SlideShare a Scribd company logo
Tracking Protection
    Working Group
    Aleecia M. McDonald

    3 May, 2012
                          1

Friday, May 4, 12
Introduction of the W3C

    ✤    World Wide Web Consortium
         creates international standards
         for the Internet

    ✤    Sir Tim Berners-Lee

          ✤     Created the World Wide Web,
                1989

          ✤     Created the W3C, 1994

    ✤    Successful track record with standards for HTML, XML, CSS, etc.

    ✤    Hundreds of billions of dollars of commerce runs on W3C standards   2

Friday, May 4, 12
Introduction of co-chairs

    ✤    Aleecia M. McDonald                   ✤   Matthias Schunter

          ✤     Half-time Mozilla Senior           ✤   IBM Research in Switzerland
                Privacy Researcher
                                                   ✤   Focus on cloud computing,
          ✤     Half-time Stanford                     security, and privacy
                Resident Fellow
                                                   ✤   P3P standards experience
          ✤     Prior: PhD privacy; software
                start ups



                                                                                   3

Friday, May 4, 12
Approach for Do Not Track

    ✤    User agent expresses a preference not to be tracked


                                                         HTTP header of
                                                            DNT:1



    ✤    Shipping today; standards work answers “what does tracking mean?”

    ✤    Websites / applications choose to honor DNT, confirm with response

    ✤    Adoption is entirely voluntary; W3C cannot compel members to act
                                                                             4

Friday, May 4, 12
Diverse TPWG Membership

    ✤    70+ group participants, plus observers

    ✤    Browser companies: Apple, Google, Opera, Microsoft, Mozilla

    ✤    Wide membership range including Alcatel-Lucent; Adobe; AdTruth;
         Article 29 Working Party; AT&T; CDD; CDT; Chapell & Associates;
         Deutsche Telekom; EFF; ESOMAR; Facebook; IAB Europe; Nielsen;
         Nokia; Online Publishers Association; TRUSTe; Yahoo!; The Walt
         Disney Company




                                                                           5

Friday, May 4, 12
Writing Standards Documents

    1. Definitions & Compliance                     2. Tracking Preference Expression

          ✤     Chair: Aleecia M. McDonald           ✤   Chair: Matthias Schunter (IBM)
                (Mozilla)
                                                     ✤   Editors: Roy Fielding (Adobe),
          ✤     Editors: Justin Brookman & Erica         David Singer (Apple)
                Newland (CDT); Sean Harvey &
                Heather West (Google)              3. Tracking Selection Lists

                                                     ✤   Chair: Matthias Schunter

                                                     ✤   Editors: Karl Dubost (Opera);
                                                         Andy Zeigler (Microsoft)

                                                                                          6

Friday, May 4, 12
Three Types of Parties

    1. First party                                2. Service provider

          ✤     Not directly liable for others’     ✤   Agents of first parties,
                actions                                 contractual relationship

          ✤     Very few restrictions               ✤   Cannot share data across
                                                        multiple first parties or use
          ✤     Cannot share data with                  for their own purposes
                others, or else must act as a
                third party                         ✤   Debating exceptions

          ✤     Can be multiple 1st; depends      3. Third parties with strong
                upon meaningful interaction          restrictions, plus exceptions
                                                                                       7

Friday, May 4, 12
Uniform Signals, Different Results

                    Eleven Point One



                    Onze Comma Un



                        Punt Elf



                    Elf Komma Eins

                                       8

Friday, May 4, 12
Tri-part DNT Signal

    ✤    Three options
           DNT: 1 - enable DNT, user saying “do not track me”
           DNT: 0 - do not enable DNT
           Nothing - users have not made a selection

    ✤    US, Nothing:                     ✤   EU, Nothing:

          ✤     Users did not choose to       ✤   Users did not consent to
                enable DNT                        tracking

          ✤     Similar to DNT: 0             ✤   Similar to DNT: 1


                                                                             9

Friday, May 4, 12
Site-specific Exemptions

    ✤    Many countries can have a            ✤   Some countries may not allow a
         global DNT: 1 value                      global DNT: 1

          ✤     Companies want to ask to          ✤   Consent may be site-by-site
                track anyway

    ✤    Use same technical mechanism in both cases

    ✤    Exception specific to advertiser on that particular first party, not
         global for the advertiser across the whole Internet and/or

    ✤    Exception global for a specific third party, Internet wide

                                                                                    10

Friday, May 4, 12
Current Big Unresolved Issues

    1. Edges of a party                   2. Permitted uses for third parties,
                                             perhaps with retention limits,
          ✤     User expectations and        e.g.
                branding
                                            ✤   Frequency capping
          ✤     “Discoverable” based on
                corporate ownership         ✤   Billing and financial logging

                                            ✤   3rd party auditing

                                            ✤   Security and fraud
                                                prevention

                                                                               11

Friday, May 4, 12
Opportunities

    ✤    For feedback:                        ✤   For media:

          ✤     Speaking with WG on call          ✤   Internet week, May 17th

          ✤     Joining the WG                    ✤   Mozilla blog

          ✤     Community Group                   ✤   Jonathan’s list of DNT
                                                      implementations
          ✤     Individual comments on Last
                Call draft



                                                                                12

Friday, May 4, 12
Interested in Learning Thoughts...

    ✤    Response mechanism                 ✤   Hard to get user consent
                                                when brand unknown
          ✤     HTTP header
                                        ✤   Does 3rd party acting as 3rd
          ✤     Well-known URL              party help?

    ✤    How do you propagate opt-out       ✤   Auditing, billing
         status now?
                                            ✤   Silo data
    ✤    Consent for specific sites
                                        ✤   Biggest technical challenge to
          ✤     EU consent issues           implement?

                                                                             13

Friday, May 4, 12
Tracking Protection
    Working Group
    Aleecia M. McDonald

    3 February, 2012
                          14

Friday, May 4, 12
Photo credits

    ✤    Tim: http://i.telegraph.co.uk/multimedia/archive/00682/
         bernerslee-404_682192c.jpg

    ✤    Elephant: http://www.flickr.com/photos/paperpariah/2446224424/
         sizes/o/in/photostream/

          ✤     Adam Foster | Codefor

          ✤     “! danger elephants at Knowsley Safari Park?”

    ✤    Cash register: http://www.flickr.com/photos/teflon/4995681266/

          ✤     Martin Deutsch
                                                                        15

Friday, May 4, 12

More Related Content

PPT
L'arjau ous tortuga platja
PDF
Khush.docx
PPTX
Gr 4 promotion of self help groups under the shg(1)
PDF
Online Privacy
PDF
Designing Tag Navigation
PDF
Business considerations for privacy and open data: how not to get caught out
PDF
Designing Tag Navigation
PPTX
IEEE Standards Impact in IoT and 5G, Day 1, Session 1 - Introduction & Overview
L'arjau ous tortuga platja
Khush.docx
Gr 4 promotion of self help groups under the shg(1)
Online Privacy
Designing Tag Navigation
Business considerations for privacy and open data: how not to get caught out
Designing Tag Navigation
IEEE Standards Impact in IoT and 5G, Day 1, Session 1 - Introduction & Overview

Similar to W3C DNT Presentation for AdMonsters (20)

PPTX
Tech For Good Meetup 10.11.14 The Good Data
PPTX
Privacy and social media for Australian governments
PDF
Data Privacy: A runbook for engineers 1st Edition Nishant Bhajaria
PDF
GDPR within Google Tag Manager - Measurecamp 2018
ODP
Grant 2011.0918
PPTX
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
PDF
Web analytics: Practical steps to GDPR compliance
PPTX
5 tactics for practical privacy protection
PDF
Online Focus Groups Privacy and Security Considerations
KEY
Trendstechnology
PPTX
Online privacy & security
PDF
Service goes accessible_2013_sh
PDF
Free your metadata
PDF
Cip Multichannel Retail Webcast 091112 (2)
PPTX
International Cooperative: APT Hunting
PDF
Online Collaboration — Delivering Benefits for Organisations and Participants
PDF
Letter to Google CEO Larry Page from privacy advocates
PPTX
Online Privacy & Computer Security Basics (September 2017)
PPTX
ISYS 363 Group Task 1
Tech For Good Meetup 10.11.14 The Good Data
Privacy and social media for Australian governments
Data Privacy: A runbook for engineers 1st Edition Nishant Bhajaria
GDPR within Google Tag Manager - Measurecamp 2018
Grant 2011.0918
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
Web analytics: Practical steps to GDPR compliance
5 tactics for practical privacy protection
Online Focus Groups Privacy and Security Considerations
Trendstechnology
Online privacy & security
Service goes accessible_2013_sh
Free your metadata
Cip Multichannel Retail Webcast 091112 (2)
International Cooperative: APT Hunting
Online Collaboration — Delivering Benefits for Organisations and Participants
Letter to Google CEO Larry Page from privacy advocates
Online Privacy & Computer Security Basics (September 2017)
ISYS 363 Group Task 1
Ad

Recently uploaded (20)

PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Encapsulation theory and applications.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Cloud computing and distributed systems.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Spectroscopy.pptx food analysis technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
A Presentation on Artificial Intelligence
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
Dropbox Q2 2025 Financial Results & Investor Presentation
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Unlocking AI with Model Context Protocol (MCP)
A comparative analysis of optical character recognition models for extracting...
Empathic Computing: Creating Shared Understanding
Encapsulation theory and applications.pdf
Chapter 3 Spatial Domain Image Processing.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
20250228 LYD VKU AI Blended-Learning.pptx
Cloud computing and distributed systems.
Mobile App Security Testing_ A Comprehensive Guide.pdf
Spectroscopy.pptx food analysis technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
MIND Revenue Release Quarter 2 2025 Press Release
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Machine learning based COVID-19 study performance prediction
Advanced methodologies resolving dimensionality complications for autism neur...
Ad

W3C DNT Presentation for AdMonsters

  • 1. Tracking Protection Working Group Aleecia M. McDonald 3 May, 2012 1 Friday, May 4, 12
  • 2. Introduction of the W3C ✤ World Wide Web Consortium creates international standards for the Internet ✤ Sir Tim Berners-Lee ✤ Created the World Wide Web, 1989 ✤ Created the W3C, 1994 ✤ Successful track record with standards for HTML, XML, CSS, etc. ✤ Hundreds of billions of dollars of commerce runs on W3C standards 2 Friday, May 4, 12
  • 3. Introduction of co-chairs ✤ Aleecia M. McDonald ✤ Matthias Schunter ✤ Half-time Mozilla Senior ✤ IBM Research in Switzerland Privacy Researcher ✤ Focus on cloud computing, ✤ Half-time Stanford security, and privacy Resident Fellow ✤ P3P standards experience ✤ Prior: PhD privacy; software start ups 3 Friday, May 4, 12
  • 4. Approach for Do Not Track ✤ User agent expresses a preference not to be tracked HTTP header of DNT:1 ✤ Shipping today; standards work answers “what does tracking mean?” ✤ Websites / applications choose to honor DNT, confirm with response ✤ Adoption is entirely voluntary; W3C cannot compel members to act 4 Friday, May 4, 12
  • 5. Diverse TPWG Membership ✤ 70+ group participants, plus observers ✤ Browser companies: Apple, Google, Opera, Microsoft, Mozilla ✤ Wide membership range including Alcatel-Lucent; Adobe; AdTruth; Article 29 Working Party; AT&T; CDD; CDT; Chapell & Associates; Deutsche Telekom; EFF; ESOMAR; Facebook; IAB Europe; Nielsen; Nokia; Online Publishers Association; TRUSTe; Yahoo!; The Walt Disney Company 5 Friday, May 4, 12
  • 6. Writing Standards Documents 1. Definitions & Compliance 2. Tracking Preference Expression ✤ Chair: Aleecia M. McDonald ✤ Chair: Matthias Schunter (IBM) (Mozilla) ✤ Editors: Roy Fielding (Adobe), ✤ Editors: Justin Brookman & Erica David Singer (Apple) Newland (CDT); Sean Harvey & Heather West (Google) 3. Tracking Selection Lists ✤ Chair: Matthias Schunter ✤ Editors: Karl Dubost (Opera); Andy Zeigler (Microsoft) 6 Friday, May 4, 12
  • 7. Three Types of Parties 1. First party 2. Service provider ✤ Not directly liable for others’ ✤ Agents of first parties, actions contractual relationship ✤ Very few restrictions ✤ Cannot share data across multiple first parties or use ✤ Cannot share data with for their own purposes others, or else must act as a third party ✤ Debating exceptions ✤ Can be multiple 1st; depends 3. Third parties with strong upon meaningful interaction restrictions, plus exceptions 7 Friday, May 4, 12
  • 8. Uniform Signals, Different Results Eleven Point One Onze Comma Un Punt Elf Elf Komma Eins 8 Friday, May 4, 12
  • 9. Tri-part DNT Signal ✤ Three options DNT: 1 - enable DNT, user saying “do not track me” DNT: 0 - do not enable DNT Nothing - users have not made a selection ✤ US, Nothing: ✤ EU, Nothing: ✤ Users did not choose to ✤ Users did not consent to enable DNT tracking ✤ Similar to DNT: 0 ✤ Similar to DNT: 1 9 Friday, May 4, 12
  • 10. Site-specific Exemptions ✤ Many countries can have a ✤ Some countries may not allow a global DNT: 1 value global DNT: 1 ✤ Companies want to ask to ✤ Consent may be site-by-site track anyway ✤ Use same technical mechanism in both cases ✤ Exception specific to advertiser on that particular first party, not global for the advertiser across the whole Internet and/or ✤ Exception global for a specific third party, Internet wide 10 Friday, May 4, 12
  • 11. Current Big Unresolved Issues 1. Edges of a party 2. Permitted uses for third parties, perhaps with retention limits, ✤ User expectations and e.g. branding ✤ Frequency capping ✤ “Discoverable” based on corporate ownership ✤ Billing and financial logging ✤ 3rd party auditing ✤ Security and fraud prevention 11 Friday, May 4, 12
  • 12. Opportunities ✤ For feedback: ✤ For media: ✤ Speaking with WG on call ✤ Internet week, May 17th ✤ Joining the WG ✤ Mozilla blog ✤ Community Group ✤ Jonathan’s list of DNT implementations ✤ Individual comments on Last Call draft 12 Friday, May 4, 12
  • 13. Interested in Learning Thoughts... ✤ Response mechanism ✤ Hard to get user consent when brand unknown ✤ HTTP header ✤ Does 3rd party acting as 3rd ✤ Well-known URL party help? ✤ How do you propagate opt-out ✤ Auditing, billing status now? ✤ Silo data ✤ Consent for specific sites ✤ Biggest technical challenge to ✤ EU consent issues implement? 13 Friday, May 4, 12
  • 14. Tracking Protection Working Group Aleecia M. McDonald 3 February, 2012 14 Friday, May 4, 12
  • 15. Photo credits ✤ Tim: http://i.telegraph.co.uk/multimedia/archive/00682/ bernerslee-404_682192c.jpg ✤ Elephant: http://www.flickr.com/photos/paperpariah/2446224424/ sizes/o/in/photostream/ ✤ Adam Foster | Codefor ✤ “! danger elephants at Knowsley Safari Park?” ✤ Cash register: http://www.flickr.com/photos/teflon/4995681266/ ✤ Martin Deutsch 15 Friday, May 4, 12