University of Leeds
https://www.leeds.ac.uk · 55/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 31/37 (6 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 1/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 13/13 |
| Accountability | 1/5 |
| AI & Automation | 4/8 |
| Interoperability | 1/3 |
| Privacy | 11/16 |
| Provenance | 2/2 |
| Security | 5/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page promotes an AI Masters course but contains no AI use policy or statement governing the university's use of AI.
Fix: Publish a clear AI use policy or statement on the site (e.g., at /ai or linked from the footer) describing institutional AI usage.
-
scope_clear: No explanation is provided about what AI is used for on the site or within the institution.
Fix: Add a section to the AI policy that clearly describes the specific purposes and contexts in which AI is used.
Privacy
- Detected 4 data-leaking services across 2 categories: adobe fonts (p.typekit.net, use.typekit.net); youtube embed (i.ytimg.com, www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.leeds.ac.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only general facts about rankings and student numbers.
Fix: Add a funding and sponsorship disclosure section to the About page identifying the University's funding sources.
-
transparent: No funding sources are identified anywhere on the page, though it mentions a £1.9 billion economic contribution without context on funding.
Fix: Clearly list funding sources such as tuition fees, research grants, government block grants, and philanthropic donations on the About page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page lists phone numbers and emails but does not publish any response timeframes for inquiries.
Fix: Add expected response times (e.g., 'we aim to reply within 5 working days') next to each contact method.
-
specific: Since no timeframes are provided at all, there are no specific day-based commitments on the page.
Fix: Specify concrete turnaround times in days or hours for each team (e.g., admissions, security, media relations) rather than vague language.
-
process_exists: The page provides general and departmental contacts but does not document a complaints or feedback process or link to one.
Fix: Add a dedicated 'Complaints and feedback' section or link to a complaints procedure page from this contact page.
-
steps_clear: No complaint steps (e.g., who to contact first, escalation path, required information) are outlined anywhere on the page.
Fix: Provide a clear step-by-step complaints procedure including initial contact, escalation, expected acknowledgement, and final review stages.
-
appeals_exists: The contact page lists general and departmental contacts but does not describe any documented appeals process.
Fix: Add a dedicated section or link outlining how users can formally appeal decisions, including steps and timelines.
-
independent: No escalation path or independent review mechanism is mentioned on the page.
Fix: Publish an escalation route to an independent body (e.g., Office of the Independent Adjudicator) for unresolved appeals.
AI & Automation
-
detailed_scope: The page only describes an AI degree program and does not detail the scope of AI use by the university.
Fix: Include a detailed scope section in the AI policy outlining all systems, departments, and use cases where AI is applied.
-
limitations: No acknowledgement of AI system limitations appears anywhere on the page.
Fix: Add a limitations section to the AI policy that candidly describes known constraints, risks, and failure modes of AI systems used.
-
safeguards: The page does not describe any safeguards, oversight, or quality-control measures for AI use.
Fix: Document safeguards such as human review, bias testing, data governance, and escalation procedures in a published AI policy.
-
marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear AI content labelling policy indicating when and how AI-assisted material is disclosed on University of Leeds pages.
-
consistent: Without a marking policy visible on the page, there is no evidence that AI content marking is applied consistently.
Fix: Adopt a standard AI disclosure label (e.g., an 'AI-assisted' tag) and apply it uniformly across all relevant content.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a statement describing how humans review AI-generated outputs before publication, linked from the footer or policies section.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Publish a short description of the editorial review and approval steps applied to AI-assisted content.
-
accountability: No individual, team, or role is identified as accountable for AI-generated content on this page.
Fix: Name an accountable owner (e.g., a specific office or role) responsible for AI content governance and include contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The notice does not explicitly state that data collection is limited to what is necessary or follows a data minimisation principle.
Fix: Add an explicit statement that the University only collects personal data that is necessary for the stated purposes, referencing the GDPR data minimisation principle.
-
specific: Retention is only specific for IP logs (one month) and some cookies; other categories defer to an external Data Retention Schedule or say it will be made clear at collection without giving periods here.
Fix: Include specific retention periods (or clear ranges) for each major data category directly in the notice, or summarise the key periods from the Data Retention Schedule.
-
equal_choices: The page only references a 'review cookie settings' button and does not demonstrate that accept and reject options are presented with equal prominence in the consent UI.
Fix: Ensure the cookie banner presents a 'Reject all' option with the same visual prominence (size, color, placement) as the 'Accept all' button at the first layer of the consent UI.
-
partner_sharing_mentioned: The banner only mentions using cookies to collect information about use of University of Leeds sites and does not disclose any data sharing with third-party partners.
Fix: Update the banner copy to explicitly state whether data is shared with third-party partners and link to a list of those partners.
-
partner_count_specific: No numeric count of partners is provided because partner sharing is not disclosed at all.
Fix: If third-party sharing occurs, state the exact number of partners (e.g., 'We share data with X partners') in the banner or linked preferences page.
Provenance
Security
- security.txt not published.
Transparency
-
detail: The page provides no detail on funding amounts, percentages, or categories of funding received.
Fix: Include a breakdown of funding with amounts or percentages by category (e.g., tuition, research councils, donations) linked from the About page.
-
complete: No funding streams are disclosed at all, so coverage of major streams cannot be established.
Fix: Publish a comprehensive funding overview covering all major income streams, ideally linking to the annual financial reports already referenced in the footer.
-
roles_clear: The page references an 'Executive team' and faculties in the footer but does not identify key roles or responsibilities on this About page itself.
Fix: Add a short section on the About page summarising key leadership roles (e.g., Vice-Chancellor, executive team members) and their responsibilities, with links to fuller biographies.
-
algorithm_explained: The About page makes no mention of any algorithms used by the University or explains their purpose.
Fix: Add a dedicated section or link describing any algorithmic systems in use (e.g., admissions, search, personalisation) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect students, staff, or visitors.
Fix: Publish a clear statement describing the impact of any algorithmic decision-making on users and the outcomes it influences.
-
annual_statement: The page links to a Privacy notice but shows no evidence of a regular or periodic review of data practices.
Fix: Add a statement on the privacy page indicating the review cadence (e.g., 'Reviewed annually') with the date of last review.
-
dated: There is no visible date or version indicator for the privacy/data practices statement on this page.
Fix: Display a 'Last updated' date or version number alongside the Privacy link or on the privacy notice itself.
Level 3 — Advanced
Accessibility
Accountability
-
enforcement: While 4.5 mentions reporting misuse to law enforcement, the page does not explain the moderation enforcement process (e.g., how contributions are reviewed, removed, appealed, or users sanctioned).
Fix: Add a section describing the moderation enforcement workflow, including how breaches are detected, how content is removed, how users are notified, and any appeal process.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page describes physical campus security services and crime reporting but contains no published cyber/data incident response plan or policy.
Fix: Publish a formal incident response plan or policy document and link to it from this or a related security/privacy page.
-
notification_commitment: The page makes no commitment to publicly notify affected users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public in the event of significant incidents.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovery).
-
policy_exists: The page is about physical campus security services (patrols, SafeZone, bike registration, lost property) and contains no published responsible-disclosure or bug-bounty policy.
Fix: Publish a responsible-disclosure/security.txt policy describing scope, expectations, and how to report software vulnerabilities.
-
clear_contact: The only contacts listed (security@leeds.ac.uk and phone numbers) are for physical safety incidents, not for reporting security vulnerabilities.
Fix: Add a dedicated vulnerability-reporting channel (e.g., a security.txt file or security-reports@leeds.ac.uk) clearly identified for disclosing technical flaws.
-
safe_harbour_or_reward: The page offers no safe-harbour statement or reward/bug-bounty structure for security researchers.
Fix: Include a safe-harbour clause assuring good-faith researchers of no legal action and, if applicable, describe any reward or recognition program.
Transparency
-
criteria_published: The page does not publish any criteria used in algorithmic decisions.
Fix: Publish the specific criteria used in any algorithmic decisions on a transparency or policies page linked from About.
-
weighting: No information is provided about the weighting or priority of any decision criteria.
Fix: Document and publish the relative weighting or priority of each criterion used by algorithmic systems.
-
auditable: The page contains no technical or procedural detail that would allow external audit or review of algorithms.
Fix: Provide an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail to support independent audit.
-
open_source: No link to source code or any open source repository is provided on the About page.
Fix: Add a link to a public code repository (e.g., a GitHub organisation) for any site components or open-source projects the University maintains.
-
tech_docs: The page does not publish or link to any technical documentation about the site.
Fix: Publish and link to technical documentation (APIs, data schemas, or site architecture) from the About or a dedicated developer page.
Responsibility to the Future
-
disclosure_exists: The page contains general 'About' information and facts and figures but no published environmental impact or sustainability disclosure is present.
Fix: Publish a dedicated sustainability or environmental impact section on the About page linking to a formal environmental disclosure or report.
-
specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
Fix: Include concrete environmental metrics such as annual carbon footprint, energy consumption, and emissions reduction targets with reporting periods.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of its website hosting infrastructure.
Fix: Add a statement disclosing the hosting provider's energy source or the carbon footprint of the site's hosting infrastructure.
-
plan_exists: The governance page describes the University's constitutional structure and committees but contains no published plan for what happens if the organisation fails, dissolves, or exits.
Fix: Publish a wind-down or continuity plan describing what would happen to the institution's operations, data, and content in the event of failure or dissolution, and link it from this governance page.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content should the organisation cease to operate.
Fix: Add a section specifying the fate of user data and published content on closure, including retention, deletion, or transfer arrangements.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content or records if the University exits.
Fix: Name any archive partners, mirrors, or successor custodians (e.g. national archives) responsible for preserving records and content, and document these arrangements on the page.
-
policy_exists: The page is a general 'About' overview and contains no published policy on worker wellbeing or working conditions, offering only a generic 'Jobs' link.
Fix: Publish and link to a dedicated worker wellbeing or working conditions policy from the About or governance section.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add explicit, measurable commitments covering fair pay, working hours, mental health support, and staff benefits.
-
accountability: The page names an executive team and governance links but assigns no accountability or oversight specifically for worker conditions.
Fix: Identify a named role, committee, or oversight body responsible for monitoring and enforcing worker wellbeing standards.