PrimeLife Privacy Dashboard

General Meeting, 23-26 March 2010, Bergamo

Dave Raggett <dsr@w3.org>

Stata building photo by See-ming Lee

MIT stata building W3C logo

Introduction

"This task will develop an open source browser extension for a privacy dashboard that will enable users to manage their identities, credentials, and privacy preferences, and enable them to track disclosures of personal data to websites"

More details in the PrimeLife Wiki

Draft Development Plan

Background

Background Work

Related work in PrimeLife

Note: lack of resources for full blown implementation of client and server side components for 5.3. Moreover, that isn't something we could widely deploy in the near term. Instead focus on demoing some aspects of 5.3 work, e.g. pre-matching.

Personal Dashboard for the Social Web

Liz Ganne's blog "My wish for 2010"

This led me to Knx.to, a web app using OAuth to access your profile and social contacts on Twitter, facebook, LinkedIn, Flickr, GoogleMail and Yahoo! Mail.

AttentionTrust

AttentionTrust believes that we all have the right 1) to own at least a copy of our data, 2) to store that data where we want and move it when we want, 3) to exchange it for something of value to us, and 4) to know what others intend to do with our data, so that we can make informed decisions about who should have access to it.

No longer under development, but still informative.

Prime DataTrack

Java source code available.

Mozilla Labs - Weave

SuperGenPass

PrivacyChoice

A service that gives users the means to opt-out of behavioral targeted ads, either completely or to restrict such ads to companies that are accountable to the best privacy practices.

You have a choice of opting out with:

Note: the EFF has worked with Google to provide an alternative solution, involving a browser add-on which allows users to permanently opt out of the DoubleClick cookie, which is an advertising cookie that Google uses.

Understandable Privacy Policies

Right to subject access

This EU right allows a data subject to be informed of the information held about them and to discover to whom it has been disclosed. The request for access must be made in writing (including fax and email) and an institution must respond to the request within a period of 40 calendar days.

Notifications

Oversight for trusted identity providers

See America's plan for national broadband

More Details

Policy Pre-Matching

Support for Credentials

Support for Credentials

A simple credential system

Dashboard UI

Needs to be informed by experience of PrimeLife team