, volunteers and the general public'.
Fix: Publish a transparent list of named funders, sponsors, and government bodies supporting Tate on this or a linked page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
steps_clear: While the internal handling process is described, the page does not lay out clear step-by-step instructions for a visitor on how to submit a complaint (e.g., which form, email, or channel to use first).
Fix: Add a numbered step-by-step guide explaining how to submit a complaint, including the specific contact channel to use initially and how to request escalation.
AI & Automation
-
detailed_scope: There is no AI policy on this page and therefore no detailed scope of AI use.
Fix: Add an AI policy page that enumerates specific AI systems, their use cases, and data inputs/outputs.
-
limitations: The page makes no reference to AI systems or their limitations.
Fix: Acknowledge known AI limitations such as inaccuracies, bias, or hallucinations within the AI policy.
-
safeguards: No AI safeguards or quality controls are described since no AI policy is present.
Fix: Describe safeguards such as human review, bias testing, data protection measures, and escalation paths for AI-related issues.
-
marking_policy: The privacy notice page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy describing how AI-assisted or AI-generated content will be labelled on Tate's website.
-
consistent: Without any visible marking policy on this page, there is no evidence that AI content marking is applied consistently.
Fix: Establish and enforce a consistent labelling convention for AI-generated content across all Tate pages and document it publicly.
-
oversight_exists: The page makes no mention of human oversight of AI outputs or any AI governance process.
Fix: Add a section to the governance or privacy materials documenting how humans oversee and validate AI outputs used by Tate.
-
review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
Fix: Describe the editorial review and approval process that AI-generated content must pass before publication.
-
accountability: The page does not identify any role, team, or individual accountable for AI-generated content.
Fix: Name an accountable role (e.g., editorial lead or data protection officer) responsible for AI-generated content and include contact information.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible page content does not explicitly state that data collection is limited to what is necessary.
Fix: Add an explicit statement (e.g. in 'The Data We Collect About You') that Tate only collects personal data that is necessary for the stated purposes.
-
proportionate: There is no visible statement addressing proportionality of data collection relative to the service provided.
Fix: Include wording confirming that data collected is proportionate to the services offered and tied to specific processing purposes.
-
retention_stated: No retention section or statement about how long data is kept is visible on the page.
Fix: Add a dedicated 'Data Retention' section explaining how long different categories of personal data are retained.
-
specific: Because no retention information is present, no specific retention periods are given.
Fix: Specify concrete retention periods (e.g. 'marketing data retained for 24 months after last interaction') for each category of data.
-
equal_choices: The page shows no visible consent interface with accept/reject options of equal prominence; only a 'Cookies' link in the footer is visible.
Fix: Provide a clearly visible cookie/consent banner with 'Accept' and 'Reject' buttons of equal size, color, and prominence.
-
no_forced_consent: The email signup form states Google reCAPTCHA and Tate's privacy policy 'apply' without offering a granular or opt-out choice, implying bundled acceptance.
Fix: Separate consent for reCAPTCHA/third-party processing from email signup and allow users to subscribe without forced acceptance of bundled terms.
-
partner_count_specific: The banner references partners and links to 'View our partners' but does not state a specific numeric count of partners on the page.
Fix: Display the exact number of third-party partners (e.g., 'We and our 123 partners...') directly in the banner copy alongside the 'View our partners' link.
Provenance
-
authorship_clear: The page is a privacy notice rather than an about page and does not identify who creates or curates Tate's content beyond a generic footer attribution.
Fix: Add a clear authorship or curatorial statement identifying the individuals or teams responsible for Tate's content on the about page.
-
credentials: No author or organisational credentials or background information is provided on this page beyond the copyright line for the Board of Trustees.
Fix: Include a section describing Tate's organisational history, governance, and the credentials of its curatorial and editorial staff.
Security
- security.txt not published.
Transparency
-
substantive: The page contains a privacy notice rather than a substantive statement of organisational purpose.
Fix: Replace or supplement this content with a detailed description of Tate's purpose, activities, and impact on the arts.
-
mission_clear: No mission statement or editorial approach is articulated on this privacy-focused page.
Fix: Add a clearly articulated mission statement explaining Tate's role in promoting public understanding and enjoyment of British and international art.
-
detail: No amounts, percentages, or categories of funding are described on this page.
Fix: Include meaningful funding detail such as percentage breakdowns by source (e.g., government grant, membership, donations, commercial).
-
complete: The page does not enumerate any major funding streams, so it cannot be considered complete.
Fix: Provide a comprehensive funding disclosure covering all major streams (public grants, memberships, corporate sponsorship, philanthropy, trading income).
-
governance_exists: The page is a privacy notice and does not describe Tate's governance or editorial structure, though a 'Governance' link exists in the footer.
Fix: Add a dedicated governance section or link prominently from this page describing Tate's board, editorial oversight, and decision-making structure.
-
roles_clear: No key roles or responsibilities (e.g., trustees, directors, editorial leads) are identified in the visible content.
Fix: Include a clear list of named roles and responsibilities such as Board of Trustees, Director, and editorial leads with brief descriptions of their duties.
-
algorithm_explained: The page mentions reCAPTCHA but does not explain the purpose of any algorithms used by Tate in processing personal data or decisions.
Fix: Add a section describing any algorithms or automated processing used (including reCAPTCHA and any profiling) and their specific purposes.
-
impact_clear: The page does not describe how algorithmic decisions affect users, such as what reCAPTCHA blocking or automated profiling might mean for them.
Fix: Include a clear statement of user-facing impacts from automated decisions, such as access restrictions, marketing targeting, or data sharing consequences.
-
annual_statement: The visible content mentions 'Updates or Changes to the Privacy Notice' as a section but shows no evidence of a regular or annual review cadence.
Fix: Add an explicit statement indicating that the privacy notice is reviewed on a regular (e.g., annual) basis and display the most recent review date.
-
dated: The privacy notice text shown on the page does not include a visible 'last updated' date or version number.
Fix: Display a clear 'Last updated' date or version identifier at the top of the privacy notice.
Level 3 — Advanced
Accessibility
-
known_issues: The visible page only links out to the statement and does not itself acknowledge any specific known accessibility issues or limitations.
Fix: Surface a summary of known accessibility issues (e.g., non-compliant content or elements) directly on this page or ensure the linked statement lists them clearly.
-
remediation_timeline: There is no mention of any timeline or commitment for fixing known accessibility issues on this page.
Fix: Add a stated timeline or commitment (e.g., 'we aim to resolve identified issues by [date]') describing when known problems will be addressed.
-
feedback_channel: While contact emails and phone numbers are provided, there is no explicit feedback mechanism tied to accessibility with a commitment on response time.
Fix: Provide a dedicated accessibility feedback channel and state a clear response commitment, such as replying within a specified number of working days.
Accountability
-
criteria_clear: The visible page only lists section headings (e.g., user-generated content, take down policy) without articulating specific criteria for what content is acceptable or will be moderated.
Fix: Expand the 'Contributions' and 'Tate Communities' sections with explicit, enumerated criteria (e.g., prohibitions on hate speech, spam, IP infringement) so users know what content will be moderated.
-
enforcement: The page references a 'Complaints and Take Down Policy' but does not describe the actual enforcement workflow, timelines, or consequences for violations.
Fix: Add a clear description of the enforcement process, including how reports are reviewed, response timelines, possible actions (removal, bans), and appeal options.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is a privacy notice describing data collection and security in general terms, but no published incident response plan or policy is present.
Fix: Publish a dedicated incident response plan or security breach policy describing how Tate detects, manages, and responds to security incidents.
-
notification_commitment: The page mentions keeping personal data secure but contains no commitment to publicly notify users of significant security incidents or breaches.
Fix: Add an explicit statement committing to notify affected users and relevant authorities in the event of a significant data breach.
-
timeframe: There is no stated timeframe for disclosing incidents to affected users anywhere in the page content.
Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users and the ICO within 72 hours of discovery) in the breach notification section.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria used in any algorithmic decision-making are published on this page.
Fix: Publish the concrete inputs and decision criteria used by any automated systems (e.g., reCAPTCHA scoring factors, segmentation rules).
-
weighting: There is no explanation of how criteria are weighted or prioritised in any algorithmic process.
Fix: Document the relative weighting or priority order of the criteria feeding any automated decisions so users understand what matters most.
-
auditable: The page provides no technical or procedural detail sufficient to enable external audit of algorithmic processes.
Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS template) with model details, data sources, and review procedures to support external audit.
-
open_source: There is no link to publicly available source code or any open-source repository on the page.
Fix: Provide a link to a public code repository (e.g., GitHub) for any open-source projects Tate maintains, or state the source code policy.
-
tech_docs: No technical documentation is published or linked from this page.
Fix: Publish and link to technical documentation such as API docs, data schemas, or developer resources from the about or footer area.
Responsibility to the Future
-
disclosure_exists: The page is a privacy notice with no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement describing the organisation's environmental commitments and performance.
-
specific_metrics: The page contains no specific figures on carbon, energy use, or emissions.
Fix: Include quantified metrics such as annual carbon footprint, energy consumption, and emissions data in an environmental disclosure.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of the site's hosting infrastructure.
Fix: Disclose the hosting provider's energy sourcing (e.g., renewable-powered data centres) and the digital carbon footprint of the website.
-
plan_exists: The governance page describes current structure, funding and charitable status but contains no published plan for what happens if the organisation fails, dissolves, or exits.
Fix: Publish a succession or wind-down plan describing what happens to Tate's assets, collections, and operations in the event of organisational failure or dissolution.
-
data_and_content_fate: The page does not address what would happen to user data or published content should the organisation cease to operate.
Fix: Add a section specifying how user data and published web content would be preserved, transferred, or deleted if Tate were to close.
-
custodians_or_mirrors: While connected charities and subsidiaries are named, no custodians, mirrors, or archive partners are identified for preserving content or data in a failure scenario.
Fix: Identify a named custodian or archive partner (e.g. The National Archives) responsible for preserving Tate's digital content and collection records if the organisation ceases operating.
-
policy_exists: The page is a privacy notice about personal data collection and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About/Governance sections.
-
specific_commitments: The page only mentions employees, workers, and volunteers in passing regarding fair conduct, with no specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete commitments covering pay, working hours, mental health support, and staff benefits to a worker wellbeing policy.
-
accountability: The page identifies no accountable person, team, or oversight mechanism for worker conditions, only referencing the Board of Trustees in a copyright notice.
Fix: Designate and publicly name a responsible role or committee overseeing worker conditions, including reporting and review arrangements.