Indication of Agent Status, Multiple Domains Owned by One Company

The following is a proposal for future work on P3P submitted following the November 2002 Workshop on the Future of P3P

Purpose

Many companies have sites on multiple domains and, with the current implementations of P3P, have had a very difficult time implementing P3P and compact policies on all its sites. When content is shared between domains, significant difficulties have been encountered with both P3P and compact policies from different sites being inconsistent with the practices of the site using the content or cookies from the second domain being blocked even when the same company owns both sites. In addition, some companies are acting as agents for another company and are simply following the contracting company's privacy policy.

There is no mechanism in the specification to allow a site to handle content sharing between domains or indicate that one site is acting as the agent for another. (HINT is sometimes incapable of fully expressing the relationship between sites.) To encourage adoption of P3P, a mechanism or mechanisms are required to permit a site to easily share content without an unduly complicated P3P policy or compact policies and to indicate that one site is the agent for another site.

Scope

Work on the issues discussed above could, without excluding other ideas, center on the following:

  1. Along with the work being done to review other aspects of compact policies, review the efficiencies, if any, associated with compact policies and even the need for compact policies given the experience of implementing P3P so far; and
  2. Creating a mechanism to allow a site to declare other sites as first-party sites, i.e., that they are all owned by the same company and have the same or similar privacy practices or are acting for another site as an agent and are bound by the other sites privacy policies, in both P3P and compact policies.

Resources

There is no known work already on this topic. However, extensive experience exists in the private sector with implementing P3P on sites that share significant amounts of content. These experiences could be leveraged to identify problems and potential solutions.

Time Frame

The issues here should be relatively easy to resolve. It should be possible to reach consensus on a mechanism to accomplish the last objective above within the timeframe for version 1.1 of the specification. Review of compact policies might take longer to complete. (See P3P Future Work Item 4.)


Brian Zwit

Last update $Date: 2003/05/23 13:58:13 $ by $Author: rigo $