University of Leeds

https://www.leeds.ac.uk · 55/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 1/10 (9 failed)

By category

CategoryResult
Accessibility 13/13
Accountability 1/5
AI & Automation 4/8
Interoperability 1/3
Privacy 11/16
Provenance 2/2
Security 5/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page promotes an AI Masters course but contains no AI use policy or statement governing the university's use of AI.
    Fix: Publish a clear AI use policy or statement on the site (e.g., at /ai or linked from the footer) describing institutional AI usage.
  • scope_clear: No explanation is provided about what AI is used for on the site or within the institution.
    Fix: Add a section to the AI policy that clearly describes the specific purposes and contexts in which AI is used.

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only general facts about rankings and student numbers.
    Fix: Add a funding and sponsorship disclosure section to the About page identifying the University's funding sources.
  • transparent: No funding sources are identified anywhere on the page, though it mentions a £1.9 billion economic contribution without context on funding.
    Fix: Clearly list funding sources such as tuition fees, research grants, government block grants, and philanthropic donations on the About page.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists phone numbers and emails but does not publish any response timeframes for inquiries.
    Fix: Add expected response times (e.g., 'we aim to reply within 5 working days') next to each contact method.
  • specific: Since no timeframes are provided at all, there are no specific day-based commitments on the page.
    Fix: Specify concrete turnaround times in days or hours for each team (e.g., admissions, security, media relations) rather than vague language.
  • process_exists: The page provides general and departmental contacts but does not document a complaints or feedback process or link to one.
    Fix: Add a dedicated 'Complaints and feedback' section or link to a complaints procedure page from this contact page.
  • steps_clear: No complaint steps (e.g., who to contact first, escalation path, required information) are outlined anywhere on the page.
    Fix: Provide a clear step-by-step complaints procedure including initial contact, escalation, expected acknowledgement, and final review stages.
  • appeals_exists: The contact page lists general and departmental contacts but does not describe any documented appeals process.
    Fix: Add a dedicated section or link outlining how users can formally appeal decisions, including steps and timelines.
  • independent: No escalation path or independent review mechanism is mentioned on the page.
    Fix: Publish an escalation route to an independent body (e.g., Office of the Independent Adjudicator) for unresolved appeals.

AI & Automation

  • detailed_scope: The page only describes an AI degree program and does not detail the scope of AI use by the university.
    Fix: Include a detailed scope section in the AI policy outlining all systems, departments, and use cases where AI is applied.
  • limitations: No acknowledgement of AI system limitations appears anywhere on the page.
    Fix: Add a limitations section to the AI policy that candidly describes known constraints, risks, and failure modes of AI systems used.
  • safeguards: The page does not describe any safeguards, oversight, or quality-control measures for AI use.
    Fix: Document safeguards such as human review, bias testing, data governance, and escalation procedures in a published AI policy.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear AI content labelling policy indicating when and how AI-assisted material is disclosed on University of Leeds pages.
  • consistent: Without a marking policy visible on the page, there is no evidence that AI content marking is applied consistently.
    Fix: Adopt a standard AI disclosure label (e.g., an 'AI-assisted' tag) and apply it uniformly across all relevant content.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans review AI-generated outputs before publication, linked from the footer or policies section.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Publish a short description of the editorial review and approval steps applied to AI-assisted content.
  • accountability: No individual, team, or role is identified as accountable for AI-generated content on this page.
    Fix: Name an accountable owner (e.g., a specific office or role) responsible for AI content governance and include contact details.

Interoperability

Privacy

  • necessity: The notice does not explicitly state that data collection is limited to what is necessary or follows a data minimisation principle.
    Fix: Add an explicit statement that the University only collects personal data that is necessary for the stated purposes, referencing the GDPR data minimisation principle.
  • specific: Retention is only specific for IP logs (one month) and some cookies; other categories defer to an external Data Retention Schedule or say it will be made clear at collection without giving periods here.
    Fix: Include specific retention periods (or clear ranges) for each major data category directly in the notice, or summarise the key periods from the Data Retention Schedule.
  • equal_choices: The page only references a 'review cookie settings' button and does not demonstrate that accept and reject options are presented with equal prominence in the consent UI.
    Fix: Ensure the cookie banner presents a 'Reject all' option with the same visual prominence (size, color, placement) as the 'Accept all' button at the first layer of the consent UI.
  • partner_sharing_mentioned: The banner only mentions using cookies to collect information about use of University of Leeds sites and does not disclose any data sharing with third-party partners.
    Fix: Update the banner copy to explicitly state whether data is shared with third-party partners and link to a list of those partners.
  • partner_count_specific: No numeric count of partners is provided because partner sharing is not disclosed at all.
    Fix: If third-party sharing occurs, state the exact number of partners (e.g., 'We share data with X partners') in the banner or linked preferences page.

Provenance

Security

Transparency

  • detail: The page provides no detail on funding amounts, percentages, or categories of funding received.
    Fix: Include a breakdown of funding with amounts or percentages by category (e.g., tuition, research councils, donations) linked from the About page.
  • complete: No funding streams are disclosed at all, so coverage of major streams cannot be established.
    Fix: Publish a comprehensive funding overview covering all major income streams, ideally linking to the annual financial reports already referenced in the footer.
  • roles_clear: The page references an 'Executive team' and faculties in the footer but does not identify key roles or responsibilities on this About page itself.
    Fix: Add a short section on the About page summarising key leadership roles (e.g., Vice-Chancellor, executive team members) and their responsibilities, with links to fuller biographies.
  • algorithm_explained: The About page makes no mention of any algorithms used by the University or explains their purpose.
    Fix: Add a dedicated section or link describing any algorithmic systems in use (e.g., admissions, search, personalisation) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect students, staff, or visitors.
    Fix: Publish a clear statement describing the impact of any algorithmic decision-making on users and the outcomes it influences.
  • annual_statement: The page links to a Privacy notice but shows no evidence of a regular or periodic review of data practices.
    Fix: Add a statement on the privacy page indicating the review cadence (e.g., 'Reviewed annually') with the date of last review.
  • dated: There is no visible date or version indicator for the privacy/data practices statement on this page.
    Fix: Display a 'Last updated' date or version number alongside the Privacy link or on the privacy notice itself.

Level 3 — Advanced

Accessibility

Accountability

  • enforcement: While 4.5 mentions reporting misuse to law enforcement, the page does not explain the moderation enforcement process (e.g., how contributions are reviewed, removed, appealed, or users sanctioned).
    Fix: Add a section describing the moderation enforcement workflow, including how breaches are detected, how content is removed, how users are notified, and any appeal process.

Interoperability

Security

  • plan_exists: The page describes physical campus security services and crime reporting but contains no published cyber/data incident response plan or policy.
    Fix: Publish a formal incident response plan or policy document and link to it from this or a related security/privacy page.
  • notification_commitment: The page makes no commitment to publicly notify affected users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public in the event of significant incidents.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovery).
  • policy_exists: The page is about physical campus security services (patrols, SafeZone, bike registration, lost property) and contains no published responsible-disclosure or bug-bounty policy.
    Fix: Publish a responsible-disclosure/security.txt policy describing scope, expectations, and how to report software vulnerabilities.
  • clear_contact: The only contacts listed (security@leeds.ac.uk and phone numbers) are for physical safety incidents, not for reporting security vulnerabilities.
    Fix: Add a dedicated vulnerability-reporting channel (e.g., a security.txt file or security-reports@leeds.ac.uk) clearly identified for disclosing technical flaws.
  • safe_harbour_or_reward: The page offers no safe-harbour statement or reward/bug-bounty structure for security researchers.
    Fix: Include a safe-harbour clause assuring good-faith researchers of no legal action and, if applicable, describe any reward or recognition program.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decisions.
    Fix: Publish the specific criteria used in any algorithmic decisions on a transparency or policies page linked from About.
  • weighting: No information is provided about the weighting or priority of any decision criteria.
    Fix: Document and publish the relative weighting or priority of each criterion used by algorithmic systems.
  • auditable: The page contains no technical or procedural detail that would allow external audit or review of algorithms.
    Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail to support independent audit.
  • open_source: No link to source code or any open source repository is provided on the About page.
    Fix: Add a link to a public code repository (e.g., a GitHub organisation) for any site components or open-source projects the University maintains.
  • tech_docs: The page does not publish or link to any technical documentation about the site.
    Fix: Publish and link to technical documentation (APIs, data schemas, or site architecture) from the About or a dedicated developer page.

Responsibility to the Future

  • disclosure_exists: The page contains general 'About' information and facts and figures but no published environmental impact or sustainability disclosure is present.
    Fix: Publish a dedicated sustainability or environmental impact section on the About page linking to a formal environmental disclosure or report.
  • specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
    Fix: Include concrete environmental metrics such as annual carbon footprint, energy consumption, and emissions reduction targets with reporting periods.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its website hosting infrastructure.
    Fix: Add a statement disclosing the hosting provider's energy source or the carbon footprint of the site's hosting infrastructure.
  • plan_exists: The governance page describes the University's constitutional structure and committees but contains no published plan for what happens if the organisation fails, dissolves, or exits.
    Fix: Publish a wind-down or continuity plan describing what would happen to the institution's operations, data, and content in the event of failure or dissolution, and link it from this governance page.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content should the organisation cease to operate.
    Fix: Add a section specifying the fate of user data and published content on closure, including retention, deletion, or transfer arrangements.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content or records if the University exits.
    Fix: Name any archive partners, mirrors, or successor custodians (e.g. national archives) responsible for preserving records and content, and document these arrangements on the page.
  • policy_exists: The page is a general 'About' overview and contains no published policy on worker wellbeing or working conditions, offering only a generic 'Jobs' link.
    Fix: Publish and link to a dedicated worker wellbeing or working conditions policy from the About or governance section.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add explicit, measurable commitments covering fair pay, working hours, mental health support, and staff benefits.
  • accountability: The page names an executive team and governance links but assigns no accountability or oversight specifically for worker conditions.
    Fix: Identify a named role, committee, or oversight body responsible for monitoring and enforcing worker wellbeing standards.