University of Birmingham

https://www.birmingham.ac.uk · 50/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 6/27 (21 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 13/13
Accountability 0/5
AI & Automation 4/8
Interoperability 1/3
Privacy 9/16
Provenance 1/2
Security 5/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page describes the Institute for Data and AI but contains no AI use policy or statement.
    Fix: Add a clear AI use policy or statement on the page outlining how AI is used by the institute and the university.
  • scope_clear: The page does not explain what AI is used for beyond vague references to research and education.
    Fix: Include a section that explicitly describes the purposes and contexts in which AI is used (e.g., research, teaching, operations).

Privacy

Security

Transparency

  • disclosure_exists: The page is a financial support and advice landing page with navigation links but contains no funding or sponsorship disclosure content.
    Fix: Add a dedicated funding disclosure section identifying the university's funding sources and sponsorships.
  • transparent: No funding sources are identified anywhere on the visible page content.
    Fix: Clearly list named funding sources (government grants, tuition, donations, research sponsors) with attribution.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic department categories (Accommodation, Admissions, HR, etc.) without naming any specific person or role responsible.
    Fix: Identify a named individual or specific role (e.g., Head of Communications) accountable for each department's enquiries.
  • response_timeframe: The page contains no published timeframe indicating when users can expect a response to their feedback.
    Fix: Add a clear statement on the feedback page specifying the maximum number of business days within which users will receive a response.
  • specific: Since no timeframe is published at all, there is also no specific day-based commitment present.
    Fix: State a specific response window (e.g., 'we will respond within 10 working days') rather than vague language.
  • process_exists: The page provides only a feedback form for website issues and does not document a complaints or feedback process.
    Fix: Publish a dedicated complaints procedure page describing how complaints are received, handled, escalated, and resolved.
  • steps_clear: No sequential steps for making a complaint are described; only form fields are presented without explanation of what happens next.
    Fix: Include a clearly numbered list of steps (submission, acknowledgement, investigation, resolution, escalation) so users understand the full complaints journey.
  • appeals_exists: The page is a general website feedback form with no documented complaints or appeals process described.
    Fix: Publish a clear complaints and appeals procedure outlining steps, timelines, and contacts for raising and escalating concerns.
  • independent: There is no mention of an independent review body or escalation path for unresolved complaints.
    Fix: Add an escalation route to an independent reviewer or ombudsman (e.g., OIA) if the initial response is unsatisfactory.

AI & Automation

  • detailed_scope: No detailed scope of AI use is provided; the page only lists institute activities and grants.
    Fix: Publish a detailed AI policy specifying the domains, use cases, and boundaries of AI applications at the institute.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Add a section acknowledging known limitations of AI systems such as bias, inaccuracy, or data constraints.
  • safeguards: No safeguards or quality controls for AI use are described on the page.
    Fix: Describe the safeguards, governance, and quality-control measures (e.g., human oversight, ethical review) applied to AI work.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy on the IDAI page explaining how AI-assisted content will be labelled or disclosed to readers.
  • consistent: Without a marking policy, there is no evidence that AI content marking is applied consistently across the page or site.
    Fix: Adopt a site-wide convention (e.g., an 'AI-assisted' tag or disclosure notice) and apply it uniformly to any page containing AI-generated material.
  • oversight_exists: The page does not mention any human oversight arrangements for AI-generated outputs.
    Fix: Add a statement describing how humans review and oversee any AI-generated content published by the Institute.
  • review_process: No review or approval workflow for AI outputs is described anywhere on the page.
    Fix: Document the editorial review or approval steps applied to AI-assisted content and publish them on the IDAI or governance page.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name a responsible owner (e.g., IDAI Director or an editorial lead) who is accountable for AI-generated content and list their contact details.

Interoperability

Privacy

  • plain_language: The visible content uses formal legal terminology like 'data controller', 'data subject', and 'privacy notices' without plain-language explanations on this landing page.
    Fix: Add brief plain-English summaries alongside legal terms (e.g., explain 'data controller' and 'data subject' in everyday language) on the main privacy landing page.
  • comprehensive: The landing page only lists section headings and linked sub-notices but does not itself describe what data is collected or why on this page.
    Fix: Include a concise summary on this page outlining the categories of data collected and the purposes, rather than requiring users to click through to multiple sub-notices.
  • plain_language: Terms like 'data controller', 'data subject', and 'processes information' appear without plain-language equivalents on the visible page.
    Fix: Rewrite section headings and introductions in jargon-free language, defining or replacing legal terms with everyday phrasing.
  • understandable: A non-expert visiting this page cannot tell what specific data is collected or why because the page only links out to category-specific notices without summarising practices.
    Fix: Add a short, user-friendly overview describing the main types of data collected and the reasons, so non-experts understand without navigating multiple sub-pages.
  • necessity: The visible page content does not state that data collection is limited to what is necessary.
    Fix: Explicitly add a statement affirming that the University only collects personal data that is necessary for the stated purposes (data minimisation principle).
  • proportionate: No statement on proportionality of data collection relative to the service is present in the visible content.
    Fix: Include a clear statement that the data collected is proportionate to the purpose, with examples tying data types to specific services.
  • retention_stated: The visible page does not mention data retention periods at all.
    Fix: Add a dedicated 'Data retention' section stating how long different categories of personal data are kept.
  • specific: Because no retention information is provided, there are no specific time periods listed.
    Fix: Publish specific retention periods (e.g., 'applicant data retained for 12 months') for each data category rather than vague statements.
  • equal_choices: The page only shows a 'Cookie settings' link with no visible evidence that accept and reject options are presented with equal prominence.
    Fix: Provide a cookie banner or settings interface where 'Reject All' is displayed with the same visual prominence (size, color, placement) as 'Accept All'.
  • banner_present: No cookie or consent banner is visible in the page content; only a footer link to 'Cookies and cookie policy' appears.
    Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookie preferences.
  • partner_sharing_mentioned: The page content does not disclose any data sharing with third-party partners in a banner or on-page consent copy.
    Fix: Add clear language to the consent banner disclosing that data may be shared with third-party partners, with a link to details.
  • partner_count_specific: No specific numeric count of partners is stated anywhere on the page since partner sharing is not disclosed.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the consent banner and link to the full partner list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified; only broad department labels like 'Human Resources' and 'Admissions' appear.
    Fix: Add the name of the team lead or contact person responsible for each enquiry category.
  • role_clear: The page does not describe the role or authority of any contact, listing only department names without responsibilities.
    Fix: Include a short description of each contact's role and scope of authority next to their details.
  • detail: The page provides no amounts, percentages, or categories describing funding.
    Fix: Include a breakdown of funding by category with amounts or percentages (e.g., tuition X%, research grants Y%, donations Z%).
  • complete: With no disclosure present, the page cannot cover any major funding streams.
    Fix: Publish a comprehensive funding statement covering all major revenue streams such as tuition, public funding, research income, and philanthropy.
  • roles_clear: The page only links to a leadership page without identifying specific roles or responsibilities on this page itself.
    Fix: Add a brief summary on the About page naming key roles (e.g., Vice-Chancellor, Chancellor, Council members) and outlining their responsibilities.
  • algorithm_explained: The About page makes no mention of any algorithms used by the University, so their purpose is not explained.
    Fix: Add a section or link describing any algorithms or automated decision systems used (e.g., in admissions or research) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff.
    Fix: Publish a clear statement outlining the impact of any algorithmic decisions on users, including potential consequences and affected groups.
  • annual_statement: The page links to a Privacy policy but shows no evidence of a regular or periodic review cycle for data practices.
    Fix: Add a note in the Privacy policy indicating when it was last reviewed and the cadence (e.g., 'Reviewed annually') for ongoing review.
  • dated: The visible Privacy/Legal links do not show a date or version for the data practices statement on this page.
    Fix: Display a 'Last updated' date or version number next to the Privacy policy link or within the policy itself.

Level 3 — Advanced

Accessibility

Accountability

  • policy_exists: The About page contains no published moderation policy or link to one.
    Fix: Publish a moderation policy page and link to it from the footer or About section.
  • criteria_clear: No moderation criteria are stated anywhere on the page.
    Fix: Clearly list the criteria used to moderate user-generated content (e.g., prohibited content, community standards).
  • enforcement: The page does not describe any enforcement process for moderation.
    Fix: Document the enforcement workflow including reporting, review, actions taken, and appeals.

Interoperability

Security

  • plan_exists: The page is an institutional 'About us' overview with no published incident response plan or security policy present.
    Fix: Publish an incident response plan or security policy and link to it from the site, for example alongside the Privacy and Legal footer links.
  • notification_commitment: The page contains no commitment to publicly notify users of significant security or data incidents.
    Fix: Add an explicit statement committing to public notification of significant incidents within the incident response or privacy documentation.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
    Fix: Publish the specific criteria (inputs/factors) used by any algorithmic systems on an accessible transparency page.
  • weighting: No weighting or priority information for any decision criteria is provided on the page.
    Fix: Include documentation describing how each criterion is weighted or prioritised in algorithmic decisions.
  • auditable: There is no technical or procedural detail sufficient to support external audit or review of any algorithm.
    Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail for independent audit.
  • open_source: There is no link to source code or any open-source repository on the about page.
    Fix: Add a link to a public code repository (e.g., GitHub/GitLab) for any open-source projects the University maintains or uses for its website.
  • tech_docs: No technical documentation for the site is linked or referenced on the page.
    Fix: Publish and link technical documentation describing the site's platform, APIs, or data standards from the about or footer area.

Responsibility to the Future

  • specific_metrics: The page provides rankings and activity counts (e.g., 360 champions, 4,300 volunteering hours) but no specific carbon, energy use, or emissions figures.
    Fix: Add concrete environmental metrics such as total carbon emissions (tCO2e), energy consumption, and progress against net zero targets directly on the page or via a clearly linked report.
  • hosting_disclosure: The website sustainability section mentions reducing data usage from images and fonts but does not disclose the carbon or energy profile of the hosting infrastructure.
    Fix: Publish the carbon or energy profile of the website's hosting (e.g., green hosting provider, energy source, or per-page carbon estimate) in the website sustainability section.
  • plan_exists: The page is a governance/publication scheme index and contains no published plan describing what happens if the University fails or exits.
    Fix: Publish a succession or wind-down plan describing continuity, transfer, or closure arrangements and link it from the governance page.
  • data_and_content_fate: Nothing on the page addresses the fate of user data or published content in the event of organisational failure or exit.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted if the organisation ceases operation.
  • custodians_or_mirrors: The page names no custodians, mirrors, or archive partners responsible for content should the organisation cease to exist.
    Fix: Identify and document named custodians, mirror sites, or archive partners (e.g. a national web archive) that would take over content preservation.
  • policy_exists: The page is a cultural attractions listing with no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the site, for example in the footer near the Modern slavery statement.
  • specific_commitments: There are no specific commitments on pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add concrete commitments covering fair pay, working hours, mental health support, and staff benefits within the wellbeing policy.
  • accountability: The page names no responsible body or oversight function for worker conditions.
    Fix: Identify a named owner or governance body (e.g., HR or an executive lead) responsible for overseeing worker conditions and cite it in the policy.