UK Legislation
https://www.legislation.gov.uk · 57/92 checks passed · government
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 31/37 (6 failed) |
| Level 2 — Enhanced | 12/27 (15 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 8/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement whatsoever.
Fix: Publish an AI use policy page (e.g., /about/ai) describing whether and how AI is used on Legislation.gov.uk.
-
scope_clear: Because no AI policy is present, the scope of AI use is not explained.
Fix: Include a clear scope section in the AI policy describing which features or processes on the site involve AI.
- Not found at any of: /ai-policy, /ai.
Privacy
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.legislation.gov.uk
- x-frame-options: sameorigin
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The page only says a team member will respond 'as soon as possible' without publishing any actual timeframe.
Fix: Publish a specific target response time (e.g. 'within 10 working days') for email and postal enquiries.
-
specific: No specific number of days or hours is given; wording is vague ('as soon as possible').
Fix: Replace vague phrasing with a concrete SLA such as '5 working days for website enquiries and 20 working days for postal enquiries'.
-
steps_clear: The page lists contact channels but does not lay out clear steps for making or escalating a complaint (e.g. what to include, what happens next, escalation route).
Fix: Add a numbered complaints procedure explaining how to submit, what information to include, expected acknowledgement, and how to escalate if dissatisfied.
-
appeals_exists: The contact page provides enquiry and feedback channels but does not document any formal appeals process for decisions or content.
Fix: Add a clearly labeled appeals section describing how users can formally challenge decisions, content, or service outcomes, including required information and timelines.
-
independent: No escalation path or independent review body is described for appealing decisions; the page only references the ICO for FOI/data protection matters, not a general appeals route.
Fix: Document an independent escalation route (e.g., to a senior reviewer, ombudsman, or external body) that users can use if they are dissatisfied with an initial response.
AI & Automation
-
detailed_scope: No AI policy or detailed scope of AI use appears on the page.
Fix: Add a dedicated AI policy section detailing specific AI applications such as search, summarisation, or editorial tooling.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include a 'Limitations' subsection explaining accuracy constraints, potential errors, and contexts where AI outputs should not be relied upon.
-
safeguards: No safeguards or quality-control measures for AI are described on the page.
Fix: Document safeguards such as human review, editorial oversight, and validation processes used when AI contributes to content.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy describing how any AI-assisted content is identified and labelled on the site.
-
consistent: Without a marking policy mentioned on this page, there is no evidence that AI content marking is applied consistently.
Fix: Define and apply a consistent labelling convention for AI-assisted content across all pages and document it publicly.
-
oversight_exists: The page does not mention any human oversight arrangements for AI-generated outputs.
Fix: Add a statement describing how humans oversee and validate any AI-generated content on the site.
-
review_process: No review or approval process for AI outputs is described on the About page.
Fix: Document the editorial review and approval workflow used before AI-assisted content is published.
-
accountability: While The National Archives is named as publisher, no specific accountability for AI-generated content is identified.
Fix: Name a role or team (e.g., the legislation editorial team) that is explicitly accountable for AI-generated content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit statement that data collection is minimised and limited to what is necessary to deliver and improve the service.
-
retention_stated: The notice does not mention how long personal information or usage data is retained.
Fix: Add a dedicated 'Data retention' section stating how long each category of data is kept before deletion or anonymisation.
-
specific: Because no retention periods are stated at all, there are no specific timeframes provided.
Fix: Specify concrete retention periods (e.g. 'server logs retained for 12 months') rather than leaving retention unaddressed.
-
partner_sharing_mentioned: The banner only mentions remembering settings and understanding browsing for improvements, with no disclosure of data sharing with third-party partners.
Fix: Update the banner to explicitly disclose any third-party partners (e.g., analytics providers) that receive cookie data and link to a full list.
-
partner_count_specific: No numeric count of partners is stated since partner sharing is not disclosed at all.
Fix: If third parties are used, state the specific number of partners (e.g., 'we share data with X partners') in the banner with a link to the full list.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
detail: The page names the governing bodies but provides no meaningful detail such as amounts, percentages, or budget categories for funding.
Fix: Add a funding breakdown section stating budget amounts or percentages from HM Government and any other revenue categories supporting the site.
-
complete: Only governmental stewardship is mentioned; there is no confirmation that this covers all funding streams such as grants, commercial licensing, or reuse revenue.
Fix: Publish a comprehensive list of all funding streams (government appropriations, licensing income, partnerships) to confirm completeness of the disclosure.
-
algorithm_explained: The About page describes the role of The National Archives and publication of legislation but does not mention or explain any algorithms used on the site.
Fix: Add a section describing any algorithms used (e.g., for search ranking or revised-version generation) and their purpose.
-
impact_clear: No description is provided of how algorithmic decisions might affect users of the site.
Fix: Include a clear statement of how any automated processing affects users' search results, content presentation, or access.
-
annual_statement: The About page links to a privacy notice but provides no evidence of an annual or periodic review of data practices.
Fix: Add a statement on the privacy notice or About page indicating when data practices are reviewed (e.g., annually) and the date of the last review.
-
dated: The About page content is not dated or versioned, and there is no visible date or version on the referenced privacy statement from this page.
Fix: Include a 'last updated' date or version number on the privacy notice and About page so users can verify currency.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement lists known issues but provides no dates or commitment for when they will be fixed.
Fix: Add a 'Non-accessible content' subsection stating target dates or a remediation plan for resolving the listed issues (e.g., missing alt text and inaccessible PDFs).
Accountability
-
policy_exists: The About page describes the site's governance and publishing authorities but does not publish any moderation policy.
Fix: Publish a clearly labelled moderation policy page (or link to one) covering user-facing content and submissions.
-
criteria_clear: No moderation criteria (what content is allowed, removed, or edited) are stated on this page.
Fix: Add explicit criteria describing the types of content that are permitted, restricted, or removed under moderation.
-
enforcement: There is no explanation of how moderation decisions are made, appealed, or enforced.
Fix: Document the enforcement workflow, including who reviews content, timelines, outcomes, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About Us page describes the site's governance and publishing remit but contains no published incident response plan or security incident policy.
Fix: Publish a dedicated incident response plan or security policy page describing how security and data incidents are handled.
-
notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
Fix: Add an explicit commitment to notify the public and affected users when significant incidents occur.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident).
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used by algorithms on the site.
Fix: Publish a list of the criteria (such as relevance factors, date filters, or classification rules) used by any site algorithm.
-
weighting: There is no information about the weighting or priority of any algorithmic criteria.
Fix: Document the relative weight or priority assigned to each criterion in a transparency or methodology page.
-
auditable: The page provides no technical or methodological detail sufficient for external audit or review of algorithms.
Fix: Publish algorithm documentation, source code references, or an audit methodology to enable independent review.
-
open_source: The about page contains no link to source code or any open-source repository for the website.
Fix: Add a link from the About page to a public repository (e.g., GitHub) containing the site's source code or note where components are openly licensed.
-
tech_docs: No technical documentation (APIs, data schemas, developer guides) is linked from the about page.
Fix: Include a link to developer/technical documentation such as the legislation API, data formats, and schemas from the About page.
Responsibility to the Future
-
disclosure_exists: The About page describes the site's governance and archival role but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement covering the website's operations and link it from the About or footer navigation.
-
specific_metrics: No specific figures on carbon, energy use, or emissions appear anywhere on the page.
Fix: Add quantified environmental metrics such as annual carbon emissions or energy consumption figures with a stated measurement methodology and reporting period.
-
hosting_disclosure: The page does not mention the carbon or energy profile of the hosting infrastructure used to run the website.
Fix: Disclose the hosting provider's energy or carbon profile, including whether servers are powered by renewable energy.
-
plan_exists: The About page describes governance and institutional history but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan describing what would happen to the service if The National Archives ceased to operate it.
-
data_and_content_fate: The page explains how content is published and maintained but never addresses the fate of user data or published legislation in a failure or exit scenario.
Fix: Add a section committing to how published content and any user data would be preserved, transferred, or archived if the service ends.
-
policy_exists: The 'About Us' page describes The National Archives' role in publishing legislation but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or corporate governance section.
-
specific_commitments: The page makes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits to the wellbeing policy.
-
accountability: The page does not identify any individual, team, or body accountable for overseeing worker conditions.
Fix: Name a responsible role or oversight body and describe how worker conditions are monitored and reported.