Tate

https://www.tate.org.uk · 47/92 checks passed · archives

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 3/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 6/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page is a privacy notice with no mention of an AI use policy or statement.
    Fix: Publish a dedicated AI use policy page outlining whether and how AI is used across Tate's digital services.
  • scope_clear: No AI-related content is present, so the scope of AI use is not explained.
    Fix: Include a clear section describing which AI tools or features are used (e.g., chatbots, recommendations, content generation) and for what purposes.

Privacy

Security

Transparency

  • purpose_clear: The /about path actually shows a Tate Privacy Notice, which does not clearly state what the organisation does.
    Fix: Ensure the /about URL resolves to an actual About page that clearly describes Tate's mission and activities, rather than the privacy notice.
  • disclosure_exists: The page is a privacy notice and contains no funding or sponsorship disclosure beyond a generic mention of 'donors, supporters'.
    Fix: Add a dedicated funding/sponsorship disclosure section (or link) identifying Tate's funders and sponsors.
  • transparent: Funding sources are not clearly identified; the page only vaguely references 'donors, supporters, employees, workers, volunteers and the general public'.
    Fix: Publish a transparent list of named funders, sponsors, and government bodies supporting Tate on this or a linked page.

Level 2 — Enhanced

Accessibility

Accountability

  • steps_clear: While the internal handling process is described, the page does not lay out clear step-by-step instructions for a visitor on how to submit a complaint (e.g., which form, email, or channel to use first).
    Fix: Add a numbered step-by-step guide explaining how to submit a complaint, including the specific contact channel to use initially and how to request escalation.

AI & Automation

  • detailed_scope: There is no AI policy on this page and therefore no detailed scope of AI use.
    Fix: Add an AI policy page that enumerates specific AI systems, their use cases, and data inputs/outputs.
  • limitations: The page makes no reference to AI systems or their limitations.
    Fix: Acknowledge known AI limitations such as inaccuracies, bias, or hallucinations within the AI policy.
  • safeguards: No AI safeguards or quality controls are described since no AI policy is present.
    Fix: Describe safeguards such as human review, bias testing, data protection measures, and escalation paths for AI-related issues.
  • marking_policy: The privacy notice page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy describing how AI-assisted or AI-generated content will be labelled on Tate's website.
  • consistent: Without any visible marking policy on this page, there is no evidence that AI content marking is applied consistently.
    Fix: Establish and enforce a consistent labelling convention for AI-generated content across all Tate pages and document it publicly.
  • oversight_exists: The page makes no mention of human oversight of AI outputs or any AI governance process.
    Fix: Add a section to the governance or privacy materials documenting how humans oversee and validate AI outputs used by Tate.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Describe the editorial review and approval process that AI-generated content must pass before publication.
  • accountability: The page does not identify any role, team, or individual accountable for AI-generated content.
    Fix: Name an accountable role (e.g., editorial lead or data protection officer) responsible for AI-generated content and include contact information.

Interoperability

Privacy

  • necessity: The visible page content does not explicitly state that data collection is limited to what is necessary.
    Fix: Add an explicit statement (e.g. in 'The Data We Collect About You') that Tate only collects personal data that is necessary for the stated purposes.
  • proportionate: There is no visible statement addressing proportionality of data collection relative to the service provided.
    Fix: Include wording confirming that data collected is proportionate to the services offered and tied to specific processing purposes.
  • retention_stated: No retention section or statement about how long data is kept is visible on the page.
    Fix: Add a dedicated 'Data Retention' section explaining how long different categories of personal data are retained.
  • specific: Because no retention information is present, no specific retention periods are given.
    Fix: Specify concrete retention periods (e.g. 'marketing data retained for 24 months after last interaction') for each category of data.
  • equal_choices: The page shows no visible consent interface with accept/reject options of equal prominence; only a 'Cookies' link in the footer is visible.
    Fix: Provide a clearly visible cookie/consent banner with 'Accept' and 'Reject' buttons of equal size, color, and prominence.
  • no_forced_consent: The email signup form states Google reCAPTCHA and Tate's privacy policy 'apply' without offering a granular or opt-out choice, implying bundled acceptance.
    Fix: Separate consent for reCAPTCHA/third-party processing from email signup and allow users to subscribe without forced acceptance of bundled terms.
  • partner_count_specific: The banner references partners and links to 'View our partners' but does not state a specific numeric count of partners on the page.
    Fix: Display the exact number of third-party partners (e.g., 'We and our 123 partners...') directly in the banner copy alongside the 'View our partners' link.

Provenance

  • authorship_clear: The page is a privacy notice rather than an about page and does not identify who creates or curates Tate's content beyond a generic footer attribution.
    Fix: Add a clear authorship or curatorial statement identifying the individuals or teams responsible for Tate's content on the about page.
  • credentials: No author or organisational credentials or background information is provided on this page beyond the copyright line for the Board of Trustees.
    Fix: Include a section describing Tate's organisational history, governance, and the credentials of its curatorial and editorial staff.

Security

Transparency

  • substantive: The page contains a privacy notice rather than a substantive statement of organisational purpose.
    Fix: Replace or supplement this content with a detailed description of Tate's purpose, activities, and impact on the arts.
  • mission_clear: No mission statement or editorial approach is articulated on this privacy-focused page.
    Fix: Add a clearly articulated mission statement explaining Tate's role in promoting public understanding and enjoyment of British and international art.
  • detail: No amounts, percentages, or categories of funding are described on this page.
    Fix: Include meaningful funding detail such as percentage breakdowns by source (e.g., government grant, membership, donations, commercial).
  • complete: The page does not enumerate any major funding streams, so it cannot be considered complete.
    Fix: Provide a comprehensive funding disclosure covering all major streams (public grants, memberships, corporate sponsorship, philanthropy, trading income).
  • governance_exists: The page is a privacy notice and does not describe Tate's governance or editorial structure, though a 'Governance' link exists in the footer.
    Fix: Add a dedicated governance section or link prominently from this page describing Tate's board, editorial oversight, and decision-making structure.
  • roles_clear: No key roles or responsibilities (e.g., trustees, directors, editorial leads) are identified in the visible content.
    Fix: Include a clear list of named roles and responsibilities such as Board of Trustees, Director, and editorial leads with brief descriptions of their duties.
  • algorithm_explained: The page mentions reCAPTCHA but does not explain the purpose of any algorithms used by Tate in processing personal data or decisions.
    Fix: Add a section describing any algorithms or automated processing used (including reCAPTCHA and any profiling) and their specific purposes.
  • impact_clear: The page does not describe how algorithmic decisions affect users, such as what reCAPTCHA blocking or automated profiling might mean for them.
    Fix: Include a clear statement of user-facing impacts from automated decisions, such as access restrictions, marketing targeting, or data sharing consequences.
  • annual_statement: The visible content mentions 'Updates or Changes to the Privacy Notice' as a section but shows no evidence of a regular or annual review cadence.
    Fix: Add an explicit statement indicating that the privacy notice is reviewed on a regular (e.g., annual) basis and display the most recent review date.
  • dated: The privacy notice text shown on the page does not include a visible 'last updated' date or version number.
    Fix: Display a clear 'Last updated' date or version identifier at the top of the privacy notice.

Level 3 — Advanced

Accessibility

  • known_issues: The visible page only links out to the statement and does not itself acknowledge any specific known accessibility issues or limitations.
    Fix: Surface a summary of known accessibility issues (e.g., non-compliant content or elements) directly on this page or ensure the linked statement lists them clearly.
  • remediation_timeline: There is no mention of any timeline or commitment for fixing known accessibility issues on this page.
    Fix: Add a stated timeline or commitment (e.g., 'we aim to resolve identified issues by [date]') describing when known problems will be addressed.
  • feedback_channel: While contact emails and phone numbers are provided, there is no explicit feedback mechanism tied to accessibility with a commitment on response time.
    Fix: Provide a dedicated accessibility feedback channel and state a clear response commitment, such as replying within a specified number of working days.

Accountability

  • criteria_clear: The visible page only lists section headings (e.g., user-generated content, take down policy) without articulating specific criteria for what content is acceptable or will be moderated.
    Fix: Expand the 'Contributions' and 'Tate Communities' sections with explicit, enumerated criteria (e.g., prohibitions on hate speech, spam, IP infringement) so users know what content will be moderated.
  • enforcement: The page references a 'Complaints and Take Down Policy' but does not describe the actual enforcement workflow, timelines, or consequences for violations.
    Fix: Add a clear description of the enforcement process, including how reports are reviewed, response timelines, possible actions (removal, bans), and appeal options.

Interoperability

Security

  • plan_exists: The page is a privacy notice describing data collection and security in general terms, but no published incident response plan or policy is present.
    Fix: Publish a dedicated incident response plan or security breach policy describing how Tate detects, manages, and responds to security incidents.
  • notification_commitment: The page mentions keeping personal data secure but contains no commitment to publicly notify users of significant security incidents or breaches.
    Fix: Add an explicit statement committing to notify affected users and relevant authorities in the event of a significant data breach.
  • timeframe: There is no stated timeframe for disclosing incidents to affected users anywhere in the page content.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users and the ICO within 72 hours of discovery) in the breach notification section.

Transparency

  • criteria_published: No specific criteria used in any algorithmic decision-making are published on this page.
    Fix: Publish the concrete inputs and decision criteria used by any automated systems (e.g., reCAPTCHA scoring factors, segmentation rules).
  • weighting: There is no explanation of how criteria are weighted or prioritised in any algorithmic process.
    Fix: Document the relative weighting or priority order of the criteria feeding any automated decisions so users understand what matters most.
  • auditable: The page provides no technical or procedural detail sufficient to enable external audit of algorithmic processes.
    Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS template) with model details, data sources, and review procedures to support external audit.
  • open_source: There is no link to publicly available source code or any open-source repository on the page.
    Fix: Provide a link to a public code repository (e.g., GitHub) for any open-source projects Tate maintains, or state the source code policy.
  • tech_docs: No technical documentation is published or linked from this page.
    Fix: Publish and link to technical documentation such as API docs, data schemas, or developer resources from the about or footer area.

Responsibility to the Future

  • disclosure_exists: The page is a privacy notice with no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement describing the organisation's environmental commitments and performance.
  • specific_metrics: The page contains no specific figures on carbon, energy use, or emissions.
    Fix: Include quantified metrics such as annual carbon footprint, energy consumption, and emissions data in an environmental disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of the site's hosting infrastructure.
    Fix: Disclose the hosting provider's energy sourcing (e.g., renewable-powered data centres) and the digital carbon footprint of the website.
  • plan_exists: The governance page describes current structure, funding and charitable status but contains no published plan for what happens if the organisation fails, dissolves, or exits.
    Fix: Publish a succession or wind-down plan describing what happens to Tate's assets, collections, and operations in the event of organisational failure or dissolution.
  • data_and_content_fate: The page does not address what would happen to user data or published content should the organisation cease to operate.
    Fix: Add a section specifying how user data and published web content would be preserved, transferred, or deleted if Tate were to close.
  • custodians_or_mirrors: While connected charities and subsidiaries are named, no custodians, mirrors, or archive partners are identified for preserving content or data in a failure scenario.
    Fix: Identify a named custodian or archive partner (e.g. The National Archives) responsible for preserving Tate's digital content and collection records if the organisation ceases operating.
  • policy_exists: The page is a privacy notice about personal data collection and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About/Governance sections.
  • specific_commitments: The page only mentions employees, workers, and volunteers in passing regarding fair conduct, with no specific commitments on pay, hours, mental health, or benefits.
    Fix: Add concrete commitments covering pay, working hours, mental health support, and staff benefits to a worker wellbeing policy.
  • accountability: The page identifies no accountable person, team, or oversight mechanism for worker conditions, only referencing the Board of Trustees in a copyright notice.
    Fix: Designate and publicly name a responsible role or committee overseeing worker conditions, including reporting and review arrangements.