Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

28
Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog: http://www.peterfleischer.blogspot.com/

Transcript of Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Page 1: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Online Privacy and Codes of ConductPeter FleischerGlobal Privacy Counsel my personal blog: http://www.peterfleischer.blogspot.com/

Page 2: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Topics

Search

Chrome

Maps

Social Networking

Health

Ads

The Cloud

Page 3: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

What do we collect in search?

• URL, including query

• IP address

• Time and date of search

• Operating system

• Browser type

• Cookie ID

Page 4: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Anonymizing server logs: 9 months for IP addresses/ 18 for cookies

Balancing various factors: privacy, security, and improving our services

• to improve our search

• to defend our systems/ fight fraud/protect users

How long do we retain search logs?

123.45.67.XX - 25/Mar/2003 10:15:32 - http://www.google.com/search?q=cars - Firefox 1.0.7; Windows NT 5.1 - XXXXXXXXXXXXXXXX

Page 5: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Web History // Putting users in control of their data

When a user signs up for Web History (to deliver personalized search results), they are given full control of the information they share with Google, including the ability to pause, remove, and bookmark items, and delete their account at any time.

Page 6: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Google Chrome

Locally stored history

Incognito mode

Google Suggest

Page 7: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Maps

Page 8: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Street ViewWhat should be private in a public space?

Page 9: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Simple Notification Tools

Page 10: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Google Earth

Page 11: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

11

Latitude: User-controlled location sharing

Page 12: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Using Google to Communicate, Show and Share

UsersUsers

Page 13: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Designing Privacy Controls In All Our Products

All Google products have sharing controls built in

Page 14: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Orkut: Detailed Privacy Controls

Page 15: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Google Health

At its foundation, Google Health is about putting people in control of their health information.

• Google Health puts users in complete control over who views their health information and who can add information to their profile.

• Google Health provide privacy protections equivalent to those required under HIPPA

Page 16: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Query-based Ad Selection – AdWords

Mutual Funds – ACME Corp Learn how mutual funds work andcompare different types of funds.www.acme.com/mutualfunds

Connect with consumers when they search

Mutual Funds – ACME Corp Learn how mutual funds work andcompare different types of funds.www.acme.com/mutualfunds

Page 17: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Advertising & the internet

17

Page 18: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

18

Third-Party Ad Serving in a nutshell

User

1. Get: www.cnn.com

ISP

Cookie:doubleclick.comUID=619

PartnerAd

2. Send: HTML page

4. Send ad for UID=619

3. Get: doubleclick.com/ad

Cookiedoubleclick.comUID=619

Page 19: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

19

NAI Code of Conduct

19

In addition to requiring notice

to consumers about the use

of 3rd party cookies, the

NAI mandates that member

advertising networks provide

an "opt-out“ mechanism for

the targeted ad programs

they provide. The NAI opt-out

tool is a simple Web-based

utility that allows you

to opt out of receiving

targeted ads from

member ad networks.

Page 20: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

UK IAB Code of Conduct

• UK Industry Self-Regulatory Code for Interest based advertising, ensuring choice and transparency.

• Google one of the founding signatories other firms include Yahoo, AOL, MSFT

• Consumer portal: www.youronlinechoices.com (screenshots below)

• Code welcomed by the UK Data Protection Authority and the communications regulator OfCom.

• Model for pan-European code under discussion within IAB-Europe.

Consumer top-tipsConsumer FAQsConsumer portal landing page

Page 21: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Transparency & Notice

Feedback – Ads by GoogleFeedback – Ads by Googlewww.PBS.org/FRONTLINEwww.PBS.org/FRONTLINE

Page 22: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Transparency & Notice – landing page for in ad notice

Link to Ads Preference Manager

Page 23: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Meaningful Choice

PERSISTENT OPT-OUT

Page 24: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Adding interests – consumer empowerment & engagement

Page 25: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Beyond notice: Google Privacy Channel

Page 26: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Updating privacy laws

1980OECD onPrivacy

1995EU PrivacyDirective

2004APEC PrivacyFramework

1993First Web Browser

2008

countries withprivacy laws

countries withno privacy laws

Page 27: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

The Cloud

Page 28: Online Privacy and Codes of Conduct Peter Fleischer Global Privacy Counsel my personal blog:

Thank youDiscussion?