EFForg / EFForg/dnt-policy

Evaluating common third party embeds/references

Open
#8 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
50
Forks
9
PR merge metrics
No merged PRs in 30d

Description

The DNT policy says this about use of third parties:

```
3. OTHER DOMAINS:

a. If this domain transfers identifiable user data about DNT Users to
contractors, affiliates or other parties, or embeds from or posts data to
other domains, we will either:

b. ensure that the operators of those domains abide by this policy overall
by posting it at /.well-known/dnt-policy.txt via HTTPS on the domains in
question,

OR

ensure that the recipient's policies and practices require the recipient
to respect the policy for our DNT Users' data.

OR

obtain a contractual commitment from the recipient to respect this policy
for our DNT Users' data.

NOTE: if an “Other Domain” does not receive identifiable user information
from the domain because such information has been removed, because the
Other Domain does not log that information, or for some other reason, these
requirements do not apply.
```

I'm considering how a site like 18f.gsa.gov, which uses one third party on every page (Google Analytics), and some third parties on individual blog posts (YouTube, Twitter, Storify, etc.), should view this part of the policy.

It's not totally clear to me how to evaluate the impact of embedding a tweet. By exposing our users' user agents and IP addresses to Twitter.com and Storify.com, do we need to verify that they are compliant with this DNT policy (or strike up a contract?) in order for our website to be considered compliant?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the quoted “OTHER DOMAINS” section of the DNT policy and the examples of Google Analytics, YouTube, Twitter, and Storify in the issue. Determine how third-party embeds expose user agents and IP addresses, and document when compliance verification, recipient policies, or a contractual commitment is required.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.