Skip the navigation

Truste tightens requirements for its seal of approval

By Patrick Thibodeau
December 11, 2002 12:00 PM ET

Computerworld - WASHINGTON -- A leading privacy seal group, Truste, has toughened its privacy seal licensing requirements as well as its ability to monitor the privacy practices of Web sites that display its seal.
One key change requires businesses to adhere to user preferences for no less than 12 months before changing them. The intent is to give customers certainty that their privacy practices won't change soon after they choose them.
Another licensing change closes a loophole that allowed a small number of companies to share personal data to third-party marketing firms without giving customers the ability to opt-out of that data sharing.
Truste is also using technology developed by Watchfire Corp. in Waltham, Mass., that uses automated agents, Web crawlers, to examine Web sites' privacy practices for compliance to their privacy policies. Truste officials believe they will learn of possible problems earlier than they would through annual reviews.
Fran Maier, executive director of San Francisco-based Truste, said the licensing changes, as well as the monitoring effort, "are really sending the message that we take enforcement compliance seriously, that we have teeth."
Truste "has been steadily raising its standards," said Ari Schwartz, associate director for the Center for Democracy and Technology in Washington. All Truste initially required of companies was that they follow their privacy policies. But that left companies free to treat customer information as they saw fit, he said.
"I think companies that commit to this are raising the bar for the industry," said Schwartz, adding that the changes aren't a substitute for privacy legislation. "We still need a baseline law."
Esther Dyson, the chairwoman of EDventure Holdings, who served as chairwoman of the Electronic Frontier Foundation at the time it co-founded Truste, said in an e-mail interview the changes are "a good step in the right direction. I think they mean Truste is putting everyone on notice -- members included -- that it realizes it needs to use its teeth in order for people to believe they are there. In the long run, its members want it to have credibility too."
Truste's license requires that people be able to opt out on third-party information-sharing, but the licensing change sets some limits on how that works. Companies are required to provide consumers with a choice to opt out before sharing their personal information, unless the entity is part of third-party service relationship, such as the shipper for a retailer.
But some companies defined their primary service relationships as marketing and used that as a vehicle to share customer data with anyone. "It wasn't something that we were necessarily allowing before, but we found a loophole that we had to close," said Maier.
Mike Weider, founder and chairman of Watchfire, said the company's systems will check a Web site and look for potential compliance problems. For instance, a company's privacy policy may say it doesn't have third-party cookies. But sometimes when new forms and programs are added to a Web site, a third-party cookie may be unintentionally added, too.
One corporate user said seal programs can help companies in two significant ways.
Mel Peterson, chief privacy officer at consumer giant Procter & Gamble Co. in Cincinnati, uses the Better Business Bureau privacy seal program. Going through the process of applying for a seal is "a good way for a company to get up to speed quickly on what needs to be done" in privacy compliance.
But Peterson said there is a "significant subset" of consumers who do put some weight behind seeing an independent seal.




Read more about Privacy in Computerworld's Privacy Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Privacy White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Privacy White Papers
Privacy Webcasts
A Road Map for Best Practice Social Media Acceptable Use Policy
Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Privacy Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs