The Guardian

https://www.theguardian.com · 53/92 checks passed · media

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 15/27 (12 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 4/5
AI & Automation 3/8
Interoperability 2/3
Privacy 9/16
Provenance 2/2
Security 8/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no mention of an AI use policy or statement.
    Fix: Publish a clear AI use policy on the About page (or link to one) stating the Guardian's stance on AI in journalism.
  • scope_clear: Because no AI policy is present, there is no explanation of what AI is used for.
    Fix: Include a section describing specific AI use cases (e.g., research, transcription, content generation) so readers understand the scope.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

AI & Automation

  • detailed_scope: The page does not detail any scope of AI use as no AI policy content appears.
    Fix: Add a detailed breakdown of where and how AI tools are applied across editorial workflows.
  • limitations: No acknowledgement of AI limitations appears anywhere on the page.
    Fix: Explicitly acknowledge AI limitations such as hallucinations, bias, and accuracy concerns in the policy.
  • safeguards: The page does not describe any safeguards or quality controls related to AI.
    Fix: Describe editorial safeguards such as human review, disclosure labels, and accuracy checks applied to AI-assisted content.
  • marking_policy: The About page contains no mention of any policy for labeling or marking AI-assisted content.
    Fix: Publish a clear policy on the About or Journalism page describing how AI-assisted content is disclosed and labeled to readers.
  • consistent: Without any stated AI marking policy on this page, there is no evidence of consistent application of AI content labeling.
    Fix: Document and link to standardized labeling conventions applied across all Guardian content where AI is used.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a section describing how editors and journalists supervise any use of AI tools in Guardian journalism.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Describe the editorial review and approval steps AI-assisted content must pass before publication.
  • accountability: The page does not identify any individual or role accountable for AI-generated content.
    Fix: Name a responsible editor or team (e.g., the editor-in-chief or a designated AI editor) accountable for AI output and link to their remit.

Interoperability

Privacy

  • necessity: The visible content does not contain an explicit statement that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit data minimisation statement affirming that the Guardian only collects personal data necessary for the specified purposes.
  • retention_stated: The visible portion of the policy does not include a section stating how long personal data is retained.
    Fix: Add a clearly labelled 'Data retention' section describing how long each category of personal data is kept.
  • specific: No specific retention time periods are stated on the visible page content.
    Fix: Specify concrete retention periods (e.g., 'account data retained for X years after account closure') for each data category.
  • equal_choices: The privacy policy page itself does not display a consent banner with visible accept and reject options for comparison of prominence.
    Fix: Ensure the consent banner presents 'Reject All' with equal visual weight (same size, color, and placement) as 'Accept All' and reference this standard within the privacy policy.
  • ads_labelled: The About page contains no advertising or sponsored content and provides no labelling policy for ads.
    Fix: Add a statement or link explaining how advertising and sponsored content are labelled across Guardian properties.
  • disclosure: There is no disclosure on this page about relationships between editorial content and advertisers.
    Fix: Include a clear disclosure or link to an advertising policy explaining the separation and relationships between editorial and advertisers.
  • banner_present: The page content shows no visible cookie or consent banner text in the provided content.
    Fix: Implement a visible cookie/consent banner on the homepage that appears on first visit to inform users about data collection.
  • partner_sharing_mentioned: There is no on-page consent copy disclosing data sharing with third-party partners in the provided content.
    Fix: Add explicit disclosure in the consent banner describing that user data may be shared with third-party advertising and analytics partners.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the page content.
    Fix: Include the exact number of third-party partners (e.g., 'We share data with X partners') in the consent banner with a link to the full partner list.

Provenance

Security

Transparency

  • detail: The page mentions reader support categories (monthly, annual, one-time, subscriptions) but provides no amounts, percentages, or breakdown of how funding is distributed across sources.
    Fix: Add a breakdown showing what percentage of revenue comes from reader contributions versus advertising, subscriptions, and other sources.
  • complete: The disclosure only addresses reader support and omits other known major streams such as advertising revenue, the Scott Trust endowment, and philanthropic grants.
    Fix: Expand the disclosure to cover all major funding streams including advertising, Scott Trust investment income, and any philanthropic or institutional grants.
  • roles_clear: While the editor-in-chief Katharine Viner is named, the page does not clearly identify the responsibilities of other key roles within the governance entities or executive team.
    Fix: Add a section listing key leadership roles (e.g., trustees, board members, executives) with brief descriptions of their responsibilities within the governance structure.
  • algorithm_explained: The About page does not mention any algorithms or explain their purpose in content selection, personalization, or decision-making.
    Fix: Add a section (or link to a dedicated page) describing any algorithms used by the Guardian (e.g., for content recommendation or ad targeting) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users, such as what content they see or how their data is processed.
    Fix: Include clear user-facing language explaining how algorithmic systems influence the reader experience and any resulting impacts on users.
  • annual_statement: The page contains no evidence of an annual or periodic review of data practices.
    Fix: Publish a regularly reviewed data practices statement (e.g., annual privacy review) and link it from the About page.
  • dated: No data practices statement is shown, and nothing on the page is dated or versioned.
    Fix: Add a dated or versioned data practices statement (or link to one) so readers can see when it was last updated.

Level 3 — Advanced

Accessibility

  • statement_exists: The page is a corporate 'About us' page describing ownership, funding and journalism, with no dedicated accessibility statement present.
    Fix: Create a dedicated accessibility statement page and link to it prominently, for example from the site footer and this About section.
  • known_issues: No accessibility content exists on the page, so there is no acknowledgement of any known accessibility issues or limitations.
    Fix: Add a section to the accessibility statement that lists known accessibility limitations and any non-conforming areas of the site.
  • remediation_timeline: The page contains no accessibility statement and therefore no timeline or commitment for fixing accessibility issues.
    Fix: Include target dates or a commitment schedule in the accessibility statement for remediating identified accessibility problems.
  • feedback_channel: While a general 'Contact us' link exists, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Provide a dedicated accessibility feedback contact (email or form) along with a stated timeframe for responding to accessibility reports.

Accountability

  • policy_exists: The visible terms cover registration, content use, and liability but do not publish a moderation policy for user-submitted content.
    Fix: Publish a dedicated moderation/community standards policy (or link to one) within the terms explaining how user content is reviewed.
  • criteria_clear: No clear criteria are stated for what content is permitted, prohibited, or subject to removal under moderation.
    Fix: Add an explicit list of content standards (e.g., prohibited behaviors, hate speech, spam) that moderators apply when reviewing submissions.
  • enforcement: While the terms mention Guardian may cancel access at its sole discretion, they do not explain the moderation enforcement process, appeals, or review workflow.
    Fix: Document the enforcement workflow including how violations are detected, notifications given to users, and how users can appeal moderation decisions.

Interoperability

Security

  • plan_exists: The About page describes ownership, funding, and journalism but contains no published incident response plan or security policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the About or Contact section.
  • notification_commitment: The page makes no commitment to publicly notify affected users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant security incident.
  • timeframe: No disclosure timeframe for incidents is mentioned anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovering an incident).

Transparency

  • criteria_published: The page contains no published criteria for any algorithmic decisions made by the Guardian.
    Fix: Publish a transparency page listing the specific inputs and criteria used by any ranking, recommendation, or moderation algorithms.
  • weighting: No weighting or prioritization information for algorithmic criteria is provided anywhere on the page.
    Fix: Disclose how different criteria are weighted or prioritized in algorithmic decisions, even at a high level.
  • auditable: The page provides no technical detail, documentation, or audit mechanism that would allow external review of any algorithms.
    Fix: Provide documentation, methodology, or an audit/contact process enabling independent review of algorithmic systems.
  • open_source: The about page does not link to any public source code repositories for Guardian's technical platforms.
    Fix: Add a link to the Guardian's open-source repositories (e.g., their GitHub organisation) from the about or work-with-us section.
  • tech_docs: No technical documentation is referenced or linked on the about page.
    Fix: Include a link to developer or technical documentation, such as an open platform, API docs, or engineering blog.

Responsibility to the Future

  • specific_metrics: The visible content references reports and blog narratives but shows no specific figures for carbon, energy use, or emissions.
    Fix: Publish concrete quantitative metrics such as annual carbon emissions (tCO2e), energy consumption (kWh), and year-over-year reduction targets on the sustainability page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or digital infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy sourcing (e.g., renewable-powered data centers) and the estimated carbon footprint of the site's digital infrastructure.
  • plan_exists: The page describes the Scott Trust's mission to secure independence 'in perpetuity' but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish an explicit continuity or wind-down plan describing what happens to the organisation and its journalism in the event of financial failure or exit.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content should the organisation cease to operate.
    Fix: Add a section detailing the fate of user data and the archive of published content in a shutdown scenario, including deletion, transfer, or preservation commitments.
  • custodians_or_mirrors: The page names the Scott Trust and Guardian Media Group as owners but does not identify any custodians, mirrors, or archive partners for preserving content if the organisation exits.
    Fix: Identify designated custodians, mirror sites, or archival partners (e.g., a library or web archive) responsible for preserving the content long-term.
  • policy_exists: The page is a Guardian culture section listing arts, music, TV, and books articles with no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
  • specific_commitments: No specific commitments regarding pay, hours, mental health, or benefits appear anywhere on this culture content page.
    Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and benefits to the wellbeing policy.
  • accountability: The page contains no reference to any person, team, or body responsible for overseeing worker conditions.
    Fix: Name a responsible role or oversight body and describe how worker conditions are monitored and reported.