15:37:00 RRSAgent has joined #dnt 15:37:00 logging to http://www.w3.org/2013/10/23-dnt-irc 15:37:02 RRSAgent, make logs world 15:37:02 Zakim has joined #dnt 15:37:04 Zakim, this will be 15:37:04 I don't understand 'this will be', trackbot 15:37:05 Meeting: Tracking Protection Working Group Teleconference 15:37:05 Date: 23 October 2013 15:37:16 zakim, this will be TRACK 15:37:16 ok, wseltzer; I see T&S_Track(dnt)12:00PM scheduled to start in 23 minutes 15:47:33 ThomasSchauf_ has joined #dnt 15:50:12 dsinger has joined #dnt 15:50:43 eberkower has joined #dnt 15:52:41 T&S_Track(dnt)12:00PM has now started 15:52:48 + +1.646.654.aaaa 15:52:54 Zakim, aaaa is eberkower 15:52:54 +eberkower; got it 15:54:15 npdoty has joined #dnt 15:54:55 trackbot, start meeting 15:54:57 RRSAgent, make logs world 15:54:59 Zakim, this will be 15:54:59 I don't understand 'this will be', trackbot 15:55:00 Meeting: Tracking Protection Working Group Teleconference 15:55:00 Date: 23 October 2013 15:55:06 Zakim, this is TRACK 15:55:06 npdoty, this was already T&S_Track(dnt)12:00PM 15:55:07 ok, npdoty; that matches T&S_Track(dnt)12:00PM 15:55:11 dwainberg has joined #dnt 15:55:13 Zakim, who is on the phone? 15:55:13 On the phone I see eberkower 15:55:54 np for once I am getting an early start :-) 15:56:11 npdoty has changed the topic to: agenda 23 Oct: http://lists.w3.org/Archives/Public/public-tracking/2013Oct/0300.html 15:56:51 ThomasSchauf has joined #dnt 15:56:56 Joanne has joined #DNT 15:56:59 + +1.646.827.aabb 15:57:09 zakim, call wendy-office 15:57:09 ok, wseltzer; the call is being made 15:57:10 zakim, aabb is dwainberg 15:57:10 +dwainberg; got it 15:57:11 +Wendy 15:57:40 +npdoty 15:57:45 GSHans has joined #dnt 15:57:54 +MECallahan 15:57:55 Chair: schunter, justin, CarlCargill 15:58:11 +Thomas_Schauf 15:58:24 regrets+ johnsimpson, ninja, walter 15:58:31 +WaltMichel 15:58:38 justin has joined #dnt 15:58:48 +Peder_Magee 15:58:49 mecallahan has joined #dnt 15:59:03 +SusanIsrael 15:59:08 susanisrael has joined #dnt 15:59:25 PM3538 has joined #dnt 15:59:26 +Carl_Cargill 15:59:37 JackHobaugh has joined #dnt 15:59:55 +[Apple] 15:59:59 zakim, [apple] has dsinger 15:59:59 +dsinger; got it 16:00:05 jeff has joined #dnt 16:00:10 +[CDT] 16:00:13 fielding has joined #dnt 16:00:14 +??P37 16:00:16 zakim, cdt has me and GShand 16:00:16 +justin, GShand; got it 16:00:21 +Jeff 16:00:23 Zakim, ??P37 is schunter 16:00:23 +schunter; got it 16:00:25 zakim, cdt has gshans 16:00:25 +gshans; got it 16:00:31 +Joanne 16:00:41 Chris_IAB has joined #dnt 16:00:43 zakim, who is on the phone? 16:00:43 On the phone I see eberkower, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, Carl_Cargill, [Apple], [CDT], schunter, Jeff, Joanne 16:00:47 [CDT] has gshans 16:00:47 [Apple] has dsinger 16:00:50 +Fielding 16:00:51 AdamP has joined #dnt 16:00:51 volunteers to scribe? 16:00:52 +Jack_Hobaugh 16:00:58 moneill2 has joined #dnt 16:00:58 sidstamm has joined #dnt 16:01:02 vinay has joined #dnt 16:01:07 +[Adobe] 16:01:17 zakim, [Adobe] is vinay 16:01:18 +vinay; got it 16:01:25 +Chapell 16:01:26 hwest has joined #dnt 16:01:36 zakim, who is on the phone? 16:01:36 On the phone I see eberkower, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, Carl_Cargill, [Apple], [CDT], schunter, Jeff, Joanne, 16:01:36 zakim, who is here? 16:01:39 ... Fielding, Jack_Hobaugh, vinay, Chapell 16:01:39 [CDT] has gshans, justin 16:01:39 [Apple] has dsinger 16:01:39 On the phone I see eberkower, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, Carl_Cargill, [Apple], [CDT], schunter, Jeff, Joanne, 16:01:40 ... Fielding, Jack_Hobaugh, vinay, Chapell 16:01:40 [CDT] has gshans, justin 16:01:40 [Apple] has dsinger 16:01:40 On IRC I see hwest, vinay, sidstamm, moneill2, AdamP, Chris_IAB, fielding, jeff, JackHobaugh, PM3538, susanisrael, mecallahan, justin, GSHans, Joanne, ThomasSchauf, dwainberg, 16:01:40 ... npdoty, eberkower, dsinger, Zakim, RRSAgent, schunter1, qchris, trackbot 16:01:40 +??P45 16:01:44 +Adamp 16:01:46 just joined 16:01:47 +[Mozilla] 16:01:50 Zakim, Mozilla has sidstamm 16:01:50 +sidstamm; got it 16:01:56 matt has joined #dnt 16:01:59 zakim, ??p45 is Chris_IAB 16:01:59 +Chris_IAB; got it 16:01:59 Agenda for the call: http://lists.w3.org/Archives/Public/public-tracking/2013Oct/0300.html 16:02:01 +moneill2 16:02:09 Zakim, please choose a scribe 16:02:09 Not knowing who is chairing or who scribed recently, I propose justin 16:02:12 Zakim, please choose a scribe 16:02:12 Not knowing who is chairing or who scribed recently, I propose schunter 16:02:14 Zakim, please choose a scribe 16:02:14 No. 16:02:14 Not knowing who is chairing or who scribed recently, I propose berkwer 16:02:20 WaltMichel has joined #DNT 16:02:32 I cannot. 16:02:36 Zakim, please choose a scribe 16:02:37 Not knowing who is chairing or who scribed recently, I propose Chapell 16:02:43 I have carpal tunnel wrist bands on 16:02:47 adrianba has joined #dnt 16:02:48 WileyS has joined #dnt 16:02:50 bryan has joined #dnt 16:02:50 Alan is not on IRC. 16:03:05 Zakim, please choose a scribe 16:03:05 Not knowing who is chairing or who scribed recently, I propose Joanne 16:03:09 kj has joined #dnt 16:03:12 +LeeTien 16:03:26 +hefferjr 16:03:30 ChrisPedigoOPA has joined #dnt 16:03:33 scribenick: Joanne 16:03:40 zakin, who is on the phone? 16:03:45 zakim, who is on the phone? 16:03:45 On the phone I see eberkower, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, Carl_Cargill, [Apple], [CDT], schunter, Jeff, Joanne, 16:03:48 ... Fielding, Jack_Hobaugh, vinay, Chapell, Chris_IAB, Adamp, [Mozilla], moneill2, LeeTien, hefferjr 16:03:48 [Mozilla] has sidstamm 16:03:48 [CDT] has gshans, justin 16:03:48 [Apple] has dsinger 16:03:48 +Bryan_Sullivan 16:05:06 Brooks has joined #dnt 16:05:07 +ChrisPedigoOPA 16:05:09 Schunter - five agenda items, update on plan by Justin, inpurt from others, processing issues to stay on plan 16:05:38 JC has joined #DNT 16:05:39 kulick has joined #dnt 16:05:57 +hwest 16:06:06 +[Microsoft] 16:06:15 hefferjr has joined #dnt 16:06:23 +kulick 16:06:27 Justin: constructive feedback on how group should move forward based on polling results. Options 3&4 had most support. some support for option 3.5 - some thing in compliance that need to be defined (e.g. def of tracking, parties) 16:07:09 ...charis working to come up with best path forward. can't please everyone but come up with path that represents most views 16:07:11 +WileyS 16:07:30 ...appreciate feedback and want to be responsive 16:07:38 +[Microsoft.a] 16:08:05 zakim, [Microsoft.a] is me 16:08:05 +adrianba; got it 16:08:07 +Brooks 16:08:08 ...try to close down issues to move forward. still figure to structure plan going forward. move to Carl 16:08:12 zakim, mute me 16:08:12 adrianba should now be muted 16:08:31 q? 16:08:42 Zakim, mute me please 16:08:42 eberkower should now be muted 16:08:43 Or questions about what I just said! 16:08:44 Carl: looking for additional feedback. last week was helpful though disconcerting(sp) 16:08:50 aerber has joined #dnt 16:09:07 q? 16:09:09 ...same rules as last week - positive statements to help move forward. 3 mins for people to speak 16:09:28 ...for those that did not speak last week. takers??? 16:09:39 q? 16:09:56 Carl: completed agenda item in record time 16:10:05 Topic: Issue-5 16:10:05 Justin: Next Issue 5 16:10:17 http://www.w3.org/2011/tracking-protection/track/issues/5 16:10:27 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Tracking_Definition 16:10:33 q+ to point out that Roy replied to that... 16:11:19 (recently, it was more like a tennis match between Roy and myself!) 16:11:27 Matthias: last week started with agressive timeline. people submitted definitions and which draw least objections. Convergence is starting - hope for consensus soon. 16:12:00 David: tennis match report. :) 16:12:22 http://lists.w3.org/Archives/Public/public-tracking/2013Oct/0287.html 16:12:41 ...Roy did provide some links. Not quite understanding each other. Asking for others to pitch in to help get head around the points being made 16:13:02 ack ds 16:13:02 dsinger, you wanted to point out that Roy replied to that... 16:13:05 Roy: looking for definition to cover what user wants to turn off 16:13:36 Roy, we addressed that ages ago when we explicitly said that first parties are allowed to track 16:13:54 ...users don't expect sites to stop working when DNT is on. Wants definition to reflect what users are looking for with DNT off 16:14:04 +q 16:14:10 +BerinSzoka 16:14:10 ...that's my goal but need more input from others in WG 16:14:19 q+ 16:14:37 q+ 16:14:40 I think our wiki doesn't have Roy's shorter version, (which I also haven't been following closely) 16:14:47 I support Roy's premise 16:15:13 Carl: need more input in order to move towards consensus 16:15:16 ack mon 16:15:18 I agree that tracking not include things that are necessary for personalization especially on 1st parties or content that the user assumes is part of the 1st party experience e.g. socnet widgets. 16:15:21 Tracking is the observation of a particular user's browsing activity across multiple distinct contexts and the retention, use, or sharing of data derived from that activity outside the context in which it occurred. 16:15:32 Matthais: pushed out call for objections. Would prefer consensus 16:15:33 are there clear versions of each that can be posted here? 16:15:40 q+ 16:15:41 clean versions, sorry 16:16:09 q+ 16:16:29 David: wouldl like non-normative text associated with definition like option 4 so non-technical people can weigh in 16:16:35 Mike ONeill proposes Roy's new text + Rob's non-normative explanation. 16:16:37 + +1.203.563.aacc 16:16:45 bryan, how do we learn users' assumptions about widgets? 16:16:57 q? 16:17:15 Roy: Rob's text is oppostie of Roy's text. Intro will need to explain whole concept. 16:17:27 I like Roy's approach and I agree that Rob's non-normative text does not align with that. 16:17:37 Rob's non-normative text doesn't account for the multiple distinct contexts. Rob's non-normative text suggests that 1st party analytics/optimization is within scope of tracking. 16:17:46 I can't support Rob's non-normative text 16:18:30 Matthias: Roy's proposed text has some traction in the goup. 16:18:31 ack Jack 16:19:08 if you want non-normative text to amplify Roy's definition, we should offer on the list non-normative text that is consistent with Roy's proposed definition 16:19:12 Jack: some folks sitting on sidelines waiting to see what direction we're going in. Need more discussion across all the options 16:19:55 To make it "user comprehensible", we need to explain what "the context in which it occurred" means, e.g. if the user is using a site that includes socnet widgets and the overall experience is part of what the user would assume to be "the context", then sharing across those parties is allowed. 16:19:57 ...good discussion between Roy and David. Some people have stop participating on public list and need more robust discussion 16:20:07 q? 16:20:10 ack justin 16:20:19 npdoty has joined #dnt 16:20:23 Justin: this is that discussion. any way we go forward will require the tracking definition 16:20:39 ...if alternative you want to propose - now is the time 16:20:44 Just to be clear, which of Roy's proposal are we talking about? There are two listed, proposal (1) and proposal (5), at http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Tracking_Definition. 16:21:02 Jack: alternatives have been proposed. Example Alan has proposed an option 16:21:18 i was talking about proposal (5), which i understood to be the basis for this discussion. Fielding, was that wrong? 16:21:25 Thomas_Schauf has joined #dnt 16:21:33 Justin: wants to include Alan's proposal in the discussion. Now is a good time to discuss Alan's option 16:21:48 -MECallahan 16:21:49 It hasn't. 16:21:51 I don't see Alan's proposal 16:21:52 bryan, would you then suggest that the socnet widgets maintain distinct contexts for each site on which they interact? 16:21:54 susan, i thought (5) as well, but after some of the discussion I thought there might be some ambiguity 16:21:56 fielding, would we need new definitions for "observation" "browsing activity" "contexts" ? 16:21:57 Alan: not sure if my proposal has made the Wiki 16:22:15 -hwest 16:22:23 q? 16:22:26 ...privacy perspecitive some the distinctions around ownership/contract are abritary (sp) 16:22:28 kulick, I thought roy respoded that it was (5) 16:22:28 q? 16:22:31 zakim, who maketh noise? 16:22:31 I don't understand your question, dsinger. 16:22:33 zakim, who is making noise? 16:22:36 http://lists.w3.org/Archives/Public/public-tracking/2013Oct/0301.html 16:22:42 -Thomas_Schauf 16:22:50 wseltzer, listening for 10 seconds I heard sound from the following: Chapell (39%), Carl_Cargill (68%), schunter (14%), Chris_IAB (5%) 16:23:09 susan, okay thx 16:23:12 +Thomas_Schauf 16:23:18 q? 16:23:25 We are not going to stop just because people have not commented on the public discussion. If it were a private discussion, Jack would have a valid point, but the folks who have not expressed a specific objection are rightly assumed to not have a strong objection (one way or another) until they do respond. 16:23:29 ...I need to jump in less than 5 but seems proposed definition didn't make the table 16:23:44 fielding, were you now discussing proposal (5) 16:24:02 -Thomas_Schauf 16:24:06 Matthias: look at Roy's definition and provide input on how to improve to meet your requirements. One proposal - lets work on improving that 16:24:11 npdoty, we need a definition of context, could use one for browsing activity, but observing is just English 16:24:28 Alan: I did that. Started with Roy's definition and added a couple of things 16:24:34 wendy, I think that may be an implication, unless the cross-site presentation of data (e.g. by the socnet widget as used in other 1st parties) is a wanted feature that the user knows about 16:25:00 bryan, thanks, that's helpful 16:25:10 +Thomas_Schauf 16:25:31 Alan's proposal is a definition of context 16:25:38 Nick: want to talk to Alan today around addressing tracking, party 16:25:49 fielding, right. 16:25:56 Matthais: doesn't want party redefined in 3-4 palces 16:25:59 zakim, who is making noise? 16:26:09 dsinger, listening for 10 seconds I heard sound from the following: Thomas_Schauf (40%), Chapell (14%), npdoty (45%) 16:26:12 Alan: tracking definition heavily weighed towards third parties 16:26:12 To be clear, this is Roy's proposed definition that we're discussing, right? 16:26:15 Tracking is the observation of a particular user's browsing activity across multiple distinct contexts and the retention, use, or sharing of data derived from that activity outside the context in which it occurred. 16:26:25 zakim, mute Thomas_Schauf 16:26:25 Thomas_Schauf should now be muted 16:26:40 sorry, mute myself 16:26:46 Nick: Suggest Alan's text is about context towards Roy's version 1 (hopefully I got that right) 16:26:46 q? 16:26:54 ack dsinger 16:27:04 I suggest that we add Alan's proposal as related to proposal 1 (Roy's related to contexts) 16:27:25 fielding, would you be supportive of Alan's change? if so, perhaps we can consolidate more 16:27:34 Not sure we need to say that visiting a site is implied consent to track . . . 16:27:49 +hwest 16:27:57 npdoty, i thought we were discussing roy's proposal (5) as an update to (1). Fielding is that correct? 16:28:10 David: whether you think first parties remembering things about you is tracking. there are limits on what first parties can do with the data. don't think we can include all inclusions, expcetions in the defintion of tracking 16:28:13 -BerinSzoka 16:28:22 Justin, I agree, I think that overcomplicates it rather than simplifying it. 16:28:33 -Chapell 16:28:39 npdoty, no, I don't consider Alan's definition of context to be consistent with regulatory notions expressed by WH and EU 16:28:58 +Amy_Colando 16:29:06 q? 16:29:10 q- 16:29:12 ack np 16:29:14 ...2 concerns with Roy's defintion. Not sure what multiple contexts are. Need to explore what is not tracking based upon what is not remmbered about a particular users 16:29:53 susanisrael, we are currently discussing the simplified version we discussed in email … I should update the wiki 16:30:14 fielding, thanks. I think that's proposal (5) rather than proposal (1). 16:30:25 no, (1) simler 16:30:30 specifically, I want to explore what personal data is not 'tracking' 16:30:34 s/simler/simpler/ 16:30:38 Matthias: how do we move forward? what I see - not sure we can reach consensus the easy way. agress with David in the need to define the words. call for obections with the 8 definitions 16:30:52 q+ 16:30:54 I think getting thoughtful comments on a few, from everyone, would be helpful 16:31:03 No more than one from each author? 16:31:04 I think there is a way to accord fielding's and chapell's. But I don't think that fielding's and dsinger's are reconciliable. 16:31:06 can we get a poll (actual user poll is preferred) on the understandability of the definitions? 16:31:09 -Thomas_Schauf 16:31:10 Carl: still gives us 7-8 definitions. Can we condense down to a couple to choose from 16:31:22 yes 16:31:32 DAvid: I can reduce mine. Thinks Roy can do the same. 16:31:57 is there any major difference between (3) and (4)? dsinger and rvaneijk 16:32:21 if we how to achieve "comprehensibility to anyone that uses the web" as I think we should, we need actual user feedback on the definitions 16:32:32 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Tracking_Definition#Proposal_.283.29:_No_change_from_text_in_02_October_2013_ED 16:32:35 s/how/hope/ 16:32:38 David W: some support for Roy's direction. there are a couple dependienceis (sp) where the group is waiting to see what direction the group heads in. 16:32:47 q? 16:32:54 +Thomas_Schauf 16:32:56 ack dw 16:32:59 s/dependienceis (sp)/dependencies/ 16:33:01 Agree with David W., we are currently in "no man's land" 16:33:19 q+ 16:33:26 q? 16:33:29 ...my proposal is we hold with Roy's as a leading contender. discuss other concepts to see how they shake out then come back to tracking 16:33:41 +q 16:33:47 would like to point out that once we say something is not 'tracking', it appears to be no longer our concern 16:34:05 q please 16:34:16 q+ Chris_IAB 16:34:16 I don't think anyone is suggesting that "tracking" must be defined in such a way that every permitted use has to be described entirely, right? 16:34:22 Justin, the problem is that there is no single "user" and no single perception of "tracking" across all users 16:34:28 Justin: storngly disagrees there are dependcies here. some folks indicate this is what the group should have done in the beginning. we are going to define tracking and close out this issue 16:34:31 Proposal: Add non-normative language saying something like "while this definition aims to define tracking rather broadly, certain forms of tracking that this definition includes may later be declared permissible in the subsequent sections of this document." (or so) 16:34:35 ack Chris_IAB 16:34:36 It defines the semantics expressed by the protocol, which HTTP says is half the protocol. 16:35:16 s/It defines/The definition of tracking determines/ 16:35:16 We've been discussing this language for a month. 16:35:25 Chris IAB: agree with David W. good point around defining tracking up front. why rush to close this out so quickly. context does apply. 16:35:48 And by "a month," I mean three years :) 16:36:02 Matthias: wants to stick to the plan. Sees David W's concern. 16:36:11 I agree with Matthias (see proposal 7) 16:36:12 I think we have had a couple of discussions on this topic over the past couple years :) 16:36:35 David W: rather than going to a vote. Put this definition up as a placeholder so we can move on to other things and come back to it. 16:36:53 this definition is THE most import dependancy 16:37:00 q+ 16:37:06 Justin: closing out dependencies is always open issue and we are ware that things may chnage as we move forward 16:37:26 Justin, it does need to get resolved, but resolved well-- let's not rush the process just to rush the process-- let's do the work well 16:37:34 Matthias: close this issue, then if we get new info we need to reopen 16:37:36 I think it is possible to reference the fact that there are permitted uses for which "tracking" is allowed even though they would otherwise fall within the scope of the definition of tracking. 16:37:49 Is consensus required here? Or can we have least strong objection to 7 proposal take the day? 16:37:54 ...can't keep all issues open indefinitely. 16:38:10 Peter had previously used a "pending review stable" status, but it's also true that we can re-open closed issues as need be 16:38:18 why is it that the poll result/direction can be kept open indefinitely, but we have to rush to close tracking today??? 16:38:43 let's pick a direction for the working group, and then move forward on solid footing 16:38:54 * wseltzer, agree that a strawman is progress 16:38:54 Carl: agrees with fellow charis. This has bane of the existance of the group - no definitoon of tracking. I think we should have a smaller number of options - 1, 2, or 3. Hear from Roy and David on their proposals 16:38:55 Chris_IAB, I'm just saying there is no way to describe this process as rushing! 16:38:57 Next week, I would like to identify a single (strong) candidate for consensus or else have a smaller number that will be used in a call for objections. 16:39:03 q? 16:39:06 justin, disagree 16:39:22 ...can we work for five more minutes to work on closing the item 16:39:26 ack ChrisPedigoOPA 16:39:44 dsinger, I think wiki proposals 3, 4 and 7 are all closely related 16:40:06 I don't agree with the "multiple sites" because I don't know what it means for an individual collector 16:40:11 Chris P: I agree with tow points that have been made. Need definition that is not overly technical. We are trying to address tracking in multiple contexts. 16:41:00 ...value in Roy's approach in defining what we are trying to stop. Think we can narrow down to 2-3 options. Footnote for the excpetions of certain types of tracking 16:41:27 David, it appears most agree with the multi-site context. Where are we losing you from an "individual collector" perspective? This is about context. If its a single collector and they collect/use in the same context, then I don't see the issue. 16:41:43 npdoty has joined #dnt 16:41:54 David: spend next few days condensing definitions down to 2-3. then be in shape to go to objections. hope ot get consensus. 16:41:55 I think we can iron this out over the next couple of days --- at least getting the options out there. 16:42:06 David, that's fine - let's move to least objection as it appears most are on the side of Roy's definition. 16:42:25 I agree 16:42:29 +1 16:42:34 not agreeing without having more discussion, is potentially a disaster-- kicking the can down the road won't solve the problem folks 16:42:37 To WileyS: if ad sites and analytics sites can remember everything that *they* see in *their* context about me, what exactly (if anything) has been turned off? 16:42:50 I see: 1) Roy w/ contexts; 2) no definition; 3) retention of non-de-identified; 5) retention of non-de-identified from multiple parties 16:42:52 q+ 16:42:56 q- 16:43:04 q? 16:43:06 Matthais: do we agree on some non-normative lang that we define this broadly and clearly say why it is broad and some forms of tracking are permitted 16:43:09 I think it's important that a notion of context (as perceived by the user) be a facet of the definition, and not just an an adjunct defined by the TCS spec 16:43:25 q+ to respond to Chris 16:43:44 David - in a service provider role? Or each site is siloed into its own bucket (similar to a service provider outcome)? In either case, the data is not being co-mingled across contexts. 16:43:47 how many docs can be partially read to have full understanding, though 16:43:49 implementers will need to read more than a sentence to correctly implement in any case, I think 16:43:50 Chris P: does not support broad definition of tracking. doesn't help someone who is trying to comply. narrow definition tells implementer what we are trying to solve for 16:44:11 q+ 16:44:13 It is critical, IMO, that the user is not misled when they ask for DNT and we say that we will honor that request. 16:44:13 Agree to who just spoke - an over broad definition of tracking will cause us significant issues downstream 16:44:14 q? 16:44:16 Matthias: permitted uses should not be part of definition. 16:44:16 schunter, now THIS is a dependency, let's address subsequently. 16:44:20 we cannot get around some normative text to explain 16:44:32 justin, when will W3C issue their final decision on the poll? Why is that decision still dragging, three calls later? how about we get that cleaned up, so people can participate in a known context? 16:44:40 ack ChrisPed 16:44:45 Chris P: we generally agree we are trying to put some restrictions around tracking acrosss multippel unrelated sites 16:44:46 +MattHayes 16:45:03 no, we do NOT have consensus 16:45:09 schunter, why can't definition reference that there are permitted uses 16:45:10 "relation" as in "multiple unrelated sites" is a user perception, and not universal 16:45:32 Justin: this isi the dispute between Daviid and Roy 16:45:35 q? 16:46:07 which is clearly covered by my definition 16:46:10 David: fundamental question arund third party collecting data about me acrosss multiple sites in its own context 16:46:17 agree with fielding, that is covered by the definition. 16:46:32 David: multile sites need context is we are going to use it 16:46:50 As long as it can't link the experiences what is the harm? This is no different than a service provider outcome. The user appears as different users in each context. 16:46:55 we are only defining what is TRACKING here, not what people are allowed to do 16:47:04 e.g. referer header 16:47:11 David: should be careful of an overly restricted definition 16:47:37 dsinger, would you accept something like (5) which says collection of data across multiple parties? 16:47:38 fielding are you talking about the issue of referencing the fact that there are nonetheless permitted uses? (then explain what they are elsewhere) 16:47:43 Chris P: what is we had footnote around permitted uses section 16:47:58 David: Option 7 addresses this 16:47:58 q+ 16:48:03 +1 to ChrisPedigoOPA, in any case, we should advise implementers to read relevant sections of the spec 16:48:07 Yes, if someone wants to add a requirement that has nothing to do with tracking, then I will not implement it -- that should be clear as well. 16:48:23 16:48:30 I can take over. 16:48:38 scribenick: GSHans 16:48:50 Zakim, drop Thomas_Schauf 16:48:50 Thomas_Schauf is being disconnected 16:48:51 -Thomas_Schauf 16:48:55 what "user"? 16:49:01 q? 16:49:06 ack dsinger 16:49:06 dsinger, you wanted to respond to Chris 16:49:16 zakim, close the queue 16:49:16 ok, justin, the speaker queue is closed 16:49:20 Dsinger: Have asked what 3d party sites are allowed to collect. Fundamental point we need to understand. 16:49:21 q- 16:49:35 Schunter: Empty the list, then move on to next issue. 16:49:36 ack bryan 16:50:00 q+ 16:50:25 vincent has joined #dnt 16:50:30 q?+ 16:50:33 Bryan: It's important that user perception of this def be pretty solid. There is no single user or perception or relation or context. We have to do the best we can & make sure that every def is tried outside the bubble. Context will be a key aspect. On a social network, might perceive that whatever you do will be shared via widgets. 16:50:39 ack dwainberg 16:51:04 bryan, I think the question of user education is separate, for what it's worth; we don't have to educate users purely by asking them to read our spec 16:51:37 no, "there are restrictions on sharing" 16:51:50 -Amy_Colando 16:51:57 dsinger, I think dwainberg is talking about use here. 16:51:59 dwainberg: 1) DSinger's concerns go to the def of context. 2) In DSinger's text for prop 7, implies that first party can use outside of first party context. Possibly not what he means to say, so need to discuss context. Not so much about parties. Parties can make things confusing. 16:52:05 One thing is apparent in this discussion: many of these terms are related and it is difficult to use undefined terms, such as "First Party" in the forming of another definition. All definitions need to be addressed simultaneously and in an iterative approach. 16:52:07 ok, can work with the word context for sure 16:52:11 nick, if we are depending upon definitions that users can understand (which we should), we need to validate those definitions with actual users - otherwise who are we serving here? 16:52:21 dwainberg might be suggesting a rewording of (7) among other things 16:52:35 Schunter: On list, having examples of what same v. diff context will be helpful. 16:52:46 Schunter: next issue is issue 10. 16:52:48 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Party_Definitions 16:53:04 justin, I think use outside my 'context' is nessarily sharing, isn't it? 16:53:21 bryan, I really like the idea of validating definitions with users and testing any education we propose 16:53:32 Carl: Anyone who has a strong objection should interject before we close. 16:53:37 Zakim, please open the queue 16:53:37 ok, npdoty, the speaker queue is open 16:53:37 disnger, I don't think that's right. I think dwainberg is worried about first parties using their own data in a third-party context. 16:53:52 q+ 16:54:01 ack Brooks 16:54:03 to Justin, OK, got that 16:54:18 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Party_Definitions 16:54:19 agree I would much prefer true understanding and consensus 16:54:20 Brooks: When you have seven defs and what you want is consensus, strong objections doesn't get you to consensus. 16:54:22 wendy, I think we should attempt both implementer and user understanding. i think implementers will be inherently able to understand user-understandable definitions. 16:54:31 +1 to Brooks point 16:54:32 Topic: issue-10 party 16:55:00 Brooks, I think we can consolidate 3, 4 and 7 (different iterations on a single idea) 16:55:35 the wiki proposals cover party, first party, and third party 16:56:02 Justin: Have sent change proposals on parties. There's 9 here, not quite right - needs to be pared down. We only have a small handful of options. On the last call, felt like there was consensus to use Roy's provided text. No one disagreed on the call. It's a distillation of first party/third party. There are two forks from his definitions. "Firstness" v "thirdness": almost universal agreement that his defs are OK. 16:56:25 was about my rationale, not my change proposal 16:56:33 -schunter 16:56:38 Lee: There can be multiple first parties in some situations. My disagreement was about what Roy's explanation assumed a search engine to be a first party in a context that it wasn't. 16:56:48 +??P7 16:57:13 Justin: Is there anyone else who agrees with Lee that Google should not be a first party when someone clicks on a link in their service? 16:57:34 If the link is provided within the context of their service then it should be 1st party. 16:57:42 Justin: Alternatively Lee, if you want to provide text to address that, and if there's support for that, we can take it to Call for Objections. 16:57:51 is that question the same as a link shortener being a 1st party? 16:58:03 Lee, could you give an example of a service you feel this wouldn't be appropriate for? 16:58:08 bryan, no, that's different. 16:58:19 puzzled. if I visit Google and do a search, and click on a result, Google is the first party for that click, and the destination becomes a first party as the link loads. what am I missing? 16:59:02 Lee: What i'm unclear on is where in the spec this is dealt with. Most of our text on what's a 1P is the scope. Coming from more of a telecom perspective where the telco is usually treated as an intermediary. Unsure in this context how it works. 16:59:14 the service provided by a link shortener is equivalent to the service provided by google IMO. Users are well aware (generally) of the role of shortener services, esp with twitter 16:59:28 Justin: Will go through to find the history on this to work out the issue (re: telcos). 17:00:01 q? 17:00:02 q? 17:00:03 Justin: Other issue left: what is a party? Two paths here. Roy's definition - distillation over the last few years' work. Also the version that Alan did based on David's comments, that contractual relations can make someone a first party. 17:00:10 -vinay 17:00:11 Contracts don't make sites the same party... 17:00:33 "Whether a party is a first or third party is determined within and limited to a specific network interaction." 17:00:58 David Wainberg: One other issue with definitions of 1P and 3P. In existing editor's draft, statement in 3P definition that makes party-ness limited established and limited to a specific network definition. This points to the context issue again. The context of where the data is collected or used. Party-ness is ephemeral. 17:01:23 Justin: General agreements on that. There are disagreements re: use. You're saying that Roy's language is diff from existing editors text? 17:01:37 Wainberg: Some disagreement. 17:01:44 Justin: ROy's def does include contextual language. 17:01:44 I think there is agreement with the editors' draft text that parties are defined per interaction 17:02:09 "Within the context of a given user action, " 17:02:09 Wainberg: doesn't make clear that party-ness ends and has to be re-established. 17:02:14 that would be a strange reading of "within" 17:02:20 Justin: but "within", not "starting with". 17:02:21 notes we have a problem (pointed out by Roy and others) that 'network interaction' is badly defined right now 17:02:32 Wainberg: Would like it to be more explicit. 17:02:50 or "For the data collected in a given network interaction, .." ? 17:03:13 any objections to adding the editors' draft sentence in addition to the "within" clause? 17:03:16 Wainberg: Need to be explicitly clear - probably not disagreement, more wordsmithing. 17:03:35 (where network interaction or transaction is an HTTP request and matching response?) 17:03:54 Justin: Jack had submitted an amendment to editor's text on affiliate lists. Language would be: affiliates must be available on each page (e.g. via link or click) - doesn't need to be on every single page. 17:04:08 q+ 17:04:23 Justin: General agreement that that was reasonable. Also language that we had discussed two calls ago that perhaps we could make clear that it needs to be in priv poly. 17:04:31 ChrisPedigoOPA and amy had suggested similar language about making the affiliate list an example rather than a specific requirement 17:04:56 Justin: Jack, would you be oK with other TPE language saying that privacy policy is OK? 17:05:02 Jack: Have to give that some thought. 17:05:03 q? 17:05:05 ack chris 17:05:08 JackHobaugh, do you think that Chris and Amy's proposal also addresses your concern? 17:05:21 I suggested it be removed, or at least moved to the section on first party. A third party does not have pages. 17:05:28 q+ 17:05:30 Chris: Have noted objections on having to link on every page. Concerned re: providing list of all affiliates. Is that helpful for consumers? 17:05:46 q+ 17:05:47 Chris: Consumers may be more aware of brands than corp entity. 17:06:22 Chris: Transparency more important - common branding or discussion of affiliate sharing. That language mirrors FTC language. Consumers can be educated in different ways. 17:06:26 I can't see any other definition for 'network transaction' than request-response; servers don't know about 'pages' (only the site author, and even then not always) 17:06:31 q+ to suggest "easy discoverability" as a qualifier on transparency 17:06:35 Chris: Language is in Wiki Proposal #2. 17:06:38 q- 17:07:53 Roy: Want to remove this from definition since these are reqs you can apply after you have a party status. Some 3d parties don't have pages. Having them have a definition that defines add'l requirements on what/where you link doesn't make sense. Would make sense in the tracking status response. Would rather have that discussion somewhere else from definition. 17:08:08 Justin: TPE requires 3d parties to have information in places other than priv pol'y? 17:08:09 ack fielding 17:08:20 Roy: Requires Tracking Status Response or in policy linked by document. 17:08:36 Roy: Link could go to someone else's site. 17:09:10 Roy: Not part of the definition of party. Don't think we can have a single requirement that applies to everyone. 17:09:25 Roy: Could be done in transparency. 17:09:33 q? 17:09:35 ack npd 17:09:35 npdoty, you wanted to suggest "easy discoverability" as a qualifier on transparency 17:10:13 +1 Nick - agree with "easily discoverable" 17:10:19 Nick: Could amend "transparency." Thinking was that "easy discoverability" was a good concept. Can we include that even if we don't say specifically affiliate lists in a single click. 17:11:06 Chris: Probably OK to do "easy discoverability". Want to go away from that every page required to have a link, or that you even need a list - would prefer flexibility on consumer education. 17:11:23 Nick: Worth trying easy discoverability. 17:11:54 ChrisPedigoOPA, I'm happy to work with you on a version of yours and Amy's text that includes "easy discoverability" while still having flexible implementation possibilities 17:12:00 Justin: General paths are pretty clear. Either contracts (alan and david's proposal), or ownership and branding/discoverability. First/thirdness we'll work out with Lee whether he wants to propose altneraitves to the intermediary issues. 17:12:10 Justin: For at least one of these we'll have to have call for objections. 17:12:35 q? 17:12:46 zakim, agenda? 17:12:46 I see nothing on the agenda 17:13:14 Justin: Contracts concept: doesn't seem to be agreement at this point. 17:14:06 I've brought up the arguments many times. Suggest you go for consent (opt-in) or follow current law and merge organizations under a single legal entity. 17:14:27 Wainberg: What are the args against contracts? Under that model, we can provide notice and transparency in a conspicuous, up front way. Legally enforceable. If there's a requirement to have ownership rules, that's also feasible. 17:14:44 Multi-first party could be another option for you as well David. 17:15:11 Justin: That may be right, and I'm not objecting it. There was substantial disagreement with that on IRC last week, though, so cannot declare consensus. We'll ask people to make args re: objections. 17:15:18 -SusanIsrael 17:15:19 Fully co-brand a site as AppNexus and Company X, common TOS, links to both company's privacy policy, etc. 17:15:29 Justin: Consumer groups objected on prior calls. 17:15:36 would WileyS or dwainberg have proposals on ways that might be amenable to more people? 17:16:07 Nick, my position is to oppose the concept of a simple contract creating a 1st party relationship. 17:16:14 dwainberg, I think it would help if you included a common group identity along with the contract, since it currently doesn't indicate any user visibility 17:16:17 …thinks it is not wise to proceed with a definition that we know will attract strong opposition, even if the people aren't on the call 17:16:22 s/relationship/context 17:16:38 Carl: One of the roles of the chairs is to speak for those who aren't here but haven't withdrawn. 17:17:01 Justin: Matthias will take us through interplay b/w user-generated exceptions and out of band consent. 17:17:03 Topic: introducing other issues 17:17:43 issue-201? 17:17:43 issue-201 -- Interplay between UGE and out of band consent -- open 17:17:43 http://www.w3.org/2011/tracking-protection/track/issues/201 17:17:45 issue-16? 17:17:46 issue-16 -- What does it mean to collect, retain, use and share data? -- open 17:17:46 http://www.w3.org/2011/tracking-protection/track/issues/16 17:18:14 Carl: Vinay's proposal for modification was accepted. Additional comments may or may not indicate a degree of acceptance. 17:18:37 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Transience_Collection 17:19:02 q+ 17:19:03 A party collects data if it receives data and either shares the data with other parties or retains the data. 17:19:11 http://www.w3.org/wiki/Privacy/TPWG/Change_Proposal_Transience_Collection 17:19:12 Carl: Strong objections to going with Vinay's proposal along with additional comments? 17:19:38 "A party shares data if the party enables another party to collect, retain or use that data. " 17:19:54 q+ 17:20:04 q+ 17:20:05 ack np 17:20:08 Nick: Questiona bout share vis-a-vis trasnfer. Question re: different def of collection vs. retention. 17:20:16 q+ to point out the problem with 'network transaction' 17:20:16 A party shares data if the party enables another party to collect, retain or use that data. 17:20:16 q? 17:20:19 ack jack 17:20:20 ack JackHobaugh 17:20:55 Jack: Question re: process. 17:21:16 it's useful to find out which proposals we need, or if we're generally in agreement 17:21:19 q? 17:21:19 Carl: We can queue this for next week. 17:21:53 Yeah, it would nice to understand the exact sticking points here. Share vs transfer . . . 17:22:05 Carl: Open to hearing what people want to discuss and propose. 17:23:03 David Wainberg: Two points on this. 1) Dependencies issue. hard to nail down w/o knowing what work terms need to do wherever they appear in spec. have concerns with inclusion of sharing inside collect. Would rather see that separate. Esp where party may be passing data thru and not retaining. 17:23:35 Wainberg: There's text there now - EFF proposal. Key component of collects is "retain." 17:23:47 Wainberg: Singer's def gets at that. 17:23:59 Wainberg: Question was re: concerns on Vinay's edit> 17:24:02 q? 17:24:04 aack dw 17:24:05 ack dwainberg 17:24:15 Carl: Trouble with concepts of sharing? 17:24:33 I think dwainberg thinks a party should be able to share data without collecting it 17:24:34 Wainberg: yes 17:24:40 ack dsinger 17:24:40 dsinger, you wanted to point out the problem with 'network transaction' 17:24:43 Yes, but dwainberg also has a problem with the current editors' text on "collect" 17:25:24 David Singer: Def of network transaction is vaguely defined. We should knock this off as it's trivial. Should define as HTTP request in response. In request, know 1p v. 3p, etc. Otherwise, determination after network interaction is impossible to determine. 17:25:29 We can add the network transaction definition for next week. I thought about doing it for this week --- good idea. 17:25:35 does "HTTP response" mean the final response, or include redirects 17:25:37 issue-228? 17:25:37 issue-228 -- Revise the Network Interaction definition -- raised 17:25:37 http://www.w3.org/2011/tracking-protection/track/issues/228 17:25:37 HTTP request and its corresponding response(s) 17:25:57 dsinger: a network transaction is an HTTP request and its matching response. (or something like that) 17:26:12 DSinger: We did discuss differentiating collecting and retaining. 17:26:16 this may be simple; we have a proposal from JackHobaugh and revisions from fielding, and maybe they could quickly agree with dsinger 17:26:23 what about persistent connections in which multiple responses may be received to a single request? 17:26:32 228 is a dup 17:26:32 Dsinger: Should keep separate in use, rather than merging in def. 17:26:33 I don't remember the issue number 17:26:49 HTTP 2.0 is likely to change to concept of request/response or at least expand it\ 17:27:18 Roy: We need a def of network interaction. I don't think it has anything to do with def of retention, other than clearly retention means beyond the current date, which is in any case a response. 17:27:20 bryan, I think fielding's "corresponding response(s)" is to address the multiple response 17:27:23 Agree with fielding, not sure they're dependencies, but we can queue up network transaction for next week in any event. 17:27:38 Carl: Agree with david's def? 17:27:49 agree with Roy, most of the terms to be defined are related and cannot be defined in isolation and without regard to other dependent definitions. 17:27:50 that's fine 17:28:00 corresponding can also include asynchronous push notifications that occur over time 17:28:06 David: We can knock this off and it will clarify other things. 17:28:40 issue-217? 17:28:40 issue-217 -- Terminology for user action, interaction, and network interaction -- raised 17:28:40 http://www.w3.org/2011/tracking-protection/track/issues/217 17:28:41 Bryan: Not sure - concept of request & response is something that's evolving. Even with http 1.1, not necessarily a fixed thing. 17:29:19 Bryan: This can be a meta-transaction. Doesn't reflect the depth of possibility in interaction. 17:29:33 David: Don't think persistent connections don't come into it. 17:29:48 Correction: Don't think persistent connections come into it. 17:30:24 apologies all, I have to drop off. 17:30:26 -[Mozilla] 17:31:23 Number of requests received on persistent connection doesn't relate to user action. 17:31:40 We will queue this up for next week. 17:32:07 Justin: We will put this on for next week. 17:32:09 Websockets is out of scope 17:32:12 -LeeTien 17:32:26 per fielding, I think we can combine issue-217 and issue-228, for what it's worth 17:32:29 (and only go to a first party) 17:32:40 would you like a summary of issue-201 sent in email? 17:32:42 -hefferjr 17:32:43 -Peder_Magee 17:32:43 -ChrisPedigoOPA 17:32:45 -eberkower 17:32:45 -Joanne 17:32:45 -[CDT] 17:32:46 -Brooks 17:32:48 -hwest 17:32:48 -Carl_Cargill 17:32:48 - +1.203.563.aacc 17:32:48 -kulick 17:32:49 npdoty, yep 17:32:49 -WileyS 17:32:49 dsinger, I think that would be useful 17:32:51 -Bryan_Sullivan 17:32:52 -Chris_IAB 17:32:52 -moneill2 17:32:52 -Jack_Hobaugh 17:32:52 -adrianba 17:32:55 -npdoty 17:32:57 -WaltMichel 17:32:58 robsherman has joined #dnt 17:32:58 -dwainberg 17:32:59 Zakim, list attendees 17:32:59 As of this point the attendees have been +1.646.654.aaaa, eberkower, +1.646.827.aabb, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, 17:33:02 ... Carl_Cargill, dsinger, justin, GShand, Jeff, schunter, gshans, Joanne, Fielding, Jack_Hobaugh, vinay, Chapell, Adamp, sidstamm, Chris_IAB, moneill2, LeeTien, hefferjr, 17:33:02 ... Bryan_Sullivan, ChrisPedigoOPA, hwest, [Microsoft], kulick, WileyS, adrianba, Brooks, BerinSzoka, +1.203.563.aacc, Amy_Colando, MattHayes 17:33:06 -Wendy 17:33:06 -Jeff 17:33:07 -MattHayes 17:33:09 rrsagent, please draft the minutes 17:33:09 I have made the request to generate http://www.w3.org/2013/10/23-dnt-minutes.html npdoty 17:33:17 -??P7 17:33:37 -[Apple] 17:33:41 -[Microsoft] 17:33:44 -Fielding 17:34:05 Chairs: Do we want to meet now or in 30min? 17:39:11 adrianba has left #dnt 18:05:01 disconnecting the lone participant, Adamp, in T&S_Track(dnt)12:00PM 18:05:02 T&S_Track(dnt)12:00PM has ended 18:05:02 Attendees were +1.646.654.aaaa, eberkower, +1.646.827.aabb, dwainberg, Wendy, npdoty, MECallahan, Thomas_Schauf, WaltMichel, Peder_Magee, SusanIsrael, Carl_Cargill, dsinger, 18:05:02 ... justin, GShand, Jeff, schunter, gshans, Joanne, Fielding, Jack_Hobaugh, vinay, Chapell, Adamp, sidstamm, Chris_IAB, moneill2, LeeTien, hefferjr, Bryan_Sullivan, ChrisPedigoOPA, 18:05:03 ... hwest, [Microsoft], kulick, WileyS, adrianba, Brooks, BerinSzoka, +1.203.563.aacc, Amy_Colando, MattHayes