University of Warwick
https://www.warwick.ac.uk · 49/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 29/37 (8 failed) |
| Level 2 — Enhanced | 10/27 (17 failed) |
| Level 3 — Advanced | 0/10 (10 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 1/5 |
| AI & Automation | 4/8 |
| Interoperability | 2/3 |
| Privacy | 8/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- autoplay without controls: {'tag': 'video', 'src': '', 'autoplay': True, 'controls': False}
- without controls: {'tag': 'video', 'src': '', 'autoplay': True, 'controls': False}
AI & Automation
-
policy_exists: The page is a sign-in gate with no visible AI policy or statement content.
Fix: Publish a publicly accessible AI use policy or statement on this page rather than requiring login.
-
scope_clear: No explanation of AI uses is visible because the content is gated behind authentication.
Fix: Include a public summary describing what AI is used for at Warwick before the sign-in requirement.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.pu…'.
- Detected 2 data-leaking services across 1 category: adobe fonts (p.typekit.net, use.typekit.net).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (2 hops): https://www.warwick.ac.uk → https://warwick.ac.uk/
- x-frame-options: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
transparent: The page identifies sponsor categories broadly but does not name specific funding bodies or organisations among the 200+ sponsors.
Fix: Publish a list or representative examples of named sponsoring organisations (e.g., specific ministries, banks, or companies) to make funding sources clearly identifiable.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page lists phone numbers and email addresses but does not publish any response timeframe for inquiries.
Fix: Add a stated response timeframe (e.g., 'We respond to email enquiries within 5 business days') near the contact details.
-
specific: Since no timeframes are published at all, no specific durations such as days or hours are provided.
Fix: Specify concrete response windows in days or hours for each contact channel (e.g., webeditor and helpdesk emails).
-
steps_clear: The page only links to the procedure without outlining the actual steps for making a complaint on this page.
Fix: Summarise the key steps of the complaints process directly on the contact page (e.g., who to contact first, escalation path, expected acknowledgement).
-
independent: The page only references a generic complaints procedure without indicating any independent review or escalation path beyond the University itself.
Fix: Add information about how complaints can be escalated to an independent body (e.g., the Office of the Independent Adjudicator) if unresolved internally.
AI & Automation
-
detailed_scope: No detailed scope of AI use is shown; only a login prompt appears.
Fix: Provide a publicly viewable section detailing the specific scope of AI applications and use cases.
-
limitations: No acknowledgement of AI limitations is visible on the gated page.
Fix: Add a public section explicitly acknowledging the limitations and risks of the AI systems in use.
-
safeguards: No safeguards or quality controls are described on the accessible page content.
Fix: Publish descriptions of governance, safeguards, and quality-control measures for AI outside the login wall.
-
marking_policy: The page is a sign-in gate with no visible policy for marking AI-assisted content.
Fix: Publish a publicly accessible policy describing how AI-assisted content is labelled on the site.
-
consistent: No AI content marking is visible on this gated page, so consistency cannot be demonstrated.
Fix: Apply and display consistent AI-content labels across public pages so reviewers can verify uniform application.
-
oversight_exists: The page requires sign-in and provides no documentation of human oversight of AI outputs.
Fix: Publish a public statement describing the human oversight model for AI outputs produced or used by the service.
-
review_process: No review or approval process for AI content is described on the visible page.
Fix: Document the specific review/approval workflow (who reviews, when, and against what criteria) in a publicly linked policy.
-
accountability: No accountable owner or role for AI-generated content is named on the page.
Fix: Name an accountable role or team (e.g., AI Centre of Excellence lead) and publish contact details for AI content accountability.
Interoperability
Privacy
-
plain_language: The page itself uses legal/compliance phrasing like 'complying with data protection legislation' and 'process data fairly and lawfully' rather than plain language.
Fix: Rewrite the introductory text in plain language (e.g., 'We explain how we use your personal information') before linking to the detailed notices.
-
comprehensive: This landing page does not itself describe what data is collected or why; it only links out to other notices without summarising their content.
Fix: Add a short summary on this page outlining the categories of data collected, purposes, and lawful bases, or inline the key contents of the core notices.
-
plain_language: The visible text uses jargon such as 'data subjects', 'processing', and 'lawful' without plain-language explanations.
Fix: Replace terms like 'data subjects' with 'people' and 'processing' with 'using/handling', and define any unavoidable legal terms inline.
-
understandable: A non-expert visiting this page cannot tell what data is collected or why without clicking into separate notices, and the summary itself is abstract.
Fix: Provide a concise, user-friendly overview on the page stating what personal data is collected, why, and who to contact, with links for detail.
-
necessity: The page does not state that data collection is limited to what is necessary; it only describes the obligation to inform data subjects.
Fix: Add an explicit statement (e.g., data minimisation principle) confirming that only data necessary for stated purposes is collected.
-
proportionate: There is no mention of proportionality between data collected and the services provided on this hub page.
Fix: Include a statement that data collection is proportionate to the purpose, with examples or links to evidence of this in the core notices.
-
retention_stated: The page contains no information about data retention periods.
Fix: Add a retention section (or summary) on this page stating how long different categories of personal data are kept.
-
specific: Since no retention periods are mentioned at all, no specific time periods are provided.
Fix: Specify concrete retention durations (e.g., 'student records kept for 6 years after graduation') rather than relying solely on linked notices.
-
equal_choices: The banner shows a prominent 'Accept all' button but no equivalent 'Reject all' button, forcing users to navigate granular toggles to decline.
Fix: Add a 'Reject all' button with equal visual prominence to the 'Accept all' button on the cookie banner.
-
partner_sharing_mentioned: The banner mentions cookie categories (functional, advertising, performance) but does not disclose data sharing with third-party partners.
Fix: Update the banner copy to explicitly state whether data is shared with third-party partners and link to a list of those partners.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Add a specific number of third-party partners (e.g., 'We share data with X partners') in the banner with a link to the full partner list.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
detail: The disclosure mentions broad sponsor categories but provides no amounts, percentages, or numbers of sponsored students per category.
Fix: Add quantitative detail such as funding amounts, percentage breakdowns by sponsor type, or the number of sponsored students in each category.
-
complete: The page only addresses external sponsors of scholars and omits other major University funding streams such as tuition fees, research grants, or government support.
Fix: Expand the disclosure (or link to a dedicated funding page) covering all major funding streams including tuition, research income, endowments, and public funding.
-
roles_clear: While offices like the Chancellor, University Executive Office, and Registrar's Office are mentioned, the page does not describe their specific roles or responsibilities.
Fix: Add brief descriptions of each governance role's responsibilities (e.g., what the Chancellor, University Executive Office, and Registrar's Office do) directly on the About page or via clearly labeled links.
-
algorithm_explained: The About page contains general institutional descriptions but does not mention or explain the purpose of any algorithms in use.
Fix: Add a section or link describing any algorithmic systems used by the university (e.g., admissions, search ranking) and their purpose.
-
impact_clear: The page does not describe how algorithmic decisions affect users such as students, applicants, or staff.
Fix: Include clear statements outlining how any algorithmic decisions impact users and link to a dedicated algorithmic transparency notice.
-
annual_statement: The page links to a Privacy policy but provides no evidence of a regular or annual review of data practices.
Fix: Add a statement on the Privacy page indicating the frequency of review (e.g., 'Reviewed annually') with the most recent review date.
-
dated: While the page itself shows 'Last revised: Wed 14 Jan 2026', the Privacy/data practices statement link is not visibly dated or versioned on this page.
Fix: Display a 'Last updated' date or version number adjacent to the Privacy link, or ensure the linked privacy statement clearly shows its effective date.
Level 3 — Advanced
Accessibility
-
known_issues: The visible content lists systems and resources but does not acknowledge any specific known accessibility issues or non-compliant areas.
Fix: Add a clearly labeled section listing the known accessibility problems and which parts of the site are not yet fully compliant with WCAG.
-
remediation_timeline: There is no stated timeline or commitment for when identified accessibility issues will be resolved.
Fix: Include target dates or a commitment describing when known issues will be fixed and when the statement will next be reviewed.
-
feedback_channel: The page only shows a "Page contact: webaccessibility" reference without a clear feedback mechanism or a commitment on response times.
Fix: Provide a clear feedback method (e.g., email address or form) alongside a stated commitment to respond within a defined timeframe.
Accountability
-
policy_exists: The terms page lists privacy, cookies, and copyright policies but no published moderation policy.
Fix: Publish a dedicated moderation policy outlining what content is moderated and link it from the terms page.
-
criteria_clear: No moderation criteria are stated anywhere in the visible terms content.
Fix: Add clear criteria describing what types of content or behaviour will be moderated or removed.
-
enforcement: The page does not explain any enforcement process for moderation decisions.
Fix: Document the enforcement workflow, including reporting channels, review steps, and appeal rights.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is a sign-in gate showing only an acceptable use policy link and community safety address, with no published incident response plan or policy visible.
Fix: Publish a publicly accessible incident response plan or policy that does not require sign-in to view.
-
notification_commitment: There is no content on the page committing to public notification of significant security incidents.
Fix: Add an explicit statement committing to notify the public or affected users when significant incidents occur.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of confirming an incident) in the published incident response policy.
-
policy_exists: The page is a sign-in gated placeholder showing only an acceptable use policy and community-safety link, with no published responsible-disclosure or bug-bounty policy visible.
Fix: Publish a publicly accessible security.txt file and/or a responsible-disclosure policy page outlining scope, reporting process, and expectations.
-
clear_contact: No email address, form, or dedicated contact channel for reporting vulnerabilities is present on the page.
Fix: Add a clear security contact such as security@warwick.ac.uk or a reporting form in a publicly viewable security disclosure page.
-
safe_harbour_or_reward: The page contains no safe-harbour statement or reward/bug-bounty structure for researchers.
Fix: Include an explicit safe-harbour clause protecting good-faith researchers and, if applicable, describe any reward or recognition program.
Transparency
-
criteria_published: No specific criteria for any algorithmic decision-making are published anywhere on this About page.
Fix: Publish the specific input criteria used in any algorithmic decisions, or link to a transparency register that lists them.
-
weighting: The page provides no information about the weighting or priority of any decision criteria.
Fix: Document and publish the relative weighting or priority of criteria used in algorithmic decisions.
-
auditable: The page lacks any technical detail, methodology, or documentation that would enable external audit or review.
Fix: Provide a detailed methodology document or model card and offer a contact route for independent auditors to review algorithmic systems.
-
open_source: No source code repository or open-source link is provided; the site notes it is 'Powered by Sitebuilder' without a link to code.
Fix: Add a link to a public code repository (e.g., GitHub) for any in-house or open-source components used on the site.
-
tech_docs: No technical documentation about the site's platform, APIs, or data is linked from the about page.
Fix: Publish and link to technical documentation for the Sitebuilder platform or any data/APIs the university exposes.
Responsibility to the Future
-
specific_metrics: The page cites ranking positions (13th globally, top 1%) but provides no specific carbon, energy use, or emissions figures.
Fix: Add concrete quantitative metrics such as annual carbon emissions (tCO2e), energy consumption, and reduction targets directly on the page.
-
hosting_disclosure: The page makes no mention of the carbon or energy profile of its web hosting or digital infrastructure.
Fix: Publish a statement disclosing whether the site is hosted on renewable-powered or green hosting infrastructure and its associated carbon footprint.
-
plan_exists: The governance page describes committee structures, business continuity, and risk management links but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish an explicit succession or wind-down plan (or link to one from the Business Continuity section) describing what happens if the University ceases operation.
-
data_and_content_fate: There is no mention of what would happen to user data or published content in the event of organisational failure or exit.
Fix: Add a section detailing the fate of user data and published content on closure, including retention, deletion, or transfer arrangements.
-
custodians_or_mirrors: The page names governance teams and contacts but identifies no custodians, mirrors, or archive partners to preserve services or records after an exit.
Fix: Identify a designated custodian, mirror, or archive partner (e.g., a national archive or digital preservation service) responsible for maintaining content if the organisation ceases to exist.
-
policy_exists: The page describes Warwick's cultural strategy and regional engagement but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this or a related page.
-
specific_commitments: The content makes no mention of specific commitments such as pay, hours, mental health, or benefits.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits within a wellbeing policy.
-
accountability: No accountability or oversight structure for worker conditions is identified beyond a general regional team contact.
Fix: Name a responsible role, committee, or oversight body accountable for monitoring and enforcing worker conditions.