P3P: A Privacy module for Web-Technology

W3C

Rigo Wenning

W3C-Track, WWW-2002
Hawaii, 8 Mai 2002

Rigo Wenning <rigo@w3.org>
W3C/INRIA
Sophia Antipolis, France

Privacy is important for E-Commerce?

I have to tell them, why laws alone are not sufficient. But I will say also, that P3P alone is not a sufficient condition for privacy

P3P is key to transparency

P3P will provide the following Information:

What else is provided?

P3P: How it works

This reflects the basic elements of the P3P protocol and how it works together. First, the user-agent tries to find the Policy Reference File, fetches and parses it. This way, it will find the appropriate Policy-file and can parse it and compare it to the user's preferences

A simple HTTP-Transaction

A HTTP-Transaction with P3P

How to make your site P3P compliant

  1. Create a privacy policy
  2. Translate it to P3P
  3. Create a policy reference file for your site
  4. Configure your server for P3P

Help for Implementers

P3P is a module

Expected to work also with

We expect, that P3P is used to integrate privacy metadata into the whole business process

P3P-Applications: User Agents

P3P-Applications: Authoring Tools

P3P-Applications: other Applications

See also the Implementations Page

Future work