home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security
W O R K S H O P  
P3P's Privacy Promises

  July 23, 2001
  By Sean Doherty


Have you ever taken the time to read a Web site's privacy policies? Wouldn't it be more efficient if the policies could be matched to your preferences automatically?



The World Wide Web Consortium (W3C) is developing a standard, Platform for Privacy Preferences Project (P3P), that will let Web sites communicate their privacy practices to end users (see www.w3.org/TR/P3P). UAs (user agents) built into browsers and other Internet applications will be able to read this format automatically. If a site's privacy practices are not in agreement with individual, user-set preferences, the discrepancies will be displayed. P3P's goal is to build trust between users and Web site operators without requiring users to read and interpret the site's privacy policies. However, it holds no guarantees that sites adhere to the policies (see "Monitoring and Privacy: Is Your Head Still in the Sand?").



P3P does not have the force of law, but it does complement legislative efforts to protect privacy. It also does not secure personal data in transit or storage, and leaves data-transfer mechanisms for future revisions (for a critical take on P3P, see www.epic.org/reports/prettypoorprivacy.html).

Despite these limitations, many organizations -- including Akamai Technologies, America Online, AT&T, Hewlett-Packard, IBM, IDcide, Microsoft, Netscape and Truste -- see P3P as a step toward protecting privacy on the Internet (see www.w3.org/P3P/implementations).

The P3P Promise

P3P comprises a standardized set of questions for privacy policies that, when answered, give a user a clear view of how a site collects and uses personal information without that user's reading a detailed policy. P3P provides a way for sites to encode data-collection and data-use practices in a machine-readable XML (Extensible Markup Language) format, known as a P3P policy. P3P policies can be retrieved and interpreted automatically by UAs incorporated into browsers.



Sample Human-Readable Privacy Policy

Click here to enlarge

The P3P specification transforms human-readable privacy policies into machine-readable policies using XML. A P3P policy identifies an entity responsible for the privacy policy, details the types of data collected by the entity and explains how the data is used. It also identifies data recipients and makes other disclosures pertinent to privacy, such as a dispute-resolution process and the location of the site's human-readable privacy policy. P3P policies are affirmative, stating what they do, not what they don't do.

UAs that parse P3P policies can be built into browsers, browser plug-ins or proxy servers. They also can be implemented as Java applets or JavaScript and included with electronic wallets or other data-management tools. UAs fetch (get) a P3P policy and compare it with preferences configured by the user; preferences are expressed in APPEL, a P3P Preferences Exchange Language (see www.w3.org/TR/P3P-preferences).



Sample Machine-Readable Privacy Policy

Click here to enlarge

If the policy is consistent with the user's preference and the proposed transfer complies with the stated policy, the UA authorizes the transfer of data. Otherwise, the user is informed of the discrepancy and given the option of releasing the data. UAs can play sounds, display symbols and even generate dialog boxes to inform users that a privacy policy is consistent or inconsistent with set preferences.

Let's say, for example, I'm using a P3P-enabled browser and surf to a site called syr-real-world.com to subscribe to a newsletter about Network Computing's labs. Our fictitious site has placed a link to a P3P policy

<link rel="p3pv1"href="http://www.syr-realworld.com/P3P/privacy.xml">

in the source code of each page and collects information by reading cookies and access logs. My browser fetches the P3P policy, parses it and compares the policy with my preconfigured preferences. If my preferences find cookies and data gathered from access logs acceptable, the page displays normally. If not, a pop-up box warns me that the site is not in agreement with my privacy preferences.




   Page: 1 | 2 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service