nationwide.co.uk
UK compliance audit.
How the score was calculated
- Starting score
- 100
- 1 critical finding
- −25
- 1 medium finding
- −5
- Final score
- 70
AI Analysis
The Nationwide.co.uk website has partially met UK GDPR and PECR compliance standards, scoring 70/100 with 25 passed checks and 2 failed checks. Key issues include a non-compliant cookie banner that fails to disclose third-party data sharing and the consequences of declining non-essential cookies, as well as vague descriptions of user benefits from accepting certain types of cookies. Seven checks were not applicable due to specific conditions not being met.
Fix these first
1 priority- 01CRITICALcheck_cookies_after_reject
Found 1 non-essential cookie(s): [FPID] (after clicking: <button#onetrust-reject-all-handler.ot-button-order-1> text='Allow essential cookies only')
Report Details
- Playbook
- UK Cookie Compliance
- Domain
- nationwide.co.uk
- Started At
- 2 Jan 2026, 12:54
- Duration
- 3m 4s
- Total Checks
- 37
- Report ID
- zWSioPaielcY
Check Results
Data Capture
3 checks All passedcapture_html_initial
INFOCaptured HTML (451824 bytes) from https://www.nationwide.co.uk/
Captured HTML:
View rendered (opens in new tab)screenshot_initial
INFOScreenshot saved: https://smesolutions.uk/artifacts/artifacts/3ab5cf22-7f2a-4bf5-92fd-958e31f221bc/screenshots/initial_state.png
Screenshot Evidence:

Pre-Consent Cookies
1 check All passedcheck_initial_cookies
CRITICALNo non-essential cookies found
Cookies (except strictly necessary) require user consent BEFORE being set
View guidance (opens in new tab)Cookie Consent Banner
6 checks All passedfind_banner
INFOFound consent banner via heuristic (height: 649px)
Clear and comprehensive information must be provided about cookie use
View guidance (opens in new tab)find_cookie_banner
INFOValue true == true: true
verify_banner_visible
INFOElement visibility is true as expected
screenshot_banner
INFOScreenshot saved: https://smesolutions.uk/artifacts/artifacts/3ab5cf22-7f2a-4bf5-92fd-958e31f221bc/screenshots/cookie_banner.png
Screenshot Evidence:

extract_banner_text
Extracted 83 words
check_banner_content
LOWValue 83 >= 10: true
Cookie notice must provide clear, comprehensive information about purposes
View guidance (opens in new tab)Cookie Controls
4 checks All passedfind_reject_button_semantic
INFOFound reject button: <button#onetrust-reject-all-handler.ot-button-order-1> text='Allow essential cookies only'
find_accept_button_semantic
INFOFound accept button: <button#onetrust-accept-btn-handler.ot-button-order-0> text='Allow all cookies' (confidence: 100%)
find_reject_button_any
CRITICALValue 1 == 1: true
find_accept_button_any
Value 1 == 1: true
Dark Pattern Detection
1 check All passedcompare_button_prominence
HIGHButtons have similar prominence
Reject option must have equal prominence to accept - asymmetric design is a deceptive pattern
View guidance (opens in new tab)AI Dark Pattern Analysis
2 checks All passedcheck_dark_patterns_vision
HIGHNo specific dark patterns identified in cookie banner
Visual deceptive patterns including color manipulation and hidden controls are prohibited
View guidance (opens in new tab)check_deceptive_buttons
HIGHButton labels are clear and not deceptive
Button labels must accurately reflect their function without ambiguity or deception
View guidance (opens in new tab)AI Content Analysis
3 checks1 failedcheck_banner_quality_llm
MEDIUM-5Banner content is not GDPR compliant
Banner Text Analyzed:
Cookie notices must provide clear, comprehensive information about purposes
View guidance (opens in new tab)check_language_consistency
LOWBanner language (en) matches page language
Information must be provided in a language users can understand
check_cookie_purposes
MEDIUMNo cookies available for purpose matching
All cookies used must be disclosed and explained in the notice
View guidance (opens in new tab)AI Accessibility Analysis
1 checkcheck_visual_accessibility
MEDIUM-3None found; the banner is visually accessible with good contrast ratios; clear button visibility; readable text size.
Cookie banners must be accessible to users with disabilities including visual impairments
View guidance (opens in new tab)Consent Verification
4 checks1 failedclick_reject_button
Clicked element <button#onetrust-reject-all-handler.ot-button-order-1> text='Allow essential cookies only'
wait_after_reject
Waited 2000ms
check_cookies_after_reject
CRITICAL-25Found 1 non-essential cookie(s): [FPID] (after clicking: <button#onetrust-reject-all-handler.ot-button-order-1> text='Allow essential cookies only')
Non-Essential Cookies:
": The cookie named FPID with a long expiration period is likely used to store user preferences or settings across sessions on the nationwide.co.uk domain, making it fall under the functional category."
When consent is withdrawn, cookies must be removed - continued tracking is unlawful
View guidance (opens in new tab)verify_banner_dismissed
LOWElement is no longer accessible (dismissed/removed from DOM)
Accessibility
1 check All passedwcag_aa_scan
HIGHNo accessibility violations found (WCAG AA)
UK websites must meet WCAG 2.1 Level AA standards; failure may constitute disability discrimination
View guidance (opens in new tab)Evidence Collection
2 checks All passedcapture_html_after_reject
INFOCaptured HTML (465916 bytes) from https://www.nationwide.co.uk/
Captured HTML:
View rendered (opens in new tab)capture_cookies_after_reject
INFOCaptured 10 cookies
Captured Cookies:
View full list (opens in new tab)Report Generation
2 checks All passedgenerate_summary
INFOAI summary generated successfully
generate_pdf
INFOPDF report generated: https://smesolutions.uk/artifacts/artifacts/3ab5cf22-7f2a-4bf5-92fd-958e31f221bc/report.pdf
Other Checks
1 check All passedscreenshot_after_reject
Screenshot saved: https://smesolutions.uk/artifacts/artifacts/3ab5cf22-7f2a-4bf5-92fd-958e31f221bc/screenshots/after_rejection.png
Screenshot Evidence:

Full Compliance Report
Loading PDF viewer...