Showing posts with label Slipstream. Show all posts
Showing posts with label Slipstream. Show all posts

Wednesday, May 1, 2013

Slipstream: Personal Data Takes a Winding Path Into Marketers’ Hands

“What’s in it for you?” said the flier from MS LifeLines, a support network for patients and their families that is financed by two drug makers, Pfizer and EMD Serono. “Strategies for managing and understanding your symptoms. Information about available treatments for relapsing M.S.”

The thing is that my friend, who requested that I keep her name out of this column, does not have multiple sclerosis, an autoimmune disease that affects the central nervous system.

But last year, she did search online for information about various diseases, including M.S., on a number of consumer health sites. She also subscribed to an online recommendation engine where she looked up consumer reviews of local physicians.

Now she wondered whether one of those companies had erroneously profiled her as an M.S. patient and shared that profile with drug-company marketers. She worried about the potential ramifications: Could she, for instance, someday be denied life insurance on the basis of that profile? She wanted to track down the source of the data, correct her profile and, if possible, prevent further dissemination of the information. But she didn’t know which company had collected and shared the data in the first place, so she didn’t know how to have her entry removed from the original marketing list.

In our data-happy society, the case of the mistaken M.S. patient illustrates a lack of visibility for people interested in how information about them changes hands. When consumers fill out warranty cards, enter sweepstakes, answer online surveys, agree to online privacy policies or sign up to receive e-mails from brands, they often don’t realize that certain details — linked to them by name or by customer ID code — may be passed along to other companies. That can make it hard for people seeking to correct errors to find the keepers of their marketing profiles.

I was ruminating on that problem in Washington on Wednesday, when I paid a visit to Senator John D. Rockefeller IV, the West Virginia Democrat, who has made consumer privacy one of his signature issues.

Americans, he says, should be allowed “to be left alone.”

In part, this belief stems from his own nature. He describes himself as an introvert, a person who would rather stay at home and listen to Bach fugues than attend Beltway shindigs. But mainly, he just thinks that privacy is a fundamental American right.

“The principles are remarkably simple,” Mr. Rockefeller said, comfortably installed in an armchair in his Senate office. Americans, he continued, should have the right to decide what kind of marketing material is sent to them and what other people know about them: “People have the right to be private insofar as it’s possible in the modern world.”

Earlier that day, the Senate Committee on Commerce, Science and Transportation, of which Mr. Rockefeller is chairman, had convened a hearing on the status of an online privacy mechanism for consumers called Do Not Track. The idea behind it is that people should be able to turn on settings in their Internet browsers to signal advertisers, data brokers and other third-party operators not to collect information about their activities across the Web. Advertising networks and other entities would theoretically honor those don’t-track-me flags by restricting the amount of information they collected.

But years after the Federal Trade Commission recommended that advertisers adopt such a browser-based system, consumer advocates and ad industry groups still seem at odds over fundamental issues — including the very definition of Do Not Track. In an attempt to pressure the ad industry to get with the program, the Senate committee held a hearing.

“I want to get to the bottom of this controversy,” Mr. Rockefeller said in his opening statement. “I want the witnesses to publicly explain exactly what they believe has gone wrong, and what they are prepared to offer to make Do Not Track a reality for consumers.”

Yet he acknowledges that this kind of privacy option for online consumers, even if it eventually goes into effect, does not address a larger issue: the thousands of details that third-party data gatherers, who typically don’t interact directly with consumers, have already amassed about a majority of adults in the United States. For instance, there is no federal law that requires such companies to allow consumers to have access to and correct marketing data that’s been compiled about them. That is partly why the Senate committee opened an investigation last year into the practices of leading data brokers.

Mr. Rockefeller says the investigation is continuing.

So I decided — after asking permission from the friend who received the M.S. flier — to see if I could find out how erroneous information about her health status moved from one company to another. It wasn’t an obvious trajectory.

Erin-Marie Beals, a spokeswoman for EMD Serono, told me that MS LifeLines sends marketing materials only to people who have indicated an interest in multiple sclerosis and have provided their contact information either directly to MS LifeLines or through other programs, like online surveys or subscriptions. Ms. Beals pointed me to the firm that had provided my friend’s information — the KBM Group, a marketing company that specializes in consumer data and analytics.

Ultimately, Barbara Palmer, the senior vice president for marketing at the KBM Group, told me that her firm had obtained the information from a survey company whose online questionnaire my friend had filled out in 2010. That survey, Ms. Palmer said, asked general questions, including some about health interests. She said it also contained a specific disclosure: “By completing the health-related questions on the survey, you are consenting to the use of this information for direct marketing purposes.”

Ms. Palmer added that her company honored people’s requests to opt out of its file. The Direct Marketing Association also provides a program for consumers who want to opt out of receiving all kinds of pitches by mail.

At the end of the day, information about my friend ended up in the hands of at least two companies she had never heard of, let alone interacted with. Other companies may also have obtained the data.

The proliferation of intimate details about people’s health, financial or academic status — even when the data are correct — particularly troubles Senator Rockefeller. Although laws like the Fair Credit Reporting Act and the Health Insurance Portability and Accountability Act limit the use of people’s credit and medical records, data brokers are often able to compile consumers’ financial and health information through other means.

“One of the things that really disturbs me in privacy, or the lack of it, is the way that data brokers can go in and buy all your health records, your financial records — they can get it one way or another,” Mr. Rockefeller said during the hearing. “What is of you, they can have.”

He added: “We are talking about a very, very large industry here which can decide to do that and which is doing that.”

E-mail: slipstream@nytimes.com.

Monday, March 4, 2013

Slipstream: Multiple Video Feeds Give Arena Fans the Comforts of Home

In a suite overlooking the home-side backboard, Chip Foley is watching the basketball game via live video feeds on his iPhone and iPad.

Mr. Foley is the director of building technology at the Forest City Ratner Companies, the real estate firm that developed the Barclays Center in Downtown Brooklyn and is a minority owner of the Nets. Last month, the center introduced the latest thing in virtual spectatorship: an app that streams three different high-definition video feeds for stadium visitors who want to use their smartphones and tablets to follow the game they have come to see in person.

The goal, arena executives say, is to reproduce the multiscreen experience that many fans have already adopted in the man caves of their dens or living rooms. Fans like Mr. Foley, for instance, whose home setup for events like the Super Bowl includes a 60-inch, flat-screen TV augmented by two laptops (one to follow the coaches, another for the overhead view), not to mention the iPad on which he monitors game-related Twitter posts. To compete with couch multitasking, Barclays Center has installed a high-density Wi-Fi network and multicast video technology from Cisco Systems, called StadiumVision Mobile, intended to power similarly speedy video streaming, tweeting and photo-sharing for fans at Nets games.

From instant replay technology to microphones that transmit players’ and coaches’ live comments, broadcasters have spent decades developing techniques to make fans at home feel as if they are part of the game. Now, some arenas like Barclays are adding a complementary strategy: “You are trying to replicate that experience you would have on your couch,” Mr. Foley says. Fans at Nets games, for example, can activate instant replays on the mobile feeds they are watching, a pause-and-rewind technique that mimics a remote control.

Live spectator sports involve a kind of communion — otherwise, why bother leaving the house? — that personal devices have the potential to dilute. Still, the professional sports industry may just be playing catch-up with screen-centric consumers.

After all, many fans already prefer watching magnified views on a Jumbotron to the miniature-seeming live play somewhere down below them. Likewise, some football fans now tailgate next to college bowls, bringing their own satellite dishes and TVs so they can watch the game from the parking lot instead of the stadium, says John Nauright, a professor of sports studies at George Mason University in Fairfax, Va.

And it’s not just sports. Many colleges now promote online courses over in-person lectures.

OVER the last several years, Cisco has tapped into this trend of audiences accustomed more to simulcast than to live spectacle; it has outfitted more than 100 arenas in 20 countries with its networks. One product, StadiumVision, is a video distribution system that allows the display of customized digital signs and videos on hundreds of monitors throughout an arena; the installation cost varies, depending on the site and the number of monitors, but it can cost several million dollars per stadium.

Sitting in the suite in the Barclays Center, Michael Caponigro, Cisco’s leader of global solutions marketing for sports and entertainment, says the idea is to keep fans continuously connected to the game via video monitors whether they are sitting in skyboxes, wandering concourses or standing in line at concession booths. Teams, sponsors and advertisers use the same video monitors to blanket stadiums with digital marketing.

The advanced system that Cisco installed in the Barclays Center extends that idea of continuous connectivity to individual seats, Mr. Caponigro says. It will also allow teams and brands to tailor mobile marketing to specific fans.

“We have placed two big bets with our customers, with video and mobility at the intersection of sport,” he says. Above and below the suite in the darkened stadium, smartphones glow and flicker out like fireflies. “We believe this is the new frontier of fan experience,” he adds.

To try out the new feeds, Mr. Foley, the director of building technology, clicks on the main video stream for the game on his iPad app, watching as Joe Johnson, the Nets shooting guard, disentangles himself from the pack, leaps, shoots and scores. During that play, Mr. Foley simultaneously watches on his iPhone a second, live video stream called the Slam Cam — a camera positioned directly behind the basket; a ball rockets into close-up view, hovers for a moment and then sinks through the net. A third device, an iPod Touch, displays a rawer video stream, from a hand-held sideline camera following the Bucks as they dribble back down the court.

E-mail: slipstream@nytimes.com. Twitter: @natashanyt

Monday, January 7, 2013

Slipstream: Legislation Would Regulate Tracking of Cellphone Users

THERE are three things that matter in consumer data collection: location, location, location.

E-ZPasses clock the routes we drive. Metro passes register the subway stations we enter. A.T.M.’s record where and when we get cash. Not to mention the credit and debit card transactions that map our trajectories in comprehensive detail — the stores, restaurants and gas stations we frequent; the hotels and health clubs we patronize.

Each of these represents a kind of knowing trade, a conscious consumer submission to surveillance for the sake of convenience.

But now legislators, regulators, advocacy groups and marketers are squaring off over newer technology: smartphones and mobile apps that can continuously record and share people’s precise movements. At issue is whether consumers are unwittingly acquiescing to pervasive tracking just for the sake of having mobile amenities like calendar, game or weather apps.

For Senator Al Franken, the Minnesota Democrat, the potential hazard is that by compiling location patterns over time, companies could create an intimate portrait of a person’s familial and professional associations, political and religious beliefs, even health status. To give consumers some say in the surveillance, Mr. Franken has been working on a locational privacy protection bill that would require entities like app developers to obtain explicit one-time consent from users before recording the locations of their mobile devices. It would prohibit stalking apps — programs that allow one person to track another person’s whereabouts surreptitiously.

The bill, approved last month by the Senate Judiciary Committee, would also require mobile services to disclose the names of the advertising networks or other third parties with which they share consumers’ locations.

“Someone who has this information doesn’t just know where you live,” Mr. Franken said during the Judiciary Committee meeting. “They know the roads you take to work, where you drop your kids off at school, the church you attend and the doctors that you visit.”

Yet many marketers say they need to know consumers’ precise locations so they can show relevant mobile ads or coupons at the very moment a person is in or near a store. Informing such users about each and every ad network or analytics company that tracks their locations could hinder that hyperlocal marketing, they say, because it could require a new consent notice to appear every time someone opened an app.

“Consumers would revolt if this was the case, and applications could be rendered useless,” said Senator Charles Grassley, the Iowa Republican, who promulgated industry arguments during the committee meeting. “Worse yet, free applications that rely on advertising could be pushed by the consent requirement to become fee-based.”

Mr. Franken’s bill may seem intended simply to protect consumer privacy. But the underlying issue is the future of consumer data property rights — the question of who actually owns the information generated by a person who uses a digital device and whether using that property without explicit authorization constitutes trespassing.

In common law, a property intrusion is known as “trespass to chattels.” The Supreme Court invoked the legal concept last January in United States v. Jones, in which it ruled that the government had violated the Fourth Amendment — which protects people against unreasonable search and seizure — by placing a GPS tracking device on a suspect’s car for 28 days without getting a warrant.

Some advocacy groups view location tracking by mobile apps and ad networks as a parallel, warrantless commercial intrusion. To these groups, Mr. Franken’s bill suggests that consumers may eventually gain some rights over their own digital footprints.

“People don’t think about how they broadcast their locations all the time when they carry their phones. The law is just starting to catch up and think about how to treat this,” says Marcia Hofmann, a senior staff lawyer at the Electronic Frontier Foundation, a digital rights group based in San Francisco. “In an ideal world, users would be able to share the information they want and not share the information they don’t want and have more control over how it is used.”

Even some marketers agree.

One is Scout Advertising, a location-based mobile ad service that promises to help advertisers pinpoint the whereabouts of potential customers within 100 meters. The service, previously known as ThinkNear and recently acquired by Telenav, a personalized navigation service, works by determining a person’s location; figuring out whether that place is a home or a store, a health club or a sports stadium; analyzing weather and other local conditions; and then showing a mobile ad tailored to the situation.

Eli Portnoy, general manager of Scout Advertising, calls the technique “situational targeting.” He says Crunch, the fitness center chain, used the service to show mobile ads to people within three miles of a Crunch gym on rainy mornings. The ad said: “Seven-day pass. Run on a treadmill, not in the rain.”

When a person clicks on one of these ads, Mr. Portnoy says, a browser-based map pops up with turn-by-turn directions to the nearest location. Through GPS tracking, Scout Advertising can tell when someone starts driving and whether that person arrives at the site.

Despite the tracking, Mr. Portnoy describes his company’s mobile ads as protective of privacy because the service works only with sites or apps that obtain consent to use people’s locations. Scout Advertising, he adds, does not compile data on individuals’ whereabouts over time.

Still, he says, if Congress were to enact Mr. Franken’s location privacy bill as written, it “would be a little challenging” for the industry to carry out, because of the number and variety of companies involved in mobile marketing.

“We are in favor of more privacy,” Mr. Portnoy says, “but it has to be done within the nuances of how mobile advertising works so it can scale.”

A SPOKESMAN for Mr. Franken said the senator planned to reintroduce the bill in the new Congress. It is one of several continuing government efforts to develop some baseline consumer data rights.

“New technology may provide increased convenience or security at the expense of privacy and many people may find the trade-off worthwhile,” Justice Samuel Alito wrote last year in his opinion in the Jones case. “On the other hand,” he added, “concern about new intrusions on privacy may spur the enactment of legislation to protect against these intrusions.”

E-mail: slipstream@nytimes.com.

Wednesday, December 12, 2012

Slipstream: Effort to Clarify Mobile App Data Rights Hits Snags

We think they’re free, or nearly free, and invite them in — without always knowing exactly what’s inside.

Apps often collect all kinds of information from our smartphones, like our contact lists and data on our precise locations. Both Android and iPhone apps are supposed to ask users’ permission first. But many people probably don’t know that third parties, like ad networks, analytics companies and data brokers, may also gain access to that information, security experts say.

An Android photo-sharing app, for instance, might request access to a user’s contacts, making it easy for that user to share photos, says Harry Sverdlove, the chief technology officer at Bit9, a cybersecurity firm. But a banner ad running on that same app, he says, might also be able to get access to that list, too, and use it to profile the user’s activities.

“It’s like the app is asking, ‘May I have permission to enter your home?’ ” Mr. Sverdlove says. “Maybe I am coming over to visit and have dinner. Maybe I am coming over to steal.”

Now, a new joint effort of the app industry and advocacy groups is working to give consumers more clarity on this issue. Last month, the coalition — it includes the Application Developers Alliance, the American Civil Liberties Union, Consumer Action and the World Privacy Forum — proposed that mobile apps voluntarily display standardized, short-form notices that would list the main types of data they collect and the entities with which that information is shared.

The idea came in response to a federal effort to update consumer privacy rights for the digital era.

“App developers want to do something that advances consumers’ trust in their industry,” says Tim Sparapani, senior adviser for policy and law at the Application Developers Alliance, an industry group. “To make it work, they want it to be implementable and easy.”

The White House earlier this year asked the National Telecommunications and Information Administration, a division of the Commerce Department, to gather industry and advocacy groups together in an effort to develop a “Consumer Privacy Bill of Rights.” After reviewing public commentary on the process, the telecommunications agency announced its first step would be to convene interested parties to work out a code of conduct for transparency in how mobile apps handle consumer data.

The process has been bumpy. The mobile app meetings have been beset by animosity and incivility. And some of the parties are operating on different channels. Some advocacy groups have been publicly pushing for comprehensive, detailed disclosures on data use by apps and third parties. Meanwhile, an advertising industry alliance has been working outside of the process to privately develop its own self-regulatory code of conduct.

A recent report about the collection of mobile device location data issued by the Government Accountability Office faulted the telecommunications agency for its unstructured approach. Although the collection and sharing of location data could put consumers at serious risk of surveillance, stalking and identity theft, the report said, the telecommunications agency “has not set specific goals, milestones and performance measures for this effort.”

“Consequently, it is unclear if or when the process would address mobile location privacy,” the G.A.O. said.

The telecommunications agency sees its role as a facilitator or convener of the process, not as a director or active member.

“I am pretty pleased with the progress the stakeholders have made so far,” John Morris, the agency’s director of the Office of Policy, Analysis and Development, said in a phone interview last Thursday. “I am looking forward to seeing them reach a conclusion.”

But some stakeholders say they have been frustrated with the lack of progress. That is why the app developer and advocacy groups worked on their own to develop a more practical approach, designing what they call “voluntary transparency screens.”

“There’s a whole lot of shouting going on about process. There’s a whole lot of shouting going on about substance,” Jon Potter, the president of the Application Developers Alliance, said at a meeting of the stakeholders on Nov. 30. “What if we close the door, lower the temperature and try to get something done?”

THE level of strife so far over the narrow issue of mobile app transparency, some advocates say, doesn’t bode well for the larger federal effort to work out a comprehensive consumer bill of privacy rights.

App industry representatives and advocates wrangled for months to hammer out prototypes for their short-form notices, negotiating over the data disclosures they felt consumers should see and different ways to present them. They came up with an idea that users could click on a disclosure screen or two before they downloaded an app.

A first screen, the coalition proposed, might list the types of data an app collected, like a device’s location, personal contacts, Web browsing history, photos, financial or health information. A second screen could list the kinds of entities — ad networks, data brokers, data analytics companies, government agencies, social networks and so on — that could also gain access to that data. Or it could all be on one screen.

The idea, Mr. Potter says, is to give consumers a quick way to compare apps not just on utility but also on the extent of data collection. In an industry where long-winded, opaque privacy policies have become the norm, the proposed short notices seem radical in their clarity and brevity.

“The process is about effectively communicating to consumers what data is being collected and who it is being shared with,” Mr. Potter says.

Ad industry representatives applauded the simplicity of the notices. But they vociferously objected to the idea that app users would have to click through a screen before they could use an app.

“That you’d have to scroll through all this privacy stuff before you get to the app, there’s no public call for that,” said Stuart P. Ingis, a lawyer representing the Direct Marketing Association, an industry group, in the negotiations on mobile app transparency. “Consumers don’t want that.”

Mr. Ingis also represents the Digital Advertising Alliance, an ad industry self-regulatory initiative that offers an ad-choices program for Internet users. The alliance, he says, has been working outside of the telecommunications agency process to privately develop its own guidelines for third parties that collect consumer data across apps.

But advocates and app developers argue that consumers should receive clear notices of mobile app and third-party data collection practices before they download apps. It would be good for consumers and for commerce, they say.

“I think app developers see the market advantage to this,” says Michelle De Mooy, a senior associate at Consumer Action, a consumer group based in San Francisco. “The goal is to provide transparency that consumers, who after all are the customer of the apps, have asked for.”

E-mail: slipstream@nytimes.com

Monday, October 15, 2012

Slipstream: Do-Not-Track Movement Is Drawing Advertisers’ Fire

Do Not Track mechanisms are features on browsers — like Mozilla’s Firefox — that give consumers the option of sending out digital signals asking companies to stop collecting information about their online activities for purposes of targeted advertising.

First came a stern letter from nine members of the House of Representatives to the Federal Trade Commission, questioning its involvement with an international group called the World Wide Web Consortium, or W3C, which is trying to work out global standards for the don’t-track-me features. The legislators said they were concerned that these options for consumers might restrict “the flow of data at the heart of the Internet’s success.”

Next came an incensed open letter from the board of the Association of National Advertisers to Steve Ballmer, the C.E.O. of Microsoft, and two other company officials. Microsoft had committed a grievous infraction, wrote executives from Dell, I.B.M., Intel, Visa, Verizon, Wal-Mart and other major corporations, by making Do Not Track the default option in the company’s forthcoming Internet Explorer 10 browser. If consumers chose to stay with that option, the letter warned, they could prevent companies from collecting data on up to 43 percent of browsers used by Americans.

“Microsoft’s action is wrong. The entire media ecosystem has condemned this action,” the letter said. “In the face of this opposition and the reality of the harm that your actions could create, it is time to realign with the broader business community by providing choice through a default of ‘off’ on your browser’s ‘do not track’ setting.”

So far, Microsoft has shrugged off advertisers’ complaints. In an e-mailed statement, Brendon Lynch, Microsoft’s chief privacy officer, said a recent company study of computer users in the United States and Europe concluded that 75 percent wanted Microsoft to turn on the Do Not Track mechanism.

“Consumers want and expect strong privacy protection to be built into Microsoft products and services,” Mr. Lynch wrote.

The tone of the industry offensive may seem a bit strident, given that the W3C has yet to decide how to implement the don’t-track-me mechanisms — or even what they signify. For the moment, that means the browser buttons are little more than digital bumper stickers whose sentiments companies are free to embrace or entirely ignore.

But what is really at stake here is the future of the surveillance economy.

The advent of Do Not Track threatens the barter system wherein consumers allow sites and third-party ad networks to collect information about their online activities in exchange for open access to maps, e-mail, games, music, social networks and whatnot. Marketers have been fighting to preserve this arrangement, saying that collecting consumer data powers effective advertising tailored to a user’s tastes. In turn, according to this argument, those tailored ads enable smaller sites to thrive and provide rich content.

“If we do away with this relevant advertising, we are going to make the Internet less diverse, less economically successful, and frankly, less interesting,” says Mike Zaneis, the general counsel for the Interactive Advertising Bureau, an industry group.

But privacy advocates argue that in a digital ecosystem where there may be dozens of third-party entities on an individual Web page, compiling and storing information about what a user reads, searches for, clicks on or buys, consumers should understand data mining’s potential costs to them and have the ability to opt out.

“If you are looking up the word ‘cancer’ ” on a health site, says Dan Auerbach, a staff technologist at the Electronic Frontier Foundation, a digital rights group in San Francisco, “there’s a high probability that you have cancer or are interested in that. This is the sort of data that can be collected.” He adds: “Consumers absolutely have a right to know how their information is being used and to opt out of having their information used in ways they don’t like.”

But the two sides seem to have reached an impasse. When the W3C met recently in Amsterdam to hammer out Do Not Track standards, as my colleague Kevin J. O’Brien reported in an article earlier this month, advertising industry executives and privacy advocates accused each other of trying to stymie the process.

“There is a strong concern that the W3C is not the right forum to be making this decision,” says Rachel Thomas, the vice president of government affairs at the Direct Marketing Association, a trade group based in Manhattan. “The attempt to set public policy is entirely outside their area of expertise.”

During the Amsterdam meeting, Ms. Thomas proposed that Do Not Track signals should actually permit data collection for advertising purposes, the very thing the mechanisms were designed to control. That provocative idea went over with European privacy advocates about as well as a smoker lighting up in a no-smoking zone full of asthmatics.

Indeed, some prominent consumer advocates have interpreted the industry’s proposal as an act of bad faith.

“While many advertisers do support privacy, there is clearly a rogue element of advertising networks that wants to subvert the process,” says Jon D. Leibowitz, the chairman of the Federal Trade Commission. “Or so it seems to me.”

Earlier this year at a White House event, the Digital Advertising Alliance, or D.A.A., an industry consortium, pledged to honor don’t-track-me signals so long as the systems required consumers to make an affirmative choice. But last Tuesday, the consortium published guidelines saying that it viewed Microsoft’s latest browser setting as an automatic, machine-driven choice preselected by a company — not a choice actively made by an individual consumer. During the installment process, Microsoft’s new software actually does give users a choice of whether to keep the mechanism on, or to turn it off. Nevertheless, the consortium said it would not require members to honor the forthcoming browser’s don’t-track-me signals.

Besides, the D.A.A. has already established its own program for consumers who want to opt out of receiving ads tailored to their online behavior, says Mr. Zaneis, whose own group is a member of that consortium. The consortium remains committed to incorporating browser signals into its program, he says, provided that the systems require consumers to make affirmative choices and give them information on the potential effects of eschewing tailored ads.

“We have self-regulation. It’s working very well,” he says. “Why don’t we give that a chance to succeed?”

SOME government officials vehemently disagree. In a letter to the F.T.C. earlier this month, Senator John D. Rockefeller IV, Democrat of West Virginia, called the industry program an “ineffective regime” riddled with exceptions.

“To date, self-regulation for the purposes of consumer privacy protection has failed,” Mr. Rockefeller wrote.

Now regulators are warning that opposition to Do Not Track could backfire on advertisers, by giving browsers more incentive to empower frustrated users.“We might see a technology arms race with browsers racing to see — by letting consumers block ads — who can be the most privacy-protective,” says Mr. Leibowitz of the F.T.C. “Maybe that’s not a bad thing.”

E-mail: slipstream@nytimes.com.

Thursday, September 20, 2012

Slipstream: In Microsoft’s New Browser, the Privacy Light Is Already On

IT could usher in a new era of online privacy. Or it might bowdlerize the Internet as we know it.

Then again, it might do almost nothing at all.

The item in question is Microsoft’s latest version of its Internet Explorer browser, scheduled to be available to consumers in late October, packaged with Windows 8. The browser comes with an option called “do not track.” It lets users indicate whether they’d like to see ads tailored to them by companies that track their online browsing histories — or whether they’d rather not have their online activities tracked, recorded, analyzed and stored for marketing purposes.

Of course, browsers like Firefox from Mozilla, Safari from Apple and even an earlier version of Internet Explorer already offered this choice for people who expressed a preference. But Microsoft is going further — by making privacy a more public issue. The new Internet Explorer 10 comes with the don’t-track-me option automatically enabled, a fact that the software makes clear. During installation, a notice will appear giving users the choice to keep that preselected don’t-track-me preference as is, or switch it off on a customization menu.

It’s a radical move for a technology company, especially one like Microsoft, with an ad business of its own.

“No one says today, when a consumer first loads a product, ‘Hey, by the way, there are some privacy choices you may want to consider,’ ” says Alex Fowler, the global privacy and policy leader at Mozilla. He believes that this may be the first time that privacy features so prominently “in the first-run experience of a consumer software product.”

Right now, however, people who raise the do-not-track flag are making a mostly symbolic choice, having their browsers send out a preference signal. Web sites that receive the signal can honor it — or simply disregard it.

Over the last few years, as tailored ads have become more personal and persistent — often pursuing users around the Web with pitches for products they recently viewed but elected not to buy — many consumers have sought ways to navigate an advertising system that can seem too close for comfort. To increase people’s options, the Digital Advertising Alliance, an industry group, publicly introduced a self-regulatory program in 2010, and more recently an updated consumer site,

youradchoices.com. It explains how behavioral advertising works and gives consumers the choice to opt out of the practice by the group’s members.

But now major browsers are flexing their muscles with an alternate option, the do-not-track button, hoping to gain traction with consumers who want to manage their Internet experience on their own devices.

“There is vast consumer awareness and concern about privacy,” says Fatemeh Khatibloo, a senior analyst in customer intelligence at Forrester Research. “If a browser can differentiate itself by saying ‘we provide you better privacy tools,’ I think they’ll increase adoptions.”

But the specter of people opting out of tracking en masse presents a serious risk for marketers.

Consumer data, marketers say, is the fuel that powers the Internet, driving ads that support free content and e-mail services, search engines and social networks. If millions of consumers opted out of behavior-based advertising, industry representatives argue, many ad-sponsored sites could shut down or put up pay walls for people who elect not to see the ads. Internet Explorer 10 is only heightening their concerns. Because consumers tend not to change preset technology options, advertisers worry that the browser could shift millions of people to the do-not-track category.

“That would drastically skew the economic model underlying the Internet,” says Stuart Ingis, counsel to the Digital Advertising Alliance. “The choice is the Internet as we know it, or a much smaller, cannibalized Internet where you don’t have the diversity.”

E-mail: slipstream@nytimes.com.

Tuesday, July 24, 2012

Slipstream: Acxiom Consumer Data, Often Unavailable to Consumers

I recently asked to see the information held about me by the Acxiom Corporation, a database marketing company that collects and sells details about consumers’ financial status, shopping and recreational activities to banks, retailers, automakers and other businesses. In investor presentations and interviews, Acxiom executives have said that the company — the subject of a Sunday Business article last month — has information on about 500 million active consumers worldwide, with about 1,500 data points per person. Acxiom also promotes a program for consumers who wish to see the information the company has on them.

As a former pharmaceuticals industry reporter who has researched all kinds of diseases, drugs and quack cures online, I wanted to learn, for one, whether Acxiom had pegged me as concerned about arthritis, diabetes or allergies. Acxiom also has a proprietary household classification system that places people in one of 70 socioeconomic categories, like “Downtown Dwellers” or “Flush Families,” and I hoped to discover the caste to which it had assigned me.

But after I filled out an online request form and sent a personal check for $5 to cover the processing fee, the company simply sent me a list of some of my previous residential addresses. In other words, rather than learning the details about myself that marketers might use to profile and judge me, I received information I knew already.

It turns out that Acxiom, based in Little Rock, Ark., furnishes consumers only with data related to risk management, like their own prison records, tax liens, bankruptcy filings and residential histories. For a corporate client, the company is able to match customers by name with, say, the social networks or Internet providers they use, but it does not offer consumers the same information about themselves.

Jennifer Barrett Glasgow, Acxiom’s chief privacy officer, said that the company kept consumer data in different databases and that its system was not designed to assemble all the information it had amassed on a single person.

“We do not have the capability to look up an individual’s data in the system,” Ms. Barrett Glasgow said. “We don’t have a search-by-name capability.”

Data brokers like Acxiom have developed advanced techniques to collect and collate information about consumers’ offline, online and mobile behavior. But they have been slow to develop innovative ways for consumers to gain access to the information that companies obtain, share and sell about them for marketing purposes.

Now federal regulators are pressuring data brokers to operate more transparently. In a report earlier this year, the Federal Trade Commission recommended that the industry set up a public Web portal that would display the names and contact information of data brokers, as well as describe consumers’ data access rights and other choices.

Julie Brill, a member of the Federal Trade Commission, said consumers should have access to all the details that data brokers collect on them, as well as any analyses that the companies sell about their behavior.

“I include in that not just the raw data, but also how that information has been analyzed to place the consumer into certain categories for marketing or other purposes,” she said. “I believe that giving consumers this kind of granularity will greatly increase consumer trust in the information flow process and will lead to more accurate marketing.”

At the moment, however, information brokers have wildly different policies. Acxiom lets people opt out of its marketing databases, while Epsilon, another marketing services firm, allows people to opt out of having their data rented to third parties. Epsilon says it will also furnish individuals, upon request, with general information about their past retail transactions — including the categories and years of purchase. But it does not include exact product or retailer names.

Andrew Frawley, the president of Epsilon, says his company has set up a task force to explore giving consumers greater access and choices.

“We agree in principle that more transparency is better,” he said.

But setting up a system for consumers to gain access to their own marketing data could be costly and technically challenging for data brokers, said Stuart Madnick, a professor of information technology at the Massachusetts Institute of Technology. Companies would have to develop security systems to verify a consumer’s identity and to ensure that no one else could have access to that individual’s record, he said. At the same time, they would have to be prepared to respond to people who questioned the accuracy of the records.

“How correct is the information they have and are disseminating on you?” Professor Madnick asked. “How do they know who is asking for it?”

Information security experts said data brokers might be reluctant to make public access easier lest consumers react by wanting to opt out of the data collection process altogether.

E-mail: slipstream@nytimes.com.

Saturday, July 21, 2012

Slipstream: Acxiom Consumer Data, Often Unavailable to Consumers

I recently asked to see the information held about me by the Acxiom Corporation, a database marketing company that collects and sells details about consumers’ financial status, shopping and recreational activities to banks, retailers, automakers and other businesses. In investor presentations and interviews, Acxiom executives have said that the company — the subject of a Sunday Business article last month — has information on about 500 million active consumers worldwide, with about 1,500 data points per person. Acxiom also promotes a program for consumers who wish to see the information the company has on them.

As a former pharmaceuticals industry reporter who has researched all kinds of diseases, drugs and quack cures online, I wanted to learn, for one, whether Acxiom had pegged me as concerned about arthritis, diabetes or allergies. Acxiom also has a proprietary household classification system that places people in one of 70 socioeconomic categories, like “Downtown Dwellers” or “Flush Families,” and I hoped to discover the caste to which it had assigned me.

But after I filled out an online request form and sent a personal check for $5 to cover the processing fee, the company simply sent me a list of some of my previous residential addresses. In other words, rather than learning the details about myself that marketers might use to profile and judge me, I received information I knew already.

It turns out that Acxiom, based in Little Rock, Ark., furnishes consumers only with data related to risk management, like their own prison records, tax liens, bankruptcy filings and residential histories. For a corporate client, the company is able to match customers by name with, say, the social networks or Internet providers they use, but it does not offer consumers the same information about themselves.

Jennifer Barrett Glasgow, Acxiom’s chief privacy officer, said that the company kept consumer data in different databases and that its system was not designed to assemble all the information it had amassed on a single person.

“We do not have the capability to look up an individual’s data in the system,” Ms. Barrett Glasgow said. “We don’t have a search-by-name capability.”

Data brokers like Acxiom have developed advanced techniques to collect and collate information about consumers’ offline, online and mobile behavior. But they have been slow to develop innovative ways for consumers to gain access to the information that companies obtain, share and sell about them for marketing purposes.

Now federal regulators are pressuring data brokers to operate more transparently. In a report earlier this year, the Federal Trade Commission recommended that the industry set up a public Web portal that would display the names and contact information of data brokers, as well as describe consumers’ data access rights and other choices.

Julie Brill, a member of the Federal Trade Commission, said consumers should have access to all the details that data brokers collect on them, as well as any analyses that the companies sell about their behavior.

“I include in that not just the raw data, but also how that information has been analyzed to place the consumer into certain categories for marketing or other purposes,” she said. “I believe that giving consumers this kind of granularity will greatly increase consumer trust in the information flow process and will lead to more accurate marketing.”

At the moment, however, information brokers have wildly different policies. Acxiom lets people opt out of its marketing databases, while Epsilon, another marketing services firm, allows people to opt out of having their data rented to third parties. Epsilon says it will also furnish individuals, upon request, with general information about their past retail transactions — including the categories and years of purchase. But it does not include exact product or retailer names.

Andrew Frawley, the president of Epsilon, says his company has set up a task force to explore giving consumers greater access and choices.

“We agree in principle that more transparency is better,” he said.

But setting up a system for consumers to gain access to their own marketing data could be costly and technically challenging for data brokers, said Stuart Madnick, a professor of information technology at the Massachusetts Institute of Technology. Companies would have to develop security systems to verify a consumer’s identity and to ensure that no one else could have access to that individual’s record, he said. At the same time, they would have to be prepared to respond to people who questioned the accuracy of the records.

“How correct is the information they have and are disseminating on you?” Professor Madnick asked. “How do they know who is asking for it?”

Information security experts said data brokers might be reluctant to make public access easier lest consumers react by wanting to opt out of the data collection process altogether.

E-mail: slipstream@nytimes.com.