Companies Simplify Data Privacy Notices
P&G, Microsoft are in forefront of move to make Web site disclosures more user-friendly
Computerworld - A European Union initiative to develop standards for shorter and more readable data-privacy notices on Web sites is shining a spotlight on a similar need in the U.S., and large companies such as Microsoft Corp. and The Procter & Gamble Co. are already adopting the condensed format.
On its corporate Web site, P&G has created a "privacy notice highlights" page that uses a modular format identical to the one approved by an EU panel in late November. The modular approach lets companies provide Web site visitors with capsule descriptions of their privacy policies as the initial step in the disclosure process.
Sandy Hughes, P&G's global privacy executive, said last week that the Cincinnati-based maker of consumer goods set up the new page after a survey of users who visited the Web site showed that 95% of them found shorter data privacy notices helpful.
The information on the page fits in a single screen on a PC and is separated into six data fields, each containing concise, bulleted information about P&G's privacy policies. Links are included that open separate windows with more detailed descriptions of the policies.
P&G has yet to implement a similar short-form notice on its European Web sites, but Hughes said it plans to do so. "What will take time is the multiple language translations to go on top of our policies, which are already in 17 languages," she said.
Peter Cullen, Microsoft's chief privacy strategist, said the software vendor also plans to implement a layered notice approach similar to the one being used by P&G.
Focus-group research done last year by Microsoft in Germany and Hong Kong showed that consumers were overwhelmingly in favor of shorter privacy notices, he said.
Microsoft will begin by implementing short-form notices on its MSN Web sites in Europe, Cullen said. He noted that the challenge is in figuring out exactly what information needs to be included in the shortened notices to make them suitable for the bulk of Microsoft's customers.
The EU's data privacy commissioners are proposing the adoption of the modular notices as a way to make privacy statements more user-friendly, said Jonathan Bamford, assistant commissioner in the U.K.'s Information Commissioner's Office.
Legal Obligations Remain
The short-form proposal does not eliminate the legal obligations that companies have to disclose their privacy polices in full, according to Bamford. "What it does is provide another layer of clarification beyond what the law says you have to do," he said.
Under the multitier approach, companies still must offer a full notice that spells


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Privacy Webcasts