University of Edinburgh

https://www.ed.ac.uk · 49/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 29/37 (7 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 1/5
AI & Automation 4/8
Interoperability 1/3
Privacy 10/16
Provenance 2/2
Security 7/11
Transparency 0/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page mentions 'Ethics and society' and 'Guidance for students and staff' in the menu but does not present an actual AI use policy or statement on this page.
    Fix: Publish a clear AI use policy or statement directly on this page (or link to it prominently) outlining principles governing AI use at the university.
  • scope_clear: The page speaks generally about AI improving health, finance, and climate but does not clearly explain what AI is specifically used for by the institution.
    Fix: Add a dedicated section describing concrete use cases and contexts in which the university deploys AI systems.

Privacy

Security

Transparency

  • purpose_clear: The page lists navigation links to sub-sections (history, strategy, governance) but does not plainly state what the University does.
    Fix: Add a short introductory paragraph at the top of the About page summarising the University's core purpose (teaching, research, public engagement).
  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only navigation links and institutional registration details.
    Fix: Add a funding and sponsorship disclosure section to the About page identifying the institution's key funders.
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly name the primary funding bodies (e.g., UKRI, government grants, tuition, donors) in a dedicated disclosure block.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists institutional links but does not identify any named person or specific role responsible for the About page or its content.
    Fix: Add a named owner or specific role (e.g., 'About Us page maintained by the Communications and Marketing team, contact: Jane Doe, Head of Digital') to the page.
  • response_timeframe: The page mentions 'timescales outlined in the Complaints Handling Procedure' but does not actually publish any timeframes on this page.
    Fix: Include the specific response timeframes for each stage directly on the page rather than only referencing them.
  • specific: No specific number of days or concrete timeframes are stated anywhere on the page.
    Fix: Add specific day counts (e.g., 'Stage 1: 5 working days; Stage 2: 20 working days') to the page.
  • steps_clear: The page only vaguely notes 'up to two stages' without explaining how to submit a complaint, what each stage involves, or how to escalate.
    Fix: Add clear step-by-step instructions describing how to file a complaint, what happens at each stage, and how to contact the SPSO.

AI & Automation

  • detailed_scope: The page provides only high-level aspirational statements about AI's potential rather than a detailed scope of AI use.
    Fix: Provide a detailed breakdown of AI applications by domain, including systems used, data processed, and decisions supported.
  • limitations: No limitations, risks, or shortcomings of AI systems are acknowledged anywhere in the visible content.
    Fix: Include an explicit section acknowledging known limitations, risks, and failure modes of the AI systems referenced.
  • safeguards: The page references 'Ethics and society' in navigation but does not describe any specific safeguards, quality controls, or oversight mechanisms.
    Fix: Describe concrete safeguards such as human oversight, bias testing, ethical review processes, and quality assurance procedures applied to AI work.
  • marking_policy: The page describes AI research and achievements but contains no policy for marking AI-assisted content.
    Fix: Add a clear policy statement indicating how AI-assisted or AI-generated content on the site will be labelled or disclosed.
  • consistent: Without a marking policy in place, there is no evidence that AI content marking is applied consistently across the page.
    Fix: Implement and visibly apply a consistent AI-content label (e.g., a tag or disclosure line) to any page sections, images, or text produced with AI assistance.
  • oversight_exists: The page mentions ethics and society but does not document any human oversight process for AI outputs published on the site.
    Fix: Publish a brief statement or link describing the human oversight procedures for AI-generated outputs associated with this site.
  • review_process: No review or approval workflow for AI content is described anywhere on the page.
    Fix: Describe the editorial review and approval process (e.g., who reviews AI outputs before publication and against what criteria) on a dedicated governance page.
  • accountability: The page does not name any individual, role, or team accountable for AI-generated content.
    Fix: Identify a named role or office (e.g., an AI content owner or editorial lead) responsible for AI-generated content and provide contact details.

Interoperability

Privacy

  • comprehensive: This index page only summarises topics and links out; the visible content itself does not detail what data is collected or why.
    Fix: Surface a concise summary on this page covering categories of data collected, purposes, and legal basis rather than relying solely on sub-page links.
  • understandable: A non-expert cannot tell from this page alone what specific data is collected or why, as the details are only hinted at behind sub-links.
    Fix: Include a brief, non-expert-friendly summary directly on this page stating the types of data collected and the specific reasons for each.
  • necessity: The visible page does not state that data collection is limited to what is necessary.
    Fix: Add an explicit statement on this page affirming that data collection is limited to what is necessary for the stated purposes (data minimisation).
  • proportionate: There is no statement on this page addressing proportionality of data collected relative to the service.
    Fix: Include a clear statement that the data collected is proportionate to the services provided, with examples tying data types to service functions.
  • retention_stated: No data retention information is mentioned anywhere on the visible page content.
    Fix: Add a retention section (or visible summary) on this page specifying how long each category of personal data is kept.
  • specific: Because no retention periods are stated, there are no specific time periods provided.
    Fix: Specify concrete retention durations (e.g. 'analytics data retained for 26 months', 'account data retained for 2 years after last login') rather than vague language.
  • equal_choices: No consent interface with accept/reject options is visible on this page, so equal prominence cannot be verified.
    Fix: Display a visible cookie consent banner on this page with Accept and Reject buttons of equal size, color, and prominence.
  • banner_present: No cookie or consent banner is visible in the page content; only a static 'Privacy & cookies' footer link is present.
    Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookie preferences.
  • partner_sharing_mentioned: The page content does not disclose any data sharing with third-party partners in banner or on-page consent copy.
    Fix: Add clear disclosure within the consent banner stating whether and how user data is shared with third-party partners, with a link to a detailed partner list.
  • partner_count_specific: No specific numeric count of partners is stated anywhere on the page since partner sharing itself is not disclosed.
    Fix: Include an explicit numeric count of third-party partners (e.g., 'We share data with X partners') within the consent banner or linked preferences page.

Provenance

Security

Transparency

  • named_person: The page references 'General enquiries' and a staff directory but does not name a specific individual or team responsible for handling enquiries.
    Fix: Explicitly name the team or individual responsible for enquiries (e.g., 'Enquiries handled by the Student Recruitment & Admissions team') alongside the contact link.
  • role_clear: No role or authority is stated for who manages the page content or responds to enquiries—only generic links are provided.
    Fix: Clearly state the role and remit of the responsible team (e.g., 'The Communications Office is responsible for maintaining this page and responding to general enquiries').
  • substantive: The visible content is essentially a menu of links with no substantive prose describing the organisation's purpose.
    Fix: Include a detailed narrative statement on the About page explaining the University's mission, values, and scope of activities.
  • mission_clear: While a 'Strategy 2030' link exists, no mission or editorial approach is articulated on this page itself.
    Fix: Surface a concise mission statement directly on the About page rather than requiring users to navigate to a strategy sub-page.
  • detail: The page provides no funding amounts, percentages, or categories.
    Fix: Publish a breakdown of funding by category with amounts or percentages, or link to the annual financial report.
  • complete: No funding streams are disclosed at all, so the disclosure cannot be considered complete.
    Fix: Provide a comprehensive list of all major funding streams (research grants, tuition, government support, philanthropy, commercial income) on the About page.
  • roles_clear: The page lists governance links and a 'People' section but does not identify specific key roles or responsibilities on this page.
    Fix: Add a brief description or list of key governance roles (e.g., Principal, Court, Senate) and their responsibilities directly on the About page or link to a clearly labeled roles page.
  • algorithm_explained: The About page lists organisational structure and governance links but does not mention or explain any algorithms used by the University.
    Fix: Add a dedicated section or link on the About page describing any algorithmic or automated decision-making systems used and their purposes.
  • impact_clear: There is no description of how algorithmic decisions affect users (students, staff, or applicants) anywhere on this page.
    Fix: Include a plain-language summary of the impact of any algorithmic decisions on users, with links to more detailed documentation.
  • annual_statement: The page links to 'Privacy & cookies' and 'Data protection / Records Management' but shows no evidence of a regular or annual review of data practices.
    Fix: Add a visible note on the privacy/data protection page stating when the data practices were last reviewed and committing to an annual review cycle.
  • dated: While the page shows a publication date of 2026-03-31, the linked data practices/privacy statements are not dated or versioned on this page.
    Fix: Display an explicit 'last updated' date or version number on the Privacy & cookies and Data protection statements.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content does not acknowledge any known accessibility issues or limitations.
    Fix: Add a section to the accessibility statement listing specific known non-compliant areas and content that is not yet accessible.
  • remediation_timeline: There is no timeline or commitment for fixing accessibility issues visible on the page.
    Fix: Include target dates or a commitment schedule detailing when known accessibility issues will be resolved.
  • feedback_channel: While 'Contact us' and 'General enquiries' links exist, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Provide a dedicated accessibility feedback contact and state a specific timeframe (e.g., within 5 working days) for responding to reports.

Accountability

  • enforcement: The page states the University may remove material 'for any other reason whatsoever' but does not explain the enforcement process, such as how reports are reviewed, notice given, or appeals handled.
    Fix: Add a section describing the enforcement workflow—how to report violations, how reviews are conducted, notification to users, and any appeal or redress mechanism.

Interoperability

Security

  • plan_exists: The page contains general About Us and governance links but no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site footer or governance section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected users when significant incidents occur.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
    Fix: Publish the specific decision criteria (e.g., for admissions, grading, or resource allocation) on a linked transparency page.
  • weighting: No weighting or priority information for any decision criteria is provided on the page.
    Fix: Disclose the relative weights or priorities applied to each criterion in any algorithmic decision process.
  • auditable: The page provides no technical or procedural detail that would allow external audit or review of any algorithms.
    Fix: Provide an auditable algorithm register including model documentation, data sources, and review procedures accessible to external reviewers.
  • open_source: The page contains no links to source code repositories for the website or its platform.
    Fix: Add a link (e.g., in the footer or a dedicated developer page) to any public repositories hosting the site's code or open-source projects.
  • tech_docs: No technical documentation for the website or its systems is linked from this page.
    Fix: Publish and link to technical documentation, such as a developer/API page or accessibility technical statement, from the About or footer area.

Responsibility to the Future

  • specific_metrics: The page references zero carbon/zero waste ambitions and performance progress but provides no specific figures for carbon emissions, energy use, or waste on this page.
    Fix: Add concrete quantified metrics (e.g., annual tonnes of CO2e, energy consumption in kWh, and percentage reductions against a baseline year) directly on the page or in a clearly linked report.
  • hosting_disclosure: The page mentions 'Digital Sustainability' in the footer but discloses no carbon or energy profile of its website hosting infrastructure.
    Fix: Publish the carbon or energy profile of the site's hosting infrastructure, such as green hosting certification or measured page/site emissions data.
  • plan_exists: The About page describes structure, governance, and strategy but contains no published plan for what happens if the University ceases operations or exits its digital services.
    Fix: Publish a succession or continuity plan describing what happens to the website and services if the organisation fails or winds down, and link to it from the About or governance pages.
  • data_and_content_fate: The page and its footer links (privacy, data protection, records management) address ongoing operations but do not state what happens to user data and published content upon organisational exit.
    Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or deleted in the event the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content should the University discontinue the site.
    Fix: Identify and name an archive partner, mirror, or custodian (e.g., a national web archive) responsible for preserving the site's content, and document this on the site.
  • policy_exists: The page is a university Careers Service landing page with no published policy on worker wellbeing or working conditions.
    Fix: Publish a clear worker wellbeing or working conditions policy and link to it from the site.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Include measurable commitments on pay, working hours, mental health support, and employee benefits within a wellbeing policy.
  • accountability: The page does not identify any accountability owner or oversight body for worker conditions.
    Fix: Name a responsible role or oversight committee accountable for monitoring and reporting on worker conditions.