Re: Proposed IETF Websites’ Privacy Policy; Community Input Requested

Bjoern Hoehrmann <derhoermi@gmx.net> Tue, 03 February 2015 16:52 UTC

Return-Path: <derhoermi@gmx.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A74A1A1B24 for <ietf@ietfa.amsl.com>; Tue, 3 Feb 2015 08:52:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.61
X-Spam-Level:
X-Spam-Status: No, score=-1.61 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3ksCsHef1WfC for <ietf@ietfa.amsl.com>; Tue, 3 Feb 2015 08:52:12 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AFA301A1A64 for <ietf@ietf.org>; Tue, 3 Feb 2015 08:52:09 -0800 (PST)
Received: from netb ([82.113.106.93]) by mail.gmx.com (mrgmx101) with ESMTPSA (Nemesis) id 0MN604-1YGSiK0jQO-006fsK for <ietf@ietf.org>; Tue, 03 Feb 2015 17:52:07 +0100
From: Bjoern Hoehrmann <derhoermi@gmx.net>
To: ietf@ietf.org
Subject: Re: Proposed IETF Websites’ Privacy Policy; Community Input Requested
Date: Tue, 03 Feb 2015 17:52:05 +0100
Message-ID: <t6t1dapr0rchiov73a1iin4bjd2ulka7t8@hive.bjoern.hoehrmann.de>
References: <20150203155217.2391.76679.idtracker@ietfa.amsl.com>
In-Reply-To: <20150203155217.2391.76679.idtracker@ietfa.amsl.com>
X-Mailer: Forte Agent 3.3/32.846
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:Q+zsMplCus2uyqSiWHIrpFThoUbkWSf69hVaV+Eve+iKi+nfTGf dR19KFyMp3JTi9SIK1opslQ9LyQTtQPKEX9mIxMl2qG1NGxuYWoxye2haduYo6MlPwe36Pe hgXtTbH/v8oE0dv06hvhqXheTckdBZWdpu/paq7xtoq5RjSw3lyenT+hO0gEDQpHt9OvXhC 4RNnjuMUWxs4Qe/F2i2RA==
X-UI-Out-Filterresults: notjunk:1;
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/WomnMFdEzroPTjOoZOBDdJePrqU>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Feb 2015 16:52:19 -0000

* IETF Administrative Director wrote:
>The proposed Privacy Policy is located here:
><https://iaoc.ietf.org/documents/IETF-Website-Privacy-Policy-16Jan15.pdf>

Missing word in "Due to the nature of the, your communications ..."

I think

  Certain visitor characteristics are reflected in our web server logs 
  (such as, operating system, browser version, and Internet Protocol 
  (IP) address). We do not take affirmative steps to link them with the 
  individual visitors to the site, except as may be required to diagnose
  performance issues or to investigate misuse of the site or other
  unlawful or inappropriate activities.

and

  When you interact with the site, we strive to make your experience
  easy and meaningful. We may use cookies and other means to track user 
  activity and collect site data. We may combine these data with the 
  personal information we have collected.

are contradictory, especially considering that the former is in the
"What Information do we collect?" section, which does not mention the
latter.

With

  This site is not intended for use by children under 13 years old. We
  do not knowingly collect personally identifiable information from, or 
  target our site to, children under the age of 13. In accordance with 
  the Children’s Online Privacy Protection Act of 1998, if we discover 
  that a child under 13 has provided us with personally identifiable
  information, we will remove it from our systems immediately.

it seems unclear what this means when an 11 year old person posts e.g. a
Last Call comment. Would the mailing list archives be altered to remove
their name and mail address?
-- 
Björn Höhrmann · mailto:bjoern@hoehrmann.de · http://bjoern.hoehrmann.de
D-10243 Berlin · PGP Pub. KeyID: 0xA4357E78 · http://www.bjoernsworld.de
 Available for hire in Berlin (early 2015)  · http://www.websitedev.de/