University College London
https://www.ucl.ac.uk · 50/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (7 failed) |
| Level 2 — Enhanced | 10/27 (17 failed) |
| Level 3 — Advanced | 0/10 (10 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 2/2 |
| Security | 6/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About UCL page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish a dedicated AI use policy page and link to it from the site footer alongside Privacy and Accessibility.
-
scope_clear: There is no mention of how or where AI is used on the site or by the institution.
Fix: Add a clear statement describing the specific purposes for which AI is used (e.g., search, content generation, analytics).
- Not found at any of: /ai-policy, /ai.
Privacy
- No hidden iframes detected.
- Detected 1 data-leaking service across 1 category: youtube embed (i.ytimg.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.ucl.ac.uk
- x-frame-options: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure of any kind.
Fix: Add a funding and sponsorship disclosure section (or link to one) on the About page identifying UCL's major funding sources.
-
transparent: Because no disclosure is present, funding sources are not clearly identified on this page.
Fix: Clearly name the key funders (e.g., UKRI, research councils, tuition, government grants, philanthropy) with links to further detail.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page lists email addresses and phone numbers but does not publish any response timeframes for enquiries.
Fix: Add a statement on the contact page indicating expected response times for each contact channel (e.g., email enquiries answered within 5 business days).
-
specific: No timeframes are provided at all, so there is nothing specific stated in days or hours.
Fix: Publish concrete, specific response windows (e.g., '2 working days' for admissions, '24 hours' for IT) alongside each contact method.
-
process_exists: The page provides general contact routes but no documented complaints or feedback process or link to one.
Fix: Add a clearly labelled 'Complaints and Feedback' section or link to UCL's formal complaints procedure on the contact page.
-
steps_clear: Because no complaints process is presented, there are no steps describing how to submit or escalate a complaint.
Fix: Publish a step-by-step complaints procedure (e.g., informal resolution, formal written complaint, escalation/appeal) with contact details and timelines for each stage.
-
appeals_exists: The contact page lists departmental contacts but contains no documented appeals process for decisions or complaints.
Fix: Add a dedicated section outlining a formal appeals/complaints procedure with clear steps, timelines, and contact points.
-
independent: No escalation path or independent review body is mentioned anywhere on the contact page.
Fix: Document an escalation route to an independent office (e.g., Office of the Independent Adjudicator or an internal ombudsperson) for unresolved appeals.
AI & Automation
-
detailed_scope: The page provides no detail about the scope of AI use, as no AI policy is present.
Fix: Create an AI policy that enumerates each AI system in use, its purpose, and the data it processes.
-
limitations: No limitations of AI systems are acknowledged anywhere on the page.
Fix: Include a section in the AI policy explicitly acknowledging known limitations such as bias, inaccuracy, or hallucination risks.
-
safeguards: No safeguards, human oversight, or quality control measures are described on the page.
Fix: Document safeguards such as human review, accuracy checks, and escalation procedures in a published AI governance statement.
-
marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or labelled.
Fix: Publish a clear policy stating how AI-generated or AI-assisted content is identified and labelled on UCL web pages.
-
consistent: No AI content markings appear anywhere on the page, so consistent application cannot be demonstrated.
Fix: Introduce standardised AI-content labels (e.g. a visible tag or disclosure line) and apply them uniformly across news items, highlights and other editorial content.
-
oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
Fix: Add a documented statement (linked from the footer or About section) describing how humans oversee any AI-generated content used by UCL.
-
review_process: There is no description of a review or approval workflow for AI-generated material on the page.
Fix: Publish a short description of the editorial review/approval steps AI-assisted content must pass before publication.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content on this page.
Fix: Name an accountable role (e.g. Head of Digital or Editorial Lead) and provide contact details for AI-content governance queries.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: The page focuses on cookies and only links out to a privacy policy, without itself detailing the full scope of data collected and the purposes for each category.
Fix: Include or inline a summary of what personal data UCL collects and the purposes for each, or ensure the linked privacy policy content is surfaced on this page.
-
necessity: The page distinguishes strictly necessary vs optional cookies but does not explicitly state that overall data collection is limited to what is necessary.
Fix: Add a clear statement affirming that UCL only collects personal data that is necessary for the stated purposes (data minimisation principle).
-
proportionate: There is no explicit statement that data collection is proportionate to the service provided.
Fix: Include language confirming that the scope of data collected is proportionate to, and no greater than required for, delivering the website's services.
-
retention_stated: The page mentions cookies can be session or persistent but does not state retention periods for personal data generally, only referring users to a separate Cookie register page.
Fix: State data retention periods directly on this page for each category of cookie/data, rather than relying on an external register.
-
specific: Durations are described vaguely (e.g., 'until you delete them' or 'reaches its expiration date') without specific timeframes.
Fix: Provide concrete retention periods (e.g., '13 months for analytics cookies') for each cookie and data category.
-
equal_choices: The consent banner offers 'Accept all cookies' and 'Accept necessary cookies' buttons but no clearly labeled 'Reject all' option with equal prominence, and settings are relegated to a less prominent link.
Fix: Add a 'Reject all' button with the same visual prominence (size, color, position) as the 'Accept all cookies' button on the consent banner.
-
partner_sharing_mentioned: The banner only mentions enhancing browsing, analysing traffic, and personalised content, but does not disclose data sharing with third-party partners (though embedded YouTube content is mentioned separately).
Fix: Update the cookie banner copy to explicitly state that data may be shared with third-party partners (e.g., YouTube, analytics, and marketing providers) for the listed purposes.
-
partner_count_specific: No numeric count of third-party partners is stated anywhere in the banner or on-page consent copy.
Fix: Include a specific number of partners (e.g., 'We share data with X partners') in the banner, linking to a full list in the cookie settings.
Provenance
Security
- security.txt not published.
Transparency
-
detail: No funding information is provided, so there are no amounts, percentages, or categories described.
Fix: Publish a breakdown of funding by category with amounts or percentages (e.g., research grants, tuition, donations) on or linked from the About page.
-
complete: With no disclosure at all, the page cannot cover any funding streams let alone all major ones.
Fix: Provide a comprehensive disclosure covering all major income streams such as tuition fees, research grants, government funding, donations, and commercial income.
-
roles_clear: While governance is mentioned, the page does not identify specific key roles or responsibilities (e.g., President, Provost, Council members).
Fix: Add a summary or linked list of named leadership roles and their responsibilities directly on the About page or within the Leadership and governance preview.
-
algorithm_explained: The About page describes UCL's mission and rankings but does not mention or explain any algorithms used on the site or in decision-making.
Fix: Add a section or link disclosing any algorithms used (e.g., for admissions, personalisation, or search) and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users such as applicants, students, or visitors.
Fix: Publish a clear statement describing how algorithmic decisions impact users and what outcomes they influence.
-
annual_statement: The page links to a privacy policy and cookie settings but shows no evidence of a regular or annual review of data practices.
Fix: Add a note to the privacy policy or footer stating when data practices are periodically reviewed (e.g., 'Reviewed annually, last reviewed [date]').
-
dated: The privacy/cookie statement shown on the page is not visibly dated or versioned.
Fix: Display a 'Last updated' date or version number on the privacy policy link and cookie notice visible from this page.
Level 3 — Advanced
Accessibility
-
known_issues: This landing page only links to statements and does not itself acknowledge any specific known accessibility issues or limitations.
Fix: Surface or summarise the known non-compliances (e.g., WCAG failures) from the underlying statements directly on this page or clearly within the linked statement.
-
remediation_timeline: The page states a commitment to improving accessibility but provides no timeline or target dates for fixing known issues.
Fix: Add specific dates or timeframes indicating when identified accessibility issues will be resolved.
-
feedback_channel: The page references Digital Accessibility Services and a 'Contact Us' link but provides no accessibility-specific feedback mechanism with a stated response-time commitment.
Fix: Provide a clear accessibility feedback contact (email/form) and state how quickly users can expect a response.
Accountability
-
policy_exists: The About page does not publish or link to any moderation policy for user-generated content or community interactions.
Fix: Publish a moderation policy (e.g., community guidelines) and link it from the footer or About section.
-
criteria_clear: No moderation criteria (what content is allowed or disallowed) are stated anywhere on the page.
Fix: Add clear criteria describing acceptable and prohibited content, tone, and behaviour within the moderation policy.
-
enforcement: The page contains no explanation of how moderation decisions are made, appealed, or enforced.
Fix: Document the enforcement workflow, including who reviews content, response times, sanctions, and an appeals process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page describes physical security services (bike security, lost property, reporting crime) and a CCTV policy but publishes no incident response plan or policy for security incidents.
Fix: Publish a dedicated incident response plan or policy outlining how the organisation detects, responds to, and manages security incidents.
-
notification_commitment: There is no statement committing to public notification of significant security incidents anywhere on the page.
Fix: Add an explicit commitment to notify affected users and the public when significant incidents occur.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of confirming an incident).
-
policy_exists: The page is about physical campus security (ID cards, bikes, lost property, CCTV) and contains no published responsible-disclosure or bug-bounty policy for security vulnerabilities.
Fix: Publish a security.txt file and a dedicated responsible-disclosure policy page explaining how researchers can report software or website vulnerabilities.
-
clear_contact: The only contact channels listed are physical security phone numbers and a switchboard, with no email or form for reporting digital vulnerabilities.
Fix: Add a dedicated security contact (e.g., a security@ucl.ac.uk address or a reporting form) specifically for disclosing vulnerabilities.
-
safe_harbour_or_reward: The page makes no mention of any safe-harbour provision, legal protections, or reward structure for security researchers.
Fix: Include explicit safe-harbour language assuring good-faith researchers of no legal action, and clarify whether any reward or recognition is offered.
Transparency
-
criteria_published: The page contains no published criteria for any algorithmic decision-making process.
Fix: Publish the specific criteria used in any algorithmic decisions on a dedicated transparency page linked from About.
-
weighting: No weighting or prioritisation of decision criteria is disclosed anywhere on the page.
Fix: Document and publish the relative weighting or priority assigned to each criterion used by algorithms.
-
auditable: The page provides no technical detail, documentation, or contact for external audit of any algorithmic systems.
Fix: Provide an algorithmic transparency record with sufficient technical detail and a contact route for external auditors or reviewers.
-
open_source: There is no link to source code or any open-source repository on the about page.
Fix: Add a link to a public repository (e.g., GitHub) if any UCL website code or digital tools are open-sourced, or link to UCL's open research/code resources.
-
tech_docs: No technical documentation about the site's platform, APIs, or data is published or linked from this page.
Fix: Publish and link to technical documentation covering the website's platform, accessibility conformance details, or any available APIs/open data endpoints.
Responsibility to the Future
-
specific_metrics: The page contains only high-level messaging and navigation links with no concrete figures for carbon emissions, energy use, or other quantified metrics.
Fix: Publish specific, dated environmental metrics (e.g., annual carbon emissions in tonnes CO2e, energy consumption in kWh) directly on the page or a clearly linked reporting section.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy source or carbon profile, such as confirmation of green/renewable-powered hosting.
-
plan_exists: The About page contains institutional overview, news, rankings, and events but no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity/succession plan describing how services and operations would be maintained or wound down if UCL ceased operating.
-
data_and_content_fate: The page addresses privacy and cookies but does not describe what would happen to user data and published content in the event of organisational failure or exit.
Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or deleted should the organisation wind down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere in the page content.
Fix: Name a designated custodian or archival partner (e.g., a national web archive or library) responsible for preserving content if the organisation ceases to exist.
-
policy_exists: The page is a UCL Museums and Collections landing page with no published policy on worker wellbeing or working conditions.
Fix: Publish or link to a worker wellbeing/working conditions policy accessible from this page or its footer.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere in the content.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits to a dedicated worker wellbeing policy.
-
accountability: No accountability structure or oversight body for worker conditions is identified on the page.
Fix: Name the responsible team or oversight body accountable for monitoring and enforcing worker conditions.