In A Race to the Bottom: Privacy Ranking of Internet Service Companies [1], Privacy International [2] spray-paints the façades of landmark companies that line today's Main Street on the Web. The painted colors are assessments of each company's performance on privacy issues. Though the rankings are colorful, what they say isn't pretty.
Nobody in the "interim rankings [3]" (.pdf) gets the top (green) mark for "Privacy-friendly and privacy enhancing". The bottom (black) mark, for "Comprehensive consumer surveillance & entrenched hostility to privacy", goes to just one company: Google.
Here's the color-band system by which each service is rated:
| Privacy-friendly and privacy enhancing |
| Generally privacy-aware but in need of improvement |
| Generally aware of privacy rights, but demonstrate some notable lapses |
| Serious lapses in privacy practices |
| Substantial and comprehensive privacy threats |
| Comprehensive consumer surveillance & entrenched hostility to privacy |
None of the ranked companies were spared rebuke. Here's a sort of the marks, with the summary justification for each
According to the report, "The analysis employs a methodology comprising around twenty core parameters. We rank the major Internet players but we also discuss examples of best and worst privacy practice among smaller companies." The "initial assessments" describe performance in ten areas:
As for motivation, Privacy International says,
We are increasingly concerned about the recent dynamics in the marketplace. While a number of companies have demonstrated integrity in handling personal information (and we have been surprised by the number of 'social networking' sites which are taking some of these issues quite seriously), we are witnessing an increased 'race to the bottom' in corporate surveillance of customers. Some companies are leading the charge through abusive and invasive profiling of their customers' data. This trend is seen by even the most privacy friendly companies as creating competitive disadvantage to those who do not follow that trend, and in some cases to find new and more innovative ways to become even more surveillance-intensive.
We felt that consumers want to know about these surveillance practices so that they can make a better-informed decision about how, whether and with whom they should share their personal information. We also believe that companies need to be more open about how they process information and why it is processed.
Most importantly, we wanted to indicate to the marketplace that their surveillance and tracking activities are being scrutinised.
So the idea here isn't just to expose shortcomings, but to put pressure on these services.
But one wonders... Why would all these companies suck so badly at respecting privacy?
I believe there are two reasons: 1) Growth in adoption of advertising-based revenue model that Google pioneered, and now provides for millions of companies, and 2) Absence of privacy (or any) control on the user's side other than refusal to cooperate.
As Privacy International puts it, privacy and advertising are strange bedfellows:
The current frenzy to "capture" ad space revenue through the exploitation of new technologies and tools will result in one of the greatest privacy challenges in recent decades. The Internet appears to be shifting as a whole toward this aim...
Although the Net itself isn't shifting anywhere (it's a quibble, but "the Internet" is not the same as the collection of websites and services that reside on it), there is a failure of imagination around business models other than retailing and advertising. Especially advertising. And there's a pile of money in advertising. Especially for Google, which is moving toward a de facto monopoly on the business, if it isn't there already.
In March ComScore published its latest numbers [26] on share of online searches. Google was a hair under 50%, and going steadily up while everybody else was going down. In "searches per user" nobody else came close to Google.
But Google's business model isn't search. It gets because effects off search. Search is free. But because of search, Google makes money with advertising [27]. That's its business model. Part of that business model is putting millions of individuals and companies into the same business. You don't need to sell a single ad to support your site or your blog with advertising. Google AdSense does all the work. It not only does that work for millions of businesses, but creates millions of businesses where before there were none.
The Internet Advertising Bureau and Price Waterhouse say online advertising [28] was $4.9 billion in Q1 of 2007. Google advertising revenues in the same quarter were $3.627450 billion. Do the math. "Google Network Web Sites" reveneues were $1.345329 billion. Those revenues were Google's side of the advertising take. The rest of the money went to the site owners.
To make advertising of this sort work best requires maximizing intelligence about users. Does this also require privacy violations? The last quoted paragraph above seems to suggest as much. So I have a question for both Google and Privacy International : Could Google and its partners do as good a job in the advertising business if they did everything it takes to get a green score?
While we're pondering that, let's look at the second problem. Online privacy as we know it today is almost entirely at the grace of the vendors we deal with. The terms are theirs. We accept them or we don't. Other than opting out, we don't have much control on our side. We can't, for example, make a global assertion of anonymity to the world, and then selectively reveal pieces of identity information to vendors, on a private and need-to-know basis that we determine. For the most part we have those privileges when we shop at stores in the physical world. But in the online world we are much more compromised by conditions that are beyond our control. We can be tagged and tracked like animals and never know it.
These conditions will stay out of our control as long as we continue to believe that markets are about supply chasing down and "capturing" demand. There has to be a better way one that serves demand at least as well as it serves supply. Whatever that better way is, advertising is part of the problem, not the solution.
Even as Google and others put millions more of us into business, it's still the advertising business. And that business is driven entirely by its supply side. Follow the money. Advertisers pay Google and its partners for click-throughs. By making advertising accountable for performance, Google moved the whole category forward an enormous distance. But it's still advertising. And advertising is still woefully inefficient. For every click-through there are hundreds, thousands or millions of "impressions" or "exposures" that are actually neither. They are noise. Instead of wasting trees (as print media do) or time (as broadcasting does), they waste server cycles, packets and pixels. Those come cheap, but they're still waste, still noise, still clutter. They are distractions, and they get in the way.
We can't leave privacy solutions entirely up to large suppliers. That can't work. We can only solve privacy problems by equipping individuals with better ways to control and reveal private information while also finding what they want in the networked world. Until we do that, Privacy International will still be ranking sites with colors other than green.
By the way, next week in San Francisco, leading up to Supernova 2007 [29], there will be an open space workshop [30] at Wharton West. While the Supernova theme is "The New Network", the open space workshop can cover any topic we like. Vendor Relationship Management [31] (which seeks to solve the "advertising problem", among other things) is on the list of proposed session topics [32] (we'll choose those as a group at the start of the day). So are some other excellent topics including whatever you want to add to the wiki or tell the group about when the day starts. The cost is $25. Includes lunch.
My own fantasy about this is that we get actual developers folks who write code to come and help the rest of us work this out. If that's you, please come. There are some pretty big itches to scratch here.
__________________________
Doc Searls is Senior Editor of Linux Journal
Links:
[1] http://www.privacyinternational.org/article.shtml?cmd[347]=x-347-553961
[2] http://www.privacyinternational.org/
[3] http://www.privacyinternational.org/issues/internet/interimrankings.pdf
[4] http://bbc.co.uk
[5] http://ebay.com
[6] http://lastfm.com
[7] http://wikipedia.com
[8] http://bebo.com
[9] http://amazon.com
[10] http://friendster.com
[11] http://linkedin.com
[12] http://livejournal.com
[13] http://myspace.com
[14] http://skype.com
[15] http://microsoft.com
[16] http://orkut.com
[17] http://Xanga.com
[18] http://youtube.com
[19] http://aol.com
[20] http://apple.com
[21] http://facebook.com
[22] http://hi5.com
[23] http://Reunion.com
[24] http://yahoo.com
[25] http://google.com
[26] http://battellemedia.com/archives/003661.php
[27] http://investor.google.com/fin_data.html
[28] http://home.businesswire.com/portal/site/digg/index.jsp?ndmViewId=news_view&newsId=20070606005799&newsLang=en
[29] http://www.supernova2007.com/
[30] http://www.socialtext.net/sn-openspace
[31] http://projectvrm.org
[32] http://www.socialtext.net/sn-openspace/index.cgi?proposed_sessions_topics