News

Microsoft Proposes Tiered Privacy in Online Advertising

By Grant Gross and Nancy Gohring, IDG News Service (Washington Bureau)

April 14, 2008

Microsoft has proposed a tiered approach to protecting the privacy of people targeted by online advertising, saying advertisers should get permission before using sensitive, personally identifiable information to deliver ads.

Microsoft filed comments on Friday in response to the U.S. Federal Trade Commission's request for comments on its proposed privacy principles that would be self-administered by the online advertising industry. Microsoft's proposal operates under the idea that the greater the risk to privacy, the greater the protection data should receive, Microsoft officials said.

Microsoft agrees with the FTC's decision to focus on an industry self-regulatory approach, but the company has also called for Congress to pass comprehensive consumer privacy legislation, noted Frank Torres, Microsoft's director of consumer affairs.

"We're supporting what the FTC is proposing, but we also believe that privacy is important for consumers," Torres said. "We're not opposed to going even further" than the FTC self-regulatory proposal.

Microsoft's proposals would give consumers control over how their personal data is used, Torres said. "When it comes to online advertising, consumers should be in the driver's seat," he said.

Among the Microsoft proposals:

-- Companies that keep records of page views or collect other information about consumers for the purpose of delivering ads should post a privacy policy on the home page, implement reasonable security procedures, and retain data only as long as necessary to fulfill a legitimate business need.

-- Companies that deliver ads or services to unrelated third-party sites should ensure that consumers receive notice of the privacy practices of those sites.

-- Companies that develop profiles of consumer activity to deliver advertising across unrelated third-party sites should also offer consumers a choice about the use of that information.

-- Third parties should be required to obtain consent from consumers before using sensitive, personally identifiable information, such as health conditions, sexual behavior or religious belief, for behavioral advertising.

Several other companies and groups, including Google, the American Advertising Federation and the Consumer Federation of America, have filed comments on the FTC's proposed rules. Google's filing last week appears to look for a narrower scope to regulations, although it said it has in the past called for a federal privacy law that would penalize offenders. Google suggests that the agency narrow its definition of behavioral advertising and distinguish between personally identifiable information and information that's not personally identifying.

The Consumer Federation of America's filing on Thursday called for stronger rules than the set of self-regulatory principles proposed by the FTC.

"Simply put, there is a fundamental mismatch between the technologies of tracking and targeting and consumers' ability to exercise informed judgment and control over their personal data," the consumer group said in its filing. "It is clear that after seven years of industry self regulation, neither the voluntary organizations nor the individual companies' approaches to privacy protection are working. Only if consumers are strongly interested, extremely literate, well-informed and highly skilled can they negotiate the opaque, inconsistent morass of opt-out procedures."

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Maximizing Site Visitor Trust Using Extended Validation SSL

VeriSignNow with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in the free VeriSign white paper.

» Read the Paper

Featured Sponsors
Sponsored Links

When Customer Relationship is Everything, Businesses Bank on SSL Solutions

Maximizing Site Visitor Trust Using Extended Validation SSL

Understanding Data Location is Imperative for Data Loss Prevention

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Efficient - Flexible - Compliant

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Managing SSL Security in Multi-Server Environments

Solving Online Credit Fraud Using Device Reputation

Secure your virtual and physical environments with the same software

Manage your IT more effectively

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Get in Compliance With Government Data Regulations

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

CA's IT Security centralizes your identity management to turn security into a proactive, business-building tool

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

Simplify your data center with Juniper Networks. View the webcast

The Case for Business Software Assurance ~ Securing Your Applications

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Taking the Botnet Threat Seriously

Any company can promise identity protection. Only Debix can prove it

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

5 Steps to Secure Outsourced Application Development