University of Bristol

https://www.bristol.ac.uk · 50/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 28/37 (9 failed)
Level 2 — Enhanced 12/27 (15 failed)
Level 3 — Advanced 0/10 (10 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 11/16
Provenance 2/2
Security 3/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish an AI use policy page and link to it from the About section and site footer.
  • scope_clear: Since no AI policy is present, there is no explanation of what AI is used for on this page.
    Fix: Include a clear scope section in the AI policy describing specific use cases of AI at the University.

Privacy

Security

  • strict-transport-security: header not set on the response.

Transparency

  • disclosure_exists: The page contains no funding or sponsorship disclosure, only general institutional information and navigation links.
    Fix: Add a dedicated funding/sponsorship disclosure section or link (e.g., to Annual Report financials) on the About page.
  • transparent: No funding sources are identified anywhere on the page.
    Fix: List primary funding sources (e.g., tuition, government grants, research councils, donations) with direct links to detailed reports.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The page contains a feedback form but does not publish any response timeframe for when submitters will hear back.
    Fix: Add a clear statement on the feedback page indicating how long it will take to respond to submissions (e.g., 'We aim to respond within 10 working days').
  • specific: Since no timeframe is published at all, there is no specific duration given in days or weeks.
    Fix: Specify an exact timeframe in days or working days rather than vague terms, for example '15 working days'.
  • process_exists: The page only offers a generic feedback form for webpage issues and does not document a formal complaints process despite the /complaints path.
    Fix: Publish a dedicated complaints procedure page describing how formal complaints are handled, including stages and escalation routes.
  • steps_clear: No step-by-step instructions for making a complaint are provided; the page only shows a name/email/message form for webpage feedback.
    Fix: List numbered steps (e.g., informal resolution, formal written complaint, escalation to an ombudsman) so complainants know exactly what to do.
  • appeals_exists: The page is a generic webpage feedback form with no documented complaints or appeals process described.
    Fix: Publish a clear, step-by-step complaints and appeals procedure on the /complaints page, including stages, timelines, and contact points.
  • independent: There is no mention of escalation to an independent reviewer, ombudsman, or higher authority for unresolved complaints.
    Fix: Add an escalation path identifying an independent body (e.g., the Office of the Independent Adjudicator) that complainants can approach if dissatisfied with the initial response.

AI & Automation

  • detailed_scope: No AI policy is present, so detailed scope of AI use is not provided.
    Fix: Create an AI policy detailing specific AI systems, departments, and activities where AI is used.
  • limitations: The page does not acknowledge any limitations of AI systems as no AI policy exists.
    Fix: Add a limitations section to the AI policy describing known risks, biases, and accuracy constraints of AI tools used.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human oversight, review processes, and data protection measures in an AI policy.
  • marking_policy: The About page contains no mention of a policy for marking or labelling AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted content is identified and labelled on University webpages.
  • consistent: No AI content markings are visible anywhere on the page, so consistency cannot be demonstrated.
    Fix: Introduce a standard visual or textual AI-content label and apply it uniformly across all pages containing AI-assisted material.
  • oversight_exists: The page does not document any human oversight arrangements for AI outputs.
    Fix: Add a statement describing the human oversight mechanisms applied to AI-generated content published on the site.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Document the editorial review and approval steps that AI-assisted content must pass before publication.
  • accountability: The page names no individual, role, or office accountable for AI-generated content.
    Fix: Designate and publish a named role or office (e.g., Digital Communications Lead) accountable for AI-generated content.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
    Fix: Add an explicit statement of data minimisation, e.g., 'We only collect personal data that is necessary for the purposes described in this policy.'
  • retention_stated: The policy does not mention how long personal data is retained.
    Fix: Add a dedicated 'Data retention' section describing how long each category of data is kept and the criteria used to determine retention periods.
  • specific: Because no retention periods are given at all, no specific timeframes are provided.
    Fix: Specify concrete retention periods (e.g., 'analytics data retained for 26 months; enquiry data deleted after 2 years') for each data type.
  • equal_choices: The page references a 'Cookie preferences' link in the footer but does not demonstrate that accept and reject options are presented with equal prominence on the consent mechanism itself.
    Fix: Ensure the cookie consent banner presents 'Reject all' with the same visual prominence (size, color, placement) as 'Accept all' rather than hiding rejection behind extra clicks.
  • no_forced_consent: The policy states 'By continuing to use this website you are agreeing to such changes,' which constitutes implied/forced consent rather than a freely given, specific opt-in.
    Fix: Remove browsewrap-style consent language and instead require an explicit, granular opt-in action for non-essential data processing, allowing users to use the site without consenting.
  • partner_sharing_mentioned: The banner only mentions essential and non-essential cookies for user experience and analytics, with no disclosure of data sharing with third-party partners.
    Fix: Update the banner copy to explicitly state whether data is shared with third-party partners (e.g., analytics or advertising vendors) and link to a partner list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or visible consent copy.
    Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full list.

Provenance

Security

Transparency

  • detail: No funding amounts, percentages, or categories are provided on the page.
    Fix: Include a breakdown of funding by category with amounts or percentages, or link prominently to the Annual Report and Financial Statements.
  • complete: Because no disclosure is present, major funding streams are not covered.
    Fix: Publish a comprehensive funding disclosure covering tuition, research grants, philanthropic giving, and commercial income streams.
  • algorithm_explained: The About page describes university governance and activities but does not mention or explain any algorithms used by the institution.
    Fix: Add a section or link describing any algorithmic systems used (e.g., in admissions, research, or student services) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect students, staff, or the public on this page.
    Fix: Publish a clear statement of the impact any algorithmic decisions have on users, including affected groups and decision outcomes.
  • annual_statement: The page links to a privacy and cookie policy but shows no evidence of an annual or periodic review of data practices.
    Fix: Add a statement to the privacy policy indicating the date of the last review and committing to a regular (e.g., annual) review cycle.
  • dated: No visible date or version information is shown for the privacy/data practices statement on this page.
    Fix: Display a 'last updated' date or version number on the privacy and cookie policy and reference it from linked pages.

Level 3 — Advanced

Accessibility

  • known_issues: The page only shows a link to accessibility statements but no acknowledgment of known accessibility issues or limitations is present in the visible content.
    Fix: Include a section in the accessibility statement that explicitly lists known accessibility barriers and non-compliant content.
  • remediation_timeline: There is no timeline or commitment for fixing accessibility issues visible on the page.
    Fix: Add target dates or a commitment for when identified accessibility issues will be remediated.
  • feedback_channel: While a general 'Feedback' and 'Contact' link exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Provide a dedicated accessibility feedback contact within the statement and specify a response timeframe for reported issues.

Accountability

  • criteria_clear: The terms page only links out to the house rules without stating any specific moderation criteria on this page.
    Fix: Summarize the key moderation criteria (e.g., prohibited content types, tone expectations) directly on the terms page with a link to the full rules.
  • enforcement: No enforcement process (who moderates, timelines, appeals, consequences) is described on this page.
    Fix: Add a short section explaining how moderation is enforced, including who reviews content, response times, removal actions, and any appeal mechanism.

Interoperability

Security

  • plan_exists: The page only lists high-level links to 'Information security' policies and 'Security services' without any published incident response plan or policy visible.
    Fix: Publish a dedicated incident response plan or policy page and link to it clearly from this security landing page.
  • notification_commitment: The page contains no commitment to publicly notify affected parties of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public of significant security incidents.
  • timeframe: No disclosure timeframe for notifying affected users of incidents is stated anywhere on the page.
    Fix: Specify a concrete timeframe (e.g., within 72 hours of discovery) for disclosing incidents to affected users.
  • policy_exists: The page covers physical security services and general information security policies but publishes no responsible-disclosure or bug-bounty policy.
    Fix: Publish a security.txt file and a dedicated vulnerability disclosure policy page outlining scope, reporting process, and expected response times.
  • clear_contact: The only contact details provided are emergency and non-emergency phone numbers for physical security, with no channel for reporting security vulnerabilities.
    Fix: Add a dedicated security email address (e.g. security-reports@bristol.ac.uk) or web form specifically for reporting vulnerabilities.
  • safe_harbour_or_reward: The page contains no mention of safe harbour protections or any reward structure for researchers who report vulnerabilities.
    Fix: Include a safe-harbour statement assuring good-faith researchers they will not face legal action, and clarify whether any rewards are offered.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
    Fix: Publish the specific decision criteria used by any algorithmic systems, e.g., in a dedicated transparency page linked from About.
  • weighting: The page does not disclose any weighting or priority of criteria for algorithmic decisions.
    Fix: Document and publish the relative weightings or priorities assigned to each criterion used in algorithmic decisions.
  • auditable: The page provides no technical detail, data sources, or methodology sufficient for external audit of any algorithmic system.
    Fix: Provide auditable documentation (methodology, data sources, validation results) or an audit-access mechanism for external reviewers.
  • open_source: There is no link to source code or any open-source repositories on the page.
    Fix: Add a link to a public code repository (e.g., GitHub) for any open-source projects or site components the University maintains.
  • tech_docs: No technical documentation about the site's platform or APIs is published or linked from this page.
    Fix: Publish and link to technical documentation such as API references, data schemas, or developer guides from the About or footer area.

Responsibility to the Future

  • specific_metrics: The page describes categories like carbon footprint reduction but presents no specific figures for carbon, energy use, or emissions on the page itself.
    Fix: Add concrete quantitative data (e.g., total tonnes of CO2e, annual energy consumption, and reduction targets with baseline years) directly on the sustainability page or a clearly linked report.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or digital infrastructure anywhere on the page.
    Fix: Include a statement disclosing the hosting provider's energy source or the site's digital carbon footprint, ideally under the 'Operations and estates' or 'Monitoring and reporting' sections.
  • plan_exists: The governance page describes bodies, constitution and policies but contains no published plan for what happens if the University fails or exits.
    Fix: Publish a succession or wind-down plan (or link to one) that describes what happens to services and operations if the organisation ceases to function.
  • data_and_content_fate: The page addresses governance structure and external regulations but says nothing about the fate of user data or published content in the event of failure.
    Fix: Add a section detailing what happens to user data and published content upon exit, including retention, transfer, or deletion arrangements.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the governance page.
    Fix: Name specific custodians, mirror sites, or archive partners (such as a national web archive) responsible for preserving content if the University exits.
  • policy_exists: The page is a people directory search with no published policy on worker wellbeing or working conditions, only navigation links like 'Working at Bristol' and 'Job listings'.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it prominently from the staff or careers sections.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits.
    Fix: Include concrete commitments on pay, working hours, mental health support, and staff benefits within a published wellbeing policy.
  • accountability: The page does not identify any accountability or oversight body responsible for worker conditions.
    Fix: Name the department, committee, or role (e.g., HR or a named executive) accountable for overseeing worker wellbeing and conditions.