The Guardian
https://www.theguardian.com · 53/92 checks passed · media
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (7 failed) |
| Level 2 — Enhanced | 15/27 (12 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 4/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 9/16 |
| Provenance | 2/2 |
| Security | 8/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 2 WCAG 2.1 Level A violations reported by axe-core: list, scrollable-region-focusable.
- 2 WCAG 2.1 Level A violations reported by axe-core: list, scrollable-region-focusable.
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish a clear AI use policy on the About page (or link to one) stating the Guardian's stance on AI in journalism.
-
scope_clear: Because no AI policy is present, there is no explanation of what AI is used for.
Fix: Include a section describing specific AI use cases (e.g., research, transcription, content generation) so readers understand the scope.
- Not found at any of: /ai-policy, /ai.
Privacy
- No requests matched the tracker/ad domain list.
- 1 inline script matched a tracker/ad pattern; first match: ' window.guardian = {"config":{"isDotcomRendering":true,"isDe…'.
- 1 hidden iframe found: https://sourcepoint.theguardian.com/index.html?hasCsp=true&message_id=1403351&consentUUID=null&consent_origin=https%3A%2F%2Fsourcepoint.theguardian.com%2Fconsent%2Ftcfv2&preload_message=true&version=v1.
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (2 hops): https://www.theguardian.com → https://www.theguardian.com/uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
AI & Automation
-
detailed_scope: The page does not detail any scope of AI use as no AI policy content appears.
Fix: Add a detailed breakdown of where and how AI tools are applied across editorial workflows.
-
limitations: No acknowledgement of AI limitations appears anywhere on the page.
Fix: Explicitly acknowledge AI limitations such as hallucinations, bias, and accuracy concerns in the policy.
-
safeguards: The page does not describe any safeguards or quality controls related to AI.
Fix: Describe editorial safeguards such as human review, disclosure labels, and accuracy checks applied to AI-assisted content.
-
marking_policy: The About page contains no mention of any policy for labeling or marking AI-assisted content.
Fix: Publish a clear policy on the About or Journalism page describing how AI-assisted content is disclosed and labeled to readers.
-
consistent: Without any stated AI marking policy on this page, there is no evidence of consistent application of AI content labeling.
Fix: Document and link to standardized labeling conventions applied across all Guardian content where AI is used.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a section describing how editors and journalists supervise any use of AI tools in Guardian journalism.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Describe the editorial review and approval steps AI-assisted content must pass before publication.
-
accountability: The page does not identify any individual or role accountable for AI-generated content.
Fix: Name a responsible editor or team (e.g., the editor-in-chief or a designated AI editor) accountable for AI output and link to their remit.
Interoperability
Privacy
-
necessity: The visible content does not contain an explicit statement that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit data minimisation statement affirming that the Guardian only collects personal data necessary for the specified purposes.
-
retention_stated: The visible portion of the policy does not include a section stating how long personal data is retained.
Fix: Add a clearly labelled 'Data retention' section describing how long each category of personal data is kept.
-
specific: No specific retention time periods are stated on the visible page content.
Fix: Specify concrete retention periods (e.g., 'account data retained for X years after account closure') for each data category.
-
equal_choices: The privacy policy page itself does not display a consent banner with visible accept and reject options for comparison of prominence.
Fix: Ensure the consent banner presents 'Reject All' with equal visual weight (same size, color, and placement) as 'Accept All' and reference this standard within the privacy policy.
-
ads_labelled: The About page contains no advertising or sponsored content and provides no labelling policy for ads.
Fix: Add a statement or link explaining how advertising and sponsored content are labelled across Guardian properties.
-
disclosure: There is no disclosure on this page about relationships between editorial content and advertisers.
Fix: Include a clear disclosure or link to an advertising policy explaining the separation and relationships between editorial and advertisers.
-
banner_present: The page content shows no visible cookie or consent banner text in the provided content.
Fix: Implement a visible cookie/consent banner on the homepage that appears on first visit to inform users about data collection.
-
partner_sharing_mentioned: There is no on-page consent copy disclosing data sharing with third-party partners in the provided content.
Fix: Add explicit disclosure in the consent banner describing that user data may be shared with third-party advertising and analytics partners.
-
partner_count_specific: No specific numeric count of partners is stated anywhere in the page content.
Fix: Include the exact number of third-party partners (e.g., 'We share data with X partners') in the consent banner with a link to the full partner list.
Provenance
Security
Transparency
-
detail: The page mentions reader support categories (monthly, annual, one-time, subscriptions) but provides no amounts, percentages, or breakdown of how funding is distributed across sources.
Fix: Add a breakdown showing what percentage of revenue comes from reader contributions versus advertising, subscriptions, and other sources.
-
complete: The disclosure only addresses reader support and omits other known major streams such as advertising revenue, the Scott Trust endowment, and philanthropic grants.
Fix: Expand the disclosure to cover all major funding streams including advertising, Scott Trust investment income, and any philanthropic or institutional grants.
-
roles_clear: While the editor-in-chief Katharine Viner is named, the page does not clearly identify the responsibilities of other key roles within the governance entities or executive team.
Fix: Add a section listing key leadership roles (e.g., trustees, board members, executives) with brief descriptions of their responsibilities within the governance structure.
-
algorithm_explained: The About page does not mention any algorithms or explain their purpose in content selection, personalization, or decision-making.
Fix: Add a section (or link to a dedicated page) describing any algorithms used by the Guardian (e.g., for content recommendation or ad targeting) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users, such as what content they see or how their data is processed.
Fix: Include clear user-facing language explaining how algorithmic systems influence the reader experience and any resulting impacts on users.
-
annual_statement: The page contains no evidence of an annual or periodic review of data practices.
Fix: Publish a regularly reviewed data practices statement (e.g., annual privacy review) and link it from the About page.
-
dated: No data practices statement is shown, and nothing on the page is dated or versioned.
Fix: Add a dated or versioned data practices statement (or link to one) so readers can see when it was last updated.
Level 3 — Advanced
Accessibility
-
statement_exists: The page is a corporate 'About us' page describing ownership, funding and journalism, with no dedicated accessibility statement present.
Fix: Create a dedicated accessibility statement page and link to it prominently, for example from the site footer and this About section.
-
known_issues: No accessibility content exists on the page, so there is no acknowledgement of any known accessibility issues or limitations.
Fix: Add a section to the accessibility statement that lists known accessibility limitations and any non-conforming areas of the site.
-
remediation_timeline: The page contains no accessibility statement and therefore no timeline or commitment for fixing accessibility issues.
Fix: Include target dates or a commitment schedule in the accessibility statement for remediating identified accessibility problems.
-
feedback_channel: While a general 'Contact us' link exists, there is no accessibility-specific feedback mechanism with a stated response commitment.
Fix: Provide a dedicated accessibility feedback contact (email or form) along with a stated timeframe for responding to accessibility reports.
Accountability
-
policy_exists: The visible terms cover registration, content use, and liability but do not publish a moderation policy for user-submitted content.
Fix: Publish a dedicated moderation/community standards policy (or link to one) within the terms explaining how user content is reviewed.
-
criteria_clear: No clear criteria are stated for what content is permitted, prohibited, or subject to removal under moderation.
Fix: Add an explicit list of content standards (e.g., prohibited behaviors, hate speech, spam) that moderators apply when reviewing submissions.
-
enforcement: While the terms mention Guardian may cancel access at its sole discretion, they do not explain the moderation enforcement process, appeals, or review workflow.
Fix: Document the enforcement workflow including how violations are detected, notifications given to users, and how users can appeal moderation decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page describes ownership, funding, and journalism but contains no published incident response plan or security policy.
Fix: Publish a dedicated incident response plan or security policy page and link to it from the About or Contact section.
-
notification_commitment: The page makes no commitment to publicly notify affected users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant security incident.
-
timeframe: No disclosure timeframe for incidents is mentioned anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovering an incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page contains no published criteria for any algorithmic decisions made by the Guardian.
Fix: Publish a transparency page listing the specific inputs and criteria used by any ranking, recommendation, or moderation algorithms.
-
weighting: No weighting or prioritization information for algorithmic criteria is provided anywhere on the page.
Fix: Disclose how different criteria are weighted or prioritized in algorithmic decisions, even at a high level.
-
auditable: The page provides no technical detail, documentation, or audit mechanism that would allow external review of any algorithms.
Fix: Provide documentation, methodology, or an audit/contact process enabling independent review of algorithmic systems.
-
open_source: The about page does not link to any public source code repositories for Guardian's technical platforms.
Fix: Add a link to the Guardian's open-source repositories (e.g., their GitHub organisation) from the about or work-with-us section.
-
tech_docs: No technical documentation is referenced or linked on the about page.
Fix: Include a link to developer or technical documentation, such as an open platform, API docs, or engineering blog.
Responsibility to the Future
-
specific_metrics: The visible content references reports and blog narratives but shows no specific figures for carbon, energy use, or emissions.
Fix: Publish concrete quantitative metrics such as annual carbon emissions (tCO2e), energy consumption (kWh), and year-over-year reduction targets on the sustainability page.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or digital infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy sourcing (e.g., renewable-powered data centers) and the estimated carbon footprint of the site's digital infrastructure.
-
plan_exists: The page describes the Scott Trust's mission to secure independence 'in perpetuity' but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish an explicit continuity or wind-down plan describing what happens to the organisation and its journalism in the event of financial failure or exit.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content should the organisation cease to operate.
Fix: Add a section detailing the fate of user data and the archive of published content in a shutdown scenario, including deletion, transfer, or preservation commitments.
-
custodians_or_mirrors: The page names the Scott Trust and Guardian Media Group as owners but does not identify any custodians, mirrors, or archive partners for preserving content if the organisation exits.
Fix: Identify designated custodians, mirror sites, or archival partners (e.g., a library or web archive) responsible for preserving the content long-term.
-
policy_exists: The page is a Guardian culture section listing arts, music, TV, and books articles with no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
-
specific_commitments: No specific commitments regarding pay, hours, mental health, or benefits appear anywhere on this culture content page.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and benefits to the wellbeing policy.
-
accountability: The page contains no reference to any person, team, or body responsible for overseeing worker conditions.
Fix: Name a responsible role or oversight body and describe how worker conditions are monitored and reported.