IRC log of dnt on 2014-05-07

Timestamps are in UTC.

Meeting: Tracking Protection Working Group Teleconference
Date: 07 May 2014
chairs: justin, carl, schunter
regrets: walter, WileyS
chair: Carl_Cargill, justin
16:04:50 [Zakim]
1. Disregard signal
16:04:50 [Zakim]
2. Unknowing data collection
16:04:50 [Zakim]
3. User agent compliance
16:04:50 [Zakim]
4. Geolocation
16:04:50 [wseltzer]
[_3538 is Peder_Magee]
16:05:03 [justin]
anyone want to scribe today?
scribenick: ninja
16:06:08 [justin]
16:06:14 [ninja]
Rob and Mike spend some more time on their proposal
16:06:18 [npdoty]
regrets+ wileys, walter
16:06:38 [ninja]
The normative req may be quite close to what we already have in TPE.
16:06:42 [dsinger]
can I be clear; this is text for the compliance document, and is complementary to the TPE requirements? Or is this intended to modify TPE?
16:07:04 [ninja]
They have added non-normative language to encourage folks to use the Tk signal
matt has joined #dnt
16:07:37 [ChrisPedigoOPA]
ChrisPedigoOPA has joined #dnt
16:07:44 [npdoty]
dsinger, I understand this conversation to be just about the Compliance document, in a complementary fashion
16:08:00 [waltM]
justin: Answer to designer. Yes this is language for TCS.
16:08:53 [npdoty]
16:09:25 [ninja]
moneill2: Our text adds the motivation to add a reason by using a qualifier.
16:09:39 [justin]
16:09:43 [npdoty]
16:09:46 [ninja]
justin: this is non-normative. Therefore it is a recommendation.
16:09:56 [ninja]
... Does anyone have problem with this text?
16:10:24 [dsinger]
I don't have a major problem, but I am concerned that the first paragraph duplicates the normative requirement in TPE
16:10:33 [npdoty]
16:10:34 [Ari]
we're talking about something that will be included in the privacy policy, not anything that is returned in via signal, right?
16:11:01 [justin]
ack ds
16:11:13 [npdoty]
Ari, the non-normative suggestion is that we could use the response signal to point to the particular part of the privacy policy
16:11:23 [ninja]
npdoty: I may have a friendly edit to this text proposal. Using a May instead of non-normative. (not sure if I got this right)
16:11:49 [ninja]
16:12:20 [Ari]
thanks nick
16:12:20 [dsinger]
to Ari: no, they are suggesting a return signal. If your policy says "I have 3 possible reasons to disregard" then they recommend that the return signal say "and you got caught by reason #2"
16:12:37 [hwest]
hwest has joined #dnt
16:12:54 [ninja]
justin: Mike, would you be okay to rather point to TPE paragraph instead of rephrasing it in TCS? With the added transparency recommendation?
yes, thank you david. I understand now. Although I wouldn't use the word caught as it sounds like we're trying to use a "gotcha" on the user
16:14:01 [ninja]
16:14:25 [wseltzer]
scribenick: wseltzer
justin: any other questions about disregard signal?
16:14:49 [justin]
16:14:51 [wseltzer]
... seems we're pretty closely aligned
16:14:58 [wseltzer]
... hope we can work out on list
16:15:05 [wseltzer]
Topic: Unknowing Data Collection
16:15:05 [ninja]
zakim, take up agendum 2
16:15:05 [Zakim]
agendum 2. "Unknowing data collection" taken up [from ninja]
16:15:06 [justin]
16:15:26 [wseltzer]
justin: no one has picked up on language Jonathan suggested
16:15:40 [wseltzer]
... it's been two weeks, so I've closed the issue
... Second question, Lee Tien and David Singer were talking about short-term data collection
16:16:08 [wseltzer]
... think that's a different issue, so I'm going to postpone that
16:16:15 [wseltzer]
... to group with research
16:16:20 [dsinger]
yes, short-term is different from both this and general research.
16:16:23 [dsinger]
16:16:28 [wseltzer]
ack dsinger
16:16:38 [wseltzer]
dsinger: I don't see how short-term is tied to other permission
16:16:50 [npdoty]
has some editorial fixes for that section, I think ("reasonably feasible" sounds awkward to me), but fine to close that issue
16:16:50 [wseltzer]
... it's about recognizing that people can't do processing in real-time
16:16:58 [wseltzer]
... there can be a gap between collection and processing
16:17:11 [wseltzer]
justin: maybe a misunderstanding
... I had the impression that you could use for any purpose, including research
16:17:39 [wseltzer]
... but would be happy to discuss separately from research
16:18:01 [wseltzer]
dsinger: Only three exits for the raw data you collect:
16:18:11 [wseltzer]
... extract data that's non-tracking
... extract data for which you had consent
16:18:25 [wseltzer]
... or permitted use
16:18:42 [wseltzer]
justin: so is the first one research uses?
16:19:04 [wseltzer]
dsinger: current proposal, says there's "a processing step"
16:19:26 [wseltzer]
... changing to say you can keep doing processing on raw data kept around is a different proposal
16:19:38 [wseltzer]
justin: fine to add back to the agenda next week; I misunderstood
16:19:50 [wseltzer]
16:19:51 [justin]
16:20:07 [ninja]
zakim, take up agendum 3
16:20:07 [Zakim]
agendum 3. "User agent compliance" taken up [from ninja]
16:20:10 [justin]
16:20:32 [wseltzer]
justin: wiki shows current editors' draft
16:21:02 [wseltzer]
... middle ground, some obligations on UA to make options available, but not prescriptive
16:21:23 [wseltzer]
... alternatively, nothing beyond TPE
16:22:14 [wseltzer]
... other proposals in the wiki. Chapell other UAs
16:22:26 [wseltzer]
... Hobaugh on which UAs
16:23:05 [justin]
The TPE seems ambiguous to me, so I think this needs to be addressed in the compliance document
16:23:12 [wseltzer]
... Biggest question: do we say it's addressed in TPE, or put something in TCS
16:23:15 [npdoty]
16:23:58 [wseltzer]
justin: are you happy with language in editors' draft, or want to add more prescriptive requirements, if we're clarifying
16:24:01 [wseltzer]
ack npdoty
16:24:04 [justin]
ack npd
16:24:19 [wseltzer]
npdoty: would like to know what's ambiguous
16:24:30 [dsinger]
again, I am concerned with having two normative documents addressing the same question. overlap is not good practive
16:24:41 [moneill2]
16:24:41 [dsinger]
16:24:55 [wseltzer]
... with the division we have now, UAs might think TPE contains their complete obligations
16:25:08 [wseltzer]
... seems less likely they'd review the TCS
16:25:15 [wseltzer]
... maybe we already have it in TPE
16:25:45 [wseltzer]
... Q2, Adrian had suggested common language for UAs and Websites seeking exception
16:25:59 [wseltzer]
... if that's what we're doing, cut it down to user indications
16:26:26 [npdoty]
User agents and web sites are responsible for determining the user experience by which a tracking preference is controlled. User agents and web sites MUST ensure that tracking preference choices are communicated to users clearly and accurately and shown at the time and place the tracking preference choice is made available to a user. User agents and web sites MUST ensure that the tracking preference choices describe the parties to whom DNT applies and MUST make
16:26:27 [npdoty]
available brief and neutral explanatory text to provide more detailed information about DNT functionality.
16:26:28 [npdoty]
That text MUST indicate that:
16:26:30 [npdoty]
if the tracking preference is communicated, it limits collection and use of web viewing data for certain advertising and other purposes;
16:26:31 [npdoty]
when DNT is enabled, some data may still be collected and used for certain purposes, and a description of such purposes; and
16:26:31 [npdoty]
if a user affirmatively allows a particular party to collect and use information about web viewing activities, enabling DNT will not limit collection and use from that party.
16:26:38 [Ari]
is there a link to adrian's proposal you are referring to that we can look at now?
16:26:45 [wseltzer]
justin: 3d alternative, taking just a part for TCS
16:26:54 [npdoty]
I get the impression that most of the other requirements are already present in the TPE, but I'd have to go line-by-line to compare
16:27:05 [justin]
16:27:09 [justin]
ack mon
16:28:11 [wseltzer]
moneill2: If we made a general preference
16:28:12 [npdoty]
right, and the first two sentences are generally duplicated from TPE
16:28:24 [justin]
16:28:38 [wseltzer]
justin: sounds reasonable editorial change
16:28:40 [dsinger]
q+ to talk about overlap
16:28:44 [wseltzer]
ack dsinger
16:28:44 [Zakim]
dsinger, you wanted to talk about overlap
16:28:47 [justin]
ack ds
16:29:09 [wseltzer]
dsinger: It's not great practices for two specs to duplicate one another
16:29:17 [wseltzer]
... I'd rather we get the language right in the TPE
16:29:21 [npdoty]
moneill2: on the first sentence (number of alternative choices), should make clear that that's for the general preference
16:29:25 [wseltzer]
... it's protocol compliance, and I thought we had
16:29:38 [wseltzer]
justin: so you're suggesting we strike the section in TCS
16:29:41 [wseltzer]
dsinger: yes
16:29:51 [justin]
16:30:03 [ninja]
the current TCS text is also missing our result from issue-153
16:30:09 [wseltzer]
zakim, next agendum
16:30:09 [Zakim]
agendum 1. "Disregard signal" taken up [from ninja]
16:30:15 [justin]
16:30:18 [ninja]
zakim, take up agendum 4
16:30:18 [Zakim]
agendum 4. "Geolocation" taken up [from ninja]
16:30:18 [npdoty]
[that's an editorial fix from moneill2, although maybe it would be obsoleted by other proposals]
16:30:25 [wseltzer]
justin: geolocation
16:30:43 [wseltzer]
... suggestion from Tom Lowenthal that we need to deal specifically with geoloc
16:31:02 [ninja]
wiki page:
16:31:33 [wseltzer]
justin: proposals to use existing language, or delete entirely
16:31:48 [wseltzer]
... because we don't treat any categories of sensitive info differently
16:31:52 [justin]
16:32:04 [adrianba]
think we should delete it
16:32:10 [npdoty]
don't feel strongly, but thought we had already settled on this text
16:32:27 [JackHobaugh]
I also think it should be deleted
16:32:29 [wseltzer]
justin: I don't think we got consensus
16:32:37 [Ari]
we should delete it
16:33:04 [ninja]
16:33:13 [ninja]
16:33:14 [dsinger]
sounds like we delete, and maybe have the non-normative note about careful handling as well
16:33:19 [justin]
ack ds
16:33:20 [wseltzer]
justin: if people want to keep it, burden on them to explain why we should keep it
16:33:31 [wseltzer]
ninja: would you take this up as a special case of de-id?
16:33:41 [wseltzer]
... or just drop talk of geoloc?
16:33:51 [adrianba]
postal code could be very specific - in the UK it is often 4 or 5 houses
16:34:05 [rvaneijk]
rvaneijk has joined #dnt
16:34:05 [wseltzer]
justin: maybe that's a middle ground
16:34:28 [dsinger]
I suggested it go after the definition of tracking, but a lot depends on the shape of the TCS
16:34:51 [wseltzer]
... maybe reasonable to point out that geoloc can be identifying
16:34:58 [justin]
16:35:14 [wseltzer]
... if no further thoughts, I'll suggest we drop and replace with dsinger's non-normative language
16:35:21 [wseltzer]
Topic: Editing
16:35:24 [vincent]
vincent has joined #dnt
16:35:33 [justin]
16:35:34 [wseltzer]
justin: we never added another editor to TCS when I became chair
16:35:48 [npdoty]
16:35:49 [wseltzer]
... so we've asked Nick, from W3C staff, to join Heather as an editor of TCS
16:36:00 [wseltzer]
ack npdoty
16:36:20 [wseltzer]
npdoty: Last Week we discussed TCS snapshot publication; that should happen tomorrow
16:36:29 [wseltzer]
As of this point the attendees have been Ninja, Jeff, dsinger, Wendy, Jack_Hobaugh, Peder_Magee, +31.65.275.aaaa, Carl_Cargill, Rob, Chris_Pedigo, eberkower, npdoty, justin,
... moneill2, Ari, hefferjr, [FTC], MattHayes, WaltMichel, Brooks, adrianba, kulick, rvaneijk
