Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Email Security and Privacy: NY Hospital Retention Ruling Points Out Importance of Policies and Awareness | Main | FTC Now Requires Organizations to Have an Identity Theft Prevention Program »

Will A "Do Not Track" List Materialize?

Today it was widely reported that several privacy groups were banding together to demand the creation of a "Do Not Track" list, similar to the FTC's "Do Not Call" list.

The groups include the Consumer Federation of America, the World Privacy Forum, the Center for Democracy and Technology, Consumer Action, the Electronic Frontier Foundation, Privacy Activism, Public Information Research, Privacy Journal, and Privacy Rights Clearinghouse.


Here's an interesting factoid from the article:

"Online ad revenue is forecast to more than double to $44 billion in 2011 from $17 billion in 2006, according to eMarketer.com."

This privacy coalition wants consumers notified when their web surfing is tracked, and they want the privacy policies more prominent and written in a way that is easier to understand than most privacy policies are now written.

The spirit and intent of this idea is certainly noble and good. Technologically, without knowing more details, it should be very easy and do-able for organizations to implement.

I don't like having so much information collected while I'm online, and most people I know don't like it either.

If there can be an implementable way to create such a "Do not Track" list and actually enforce it, that would be great! The spammers and other shady tracking entities would not observe such a list, though, so hopefully some baseline numbers can be created prior to the implementation to compare with the after implementation numbers to determine how effective such a law is in practice. Because of the very wide range of technologies involved it will be a much more complex task to implement such a centralized list compared to the "Do Not Call" list.

Does your organization do such website tracking? If so, be aware of this potential new law. You'll want to be involved with how to implement it successfully and effectively if it is enacted.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/561

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.