When Is It Acceptable to Spy on Your Web Visitors?
Never spy on your web site visitors. Users of your web site/application will not appreciate it. It may also be illegal.
The story in the Times newspaper concerning Council Uses Terror Law to Spy on Shirker in Shower reminded me how easy it is to get carried away with inappropriate monitoring and analysis.
Like employment contracts for staff, make sure your web site privacy policy defines what data you collect, and for what purposes. Don't be tempted to mine this data for other purposes (e.g. marketing) especially if it includes personally identifiable information and users have not opted in for this use.
Check who and what has access to web site and web application logs and audit trails, including archives and back-ups. People with access need to be trained how to handle such data appropriately, for what purposes and to ensure they do not violate laws.
This data should also be subject to an agreed data retention and disposal policy.
Posted on: 29 May 2009 at 08:05 hrs

Comments are filtered automatically and should appear shortly after they been checked.