University of Bristol
https://www.bristol.ac.uk · 50/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 28/37 (9 failed) |
| Level 2 — Enhanced | 12/27 (15 failed) |
| Level 3 — Advanced | 0/10 (10 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 11/16 |
| Provenance | 2/2 |
| Security | 3/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish an AI use policy page and link to it from the About section and site footer.
-
scope_clear: Since no AI policy is present, there is no explanation of what AI is used for on this page.
Fix: Include a clear scope section in the AI policy describing specific use cases of AI at the University.
- Not found at any of: /ai-policy, /ai.
Privacy
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.bristol.ac.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
disclosure_exists: The page contains no funding or sponsorship disclosure, only general institutional information and navigation links.
Fix: Add a dedicated funding/sponsorship disclosure section or link (e.g., to Annual Report financials) on the About page.
-
transparent: No funding sources are identified anywhere on the page.
Fix: List primary funding sources (e.g., tuition, government grants, research councils, donations) with direct links to detailed reports.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The page contains a feedback form but does not publish any response timeframe for when submitters will hear back.
Fix: Add a clear statement on the feedback page indicating how long it will take to respond to submissions (e.g., 'We aim to respond within 10 working days').
-
specific: Since no timeframe is published at all, there is no specific duration given in days or weeks.
Fix: Specify an exact timeframe in days or working days rather than vague terms, for example '15 working days'.
-
process_exists: The page only offers a generic feedback form for webpage issues and does not document a formal complaints process despite the /complaints path.
Fix: Publish a dedicated complaints procedure page describing how formal complaints are handled, including stages and escalation routes.
-
steps_clear: No step-by-step instructions for making a complaint are provided; the page only shows a name/email/message form for webpage feedback.
Fix: List numbered steps (e.g., informal resolution, formal written complaint, escalation to an ombudsman) so complainants know exactly what to do.
-
appeals_exists: The page is a generic webpage feedback form with no documented complaints or appeals process described.
Fix: Publish a clear, step-by-step complaints and appeals procedure on the /complaints page, including stages, timelines, and contact points.
-
independent: There is no mention of escalation to an independent reviewer, ombudsman, or higher authority for unresolved complaints.
Fix: Add an escalation path identifying an independent body (e.g., the Office of the Independent Adjudicator) that complainants can approach if dissatisfied with the initial response.
AI & Automation
-
detailed_scope: No AI policy is present, so detailed scope of AI use is not provided.
Fix: Create an AI policy detailing specific AI systems, departments, and activities where AI is used.
-
limitations: The page does not acknowledge any limitations of AI systems as no AI policy exists.
Fix: Add a limitations section to the AI policy describing known risks, biases, and accuracy constraints of AI tools used.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human oversight, review processes, and data protection measures in an AI policy.
-
marking_policy: The About page contains no mention of a policy for marking or labelling AI-assisted content.
Fix: Publish a clear policy stating how AI-assisted content is identified and labelled on University webpages.
-
consistent: No AI content markings are visible anywhere on the page, so consistency cannot be demonstrated.
Fix: Introduce a standard visual or textual AI-content label and apply it uniformly across all pages containing AI-assisted material.
-
oversight_exists: The page does not document any human oversight arrangements for AI outputs.
Fix: Add a statement describing the human oversight mechanisms applied to AI-generated content published on the site.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Document the editorial review and approval steps that AI-assisted content must pass before publication.
-
accountability: The page names no individual, role, or office accountable for AI-generated content.
Fix: Designate and publish a named role or office (e.g., Digital Communications Lead) accountable for AI-generated content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit statement of data minimisation, e.g., 'We only collect personal data that is necessary for the purposes described in this policy.'
-
retention_stated: The policy does not mention how long personal data is retained.
Fix: Add a dedicated 'Data retention' section describing how long each category of data is kept and the criteria used to determine retention periods.
-
specific: Because no retention periods are given at all, no specific timeframes are provided.
Fix: Specify concrete retention periods (e.g., 'analytics data retained for 26 months; enquiry data deleted after 2 years') for each data type.
-
equal_choices: The page references a 'Cookie preferences' link in the footer but does not demonstrate that accept and reject options are presented with equal prominence on the consent mechanism itself.
Fix: Ensure the cookie consent banner presents 'Reject all' with the same visual prominence (size, color, placement) as 'Accept all' rather than hiding rejection behind extra clicks.
-
no_forced_consent: The policy states 'By continuing to use this website you are agreeing to such changes,' which constitutes implied/forced consent rather than a freely given, specific opt-in.
Fix: Remove browsewrap-style consent language and instead require an explicit, granular opt-in action for non-essential data processing, allowing users to use the site without consenting.
-
partner_sharing_mentioned: The banner only mentions essential and non-essential cookies for user experience and analytics, with no disclosure of data sharing with third-party partners.
Fix: Update the banner copy to explicitly state whether data is shared with third-party partners (e.g., analytics or advertising vendors) and link to a partner list.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or visible consent copy.
Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full list.
Provenance
Security
- security.txt not published.
Transparency
-
detail: No funding amounts, percentages, or categories are provided on the page.
Fix: Include a breakdown of funding by category with amounts or percentages, or link prominently to the Annual Report and Financial Statements.
-
complete: Because no disclosure is present, major funding streams are not covered.
Fix: Publish a comprehensive funding disclosure covering tuition, research grants, philanthropic giving, and commercial income streams.
-
algorithm_explained: The About page describes university governance and activities but does not mention or explain any algorithms used by the institution.
Fix: Add a section or link describing any algorithmic systems used (e.g., in admissions, research, or student services) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect students, staff, or the public on this page.
Fix: Publish a clear statement of the impact any algorithmic decisions have on users, including affected groups and decision outcomes.
-
annual_statement: The page links to a privacy and cookie policy but shows no evidence of an annual or periodic review of data practices.
Fix: Add a statement to the privacy policy indicating the date of the last review and committing to a regular (e.g., annual) review cycle.
-
dated: No visible date or version information is shown for the privacy/data practices statement on this page.
Fix: Display a 'last updated' date or version number on the privacy and cookie policy and reference it from linked pages.
Level 3 — Advanced
Accessibility
-
known_issues: The page only shows a link to accessibility statements but no acknowledgment of known accessibility issues or limitations is present in the visible content.
Fix: Include a section in the accessibility statement that explicitly lists known accessibility barriers and non-compliant content.
-
remediation_timeline: There is no timeline or commitment for fixing accessibility issues visible on the page.
Fix: Add target dates or a commitment for when identified accessibility issues will be remediated.
-
feedback_channel: While a general 'Feedback' and 'Contact' link exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
Fix: Provide a dedicated accessibility feedback contact within the statement and specify a response timeframe for reported issues.
Accountability
-
criteria_clear: The terms page only links out to the house rules without stating any specific moderation criteria on this page.
Fix: Summarize the key moderation criteria (e.g., prohibited content types, tone expectations) directly on the terms page with a link to the full rules.
-
enforcement: No enforcement process (who moderates, timelines, appeals, consequences) is described on this page.
Fix: Add a short section explaining how moderation is enforced, including who reviews content, response times, removal actions, and any appeal mechanism.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page only lists high-level links to 'Information security' policies and 'Security services' without any published incident response plan or policy visible.
Fix: Publish a dedicated incident response plan or policy page and link to it clearly from this security landing page.
-
notification_commitment: The page contains no commitment to publicly notify affected parties of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public of significant security incidents.
-
timeframe: No disclosure timeframe for notifying affected users of incidents is stated anywhere on the page.
Fix: Specify a concrete timeframe (e.g., within 72 hours of discovery) for disclosing incidents to affected users.
-
policy_exists: The page covers physical security services and general information security policies but publishes no responsible-disclosure or bug-bounty policy.
Fix: Publish a security.txt file and a dedicated vulnerability disclosure policy page outlining scope, reporting process, and expected response times.
-
clear_contact: The only contact details provided are emergency and non-emergency phone numbers for physical security, with no channel for reporting security vulnerabilities.
Fix: Add a dedicated security email address (e.g. security-reports@bristol.ac.uk) or web form specifically for reporting vulnerabilities.
-
safe_harbour_or_reward: The page contains no mention of safe harbour protections or any reward structure for researchers who report vulnerabilities.
Fix: Include a safe-harbour statement assuring good-faith researchers they will not face legal action, and clarify whether any rewards are offered.
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
Fix: Publish the specific decision criteria used by any algorithmic systems, e.g., in a dedicated transparency page linked from About.
-
weighting: The page does not disclose any weighting or priority of criteria for algorithmic decisions.
Fix: Document and publish the relative weightings or priorities assigned to each criterion used in algorithmic decisions.
-
auditable: The page provides no technical detail, data sources, or methodology sufficient for external audit of any algorithmic system.
Fix: Provide auditable documentation (methodology, data sources, validation results) or an audit-access mechanism for external reviewers.
-
open_source: There is no link to source code or any open-source repositories on the page.
Fix: Add a link to a public code repository (e.g., GitHub) for any open-source projects or site components the University maintains.
-
tech_docs: No technical documentation about the site's platform or APIs is published or linked from this page.
Fix: Publish and link to technical documentation such as API references, data schemas, or developer guides from the About or footer area.
Responsibility to the Future
-
specific_metrics: The page describes categories like carbon footprint reduction but presents no specific figures for carbon, energy use, or emissions on the page itself.
Fix: Add concrete quantitative data (e.g., total tonnes of CO2e, annual energy consumption, and reduction targets with baseline years) directly on the sustainability page or a clearly linked report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting or digital infrastructure anywhere on the page.
Fix: Include a statement disclosing the hosting provider's energy source or the site's digital carbon footprint, ideally under the 'Operations and estates' or 'Monitoring and reporting' sections.
-
plan_exists: The governance page describes bodies, constitution and policies but contains no published plan for what happens if the University fails or exits.
Fix: Publish a succession or wind-down plan (or link to one) that describes what happens to services and operations if the organisation ceases to function.
-
data_and_content_fate: The page addresses governance structure and external regulations but says nothing about the fate of user data or published content in the event of failure.
Fix: Add a section detailing what happens to user data and published content upon exit, including retention, transfer, or deletion arrangements.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the governance page.
Fix: Name specific custodians, mirror sites, or archive partners (such as a national web archive) responsible for preserving content if the University exits.
-
policy_exists: The page is a people directory search with no published policy on worker wellbeing or working conditions, only navigation links like 'Working at Bristol' and 'Job listings'.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it prominently from the staff or careers sections.
-
specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits.
Fix: Include concrete commitments on pay, working hours, mental health support, and staff benefits within a published wellbeing policy.
-
accountability: The page does not identify any accountability or oversight body responsible for worker conditions.
Fix: Name the department, committee, or role (e.g., HR or a named executive) accountable for overseeing worker wellbeing and conditions.