FTC calls for 'do not track' browser button

By Bill Brenner, CSO |  Security, do not track, FTC Add a new comment

The Federal Trade Commission (FTC) wants browsers to have a setting that lets you decide if data on your Web surfing activities can be collected. Think of it as an online version of the "Do Not Call" registry.

It's just one of the suggestions in a recently-released preliminary staff report calling for a framework to balance the privacy interests of consumers. The report dismisses industry efforts to address privacy through self-regulation as too slow. "Up to now," the report says, self regulation has "failed to provide adequate and meaningful protection."

The report is the FTC's way of getting its 2 cents to policymakers, including Congress, as they develop potential laws governing privacy.

MORE ABOUT PRIVACY

"Technological and business ingenuity have spawned a whole new online culture and vocabulary e-mail, IMs, apps and blogs -- that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that's what most Americans want as well," says FTC Chairman Jon Leibowitz.

He added that the FTC will take action against companies that violate consumers' privacy -- especially when children and teens are involved.

The report calls on companies to adopt a "privacy-by-design" mentality where protections are built into their everyday business procedures. "Such protections include reasonable security for consumer data, limited collection and retention of such data, and reasonable procedures to promote data accuracy," the report said, adding, "Companies also should implement and enforce procedurally sound privacy practices throughout their organizations, including assigning personnel to oversee privacy issues, training employees, and conducting privacy reviews for new products and services."

Consumer choice is a major theme throughout the report. Consumers should be able to determine who can collect their data, what kind of data can be collected and where it can be used. The "do not track" setting is the best example of how to do that, the report adds.

The reaction among legal and privacy experts is positive so far.

"The current cookie based opt-out system is ineffective in managing consumer choices. Rightly, the commission calls for a better system for users to be able to control online data collection," Jules Polonetsky and Christopher Wolf of the Future of Privacy Forum said in a joint statement. "The Commission was widely expected to call for legislation of a do-not-track mechanism, but wisely left the door open to either legislative or self regulatory solutions."

Read more about data privacy in CSOonline's Data Privacy section.


Originally published on CSO |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question