Future of Privacy Forum Letter to the White Office of Science and Technology Policy

Future of Privacy Forum Letter to the White Office of Science and Technology Policy

 

 

 

 

Following is the test of the letter we sent to the White House in response to the call for feedback on the President’s memo on Openness and Transparency

April 3, 2009

Dear Ms. Noveck:

The Future of Privacy Forum is providing the below suggestions to offer a roadmap for enabling use of analysis, site optimization and tracking technologies by government agencies.  Personalizing site content for users, enabling log term shopping carts and improving site usage are key to providing the public the best possible web experience and these functions are reliant on cookies and other technologies currently limited by various approval requirements.  As a result, agencies may end up either forgoing the use, or they seek approval but may not seek to establish additional necessary controls to ensure these technologies are used in the most privacy friendly manner.

We provide below practical guidelines that could enable the use of cookies to better serve the public as desired by many government web managers.  Some of these concepts are already in place at some of the most progressive private sector companies, and government leadership in this area would spur wider adoption of these practices that both optimize the user experience and ensure privacy and transparency in data use.

We propose that the current restrictions on cookies and similar technologies be abolished.  In their place should be requirements that establish leading practices for such technology practices.


Ensuring that Interactive Tools used by Government Provide Users with Enhanced Transparency and Controls for Data Collection and Retention


Analytics, Research or Others Using Cookies, Tracking Pixels or Other Tools


1. Delete log-files after a defined period of time.

a. Data retention periods for “non-personal” log-files vary widely across vendors, are not publicly disclosed and are rarely committed to contractually.

2. Cookies should have limited expiration periods and should not be used to store information unprotected.

3. IP addresses logged by vendors should be obscured or deleted as soon as possible.

a. Some vendors can use and then immediately scramble IP addresses as they log them.

4. The use of the tools and user options should be transparent and prominently explained.

5. Consider implications of use of “first party” White House domain for analytics, rather than “third party” domain, to avoid potential for unwanted correlation.

6. Contractual representations barring use of data for purposes other than services contracted, other than aggregate reporting.

We will be pleased to provide further detail about the above upon request.

Sincerely

Jules Polonetsky

Future Of Privacy Forum

www.futureofprivacy.org

Leave a Reply


Privacy Calendar

Jan
26
Mon
8:30 am Privacy as a Profit Center: Leve... @ Old Slip by Convene
Privacy as a Profit Center: Leve... @ Old Slip by Convene
Jan 26 @ 8:30 am – Jan 27 @ 4:15 pm
Learn how those on the leading edge of privacy governance and digital innovation from companies including Cigna, Cisco Systems, eBay Inc. Public Policy Lab, FocusMotion,Ghostery, Goodyear Tire & Rubber Company, Google, HP Enterprise Security Products, JPMorgan[...]
Jan
28
Wed
all-day Data Privacy Day
Data Privacy Day
Jan 28 – Jan 29 all-day
“Data Privacy Day began in the United States and Canada in January 2008, as an extension of the Data Protection Day celebration in Europe. The Day commemorates the 1981 signing of Convention 108, the first[...]
Mar
4
Wed
all-day Global Privacy Summit 2015
Global Privacy Summit 2015
Mar 4 – Mar 6 all-day
For more information, click here.
Mar
10
Tue
6:00 pm CDT Annual Dinner “TechProm” 2015
CDT Annual Dinner “TechProm” 2015
Mar 10 @ 6:00 pm – 9:00 pm
Featuring the most influential minds of the tech policy world, CDT’s annual dinner, TechProm, highlights the issues your organization will be facing in the future and provides the networking opportunities that can help you tackle[...]
Mar
13
Fri
all-day BCLT Privacy Law Forum
BCLT Privacy Law Forum
Mar 13 all-day
This program will feature leading academics and practitioners discussing the latest developments in privacy law. UC Berkeley Law faculty and conference panelists will discuss cutting-edge scholarship and explore ‘real world’ privacy law problems. Click here[...]
May
27
Wed
all-day PL&B’s Asia-Pacific Roundtable (...
PL&B’s Asia-Pacific Roundtable (...
May 27 all-day
PROFESSOR GRAHAM GREENLEAF, Asia-Pacific Editor, Privacy Laws & Business International Report, will lead a roundtable on the countries of most interest to business in the Asia-Pacific region. Click here for more information.
Jul
6
Mon
all-day PL&B’s 28th Annual International...
PL&B’s 28th Annual International...
Jul 6 – Jul 8 all-day
The Privacy Laws & Business 27th Annual International Conference featured more than 40 speakers and chairs from many countries over 3 intensive days. At the world’s longest running independent international privacy event participants gained professionally by[...]

View Calendar