Wellcome Collection

https://wellcomecollection.org · 52/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 11/16
Provenance 2/2
Security 4/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no mention of an AI use policy or statement.
    Fix: Publish a dedicated AI use policy page and link to it from the About and Policies sections.
  • scope_clear: No AI-related content appears on the page, so the scope of any AI use is not explained.
    Fix: Include a section describing where and how AI is used across Wellcome Collection's services (e.g., search, cataloguing, transcription).

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists phone numbers and email addresses but does not state any expected response timeframe for enquiries.
    Fix: Add a statement next to each contact method indicating how long visitors should expect to wait for a response (e.g., 'We aim to reply within 5 working days').
  • specific: Since no timeframes are published at all, there are no specific durations given.
    Fix: Publish concrete response windows in days or hours for each enquiry channel rather than vague language.
  • process_exists: The page covers venue, access, library, and scam reporting but does not describe any complaints or feedback process.
    Fix: Add a dedicated 'Complaints and feedback' section on the contact page explaining how users can submit a complaint or feedback.
  • steps_clear: Because no complaints process is documented, there are no clear steps for making a complaint.
    Fix: Include a numbered, step-by-step procedure (who to contact first, escalation path, and how to reach an ombudsman or regulator) for raising complaints.
  • appeals_exists: The contact page lists enquiry channels and scam reporting but does not document any appeals process for decisions made by Wellcome Collection.
    Fix: Add a clearly labeled 'Appeals' section describing how users can formally challenge decisions, including required information and expected timelines.
  • independent: No escalation path or independent reviewer is mentioned; all contacts route to general Wellcome Collection enquiry inboxes.
    Fix: Document an escalation route to an independent body or senior reviewer (e.g., an ombudsman or designated appeals officer) separate from the original decision-maker.

AI & Automation

  • detailed_scope: The page does not mention AI at all, let alone detail its scope of use.
    Fix: Add detailed descriptions of specific AI applications, systems, and use cases within the organisation's AI policy.
  • limitations: No acknowledgement of AI limitations is present on the page.
    Fix: Document known limitations, risks, and potential biases of AI systems used in a published AI policy.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Describe human oversight, review processes, and quality assurance safeguards governing any AI deployments.
  • marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish an AI content policy that explains how AI-assisted or AI-generated content is labelled on the site.
  • consistent: Without a marking policy visible on the page, there is no evidence AI content marking is applied consistently.
    Fix: Adopt a documented labelling convention (e.g., an 'AI-assisted' tag) and apply it uniformly across exhibitions, stories and collection entries.
  • oversight_exists: The page does not mention any human oversight arrangements for AI outputs.
    Fix: Add a statement (e.g., within Policies and plans) confirming that AI outputs are subject to human oversight before publication.
  • review_process: No review or approval workflow for AI-generated material is described on the page.
    Fix: Describe the editorial review and sign-off steps applied to AI-assisted content in a public-facing policy document.
  • accountability: No individual, role or team is identified as accountable for AI-generated content.
    Fix: Name an accountable role (for example, an editorial lead or Head of Digital) responsible for AI-generated content and list them in the About or Policies section.

Interoperability

Privacy

  • comprehensive: The page is a cookie policy focused only on cookies and redirects users elsewhere for the full Privacy Policy, so it does not itself comprehensively cover what personal data is collected and why.
    Fix: Include or inline the full Privacy Policy content (categories of personal data collected, purposes, legal bases, sharing) on this page rather than only linking to it.
  • necessity: The policy does not explicitly state that data collection is limited to what is necessary; it only notes that strictly necessary cookies cannot be switched off.
    Fix: Add an explicit statement of data minimisation, e.g., 'We only collect data that is necessary for the purposes described and nothing more.'
  • proportionate: There is no statement addressing proportionality of data collection relative to the service provided.
    Fix: Include a sentence affirming that the data collected is proportionate to providing and improving the Wellcome Collection website services.
  • specific: While many entries are specific, some retention values are vague or inconsistent such as 'Persistant' for SessionID and a far-future date '2036-12-31T23:59:59Z', and broader personal data retention periods are not given.
    Fix: Replace vague values like 'Persistant' with concrete durations and add specific retention periods for non-cookie personal data categories collected by the site.
  • partner_count_specific: The banner references 'third parties' generically without stating any specific numeric count of partners.
    Fix: Add the exact number of third-party partners (e.g., 'shared with 12 partners') in the cookie banner or Manage cookies panel.

Provenance

Security

Transparency

  • detail: The page mentions Wellcome as the parent foundation but provides no amounts, percentages, or categories of funding.
    Fix: Add specifics such as annual funding amount from Wellcome, percentage breakdowns, or categories (e.g., grants, endowments, earned income) to the About page or link to a financial report.
  • complete: The disclosure only references Wellcome and does not address other potential funding streams such as donations, retail/café revenue, or partnerships.
    Fix: Expand the disclosure to enumerate all major funding streams (parent foundation, commercial income, donations, grants, partnerships) or link to an annual report detailing them.
  • governance_exists: The page describes the museum's mission and offerings but does not describe its governance or editorial structure beyond noting it is part of Wellcome, a charitable foundation.
    Fix: Add a dedicated section or link to a page outlining the governance structure (e.g., board of trustees, editorial oversight, decision-making bodies) on the About us page.
  • roles_clear: No key roles or responsibilities (such as leadership, trustees, or editorial staff) are identified on the page.
    Fix: List or link to a page identifying key roles such as the director, trustees, and editorial leadership along with their responsibilities.
  • algorithm_explained: The About page does not mention any algorithms or explain their purpose on the site.
    Fix: Add a section or link describing any algorithms used (e.g., for search, recommendations, or collections) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include clear information about how algorithmic outputs influence what users see and any consequences for them.
  • annual_statement: The page links to a privacy notice and cookie policy but provides no evidence of regular or annual review of data practices.
    Fix: Publish a statement indicating that privacy and data practices are reviewed on a defined periodic (e.g., annual) basis, with the last review date shown.
  • dated: The page references a privacy notice and cookie policy but shows no dates or version numbers for data practices statements.
    Fix: Add a 'last updated' date or version number to the privacy notice and cookie policy and surface it where these are referenced.

Level 3 — Advanced

Accessibility

  • statement_exists: The page only offers a generic 'Accessibility' link and lists building features like step-free access and hearing loops, but no dedicated accessibility statement is present on this page.
    Fix: Publish a dedicated accessibility statement covering both the website and physical venue, and link to it prominently from the About us page.
  • known_issues: There is no acknowledgement of any known accessibility issues or limitations anywhere in the visible content.
    Fix: Include a section in the accessibility statement that lists known accessibility barriers and any content that is not yet fully accessible.
  • remediation_timeline: The page provides no timeline or commitment for fixing accessibility issues.
    Fix: State target dates or an ongoing commitment for remediating identified accessibility issues within the accessibility statement.
  • feedback_channel: While general contact details (info@wellcomecollection.org, phone) are listed, there is no accessibility-specific feedback mechanism with a stated response commitment.
    Fix: Add a dedicated accessibility feedback channel and specify how quickly users can expect a response to accessibility reports.

Accountability

  • policy_exists: The About page mentions 'Policies and plans' generically but does not publish or link to a specific moderation policy.
    Fix: Publish a dedicated moderation policy page and link to it from the About and community/engagement sections.
  • criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on this page.
    Fix: Add explicit moderation criteria describing prohibited content and acceptable behavior standards.
  • enforcement: The page does not describe any enforcement process, appeals route, or who enforces moderation decisions.
    Fix: Document the enforcement workflow, including reporting mechanisms, responsible team, and appeal procedures.

Interoperability

Security

  • plan_exists: The page references general policies and plans but shows no published incident response plan or security incident policy.
    Fix: Publish a dedicated incident response plan or policy and link to it from the 'Policies and plans' section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected users of significant incidents within your incident response documentation.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident) in your incident response policy.

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published on the About page.
    Fix: Publish the specific criteria (inputs, rules, data sources) used by any algorithms on a dedicated transparency page.
  • weighting: The page does not explain the weighting or priority of any decision criteria.
    Fix: Document how criteria are weighted or prioritised within any algorithmic processes used by the site.
  • auditable: There is insufficient technical or procedural detail provided for external audit or review.
    Fix: Provide audit-ready documentation such as model cards, data provenance and review processes accessible to external reviewers.
  • open_source: The About page contains no link to source code repositories, though a 'Developers' link exists in the footer which may lead elsewhere.
    Fix: Add a direct link from the About page to any public source code repositories (e.g., GitHub) associated with Wellcome Collection's digital platforms.
  • tech_docs: No technical documentation is linked from the About page content itself, only a generic 'Developers' footer link without context.
    Fix: Include a clearly labelled link to technical/API documentation from the About page to help developers and researchers find it.

Responsibility to the Future

  • disclosure_exists: The About page describes the museum, library, and Wellcome charitable foundation but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About or Policies and plans section.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Include concrete environmental metrics such as annual carbon emissions or energy consumption within a sustainability report.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the site's hosting provider and its green/carbon credentials, ideally noting use of renewable-powered or low-carbon hosting.
  • plan_exists: The About page describes the museum, its mission, and policies but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan (e.g., within the 'Policies and plans' section) describing what will happen to the collection and services if the organisation ceases operations.
  • data_and_content_fate: The page mentions a privacy notice and Creative Commons licensing but does not state what would happen to user data or published content if the organisation ceased to exist.
    Fix: Add a statement addressing the long-term fate of user data and published content in the event of closure, including retention, deletion, or transfer arrangements.
  • custodians_or_mirrors: The page notes Wellcome Collection is part of the Wellcome charitable foundation but does not identify any custodians, mirrors, or archive partners to preserve content if it exits.
    Fix: Name specific archive partners, custodians, or mirror arrangements (such as a national archive or library) that would preserve the collections and digital content.
  • policy_exists: The page references a 'Visitor care statement,' 'Policies and plans,' and a 'Modern slavery statement,' but none is identified as a published policy on worker wellbeing or working conditions for staff.
    Fix: Publish and link to a dedicated worker wellbeing or working conditions policy from the About us or Policies and plans section.
  • specific_commitments: The page contains no specific commitments on pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the worker wellbeing policy.
  • accountability: The page names a media office and general contacts but does not identify any accountability or oversight function for worker conditions.
    Fix: Name a responsible person, team, or governance body (e.g., HR or a board committee) accountable for overseeing worker conditions.