Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Checking user understanding of shared identity #78

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions ua_policy_proposal.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,11 +59,11 @@ For each element of the First Party Set policy, we propose an enforcement method
<tr>
<td>A group identity that is easily discoverable by a users </td>
<td>UI treatment (and co-branding in some cases)<sup>2</sup> </td>
<td>None (solely the browser's and site author's responsibility)</td>
<td>Conduct user surveys to determine if common identity is understandable to users<sup>3</sup></td>
</tr>
<tr>
<td>Common Privacy Policy </td>
<td>Technical checks<sup>3</sup> </td>
<td>Technical checks<sup>4</sup> </td>
<td>Performs technical check to ensure Privacy Policy is the same across all sites in the same set </td>
</tr>
</tbody>
Expand All @@ -78,7 +78,9 @@ For each element of the First Party Set policy, we propose an enforcement method
+ sites within the set are prominently co-branded
+ sites within the set prominently disclose to users the parent company owner/operator (via a notice one click away from the home page, pop-up, or other method)

<sup>3</sup> Site authors must ensure that a hyperlink to the common group privacy policy is placed on the default page of each domain listed on their proposed set; such that an automated technical check can be used to verify its presence.
<sup>3</sup> The IEE will conduct some user surveys on randomly selected sets, for calibration, along with surveys as needed in order to handle reports of invalid sets.

<sup>4</sup> Site authors must ensure that a hyperlink to the common group privacy policy is placed on the default page of each domain listed on their proposed set; such that an automated technical check can be used to verify its presence.

Additional roles of enforcement entity:

Expand Down