User Analytics and Tracking
A recent proposed revision of the policy on web tracking technologies for US federal web sites by the Office of Management and Budget set out four principles regarding user analytics and tracking.
- Adhere to all existing laws and policies (including those designed to protect privacy) governing the collection, use, retention, and safeguarding of any data gathered from users.
- Post clear and conspicuous notice on the website of the use of web tracking technologies.
- Provide a clear and understandable means for a user to opt-out of being tracked.
- Not discriminate against those users who decide to opt-out, in terms of their access to information.
The document recommends avoiding outsourced tracking and outsourced data analysis—issues not thought about by many organisations. Just because a third-party service is cheap, doesn't necessarily mean it's the appropriate method to use. I'm less convinced about the example of using cookies to record opt-outs.
The proposed revision attracted a well-considered joint response from the Center for Democracy & Technology and the Electronic Frontier Foundation. They suggested three additional principles.
- Limit use of tracking data.
- Limit retention of tracking data.
- Obtain third-party verification.
The response also referenced their May 2009 Open Recommendations for the Use of Web Measurement Tools on Federal Government Web Sites which recommended the following:
- Use data only for measurement.
- Prominently disclose.
- Offer choice.
- Limit data retention.
- Limit cross-session measurement.
- Obtain third-party verification.
Whilst none of the final guidelines will be mandatory outside the US federal sector, the issues raised are worth consideration by all commercial and non-commercial web sites. For example, the recommendations and principles above could be used to help guide a privacy impact assessment of an organisation's own use of web analytics and tracking technologies.
Posted on: 25 August 2009 at 08:37 hrs

Comments are filtered automatically and should appear shortly after they been checked.