Personal Privacy Policies Overview
Personal Privacy Policies Overview
privacy. This means that the consumer would only be will- Management Model, which explains how personal pri-
ing to have her privacy reduced by a certain amount, as vacy policies can be used to protect consumer privacy,
represented by the privacy provisions in her privacy policy. including how they may be negotiated between e-serv-
There is a match between a provider’s privacy policy and ice consumer and e-service provider. The “Discussion
the corresponding consumer’s policy where the amount of and Related Work” section discusses our approaches and
privacy reduction allowed by the consumer’s policy is at presents related work. The chapter ends with conclusions
least as great as the amount of privacy reduction required and a description of possible future work in these areas.
by the provider’s policy (more details on policy match-
ing follow). Otherwise, there is a mismatch. Where time
is involved, a private item held for less time is considered 2. CONTENT OF PERSONAL PRIVACY
less private. A privacy policy is considered upgraded if the POLICIES
new version represents more privacy than the prior version.
In Canada, privacy legislation is enacted in the Personal
Similarly, a privacy policy is considered downgraded if the
Information Protection and Electronic Documents Act
new version represents less privacy than the prior version.
(PIPEDA)7 and is based on the Canadian Standards
So far so good, but what should go into a personal pri-
Association’s Model Code for the Protection of Personal
vacy policy? How are these policies constructed? Moreover,
Information,8 recognized as a national standard in 1996.
what can be done to construct policies that do not lead to
This code consists of ten Privacy Principles that for
negative unexpected outcomes (an outcome that is harm-
convenience, we label CSAPP.
ful to the user in some manner)? Consumers need help
in formulating personal privacy policies. The creation of
such policies needs to be as easy as possible or consumers Privacy Legislation and Directives
would simply avoid using them. Existing privacy specifi-
cation languages such as P3P and APPE5,6 that are XML- Data privacy in the European Union is governed by a
based are far too complicated for the average Internet user very comprehensive set of regulations called the Data
to understand. Understanding or changing a privacy policy Protection Directive.9 In the United States, privacy pro-
expressed in these languages effectively requires knowing tection is achieved through a patchwork of legislation at
how to program. What is needed is an easy, semiautomated the federal and state levels. Privacy legislation is largely
way of deriving a personal privacy policy. sector-based.10
In this chapter, we present two semiautomated
approaches for obtaining personal privacy policies for
Requirements from Privacy Principles
consumers. We also show how these policies should
be specified to avoid negative unexpected outcomes. In this section, we identify some attributes of private
Finally, we describe our Privacy Management Model that information collection or personally identifiable infor-
explains how personal privacy policies are used to protect mation (PII) collection using CSAPP as a guide. We then
consumer privacy, including how policies may be negoti- apply the attributes to the specification of privacy policy
ated between e-service consumer and e-service provider. contents. Note that we use the terms private informa-
The “Content of Personal Privacy Policies” section tion and PII interchangeably. We use CSAPP because it
examines the content of personal privacy policies by is representative of privacy legislation in other countries
identifying some attributes of private information collec- (e.g., European Union, Australia) and has withstood the
tion. The “Semiautomated Derivation of Personal Privacy
Policies” section shows how personal privacy policies 7 Canadian Standards Association, “Model code for the protection of
can be semiautomatically generated. The “Specifying personal information,” retrieved Sept. 5, 2007, from [Link]/stan-
Well-Formed Personal Privacy Policies” section explains dards/privacy/code/[Link]?articleID 5286&language English.
8 Office of the Privacy Commissioner of Canada, “The personal infor-
how to ensure that personal privacy policies do not mation protection and electronic documents act,” retrieved May 1,
lead to negative unexpected outcomes. “The Privacy 2008, from [Link]/legislation/02_06_01_e.asp.
9 European Union, “Directive 95/46/EC of the European Parliament
Management Model” section presents our Privacy
and of the Council of 24 October 1995 on the protection of individuals
with regard to the processing of personal data and on the free move-
5 W3C Platform, “The platform for privacy preferences,” retrieved ment of such data,” unofficial text retrieved Sept. 5, 2003, from http://
Sept. 2, 2002, from [Link]/P3P/. [Link]/datacncl/[Link].
6 W3C APPEL, “A P3P preference exchange language 1.0 10 Banisar, D., “Privacy and data protection around the world,”
(APPEL1.0),” W3C Working Draft 15, April 2002, retrieved Sept. 2, Proceedings, 21st International Conference on Privacy and Personal
2002, from: [Link] Data Protection, September 13, 1999.
TABLE 29.1 CSAPP: The Ten Privacy Principles from the Canadian Standards Association
Principle Description
1. Accountability An organization is responsible for personal information under its control and
shall designate an individual or individuals accountable for the organization’s
compliance with the privacy principles.
2. Identifying Purposes The purposes for which personal information is collected shall be identified by
the organization at or before the time the information is collected.
3. Consent The knowledge and consent of the individual are required for the collection,
use, or disclosure of personal information, except when inappropriate.
4. Limiting Collection The collection of personal information shall be limited to that which is
necessary for the purposes identified by the organization. Information shall be
collected by fair and lawful means.
5. Limiting Use, Disclosure, and Retention Personal information shall not be used or disclosed for purposes other than
those for which it was collected, except with the consent of the individual or as
required by the law. In addition, personal information shall be retained only as
long as necessary for fulfillment of those purposes.
9. Individual Access Upon request, an individual shall be informed of the existence, use and
disclosure of his or her personal information and shall be given access to
that information. An individual shall be able to challenge the accuracy and
completeness of the information and have it amended as appropriate.
10. Challenging Compliance An individual shall be able to address a challenge concerning compliance with
the above principles to the designated individual or individuals accountable for
the organization’s compliance.
test of time, originating from 1996. In addition, CSAPP information is being collected. Principles CSAPP.3,
is representative of the Fair Information Practices, a set CSAPP.5, and CSAPP.9 imply that the private informa-
of standards balancing the information needs of the busi- tion can be disclosed to other parties, giving a disclose-to
ness with the privacy needs of the individual.11 Table attribute. Principle CSAPP.5 implies a retention time
29.1 shows CSAPP. attribute for the retention of private information. Thus,
In Table 29.1, we interpret organization as “provider” from the CSAPP we derive five attributes of private
and individual as “consumer.” In the following, we use information collection: collector, what, purposes, reten-
CSAPP.n to denote Principle n of CSAPP. Principle tion time, and disclose-to.
CSAPP.2 implies that there could be different provid- The Privacy Principles also prescribe certain opera-
ers requesting the information, thus implying a collec- tional requirements that must be satisfied between
tor attribute. Principle CSAPP.4 implies that there is a provider and consumer, such as identifying purpose
what attribute, that is, what private information is being and consent. Our service model and the exchange of
collected? Principles CSAPP.2, CSAPP.4, and CSAPP.5 privacy policies automatically satisfy some of these
state that there are purposes for which the private requirements, namely Principles CSAPP.2, CSAPP.3,
and CSAPP.8. The satisfaction of the remaining opera-
tional requirements depends on compliance mechanisms
11 K. S. Schwaig, G. C. Kane, and V. C. Storey, “Privacy, fair infor-
(Principles CSAPP.1, CSAPP.4, CSAPP.5, CSAPP.6,
mation practices and the fortune 500: the virtual reality of compli-
ance,” The DATA BASE for Advances in Information Systems, 36(1), CSAPP.9, and CSAPP.10) and security mechanisms
pp. 49–63, 2005. (Principle CSAPP.7).
Policy Use: E-learning Policy Use: Bookseller Policy Use: Medical Help
Owner : Alice Consumer Owner : Alice Consumer Owner : Alice Consumer
Policy Use: E-learning Policy Use: Bookseller Policy Use: Medical Help
Owner : E-learning Unlimited Owner : All Books Online Owner : Medics Online
Collector : E-learning Unlimited Collector : All Books Online Collector : Medics Online
What: name, address, tel What: name, address, tel What : name, address, tel
Purposes: identification Purposes: identification Purposes: contact
Retention Time: unlimited Retention Time: unlimited Retention Time: unlimited
Disclose-To: none Disclose-To: none Disclose-To: pharmacy
Collector : E-learning Unlimited Collector: All Books Online Collector : Medics Online
What: course marks What: credit card What : medical condition
Purposes: records Purposes: payment Purposes: treatment
Retention Time: 1 years Retention Time: until paid Retention Time: 1 year
Disclose-To: none Disclose-To: none Disclose-To: pharmacy
Surveys,
Studies Internet Users
Provider
WPR, Policies
PSL Scale
Provider
PSL Policies
Consolidation
Retrieve
Rules
Personal
Consumer
Policies
1
for a particular policy use. We present two approaches Party Surveys”) of user perceptions of data privacy
for such derivations. The first approach relies on third- (Figure 29.3). The second approach is based on retrieval
party surveys (see sidebar, “Derivation Through Third from a community of peers.
Derivation Through Third-Party Surveys consolidates the PSLs from (a) such that the WPRs are
selectable by a single value privacy level from a “privacy
(a) A policy provider makes use of third-party surveys per- slider” for each service provider policy. There are differ-
formed on a regular basis, as well as those published in ent ways to do this consolidation. One way is to assign
research literature, to obtain user privacy sensitivity lev- a WPR the median of its PSL range as its privacy level
els (PSLs) or perceptions of the level of privacy for vari- (illustrated in a moment). The outcome of this process is
ous combinations of what, purposes, retention time a set of consumer privacy rules (expressed using a policy
in provider policy rules. We call what, purposes, language such as APPEL) ranked by privacy level for dif-
retention time WPR, for short. This gives a range of ferent providers, and with the collector and disclose-to
PSLs for different WPRs in different provider policies. fields as “any” and “none,” respectively. (The consumer
Formally: can change these fields later if desired.) Formally, using
Let pi represent a WPR from a provider policy, I repre- the notation introduced in (a):
sent the set of pi over all provider policies, fk,i represent the
Let P represent a provider’s privacy policy. Then for each
privacy sensitivity function of person k to sharing pi with
WPR pi苸P, we have from (a) a set of PSLs: Si(P) {sk,i |
a service provider. We restrict fk,i to an integer value in a
pi苸P, ∀ k苸K}. Our goal is to map Si(P) to a single privacy
standard interval [M,N], that is, M fk,i N for integers M,
level from a privacy slider. Let g be such a mapping. Then
N (e.g., M 1, N 5). Then the PSLs sk,i are obtained as
this step performs the mapping g(Si(P)) n, where n is the
privacy slider value. For example, the mapping g can be
sk,i fk,i (pi ) ∀ k∈ K , i∈ I
“take the median of” (illustrated below) or “take the aver-
where K is the set of consumers interested in the pro- age of.” We have assumed that the range of slider values
viders’ services. This equation models a person making a is the same as [M,N] in (a). If this is not the case, g would
choice of what PSL to assign a particular pi. need to incorporate normalization to the range of slider
values.
(b) Corresponding to a service provider’s privacy policy (which
specifies the privacy rules required), a policy provider (c) Consumers obtain online from the policy provider the
(or a software application used by the policy provider) privacy rules that make up whole policies. They do
this by first specifying the provider for which a con- cific names to collector and disclose-to for all rules. This
sumer privacy policy is required. The consumer is then can be done through a human-computer interface that
prompted to enter the privacy level using the privacy shelters the user from the complexity of the policy lan-
slider for each WPR from the service provider’s policy. guage. In this way, large populations of consumers may
The selected rules would then automatically populate quickly obtain privacy policies for many service provid-
the consumer’s policy. The consumer then completes ers that reflect the privacy sensitivities of the communi-
his privacy policy by adding the header information ties surveyed.
(i.e., policy use, owner, valid) and, if desired, add spe-
Personal Policy
Policy Search
Policies Interpreter User
Interaction
Consumer
Personal Policy
Amendments
Consumers may interactively adapt their existing records, 12 months . The steps are implemented as
privacy policies for new service provider policies based follows:
on the PSLs of the WPRs and the new provider policies,
1. The third-party survey generates the following
as illustrated in Figure 29.4. In Figure 29.4, the Policy
results for the WPR (the lowest privacy sensitivity
Interpreter interactively allows the user to establish
level is M 1, the highest is N 5).
(using a privacy slider) the privacy levels of required
rules based on the new provider policy and the PSLs WPR (pi) PSL (sk,i)
from a policy provider. Policy Search then retrieves the course marks, records, 6 months 3
user policy that most closely matches the user’s privacy- course marks, records, 6 months 4
established rules. This policy may then be further course marks, records, 6 months 4
amended interactively via the Policy Interpreter to obtain course marks, records, 6 months 5
the required personal privacy policy. This assumes the course marks, records, 12 months 1
availability of an easy-to-understand interface for the user course marks, records, 12 months 1
interaction as well as software to automatically take care course marks, records, 12 months 2
of any needed conversions of rules back into the policy course marks, records, 12 months 3
language (APPEL).
Note that the higher the number of months the marks
are retained, the lower the PSL (the lower the privacy
perceived by the consumer). The different PSLs
An Example
obtained constitute one part of the privacy sensitivity
Suppose a consumer wants to generate a personal pri- scale.
vacy policy for a company called E-learning Unlimited. 2. In this step, the policy provider consolidates the PSL
For simplicity, suppose the privacy policy of E-learning in Step 1 using the median value from the corre-
Unlimited has only one WPR, namely course marks, sponding PSL range. Thus for the four course-mark
D E
C
F
B
A
(a) New consumer “A” broadcasts request for privacy rules to the community
D E
C
F
B
A
completing the headers and possibly changing privacy, that is, require less privacy reduction. This could
the collector and disclose-to as in the preceding mean that the provider is requiring less information that
derivation from surveys approach. is private. In this case, the provider or consumer may not
● The consumer adapts a privacy policy to the service realize the extra costs that may result from not having
provider’s policy, as in the derivation by surveys access to the private information item or items that were
approach (Figure 29.4), to try to fulfill provider eliminated through upgrading. For example, leaving out
requirements. the social security number may lead to more costly means
of consumer identification for the provider. As another
example, consider the provider and consumer policies
4. SPECIFYING WELL-FORMED of Figure 29.6. In this figure, suppose All Books Online
PERSONAL PRIVACY POLICIES upgraded its privacy policy by eliminating the credit-card
requirement. This would lead to a match with Alice’s pri-
This section explains how unexpected outcomes may
vacy policy, but it could cost Alice longer waiting time to
arise from badly specified personal privacy policies. It
get her order, since she may be forced into an alternate
then gives guidelines for specifying “well-formed” poli-
and slower means of making payment (e.g., mailing a
cies that avoid unexpected outcomes.
check) if payment is required prior to shipping.
condition is kept confidential. The provider may not have situation (one way is simply to have an overriding condi-
fully realized the sensitivity of the extra information. tion that in an emergency, Alice must give her condition
to any doctor or nurse on staff), but our point still holds:
Outcomes from the Content of the Matching An improperly specified collector attribute can lead to
Policy unexpected serious consequences.
We give here some example unexpected outcomes due to
the content of the matching policy. We examine the con- Retention Time
tent of the header and privacy rules in turn, as follows. Care must also be taken to specify the appropriate reten-
tion time for a particular information item. The respon-
Valid Field sibility for setting an appropriate retention time lies with
If the valid field of the consumer’s policy is not care- both the provider and the consumer. For example, con-
fully specified, the provider may become confused sider once again the policies of Figure 29.7. Suppose
upon expiry if there is not another consumer policy that Alice changes her privacy rule for medical condition
becomes the new policy. In this state of confusion the from Dr. A. Smith to any and from unlimited to 2 years.
provider could inadvertently disclose the consumer’s Then the policies match and the service can proceed.
private information to a party that the consumer does not At the end of two years, the provider complies with the
want to receive the information. consumer’s privacy policy and discards the informa-
tion it has on Alice’s medical condition. But suppose
Collector Field that after the two years, medical research discovers that
Alice’s condition is terminal unless treated with a certain
Specification of who is to collect the consumer’s pri-
new drug. Then Nursing Online cannot contact Alice to
vate information needs to consider what happens if the
warn her, since it no longer knows that Alice has that
collector is unavailable to receive the information. For
condition. Poor Alice! Clearly, both the provider and
example, consider the privacy policies of Figure 29.7.
the consumer are responsible for setting the appropriate
The policies are not compatible, since Alice will reveal
retention time. One could conclude that in the case of a
her medical condition only to Dr. Smith, whereas the
medical condition, the retention time should be unlim-
provider would like any doctor or nurse on staff to take
ited. However, unlimited can also have its risks, such
the information. Suppose the provider upgrades its pol-
as retaining information beyond the point at which it
icy to satisfy Alice by allowing only Dr. Smith to receive
no longer applies. For example, Alice could one day be
information on Alice’s condition. Then an unexpected
cured of her condition. Then retention of Alice’s condi-
outcome is that Alice cannot receive help from Nursing
tion could unjustly penalize Alice if it somehow leaked
Online because Dr. Smith is not available (he might have
out when it is no longer true.
been seriously injured in an accident), even though the
policies would match and the service could theoretically
proceed. There are various ways to solve this particular Disclose-To Field
If the disclose-to attribute of the consumer’s privacy
Policy Use: Medical Help Policy Use: Medical Help policy is not specified or improperly specified, providers
Owner: Nursing Online Owner : Alice Consumer can share the consumer’s private information with other
Valid: unlimited Valid: December 2009 providers or consumers with resulting loss of privacy.
Consider the following examples.
Collector: Nursing Online Collector: any Suppose Alice has a critical health condition and she
What: name, address, tel What: name, address, tel
Purposes: contact Purposes: contact does not want her employer to know for fear of losing her
Retention Time: unlimited Retention Time: unlimited job (the employer might dismiss her to save on sick leave
Disclose-To: pharmacy Disclose-To: pharmacy
or other benefits—this really happened!14). Suppose that
Collector: Nursing Online Collector: Dr. A. Smith she is able to subscribe to Nursing Online as in the pre-
What: medical condition What: medical condition ceding examples. Then through the execution of the serv-
Purposes: treatment Purposes: treatment
Retention Time: 1 year Retention Time: unlimited ice, Nursing Online shares her condition with a pharmacy
Disclose-To: pharmacy Disclose-To: pharmacy
14 J. K. Kumekawa, “Health information privacy protection: crisis or
FIGURE 29.7 Example of medical help provider (left) and consumer common sense?”, retrieved Sept. 7, 2003, from [Link].
privacy policies (right). org/ojin/topic16/tpc16_2.htm.
to fill her prescription. Suppose the company that Alice Since all unexpected outcomes derive from the personal
works for is a pharmaceutical supplier and needs to know privacy policy (at least in this work), it is necessary to
contact information of patients in the area where Alice ensure “well-formed” policies that can avoid unexpected
lives so that the company can directly advertise to them negative outcomes. Further, if a non-well-formed policy
about new drugs effective for Alice’s condition. Suppose matches the first time and leads to negative outcomes, it
further that the pharmacy with which Nursing Online is too late to do anything about it. Based on the discus-
shared Alice’s condition is a consumer of the pharmaceu- sion of the preceding section, let’s define our terms.
tical supplier and the pharmacy’s privacy policy does not
restrict the sharing of patient information that it receives
Definition 1
secondhand. Then the pharmaceutical supplier, Alice’s
employer, can learn of her health condition from the An unexpected negative outcome is an outcome of the
pharmacy, and Alice could lose her job—an unexpected use of privacy policies such that (1) the outcome is unex-
outcome with serious consequences. A possible solution pected by both the provider and the consumer, and (2)
to this situation is for Alice to specify pharmacy, no fur- the outcome leads to either the provider or the consumer
ther for disclose-to. Then to comply with Alice’s policy, or both experiencing some loss, which could be private
Nursing Online, as a consumer of the pharmacy, in its pri- information, money, time, convenience, job, and so on,
vacy policy with the pharmacy would specify none for the even losses that are safety and health related.
disclose-to corresponding to Alice’s condition, thus pre-
venting Alice’s employer from learning of her condition Definition 2
and so preserving her privacy.
As another example, suppose Alice, as a consumer, A well-formed (WF) privacy policy (for either consumer
uses graphics services from company A and company B. or provider) is one that does not lead to unexpected
Her privacy policy with these companies stipulates that negative outcomes. A near well-formed (NWF) privacy
the rates she pays them is private and not to be disclosed policy is one in which the attributes valid, collector,
to any other party. Suppose she pays company A a higher retention time, and disclose-to have each been consid-
rate than company B. Now suppose companies A and B ered against all known misspecifications that can lead to
are both consumers of company C, which provides data unexpected negative outcomes.
on rates paid for graphics services. To use company C’s In Definition 2, the misspecifications can be accu-
services, companies A and B must provide company C mulated as a result of experience (e.g., trial and error)
with deidentified information regarding rates they are or by scenario exploration (as earlier). We have already
paid. This does not violate the privacy policies of con- presented a number of them in the preceding section. An
sumers of companies A and B, because the information NWF privacy policy is the best that we can achieve at this
is deidentified. However, company B now learns of the time. Clearly, such a policy does not guarantee that unex-
higher rate paid company A and seeks a higher rate from pected negative outcomes will not occur; it just reduces
Alice. There does not appear to be any solution to this the probability of an unexpected negative outcome.
situation, since Alice has already specified disclose-to as
none. This example shows that there can be unexpected
Rules for Specifying Near Well-Formed
outcomes that may not be preventable.
We have presented a number of unexpected outcomes
Privacy Policies
arising from the way the policy match was obtained and Let’s consider once more the content of a personal pri-
how the content of the policy was specified. Our outcomes vacy policy by looking at the header and the privacy
are all negative ones because they are the ones we need rules.
to be concerned about. There are also, of course, positive The header (Figure 29.1) consists of policy use, owner,
unexpected outcomes, but they are outside the scope of and valid. Policy use and owner serve only to identify the
this chapter. policy and, assuming they are accurately specified, they
are unlikely to lead to unexpected negative outcomes.
5. PREVENTING UNEXPECTED NEGATIVE That leaves valid. As discussed, valid must be specified
OUTCOMES so that it is never the case that the provider is in posses-
sion of the consumer’s private information without a
The problem at hand is how to detect and prevent the corresponding valid consumer policy (i.e., with the pol-
unexpected outcomes that are negative or dangerous. icy expired). Another way to look at this is that it must
be true that the provider is no longer in possession of the Otherwise, or if there is doubt, specify none or name of
consumer’s information at the point of policy expiration. receiving party, no further.
Hence we can construct a rule for specifying valid. These rules address the problems discussed in the
section “Outcomes from the Content of the Matching
Rule for Specifying Valid Policy” that lead to unexpected negative outcomes.
Except for valid, in each case we require the consumer
The time period specified for valid must be at least as
or provider to consider the consequences of the intended
long as the longest retention time in the privacy policy.
specification, and propose specification alternatives,
This rule ensures that if the provider is in possession of
where the consequences lead to unexpected negative
the consumer’s private information, there is always a
outcomes or there is doubt. By definition, application of
corresponding consumer privacy policy that governs the
these rules to the specification of a privacy policy will
information, which is what is needed to avoid the unex-
result in a near well-formed policy. Undoubtedly, math-
pected outcomes from an improperly specified valid.
ematical modeling of the processes at play together with
Let’s now consider the content of a privacy rule. The
state exploration tools can help to determine whether
privacy rule consists of the attributes collector, what,
or not a particular specification will lead to unexpected
purposes, retention time, and disclose-to (Figure 29.1).
negative outcomes. Such modeling and use of tools is
What and purposes serve only to identify the informa-
part of future research.
tion and the purposes for which the information will be
put to use. Assuming they are accurately specified, they
are unlikely to lead to unexpected negative outcomes. Approach for Obtaining Near Well-Formed
That leaves collector, retention-time, and disclose-to, Privacy Policies
which we discussed. Based on this discussion, we can
We propose that these rules for obtaining near well-formed
formulate specification rules for these attributes.
policies be incorporated during initial policy specification.
This is best achieved using an automatic or semiautomatic
Rule for Specifying Collector method for specifying privacy policies, such as the meth-
When specifying an individual for collector, the conse- ods in the section “Semiautomated Derivation of Personal
quences of the unavailability of the individual to receive Privacy Policies.” The rule for valid is easy to implement.
the information must be considered. If the consequences Implementation of the remaining rules may employ a
do not lead to unexpected negative outcomes (as far as combination of artificial intelligence and human-computer
can be determined), proceed to specify the individual. interface techniques to assist the human specifier to rea-
Otherwise, or if there is doubt, specify the name of the son out the consequences. Alternatively, the rules may be
provider (meaning anyone in the provider’s organization). applied during manual policy specification in conjunction
with a tool for determining possible consequences of a
particular specification.
Rule for Specifying Retention Time
When specifying retention time, the consequences of the 6. THE PRIVACY MANAGEMENT MODEL
expiration of the retention time (provider destroys corre-
sponding information) must be considered. If the conse- In this part of the chapter, we explain how our Privacy
quences do not lead to unexpected negative outcomes (as Management Model works to protect a consumer’s pri-
far as can be determined), proceed to specify the desired vacy through the use of personal privacy policies.
time. Otherwise, or if there is doubt, specify the length of
time the service will be used.
How Privacy Policies Are Used
An e-service provider has a privacy policy stating what
Rule for Specifying Disclose-To
PII it requires from a consumer and how the information
When specifying disclose-to, the consequences of succes- will be used. A consumer has a privacy policy stating
sive propagation of your information starting with the what PII the consumer is willing to share, with whom
first party mentioned in the disclose-to must be consid- it may be shared, and under what circumstances it may
ered. If the consequences do not lead to unexpected neg- be shared. An entity that is both a provider and a con-
ative outcomes (as far as can be determined), proceed sumer has separate privacy policies for these two roles.
with the specification of the disclose-to party or parties. A privacy policy is attached to a software agent, one that