Posts Tagged ‘SpecificMEDIA’

It’s a good time to clean house (and get a retention policy)

December 1, 2009

Update: On 12/17 Audience Science adopted a 2-year retention policy. The housecleaning continues …

Update: 24/7 Real Media, the WPP subsidiary, now also has a retention policy we first logged on 12/09. They’ve chosen 13 months across the board.

We’ve seen a number of upgrades to ad network privacy policies in the last couple of weeks, which may indicate that networks are starting to clean up missing and non-typical provisions in their privacy policies. The timing is good, since the FTC Roundtables on privacy that commence next week will no doubt raise attention around ad-network privacy policies.

One notable recent policy improvement comes from x+1, which added a retention policy, stating that log file information is only kept available for 90 days from the date of collection. Accordingly, I’ve removed them from the list of NAI members lacking a specific retention policy, leaving only three four NAI members left without published data retention policies: Audience Science, Microsoft, and SpecificMEDIA and 24/7 Real Media.

As part of the PrivacyChoice submission to the FTC Roundtables on privacy, we will be providing a set of overall statistics on privacy policy provisions and practices, based a snapshot from our database later this week.

PS Apologies to regular readers for the silence on this blog in the last month. While it hasn’t been a great month for writing, it has been a terrific month of meetings with industry and thought leaders, and a ton of product design and development, which we will be unveiling very soon. Stay tuned!


No mention of retention (results of our policy review)

May 8, 2009

In the course of our research for privacychoice 2.0, we’ve been surprised at how hard it is to get a handle on the data retention policies of the ad and tracking networks.  This is despite the fact that data retention practices are a key disclosure point for consumer online privacy. The FTC principles called this out:

To address the concern that data collected for behavioral advertising may find its way into the hands of criminals or other wrongdoers, and concerns about the length of time companies are retaining consumer data, the FTC staff proposes:  Any company that collects or stores consumer data for behavioral advertising should provide reasonable security for that data and should retain data only as long as is necessary to fulfill a legitimate business or law enforcement need.

Here’s what the NAI guidelines (PDF) require of their members:

Each member directly engaging in [Online Behavioral Advertising], a) Multi-Site Advertising and/or Ad Delivery & Reporting shall clearly and conspicuously post notice on its website that describes its data collection, transfer, and use practices. Such notice shall include clear descriptions of the following, as applicable: …  The approximate length of time that data used for OBA, vi. Multi-Site Advertisiisiising and/or Ad Delivery & Reporting will be retained by the member company.

In reviewing the policies of 63 targeting networks, here’s what we learned:

1. Most companies don’t disclose their retention timeframe, or do so obliquely.

Suprisingly, for 41 of the companies (nearly two-thirds), we could not find an express statement of how long consumer data is retained.  In the NAI membership, we could not find such a statement for any of these companies:

24/7 Real Media (WPP) (retention provisions added 12/09)
Audience Science (added two-year retention period 12/09)
Microsoft (subsidiary Atlas discloses a 2 year timeframe)
[x+1] (retention provision added 11/09)

Two of the other heavyweights in the NAI — Google and Yahoo! — have published information about their retention practices, in the press or on their blogs. (Here’s a round up of some of these statements.)  But as far as we could tell, they have not included an express timeframe in their privacy policies, where a consumer would expect to find it.

2. Retention periods vary widely, but the trend is toward a year or less.

Of those 22 networks who have put a time frame in their disclosure policies, there’s a wide range, but with accumulation at or below one year (particularly for the larger networks).

One year or less:  13
Over one year but not more than 2 years: 6
Three years: 2
Indefinite: 1

Special mention goes to Fetchback, which is clear in their disclosures that they retain the information indefinitely. Whatever you might think about that policy, at least the disclosure is clear and where a consumer would expect to find it.

For 41 other companies:  Until your policies are more clear, consumers and (yikes) regulators can fairly assume that you are also retaining and using the information indefinitely.