Vendors Huddle over Privacy

SAN MATEO (06/21/2000) - To quell some of the consumer privacy concerns now tied to e-commerce, a group of high-profile vendors will gather Wednesday to test a new browser standard designed to filter through Web site privacy policies.

Dubbed P3P, for the Platform for Privacy Preferences, the new standard was developed as a common way to let consumers browse Web sites without concerns over whether information is being collected about them or how that personal information will be used.

P3P has been more than four years in the making and was spearheaded by the W3C (World Wide Web Consortium) and major vendors, including Microsoft Corp., AT&T Corp., and IBM Corp.

Those companies and others will meet in New York Wednesday to test the interoperability of the products each has developed using the P3P standard.

"This is a technical standard designed to give users more control over their privacy and to make it easier to extend that kind of control to users, which will build more trust in e-commerce," said Daniel Weitzner, W3C's technology and domain leader, in Cambridge, Mass.

A W3C team headed up by an executive at AT&T Labs developed P3P as a plain-vanilla capability that sifts through XML tags tied to elements contained in a corporate privacy statement.

Those tags then trigger privacy settings matched to a user's set of privacy preferences. For example, an icon similar to the SSL encryption key -- prevalent in e-commerce transactions -- may pop up to indicate that a site matches a user's privacy tolerance level.

"At the interoperability session, we will be showing a browser helper object that works with Microsoft Explorer as a plug in," said Lorrie Cranor, of AT&T Labs-Research and chair of the P3P Specification Group, based in Basking Ridge, New Jersey.

Cranor said users will likely be able to download the plug-in for free, and future versions of Explorer and other browsers will probably be P3P-compliant.

W3C intentionally made P3P a plain-vanilla standard and asked vendors to develop specific products on their own. The Wednesday session will give those companies a chance to check out each other's P3P offerings and test interoperability.

The ultimate goal is to derive an easy way for consumers to relax fears about data collection and privacy infringement while online, sources said.

"Right now, consumers have to hunt for privacy documents, and that can sometimes be scary, when they see all they will have to read and sort through.

Hopefully this will be a way they can see easily how a site matches their personal preferences," Cranor said.

Cranor and others said the cost and time investment companies will have to commit to in order to make their corporate Web sites P3P-compliant will be minimal.

Other companies attending the interoperability session include Citigroup, PrivacyBank, NCR, NEC,, and Nokia.

Jennifer Jones is an InfoWorld senior editor.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

More about AT&TCitigroupIBM AustraliaMicrosoftNCR AustraliaNECNokiaW3CWorld Wide Web Consortium

Show Comments