Wellcome Collection
https://wellcomecollection.org · 52/92 checks passed · libraries
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (7 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 11/16 |
| Provenance | 2/2 |
| Security | 4/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish a dedicated AI use policy page and link to it from the About and Policies sections.
-
scope_clear: No AI-related content appears on the page, so the scope of any AI use is not explained.
Fix: Include a section describing where and how AI is used across Wellcome Collection's services (e.g., search, cataloguing, transcription).
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' window.dataLayer = window.dataLayer || []; function gt…'.
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://wellcomecollection.org
- x-frame-options: DENY
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page lists phone numbers and email addresses but does not state any expected response timeframe for enquiries.
Fix: Add a statement next to each contact method indicating how long visitors should expect to wait for a response (e.g., 'We aim to reply within 5 working days').
-
specific: Since no timeframes are published at all, there are no specific durations given.
Fix: Publish concrete response windows in days or hours for each enquiry channel rather than vague language.
-
process_exists: The page covers venue, access, library, and scam reporting but does not describe any complaints or feedback process.
Fix: Add a dedicated 'Complaints and feedback' section on the contact page explaining how users can submit a complaint or feedback.
-
steps_clear: Because no complaints process is documented, there are no clear steps for making a complaint.
Fix: Include a numbered, step-by-step procedure (who to contact first, escalation path, and how to reach an ombudsman or regulator) for raising complaints.
-
appeals_exists: The contact page lists enquiry channels and scam reporting but does not document any appeals process for decisions made by Wellcome Collection.
Fix: Add a clearly labeled 'Appeals' section describing how users can formally challenge decisions, including required information and expected timelines.
-
independent: No escalation path or independent reviewer is mentioned; all contacts route to general Wellcome Collection enquiry inboxes.
Fix: Document an escalation route to an independent body or senior reviewer (e.g., an ombudsman or designated appeals officer) separate from the original decision-maker.
AI & Automation
-
detailed_scope: The page does not mention AI at all, let alone detail its scope of use.
Fix: Add detailed descriptions of specific AI applications, systems, and use cases within the organisation's AI policy.
-
limitations: No acknowledgement of AI limitations is present on the page.
Fix: Document known limitations, risks, and potential biases of AI systems used in a published AI policy.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Describe human oversight, review processes, and quality assurance safeguards governing any AI deployments.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish an AI content policy that explains how AI-assisted or AI-generated content is labelled on the site.
-
consistent: Without a marking policy visible on the page, there is no evidence AI content marking is applied consistently.
Fix: Adopt a documented labelling convention (e.g., an 'AI-assisted' tag) and apply it uniformly across exhibitions, stories and collection entries.
-
oversight_exists: The page does not mention any human oversight arrangements for AI outputs.
Fix: Add a statement (e.g., within Policies and plans) confirming that AI outputs are subject to human oversight before publication.
-
review_process: No review or approval workflow for AI-generated material is described on the page.
Fix: Describe the editorial review and sign-off steps applied to AI-assisted content in a public-facing policy document.
-
accountability: No individual, role or team is identified as accountable for AI-generated content.
Fix: Name an accountable role (for example, an editorial lead or Head of Digital) responsible for AI-generated content and list them in the About or Policies section.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: The page is a cookie policy focused only on cookies and redirects users elsewhere for the full Privacy Policy, so it does not itself comprehensively cover what personal data is collected and why.
Fix: Include or inline the full Privacy Policy content (categories of personal data collected, purposes, legal bases, sharing) on this page rather than only linking to it.
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary; it only notes that strictly necessary cookies cannot be switched off.
Fix: Add an explicit statement of data minimisation, e.g., 'We only collect data that is necessary for the purposes described and nothing more.'
-
proportionate: There is no statement addressing proportionality of data collection relative to the service provided.
Fix: Include a sentence affirming that the data collected is proportionate to providing and improving the Wellcome Collection website services.
-
specific: While many entries are specific, some retention values are vague or inconsistent such as 'Persistant' for SessionID and a far-future date '2036-12-31T23:59:59Z', and broader personal data retention periods are not given.
Fix: Replace vague values like 'Persistant' with concrete durations and add specific retention periods for non-cookie personal data categories collected by the site.
-
partner_count_specific: The banner references 'third parties' generically without stating any specific numeric count of partners.
Fix: Add the exact number of third-party partners (e.g., 'shared with 12 partners') in the cookie banner or Manage cookies panel.
Provenance
Security
- security.txt not published.
Transparency
-
detail: The page mentions Wellcome as the parent foundation but provides no amounts, percentages, or categories of funding.
Fix: Add specifics such as annual funding amount from Wellcome, percentage breakdowns, or categories (e.g., grants, endowments, earned income) to the About page or link to a financial report.
-
complete: The disclosure only references Wellcome and does not address other potential funding streams such as donations, retail/café revenue, or partnerships.
Fix: Expand the disclosure to enumerate all major funding streams (parent foundation, commercial income, donations, grants, partnerships) or link to an annual report detailing them.
-
governance_exists: The page describes the museum's mission and offerings but does not describe its governance or editorial structure beyond noting it is part of Wellcome, a charitable foundation.
Fix: Add a dedicated section or link to a page outlining the governance structure (e.g., board of trustees, editorial oversight, decision-making bodies) on the About us page.
-
roles_clear: No key roles or responsibilities (such as leadership, trustees, or editorial staff) are identified on the page.
Fix: List or link to a page identifying key roles such as the director, trustees, and editorial leadership along with their responsibilities.
-
algorithm_explained: The About page does not mention any algorithms or explain their purpose on the site.
Fix: Add a section or link describing any algorithms used (e.g., for search, recommendations, or collections) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include clear information about how algorithmic outputs influence what users see and any consequences for them.
-
annual_statement: The page links to a privacy notice and cookie policy but provides no evidence of regular or annual review of data practices.
Fix: Publish a statement indicating that privacy and data practices are reviewed on a defined periodic (e.g., annual) basis, with the last review date shown.
-
dated: The page references a privacy notice and cookie policy but shows no dates or version numbers for data practices statements.
Fix: Add a 'last updated' date or version number to the privacy notice and cookie policy and surface it where these are referenced.
Level 3 — Advanced
Accessibility
-
statement_exists: The page only offers a generic 'Accessibility' link and lists building features like step-free access and hearing loops, but no dedicated accessibility statement is present on this page.
Fix: Publish a dedicated accessibility statement covering both the website and physical venue, and link to it prominently from the About us page.
-
known_issues: There is no acknowledgement of any known accessibility issues or limitations anywhere in the visible content.
Fix: Include a section in the accessibility statement that lists known accessibility barriers and any content that is not yet fully accessible.
-
remediation_timeline: The page provides no timeline or commitment for fixing accessibility issues.
Fix: State target dates or an ongoing commitment for remediating identified accessibility issues within the accessibility statement.
-
feedback_channel: While general contact details (info@wellcomecollection.org, phone) are listed, there is no accessibility-specific feedback mechanism with a stated response commitment.
Fix: Add a dedicated accessibility feedback channel and specify how quickly users can expect a response to accessibility reports.
Accountability
-
policy_exists: The About page mentions 'Policies and plans' generically but does not publish or link to a specific moderation policy.
Fix: Publish a dedicated moderation policy page and link to it from the About and community/engagement sections.
-
criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on this page.
Fix: Add explicit moderation criteria describing prohibited content and acceptable behavior standards.
-
enforcement: The page does not describe any enforcement process, appeals route, or who enforces moderation decisions.
Fix: Document the enforcement workflow, including reporting mechanisms, responsible team, and appeal procedures.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page references general policies and plans but shows no published incident response plan or security incident policy.
Fix: Publish a dedicated incident response plan or policy and link to it from the 'Policies and plans' section.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify the public and affected users of significant incidents within your incident response documentation.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident) in your incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published on the About page.
Fix: Publish the specific criteria (inputs, rules, data sources) used by any algorithms on a dedicated transparency page.
-
weighting: The page does not explain the weighting or priority of any decision criteria.
Fix: Document how criteria are weighted or prioritised within any algorithmic processes used by the site.
-
auditable: There is insufficient technical or procedural detail provided for external audit or review.
Fix: Provide audit-ready documentation such as model cards, data provenance and review processes accessible to external reviewers.
-
open_source: The About page contains no link to source code repositories, though a 'Developers' link exists in the footer which may lead elsewhere.
Fix: Add a direct link from the About page to any public source code repositories (e.g., GitHub) associated with Wellcome Collection's digital platforms.
-
tech_docs: No technical documentation is linked from the About page content itself, only a generic 'Developers' footer link without context.
Fix: Include a clearly labelled link to technical/API documentation from the About page to help developers and researchers find it.
Responsibility to the Future
-
disclosure_exists: The About page describes the museum, library, and Wellcome charitable foundation but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About or Policies and plans section.
-
specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
Fix: Include concrete environmental metrics such as annual carbon emissions or energy consumption within a sustainability report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the site's hosting provider and its green/carbon credentials, ideally noting use of renewable-powered or low-carbon hosting.
-
plan_exists: The About page describes the museum, its mission, and policies but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan (e.g., within the 'Policies and plans' section) describing what will happen to the collection and services if the organisation ceases operations.
-
data_and_content_fate: The page mentions a privacy notice and Creative Commons licensing but does not state what would happen to user data or published content if the organisation ceased to exist.
Fix: Add a statement addressing the long-term fate of user data and published content in the event of closure, including retention, deletion, or transfer arrangements.
-
custodians_or_mirrors: The page notes Wellcome Collection is part of the Wellcome charitable foundation but does not identify any custodians, mirrors, or archive partners to preserve content if it exits.
Fix: Name specific archive partners, custodians, or mirror arrangements (such as a national archive or library) that would preserve the collections and digital content.
-
policy_exists: The page references a 'Visitor care statement,' 'Policies and plans,' and a 'Modern slavery statement,' but none is identified as a published policy on worker wellbeing or working conditions for staff.
Fix: Publish and link to a dedicated worker wellbeing or working conditions policy from the About us or Policies and plans section.
-
specific_commitments: The page contains no specific commitments on pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits to the worker wellbeing policy.
-
accountability: The page names a media office and general contacts but does not identify any accountability or oversight function for worker conditions.
Fix: Name a responsible person, team, or governance body (e.g., HR or a board committee) accountable for overseeing worker conditions.