University of Nottingham
https://www.nottingham.ac.uk · 40/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 25/37 (12 failed) |
| Level 2 — Enhanced | 5/27 (22 failed) |
| Level 3 — Advanced | 0/10 (10 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 4/8 |
| Interoperability | 1/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 3/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: select-name.
- 1 WCAG 2.1 Level A violation reported by axe-core: select-name.
AI & Automation
-
policy_exists: The page describes AI research activities but contains no AI use policy or governance statement.
Fix: Publish a clear AI use policy or statement outlining principles for responsible AI use at the university.
-
scope_clear: While the page lists general AI application areas, it does not clearly state what AI is used for by the university itself in a policy sense.
Fix: Add a dedicated section specifying the concrete scope of AI use within the institution, distinct from general AI research descriptions.
Privacy
- No hidden iframes detected.
- Detected 2 data-leaking services across 2 categories: cookie consent saas (cdn-ukwest.onetrust.com); google fonts (fonts.googleapis.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.nottingham.ac.uk
- x-frame-options: sameorigin
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
purpose_clear: The page lists navigation links but does not clearly state what the University does or its purpose on the landing view.
Fix: Add an introductory paragraph at the top of the About page explaining the University's purpose, mission, and core activities.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page only references generic groups like 'general switchboard' and 'Student services' without naming an individual or specific responsible role.
Fix: Add the name or job title of a specific person or team lead (e.g., Head of Communications) accountable for enquiries.
-
response_timeframe: The page lists phone line opening hours (Mon-Fri 9.00am-4.30pm) but does not publish any timeframe for responding to enquiries.
Fix: Add a clear statement specifying how quickly enquiries will be answered (e.g., 'We respond to email enquiries within 5 working days').
-
specific: No response timeframe is given at all, so there are no specific durations such as days or hours stated.
Fix: Publish concrete response targets in measurable units (e.g., '2 business days for email, 24 hours for urgent queries'). (Note: see recommendation field.)
-
, : No response timeframe is given, so specific durations cannot be present.
Fix: Once timeframes are added, ensure they are stated in specific units like 'within 3 working days' rather than vague terms like 'soon' or 'promptly'.
-
process_exists: The contact page provides general phone numbers and contact categories but does not document a complaints or feedback process.
Fix: Add a dedicated section or link to a formal complaints/feedback procedure (e.g., 'How to make a complaint') on the contact page.
-
steps_clear: Because no complaints process is presented, there are no steps to evaluate for clarity.
Fix: Publish a numbered, step-by-step complaints procedure covering how to submit, what information to include, who reviews it, and expected next steps.
-
appeals_exists: The contact page lists general enquiry phone numbers and department links but contains no documented appeals process.
Fix: Add a dedicated appeals section or link to a formal appeals policy document outlining how users can formally contest decisions.
-
independent: No appeals process is described, so there is no indication of independent review or escalation paths.
Fix: Publish an appeals procedure that specifies an independent reviewer or escalation route (e.g., ombudsperson or external body) separate from the original decision-maker.
AI & Automation
-
detailed_scope: The page lists broad research themes but provides no detailed policy-level scope of AI use.
Fix: Include a detailed scope section in the AI policy describing specific systems, contexts, and user groups for AI deployment.
-
limitations: No limitations, risks, or shortcomings of AI systems are acknowledged anywhere on the page.
Fix: Add a section explicitly acknowledging limitations of AI systems such as bias, accuracy issues, and contexts where AI should not be relied upon.
-
safeguards: The page does not describe any safeguards, quality controls, or oversight mechanisms for AI use.
Fix: Document safeguards such as human oversight, ethical review processes, and quality assurance measures applied to AI systems.
-
marking_policy: The page describes AI research and courses but contains no policy for marking or labeling AI-assisted content.
Fix: Publish a clear policy statement on the page indicating how any AI-assisted content is identified and labeled.
-
consistent: Without a marking policy present, there is no evidence of consistent application of AI content marking on the page.
Fix: Adopt and apply a uniform AI-content label (e.g., a visible tag or disclosure) across all AI-assisted sections of the site.
-
oversight_exists: The page makes no reference to human oversight of AI outputs or any governance mechanism.
Fix: Add a section documenting how humans review and oversee AI-generated outputs used on the site.
-
review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
Fix: Describe the editorial review and approval steps that AI-assisted content must go through before publication.
-
accountability: Although Professor Ender Özcan is listed for enquiries, no individual or role is identified as accountable for AI-generated content.
Fix: Name a specific person or role responsible for AI-generated content and provide their contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: This landing page describes rights and general principles but defers the specifics of what data is collected and why to separate linked privacy notices, so the page itself does not comprehensively cover data collection purposes.
Fix: Summarize the key categories of data collected and the purposes for each audience directly on this page, or embed that information rather than only linking out to sub-notices.
-
understandable: A non-expert would not learn from this page what specific data is collected or why, as those details are deferred to separate role-specific privacy notices.
Fix: Add a concise plain-language summary on this page listing the main types of data collected and the reasons for collection before directing users to detailed notices.
-
necessity: The page states data is processed 'for specified purposes' and 'justified in accordance with data protection law' but does not explicitly state that collection is limited to what is necessary.
Fix: Add an explicit statement, such as a data minimisation principle, confirming that only data necessary for the stated purposes is collected.
-
proportionate: The page does not address proportionality of data collection relative to the services provided.
Fix: Include a clear statement that the amount and type of data collected is proportionate to the purpose and service being delivered.
-
specific: Retention periods are not given on this page; it only refers users to a separate Records Retention Schedule or relevant privacy notice without stating concrete time periods.
Fix: List specific retention periods (e.g. number of years) for the main data categories directly on this page, or link to a clearly accessible schedule with concrete timeframes.
-
equal_choices: The page only references a 'Cookie Settings' link without showing the actual consent interface, so equal prominence of accept and reject options cannot be confirmed from this page.
Fix: Ensure the cookie consent banner presents 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement) on the first layer.
-
partner_sharing_mentioned: The banner only mentions storing cookies for navigation, analytics, and marketing but does not disclose data sharing with third-party partners.
Fix: Update the banner copy to explicitly disclose that cookie data may be shared with third-party partners and link to a partner list.
-
partner_count_specific: No specific numeric count of third-party partners is stated anywhere in the banner or on-page consent copy.
Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full partner list.
Provenance
-
credentials: The about page does not provide organisational background or credentials on this landing view, only links to sub-pages like History and Vice-Chancellor.
Fix: Include a brief summary of the University's credentials (e.g., founding date, accreditations, rankings) directly on the About landing page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified; only generic categories like 'General enquiries' and 'Student services' are listed.
Fix: Identify the specific team (e.g., 'Enquiries Team') or individual handling each contact route by name.
-
role_clear: While categories are grouped (UK students, alumni, security), the role or authority of who answers and what they can resolve is not explicitly stated.
Fix: Add a brief description next to each contact channel clarifying the role, remit, and decision-making authority of the team responding.
-
substantive: The About page contains only short link descriptions rather than a substantive statement of purpose.
Fix: Expand the About page with detailed content describing the University's identity, values, and scope of work.
-
mission_clear: No mission statement or editorial approach is articulated on the page.
Fix: Add an explicit mission statement describing the University's educational and research goals.
-
complete: While major funding streams are mentioned, details on discretionary scholarships, individual studentship values, and alumni scholarship amounts are missing or vague.
Fix: Add specific amounts, eligibility criteria, and coverage details for discretionary scholarships, alumni scholarships, and individual studentships to ensure all major funding streams are fully disclosed.
-
roles_clear: While the page mentions a Vice-Chancellor link and University structure, it does not clearly identify key roles or their responsibilities on this About page itself.
Fix: Add a brief summary of key leadership roles (e.g., Vice-Chancellor, Council, Senate) and their responsibilities directly on the About page or in a clearly labeled leadership section.
-
algorithm_explained: The About page contains no mention of any algorithms or their purpose.
Fix: Add a section or link disclosing any algorithmic systems used by the University and explain their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include a clear statement describing how any algorithmic decisions impact students, staff, or visitors, with examples.
-
annual_statement: The page links to a Privacy notice but shows no evidence of an annual or periodic review of data practices.
Fix: Add a statement to the privacy page indicating the cadence (e.g., annual) at which data practices are reviewed and last reviewed date.
-
dated: No date or version information is visible for privacy/data practices on this page.
Fix: Display a 'last updated' date or version number on the Privacy and Cookie policy links referenced in the footer.
Level 3 — Advanced
Accessibility
-
known_issues: The page content provides no acknowledgement of known accessibility issues or limitations, only a link labelled 'Accessibility'.
Fix: Add a section to the accessibility statement that lists specific known non-compliant elements and content that is not fully accessible.
-
remediation_timeline: There is no timeline or commitment for fixing accessibility issues visible in the provided content.
Fix: Include target dates or a commitment describing when identified accessibility issues will be resolved.
-
feedback_channel: The page offers only a generic 'Contact us' email and no accessibility-specific feedback mechanism or response-time commitment.
Fix: Provide a dedicated accessibility feedback contact and state how quickly users can expect a response.
Accountability
-
enforcement: While the page states the University may disable passwords and that user rights cease on breach, it explicitly says it is 'under no obligation to oversee, monitor or moderate' interactive services and does not explain how moderation enforcement actually occurs.
Fix: Add a clear enforcement section describing how violations are reported, reviewed, and acted upon (e.g., content removal, account suspension, appeals process, and timelines).
Interoperability
- Not found at: /status
Security
-
plan_exists: The page describes the Security service's purposes and contact details but contains no published incident response plan or policy for handling security incidents.
Fix: Publish a documented incident response plan or policy outlining how the university detects, responds to, and manages security incidents.
-
notification_commitment: The page makes no commitment to publicly notify affected parties when significant incidents occur.
Fix: Add a clear statement committing the university to notify affected users and the public in the event of significant security incidents.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a defined timeframe (e.g., within 72 hours of detection) for disclosing incidents to affected users.
-
policy_exists: The page covers physical campus security services and CCTV but contains no published responsible-disclosure or bug-bounty policy for reporting security vulnerabilities.
Fix: Publish a security.txt file and a dedicated responsible-disclosure/vulnerability disclosure policy page outlining scope and reporting procedures.
-
clear_contact: The only contacts listed (security@nottingham.ac.uk and phone numbers) are for physical security services, with no dedicated channel for reporting information-security vulnerabilities.
Fix: Provide a clearly labelled security contact (e.g., security-report@nottingham.ac.uk) or security.txt entry specifically for vulnerability reports.
-
safe_harbour_or_reward: The page makes no mention of safe harbour protections or any reward structure for security researchers.
Fix: Add a safe harbour statement assuring researchers acting in good faith will not face legal action, and clarify whether any reward or recognition is offered.
Transparency
-
criteria_published: No specific criteria for any algorithmic decisions are published on the page.
Fix: Publish the specific decision criteria used by any algorithms, for example in a dedicated transparency or governance page.
-
weighting: The page does not explain the weighting or priority of any decision criteria.
Fix: Document how each criterion is weighted or prioritised within algorithmic decisions and link it from the About page.
-
auditable: The page provides no technical or procedural detail sufficient for external audit.
Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail to support independent audit.
-
open_source: No link to source code or open-source repositories is provided on the page.
Fix: Link to any publicly available code repositories (e.g., a university GitHub organisation) from the About or technical sections.
-
tech_docs: No technical documentation is published or linked from the About page.
Fix: Provide or link to technical documentation about the website's platform, APIs, or open data resources.
Responsibility to the Future
-
specific_metrics: The page references 'ambitious carbon reduction targets' and 'carbon reduction goals' but provides no specific figures for carbon, energy use, or emissions on this page.
Fix: Publish concrete numbers such as baseline emissions, annual energy use, and target reduction percentages with dates directly on the sustainability page.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy source (e.g., renewable-powered data centres) and the site's estimated carbon footprint.
-
plan_exists: The governance page describes committees, the University Calendar, and charity information but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a wind-down or continuity plan describing the steps and responsibilities that apply if the University ceases operations or exits provision.
-
data_and_content_fate: The page addresses records and information compliance generally but does not state what happens to user data and published content in the event of organisational failure or exit.
Fix: Add a clear statement covering the retention, transfer, or deletion of user data and the fate of published content should the organisation cease to operate.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the governance page.
Fix: Name a designated custodian or archive partner (for example a national web archive or successor body) responsible for preserving content and data if the organisation exits.
-
policy_exists: The page is a Careers and Employability Service landing page and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the page.
-
specific_commitments: The page makes no specific commitments regarding pay, working hours, mental health, or benefits.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits within the wellbeing policy.
-
accountability: The page does not identify any accountability or oversight body responsible for worker conditions.
Fix: Name the department or role responsible for overseeing worker wellbeing and provide contact or reporting channels.