University of Glasgow
https://www.gla.ac.uk · 34/68 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 25/37 (12 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/4 (4 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/12 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 1/2 |
| Security | 3/9 |
| Transparency | 6/13 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: link-name.
- 1 WCAG 2.1 Level A violation reported by axe-core: link-name.
AI & Automation
-
policy_exists: The page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish an AI use policy page and link to it from the footer alongside Privacy, Terms of use, and Accessibility statement.
-
scope_clear: Without any AI policy on the page, there is no explanation of what AI is used for.
Fix: Within the new AI policy, clearly describe the specific use cases (e.g., chatbots, search, content generation) where AI is employed on University services.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' // Define dataLayer and the gtag function. window.dataLayer = window.dataLa…'.
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.gla.ac.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
disclosure_exists: The page describes Research & Innovation Services but contains no funding or sponsorship disclosure.
Fix: Add a dedicated funding disclosure section identifying sponsors and funders of the university's research and services.
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly list named funding bodies, grants, or sponsors supporting Research & Innovation Services.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic team mailboxes (e.g., Media Relations, webteam, recruitment) and departments but no named individual or specific role-holder is identified as responsible.
Fix: Add at least one named person or specific role title (e.g., Head of Media Relations) accountable for each contact area.
-
response_timeframe: The page references a Complaints Handling Procedure and headings like 'How long do I have to make a complaint?' and 'What happens when I have complained?' but does not display any actual response timeframes on this page.
Fix: Publish the specific response timeframes directly on this page (e.g., acknowledgement within X working days, full response within Y working days).
-
specific: No specific timeframes in days or weeks are stated anywhere on the visible page content.
Fix: Add concrete figures such as 'we will acknowledge your complaint within 3 working days and respond in full within 20 working days' to the page.
-
steps_clear: While section headings like 'How do I complain?' and 'What happens when I have complained?' are listed, the page itself does not spell out the actual step-by-step instructions for submitting a complaint.
Fix: Expand each listed heading into visible content with numbered, sequential steps explaining exactly how to submit a complaint and what happens at each stage.
AI & Automation
-
detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
Fix: Create an AI policy that enumerates each AI system in use, its purpose, the data it processes, and the audience it serves.
-
limitations: The page does not mention any AI systems or their limitations.
Fix: Add a section to the AI policy acknowledging known limitations such as potential inaccuracies, bias, and data currency constraints of AI tools.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human review, accuracy monitoring, bias testing, and user redress mechanisms within the AI policy.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy describing how AI-assisted content is identified and labelled on the site.
-
consistent: No AI content markings appear anywhere on the page, so consistent application cannot be demonstrated.
Fix: Apply standardised AI-content labels across all pages and document the convention in an editorial guideline.
-
oversight_exists: The page does not mention any human oversight arrangements for AI outputs.
Fix: Add a statement describing human oversight procedures for any AI-generated or AI-assisted content.
-
review_process: There is no description of a review or approval workflow for AI content on this page.
Fix: Document a review and approval process (e.g., editorial sign-off steps) for AI-generated content and link to it from relevant pages.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name a responsible role or office (e.g., Digital Editorial Lead) accountable for AI content and publish their contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary for the stated purposes.
Fix: Add an explicit statement (e.g., a data minimisation clause) confirming that only data necessary for the specified purposes is collected.
-
retention_stated: The policy says log information 'will be retained' and that web form retention is 'explained at the point of collection' but does not state retention periods on this page.
Fix: Add explicit retention periods for each data category (log files, web form submissions, cookies) directly within the privacy policy.
-
specific: No specific time periods are given; cookie duration is described only as 'session or indefinitely' and log retention is unquantified.
Fix: Specify concrete retention durations (e.g., 'log files retained for 12 months', 'cookie X expires after 30 days') instead of vague terms.
-
equal_choices: The page lists cookie categories under 'Manage your preferences' but does not visibly present equally prominent accept and reject controls on this privacy page.
Fix: Provide clearly visible and equally prominent 'Accept all' and 'Reject all' buttons alongside the preference toggles for performance and marketing cookies.
-
ads_labelled: The cookie notice mentions personalised advertising via third parties but the page itself contains no labelled ads or sponsored content indicators.
Fix: Clearly label any sponsored or advertising content on the page with visible 'Advertisement' or 'Sponsored' tags.
-
disclosure: The page does not disclose relationships with any advertisers or third-party ad partners beyond a generic cookie reference.
Fix: Add a clear disclosure statement identifying advertising partners and the nature of any commercial relationships, linked from the main content.
-
partner_count_specific: The banner references 'third parties' generically without stating any specific numeric count of partners.
Fix: Add a specific partner count (e.g., 'we share data with X advertising partners') in the banner or link to a list of named partners.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
detail: The page provides no amounts, percentages, or categories of funding.
Fix: Include specific funding figures or categorical breakdowns (e.g., government grants, industry partnerships, charitable donations) with amounts or percentages.
-
complete: There is no disclosure present, so no major funding streams are covered.
Fix: Publish a comprehensive funding statement covering all major income streams such as research councils, industry, philanthropy, and public funds.
-
governance_exists: The page describes the university's history, rankings, and commitments but does not outline any governance or editorial structure for the institution or website.
Fix: Add a section or link describing the university's governance bodies (e.g., Court, Senate, Executive) and editorial oversight of the site.
-
roles_clear: While a 'Who's who' link is mentioned, the page itself does not identify key roles or responsibilities of leadership or editorial staff.
Fix: Include named roles and responsibilities (e.g., Principal, Vice-Chancellors, web editorial owners) directly on the About page or clearly link to a roles overview.
-
algorithm_explained: The About page makes no mention of any algorithms used by the University or their purpose.
Fix: Add a section or link describing any algorithmic systems used (e.g., for admissions, personalised ads) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or site visitors.
Fix: Publish a clear statement outlining the impact of algorithmic decisions on users, including consequences and affected groups.
-
annual_statement: The page provides no evidence of a periodic or annual review of data/privacy practices.
Fix: Publish a note on the privacy page indicating the review cadence (e.g., 'Reviewed annually') and the date of the most recent review.
-
dated: No date or version information is visible for the privacy/cookies statement linked from this page.
Fix: Add a 'Last updated' date or version number to the privacy and cookies statement.
Level 3 — Advanced
Accountability
-
enforcement: The page states the University may withdraw or amend the service but does not explain a moderation/enforcement process (e.g., how violations are reported, reviewed, or acted upon).
Fix: Add a section describing the enforcement process, including how users can report violations, how the University reviews them, and the consequences (warnings, removal, account restrictions) for breaches.
Interoperability
- Not found at: /status
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are disclosed on the page.
Fix: Publish the specific criteria (inputs, factors, thresholds) used in any algorithmic decision-making processes.
-
weighting: The page does not explain the weighting or priority of any decision criteria.
Fix: Document the relative weighting or priority assigned to each criterion in algorithmic decisions.
-
auditable: Insufficient technical or procedural detail is provided to enable external audit or independent review.
Fix: Provide an algorithmic transparency report or audit documentation with enough detail for independent external review.
-
open_source: No link to source code or any open-source repository is provided on the page.
Fix: Add a link to a public code repository (e.g., GitHub) for any open-source projects maintained by the University's digital team.
-
tech_docs: The page contains no technical documentation or links to developer/technical resources.
Fix: Publish and link to technical documentation (such as APIs, open data, or developer guides) from the About or Services section.