Brian Kardell and Eric Meyer chat with Nick Doty from the Center for Democracy and Technology, and Justin Brookman from Consumer Reports about the W3C's Global Privacy Control specification
Eric Meyer: Hello, welcome to Igalia Chats. My name is Eric Meyer. I'm a Developer Advocate at Igalia.
Brian Kardell: And I am Brian Kardell, also a Developer Advocate at Igalia. And today, we have two guests with us. Do you want to introduce yourself, Nick?
Nick Doty: Sure. Hi, everyone. Nick Doty, I'm a Senior Technologist at the Center for Democracy and Technology, and I've been in the web standard space for a while. I used to work on privacy for W3C and wrote my dissertation on privacy and security and standard setting. And now I co-chair the privacy working group at W3C.
Justin Brookman: I am Justin Brookman, I am a Head of Technology Policy at Consumer Reports. I am by training a lawyer and a technologist, but I have been involved in W3C on the Global Privacy Control project, which we're going to talk about today, and then previous similar iterations of other tools.
Eric Meyer: Global privacy, that sounds very important, but it could also mean a lot of things. So, can we get a brief summary of what you mean when you're talking about that?
Justin Brookman: Sure. I can start and then feel free to jump in, Nick. So I'm a lawyer, and one of the things I do in my main job is trying to get privacy laws passed. And worked at the federal level for a long time, haven't ever been able to crack that. But starting around seven or eight years ago, we started to get these state laws passed, first in California, now about half the states have them. But they're also a little weaker than I would like, they're all opt-out based. So you have to affirmatively say, 'Hey, I don't want my data shared. I don't want targeted advertising. I don't want this, that, or the other.' But it's really hard to exercise opt-out rights one by one. Every single website you go to, every single service, every single store you enter, it's tedious enough that every site seems to have cookie banners and I don't want to have to micromanage cookies. So I would like to, if I don't want targeted advertising or my data shared, I want to tell everyone all at once. If I feel that way about the New York Times, I'd probably feel that way about ESPN and all the other sites I go to. So, Global Privacy Control is a browser based tool. You turn it on and as part of browsing the web, every single website you go to gets this general preference that says, 'Hey, I don't want to be tracked. I don't want to. Don't share my data.' And so, it's binary switch and it's like a header that goes to every website you go to, generally conveying this preference that, 'Knock it off.' We can get into details later about what exactly it means, but some of these states that now have privacy laws have interpreted that to mean, oh, that's actually an opt-out, it's a legally binding opt-out in this state. So if you see that, then you need to stop or at least limit tracking or some of the things you do with personal data.
Eric Meyer: Okay. So I in my browser basically say something like, 'I never want to be tracked.' Let's say that's one of the preferences. And so, my browser sends an HTTP header to every website that I visit and they're supposed to grab that header or look for it, and if it's there, grab it, and then act accordingly.
Justin Brookman: Yeah, that's the theory. Right? And again, in many places it's aspirational, right? If I'm in South Carolina where I grew up, there's no privacy law in South Carolina, I send this out, 'Hey, I don't like to be tracked,' and let's say a site sees me and says, 'Yes, I see that.' Some sites might honor it anyway. There are definitely a number of sites that say, 'No matter who has this, we're going to do something to limit tracking.' But there's no legal obligation probably in a state like South Carolina or places around the world to then do anything about it. But more and more states now, probably like five or six or seven have explicitly said that GPC, global privacy control, does have some legal meaning. It doesn't mean you need to stop everything, but it does have some consequences.
Brian Kardell: This is one of those things that's deceptively simple at some level. Right? I mean, it's just like there's a Boolean and it's like how many people can we get to work for how many years to make a Boolean work? You know? It just feels like, can we agree that you shouldn't track? And it's like, well, no, actually we can't agree. And it's like, well, it depends. What do you mean by track, right? What do you mean by all these things? It really gets into the weeds. And there was this previous effort for, Do Not Track, right? It was a spec, it lived this whole life for a long time, a lot of work went into it. I think, Nick, you were involved in that too, right?
Nick Doty: Yeah. I helped charter and run the tracking protection working group and recruited all these people, including Justin to participate. And that was a really huge recruiting effort to try to get advertising industry and regulators around the world and civil society, consumer advocates, all to agree on a voluntary system where the rules would not be defined in law but would actually be defined in standards. That was a harder project to get that type of consensus, and it didn't have the same forcing function of, at that time, many legal rights that those consumers had.
Brian Kardell: But it's again, another example of something that's deceptively tricky because Internet Explorer just flipped it by default. Right? They just released it and they just said, 'Yeah, I mean, we want to be the privacy browser, of course.' I mean, sure, it's a good thing for our users, but then that somehow poisoned the well and the whole thing died in the end. Part of what I wanted to ask in having you all on here is there's this, from the outside, you can simplify it to well, Do Not Track. Well, Do Not Track was actually much more complicated, I think. Is that-
Nick Doty: Yeah, the standards were more complicated in that it was defining not just this signal, not just the way to express the preference, but also how to comply with the preference for any type of website in any situation. So this is much simpler and not trying to do that, just letting laws do that since laws have legal accountability, and instead just defining the sending a preference side.
Brian Kardell: So what I like about it is A, it's very, very simple. B, it's like, okay, I guess we can't agree. Right? There is this kind of status quo. Some people have argued that, okay, if you download a 'privacy focused browser,' you are opting in. The act of you downloading a non-default browser that is focused on privacy, you are trying to inherently tell you that. And then, it doesn't get into a lot about how you express that. But what I like about it is, I think the effort actually started even outside W3C and there are laws. And not only are there laws, but there's some enforcement of this already, right?
Justin Brookman: Yeah. It started outside of W3C as people, again, trying to take advantage of the fact that California now has a law. Like I said, I worked with Nick Beck and Do Not Track back in the day. And originally, it seemed like we were pretty close to having a privacy law, and so all stakeholders said, 'Okay...' Well, maybe some companies were scared of privacy law and they said, 'Okay, let's try to find some common ground on a self-regulatory solution.' Then it starts being dragged on and on and on and what is tracking and what is all these questions? And over time, now Microsoft's saying it by default. And then at the same time, the legislative pressure was weakening. It seemed less and less likely we're going to get a privacy law. And so there was less need for companies to come to the table and less need to find common ground. And so, it just died. Then California very quickly passes a privacy law in 2018, 2019 or so, and it has this language in there saying you can designate someone to opt out for you, you can appoint it to someone. And then some technologists said, 'Well, maybe you should be the browser. You should tell the browser to opt out for you.' And so, they wrote this extension, I think it's called preference for a single controller. You just want to deal with the website you're going to. I want to deal with the New York Times, I want to deal with ESPN. I don't want all these hundreds of ad trackers there. I can express my preference just to limit the tracking as much as possible. And then there was an effort then to try to recruit policymakers in California to recognize that as, oh, that is someone appointing someone to opt out for them. And so, the attorney general then of California said actually in a tweet, 'You know what? This GPC signal, it sounds like an opt-out, therefore you need to treat it as an opt-out.' And then industry can then scramble like, oh, okay, this is a legally binding request. I need to do something about it now.
Nick Doty: Yeah. I think that's kind of the difference on that meaning of global or some places have talked about it as a universal opt-out mechanism. But I think for decades, different parts of industry have had custom individualized opt-out mechanisms where you could install an opt-out cookie, or you could go to every website, or you could go through all the settings of those cookie banners, or you could send certified mail to a certain address or something. So opt-out rights have been recognized, but what's different is the ability to do it globally or universally to make a single choice and have that repeated, because I think everyone understands that it's not actually practical to say, 'Well, you're just going to communicate separately with every party that you might possibly interact with or that a service that you browse to might interact with.' And so, technical mechanisms are good for that type of thing. Even if it's preference expression, not like a self-enforcing technical protection. Technical mechanisms are quite good at clear, simple communication. And so I think that's the opportunity for a preference expression mechanism.
Justin Brookman: Yeah. And then like you said, there has been, like after the attorney general said, 'Yes, this is legally binding,' this increasingly got formalized. They wrote FAQs on their website said, 'Okay. Yes, you have to honor this.' And then there have been a handful of enforcement actions. The first was against Sephora, the makeup company, for failure to honor GPC, but there's been several others. And then in addition to California, Colorado then actually have an official registry of opt-outs and of universal opt-outs. And right now, GPC is only one. They say in Colorado, you have to honor GPC. Other states like New Jersey, Connecticut, have issued informal guidance saying that you have to honor it in those states as well. And then last year-
Brian Kardell: Is it Oregon as well?
Justin Brookman: Yeah, Oregon, I think. Yeah, and then a few states like Texas and Nebraska say, 'Well, if another state honors it, then you got to honor it here too.' So, maybe there's an argument that is probably binding in those places as well. And then some of the attorney generals in other states announced that they're doing a GPC sweep so that they've noticed that maybe not enough companies are currently honoring this. And so in addition to the cases they brought, they're going to focus on whether websites are honoring GPC headers. I think that was the California, Colorado, and Connecticut, attorney general offices.
Brian Kardell: So a couple of browsers actually support it, right? I think Firefox, Brave, DuckDuckGo, all support out of the box. Are there other ones?
Justin Brookman: Yeah, so DuckDuckGo and Brave send it by default, they're privacy browsers. They also block a lot of the trackers by default. Firefox, it is an option in Firefox, you can go turn it on. For other more mainstream browsers, you would have to create an extension or download an extension that can send GPC. There are a lot of ad blockers that both will try to block ads, but also send GPC, kind of a belt and suspenders approach. California passed a law last year that actually says that browsers have to offer universal opt-out starting January 1st, 2027. So, we'll see. You might then now see GPC in Chrome, Safari, Edge. It doesn't say what it has to be, so they might roll their own, they might create their own opt-out thing, but starting in a few months, all browsers are going to have to have some sort of universal opt-out signal or mechanism.
Eric Meyer: Yeah. And like you say, it's opt-out and you have to go find it in Firefox. Firefox is actually what I use. And as a result of preparing for this chat, I discovered that under privacy and security, there's this whole thing about enhanced tracking protection and here's the standard setting and then you can do advanced settings, which are really just three levels. But then if I scroll down enough, I find under additional protections, tell websites not to sell or share my data, which that turns out to be the global privacy control. You can find that out, but it's not super obvious. It's weird to me how browsers are not more clear about communicating like, what does this do? What does this do? Let's take these things and put them together, as examples. Let's put the things where you assert control or whatever control you can, where you assert your preferences together, not on the same page, but literally physically, visually together.
Nick Doty: Yeah. I think it's... and in a way it's like a new challenge for browsers and it's a challenge I want browsers to take up of, how can you communicate to users that you are expressing a preference without a guarantee? And I think understandably, the longtime staff of browser vendors have to have this strong user agent philosophy and we're not going to over promise things to our users, and want to be very precise about what is and isn't provided. And I think just realistically, we need to understand that while that's good intent, that that was often not the situation. Yeah, you can tell your users that you're blocking cookies. Do users know what it means to block cookies or under which edge cases are you blocking or not blocking cookies? Or can other parties use different mechanisms to try to communicate as cookie-like signal between different websites, even if cookies are being blocked? We were already in this situation where users didn't have these simple guarantees. And so, I think we have something similar with preference expression. I think browsers should be careful because yes, telling websites not to track is not going to prevent all websites from tracking. Telling websites not to sell your data is definitely not going to stop all websites from selling your data. But also, many of our privacy protections are not quite as universal as we would like them to be. And we'll keep working on it. I'm going to keep talking to browser vendors. I'm going to keep working in web standards to try to make some of those privacy protections a little more universal, but they're never going to be absolute. And so, I don't really want browser vendors to have the names of the HTTP headers in their UI. I don't think it matters if something is DNT or GPC or Sec-GPC. I don't think any user cares about that, but I think browser vendors have a chance to try to help users see that preference expression is a tool, even if it's not a guarantee.
Eric Meyer: I noticed you didn't mention P3P in your list of things.
Nick Doty: No, I think that's a great example. Yeah, this is a way to make it simpler, but I think has a somewhat similar history to that.
Brian Kardell: Can you tell us about P3P, because I don't know that everybody's going to know what that is?
Nick Doty: Yeah, sure. The platform for privacy preferences project. P3P was a W3C standard from the late '90s, early 2000s, to define the privacy practices of different websites and to describe it in a machine-readable way. So that was early days, maybe if we came back to that now, it would work differently. That clearly didn't take off at the time. And I think I even played around with some of those tools. It's a nice opportunity to have, but I think in some ways we don't want to necessarily... Even though I like the idea of having machine-readable data and more metadata and more information for users, I think we want to avoid the situation where users have the burden of parsing through everything. That if you have a situation where now you have to check every website, whether or not it's safe or if it's going to be your fault for clicking on a website if it's in the red category or something, I think a lot of users will throw up their hands because it's too complicated or too much to keep up with, or they don't really feel like they have a choice. You have to use this website in order to search the web or to keep in touch with your friends or to buy something. Because of other market pressures, you might not have all those choices, and so metadata itself may not have this revolutionary effect. So I still like the idea, but I don't think we should be pushing too much onto the user side. And I think there's a real advantage of, to the extent that you already have some legally enforceable right through your data protection authority or through your state attorney general or something like that, it's easy to set that as a signal, rather than you having to take on some responsibility of making those choices.
Eric Meyer: Yeah. I'm giving away my age there, because I actually ran the P3P browser extension for a while and was at some of the first P3P W3C meetings. I thought it was a really great idea and I don't remember the exact details, but I remember that there was little dropdowns for a whole bunch of different things that you could create a fine-grained preference expression. And here in Firefox, I don't think that this is how it's required to be, but the global privacy control is literally a checkbox. Tell websites not to sell or share my data. Right? And I actually, granted, I am not most web surfers, but I would actually like there to be an allow list. Right? There might be some sites where I would actually like to tell them that it's okay to sell or share my data, because they're charities or nonprofits that I'm particularly supportive of and I want them to be able to share my data with similar organizations that I might not have heard of. Whereas I probably don't want Amazon to sell or share my data, to pick examples. But I assume that GPC doesn't mandate, there must be one checkbox, right? It's more of a, here's how this is communicated and how fine-grained the browser lets people be is up to that browser. Is that correct?
Justin Brookman: Yeah, that's right. They can deploy it however they want. I think most users probably don't want to have to make... Again, the point of doing universal control is that you don't get bombarded, and I don't want every website to say, 'Hey, please white list me.' And we've seen some user interfaces-
Eric Meyer: Sure.
Justin Brookman: ... like, 'Oh, hey, maybe can you turn off GPC? We need to make money here.' And actually, California has regulations about how annoying they can be with that. But yeah, I mean, conceptually there is a white listing capability. Do not track had a whole formal system for it. This is less specific, but if a browser wanted to implement it that way and someone says, 'Hey, you can keep GPC on, but can you give us permission to ignore it going forward?' That's totally legal and envisioned by the standard.
Nick Doty: The simplicity question is a live one, it continues to come up. I think there is that question about maybe I have different preferences for different sites or in different contexts. Maybe I'm in certain browsing modes and I really don't care and I'm in other browsing modes and I really don't want my data to be sold. But the other question where it comes up is some people say, 'Well, I mean, people might have more fine grain preferences about how they want their data to be sold or shared, that they're okay if data is shared for one purpose but not for another. Or you might have legal rights that refer to different types of purposes or different groups of organizations that you're sharing with and some of the sort of cookie banner infrastructure has some of that granularity.' And so, we've certainly heard the idea and it is very reminiscent for me of the P3P experience. I wasn't quite old enough to be around for it, but the Center for Democracy and Technology was, that was how we first got involved in web standards. I think it's very reminiscent of P3P to say, 'Well, enumerate all the list of purposes or types of organizations that you're willing to share data with or not, and then we can then automatically handle these arbitrarily complex consent dialogues for you.' GPC doesn't provide for that capability and it would be quite a change for it to be able to do so. So you can turn it on and off, your browser could turn it on on different sites. It doesn't have the capability of saying, 'Okay, don't just send don't sell or share my data, but send this more complicated set of preferences.' I think based on that P3P experience that I'm not optimistic about trying to design or make interoperable that type of complicated system across the world, but some people are going to be interested in it. I'm sure we'll keep hearing about that idea and we'll keep seeing if there is appetite for it.
Justin Brookman: Yeah, it is. Again, I don't want to overwhelm people, right? I mean, again, forcing people to make cookie choices alone is super annoying. Again, do you want functional cookies, non-necessary cookies, marketing cookies? I mean, no, leave people alone. And so the beauty of GPC is, again, it's not going to solve all your problems, right? It's not going to stop first party tracking. They can still use first party cookies to recognize you when you log in. And again, there's a question of how much you need to communicate to someone, but the sort of thing that annoys people, like the retargeting, you go to a website and the shoes follow you around the web that you looked at several months ago, it's just designed to turn that off. Again, not overwhelming the user with information, not asking them to make complex choices or weighing the value of cookies, just stop it as much as you can. Again, I don't need to know all about how the web works. I don't need to understand pixels. I don't need to understand everything. Just a general preference, I just want to deal with the site I'm going to, and I don't like all the other stuff. And again, even in states that do recognize, it doesn't turn all that off. They still can track you for attribution or for other things, and I wish that they wouldn't. Right? I wish that it was stronger, that the law actually blocked a lot of the tracking, but it does have consequences and it does stop at least some of the stuff that I think most people are generally aware of and find to be annoying.
Brian Kardell: That's completely up to the interface and what are the defaults. And so, I do think that the interesting thing here is that. What will the defaults look like? Who's going to win that argument? Because I think there are even court cases right now about browser is downloaded, at least non-default browser that is a privacy browser that can be treated, at least in the context it was legislated as a signal from the user that they want their privacy respected. So anyway, I think there's nothing problematic in that to me. I think they can experiment with different solutions and hopefully the market does a good thing there by servicing something that really helps people. There's also an aspect of this that allows a site to advertise, like we respect it, right? Do you want to talk about that a little bit?
Justin Brookman: Yeah. So first, I mean, on the question of defaults, most of the states that have universal opt-out provisions also have language in there saying pretty much that it shouldn't be on by default. Right? We as a state have decided on an opt-out model, that's as far as we're willing to go. We want to make it easy for folks, but it has to be really the user's volition. And so they say general purpose browsers should not be doing that. Now, California is more vague on that, and Colorado, which had the most detailed regulations on it, did make the point that you did that, well, if you're making a choice for a privacy browser like DuckDuckGo or that does block ads, then yeah, you probably do want GPC turned on. So in those cases, it seems that they're allowed to turn on by default. When the bigger browsers, the general purpose browsers start to roll this out in January, it'll be interesting to see what they do. Apple Safari does block a lot of tracking by default, and so then how do you append an opt-out solution on top of that? That's the problem they've got to deal with. You might worry that Chrome, who Google depends on advertising might try to bury it a little bit, like Eric said, he had trouble finding it on Firefox. But then the law says it has to be easy to find, so it'll be really interesting. I mean, we've been trying to talk to the browsers about how they're going to do it, but we'll see on January 1st. But yeah, to your point that browsers do have the ability to convey to folks, 'Yeah, hey, we see that. We're honoring it.' There's a couple ways. I mean, they can do it visually in an interface. I've definitely seen some folks doing that. I've seen some folks do it in the cookie banner saying, 'Oh, we see GPC is turned on. We're just going to turn off a lot of the cookies,' which is consistent with what some folks do. There's also a well-known resource that you can publish to the world like, 'Hey, we are compliant with GPC.' It's kind of binary, so it's not quite sure. What you mean by that, that you're compliant with GPC? Does that mean you're compliant everywhere? Does it mean you're compliant in states that require it? Does that mean you turn everything off or that you just turn off targeted advertising? A little bit unclear, but there is a way for folks to at least convey, 'Yes, we're aware of this,' and we do something in response to it. California had considered requiring a visual indicator to tell folks that that is happening. I think they decided that was a little bit too heavy-handed regulation even for California, and so they're not doing that right now. But they might consider it, especially if their investigatory suite finds that not enough folks are actually honoring it today.
Brian Kardell: So I wonder also, the web is inherently global. You know? So it's like, this is not like the California web versus the Colorado web versus the Pennsylvania web versus the Saudi Arabian web versus the French web. You know what I mean? It's just one global web, but we do increasingly see there are differences because of laws and things like that. So if you want to use your direct messages in Bluesky in Europe, well, not in Europe, I think it's just in the UK, you have to prove you are who you say you are. And there's all these new age verification things and stuff like that. And what I think is really interesting about this is that there are many historical examples of where it just becomes too cumbersome to disagree. It's too expensive to disagree and it's easier to just agree. And so, I wonder if we will see a kind of a coalescing. And if that's almost what we're hoping here is that we change something about the sort of default global privacy model across the board, even outside of individual states, even outside of the US, that we hope that these things influence around the world. And I mean, I hope that to a degree, and I hope that in part because also it's not the US web and all of these laws we're talking about are in the US, so.
Justin Brookman: Yeah, I'll say that's my hope too, that we'll see. Again, more and more states are passing laws that are similarly opt-out based. I would like just most companies to say, 'You know what? If we see this, we're going to limit tracking as much as possible, maybe even block some pixels.' Again, these laws are getting more and more ratcheted up over time. Like California passed their law in 2018, they've come back and tightened it each year. So again, I would love to see a general experience that if you're in America at least, we'll talk about the world in a second, if you turn on GPC, then you'll have a more private experience for everyone. And all the laws actually tend to say this should be interpreted comparably to other states because they're all worried about 50 different state laws, and the regulators talk to each other and both the legislators and the enforcers to try to draft them pretty similarly. It'll be interesting to see what it means in Europe. Europe has more of an opt-in approach, at least for cookies. You need permission to place cookies, and that's why cookie consent screens have been deemed to be mandated there. But GPC is an opt-out based solution. So, it's really unclear how they mesh. I would just assume companies can drop first party functional cookies by default. That might require the lot of change, but then GPC could turn off all the other stuff. They're in the middle of revising GDPR after, I guess 10 years after it's been in effect. And they're talking about what universal signals should do. And so they're thinking about it, but it is a different legal regime, so there's got some thinking to do.
Brian Kardell: So with regard to you advertising it, I wonder if anybody has talked about using these signals in search engines or in your browser, so that we could give you a signal on the link, whether that link is going to take you somewhere safe or not. It seems to me that there are a lot of things you could do at the browser level that would promote that people knew about this and wanted to support it. And it's a little bit... What I really like about this is that I think anytime you have something like this, it needs to be a little bit of the tail wags the dog, rather than the other way around. You know? And I see the fact that there is a movement and there are other people talking about this and trying to push it from the outside. And I wonder if you see some similarity here to UL in the US or some other things, I guess like consumer reports, where there is desire for you to get a good grade because it helps your business. You know what I mean? And that's really the only reason that you would do it. Right? I mean, if you were making electrical appliances when the UL came along, why would you want UL listing? Why would stores want to only carry UL listing? Why would consumers look for UL listing? And the answer is, it's all played into one another so that, well, it's safe and then people learn that it's safe, and then people only want to buy the things that are safe. And I wonder if we have an opportunity here to push a lot of right buttons to make that happen.
Nick Doty: It's certainly an interesting idea and it does feel like a callback to P3P. A lot of people were excited and the vision, and I think it was a promising one. The vision was that once websites documented all of those practices, then your browser could consume that and warn you of things and search engines could say, 'Hey, this website has better privacy practices than this one or use logos or trust marks or different colors and things like that.' I feel like maybe someone should check this, but I feel like Lori Cramer at AT&T or at Carnegie Mellon or something actually built one of those search engines.
Eric Meyer: So I will admit, even though it said in the show notes that the GPC spec is wildly simple, I have not read it. My experience is from the user side, which is the, I've checked a box and that tells me that my browser will omit a signal and hopefully a website will hear that signal and act appropriately. Just as a implementer question, is there anything in the spec that the site should basically admit back, 'Okay, I heard you and I will comply'?
Justin Brookman: No, that was something that was envisioned in Do Not Track and we did not include that counter signal. Partly for Do No Track, because it was a self-regulatory solution that you wanted the site to have to say something to then make legally binding. Right? Because if a spec says nothing in response, you're like, 'Did that work or not?' But if the site has to say back, 'Acknowledged, okay, I'm following that,' then the Federal Trade Commission or some other enforcer could then enforce that. With California and other states, it's already legally required, so we did not build that into the spec, but it is still sometimes scary. Like okay, I'm sending this out there. Are people listening? And actually, we did a study last year to try to track that as much as possible. Sebastian Zimmeck at Wesleyan, who we work with on the spec has also done a few investigations into that. And we found some major companies, we didn't quite know what was going on in the background, but at the very least it should turn off targeted advertising. And we found a number of sites in jurisdictions where it was legally binding were still sending re-targeted ads after I left the site, which would seem to be an indication that it wasn't really working. So there is an argument they should be required to say back to you, 'Yes, we're totally doing it.' That's why I think California was thinking about mandating that. And again, they might come back to that, to have some sort of visual indicator, like a green light in the corner or something to let you know like, 'Oh, yep, we see it. We're on it. Don't worry.'
Eric Meyer: Yeah, that's what I was thinking. Some way of being able to put in the URL bar, a little thumbs up or whatever, the GPC has been heard. Which I think would feed into what Brian was looking for, a way of signaling this has been used and it's useful in the underwriter's laboratory kind of way.
Brian Kardell: Yeah. I mean, I can imagine that being surfaced by a search engine. I can imagine it being surfaced by your LLM when it gives you a link, which is basically similar idea. Or even an extension that paints a little indicator next to links with CSS generated content. It's like, yeah, this one, the well-known URL is there and they claim to support it. So, at least they're aware of it. You know what I mean? Because I think one trouble with this potentially is that a lot of sites are running on fumes. Do you know what I mean? A really, really large portion of the web is still running jQuery and not because people are adopting jQuery now, but because mom and pop paid $10,000 to some little company to make their website 20 years ago. And now, it's just like they get their grandkids to do some basic HTML CSS to keep it up to date or whatever. And so, I'm not saying that that's good or bad or they should be held to a different account or anything. I'm just saying it would be nice to know who is even aware of this, but just as a simple UL listing so that people know, well, I would like to get the checkbox on my website and I would like to let people know that they're safe with me. Of course, anybody can say anything, right? But it does, I think even legally, it looks worse for you if you say you support it and then you don't. Right? I think any judge is going to be pretty in your face about that, I would imagine. I'm not a lawyer, so don't take my advice for it, but.
Justin Brookman: Yeah. I mean, I think most website developers now, even small ones are aware they have legal privacy obligations around the world. GDPR has been in effect, I mean, even before that, data protection directive was in effect since 1995. Most sites have to have some sort of middleware infrastructure they use to help comply, manage cookies and whatnot. And most of the middleware companies do have easy GPC configuration settings. So you can just pull up the screen and say, 'Okay, when we see GPC in these states, turn off these cookies.' And so there is a good, a big privacy compliance infrastructure out there to help people do this. But you're right, they're not using it. I mean, firstly, they're small enough where they're not even using that. They might just not be legally required to do anything, because most of these state laws only kick in if you're a big enough company. But again, I think certainly among the privacy community, if you are big enough to have a privacy person on staff, then you're probably aware of GPC, if for no other reason that most of the compliance actions have included a GPC count. Right? 'You didn't do X, Y, and Z, you didn't let people delete their data, you didn't show this notice. And by the way, you also didn't honor GPC settings.' And so again, that fear of God, if nothing else, has made a lot of people, and probably not everyone, but certainly the privacy community aware of their obligations to honor GPC.
Nick Doty: I mean, I get the sense that browser developers have tended away from this direction. Right? It used to be we had status bars and more rich, complex logos in the URL bar to try to indicate security or privacy or all sorts of settings. And I think browser vendors though, hey, users are just getting inundated and confused that they don't really know how to make any decisions based on this. We should stop giving individual users information that they're not going to make a meaningful decision on, either because we care about overburdening them or just because we want our software to look more elegant. And either way, the direction has been fewer of these icons and logos. So, I don't see a current appetite for that, but I actually think there are other ways that you can provide some of that accountability. It might not be the average user is going to check for this logo or something, but it might be if there is some statement made that then some enterprising researcher can come along and see, oh, I did a crawl of the 10,000 most popular websites that people in this jurisdiction visit, and this is what I could detect about the promises that they had already made. And that can help drive things like enforcement actions. And I think those are going to tend to be focused on the larger players anyway, because that's what the data protection authorities care about, that's the largest way to have an impact for the citizens in your jurisdiction. So, I don't think we should give up on websites making these declarations or promises, but I'm not sure it's necessarily going to be end user focused, that every user sees an icon and makes a bunch of decisions based on it. But at a group or meta level, if lots of websites do that, then researchers, policymakers, these other accountability mechanisms, the press could say, 'Hey, we did this analysis. Can you believe that these super sensitive sites don't even support this privacy feature?' That type of thing. That there are other places that can do that, gathering and awareness better than every user looking at icons in their browser.
Justin Brookman: Right. I mean, like the HTTPS block is gone now, right? Not even that, they're going to surface for you. But the browser's like, well, if you try to go to a site, they're going to try to warn you maybe you shouldn't be going there. So maybe that could happen with C2, that you don't have to make a choice, but if the browser suspects that your privacy is not being honored, then maybe they say, 'Don't go there.' That could be where it ends up, especially as the browsers are going to be required to offer tools to folks, and if they're not working, then that looks bad for them. I think that's one reason they're a little slow to roll them out, because Do Not Track was announced in 2012. Everyone's like, 'Oh yeah, Do Not Track, it's just going to solve all our problems.' And in a matter of weeks, all the big browsers put Do Not Track in there, but it didn't do anything. I mean, for 10 years, everyone's like, 'Oh, we're still figuring out what it means. We'll get around to telling you later.' And then I think they eventually all deprecated it slowly, but they offered a tool to folks and it didn't mean anything. And so they're going to want when they're required to offer a universal opt-out that it actually has some meaning for folks and maybe not just in the handful of states right now that mandate it. But over time, to your point, everyone should, who's telling the world, 'Please, leave me alone,' the browser's giving you the tool to say, 'Please leave me alone,' The browser has some interest in enforcing that or getting the user to the state that they have asked for.
Brian Kardell: It is an interesting choice that I think unlike Do Not Track, this is very much a simple Boolean and it intentionally leaves no mechanism for extension and clarification of itself. And it's like, send a different header. Do you want to speak to how that came about, or is it a good decision in the end? Is it a thing that you struggled with? Or I'm not saying it's a good or a bad decision, but I expected it to be extensible because it does feel like there's a lot of opportunity for added nuance here, especially in the JSON about what I know. In the JSON where you can advertise, we know about this, we support this. There's opportunity in that JSON to give more information about what that means that you support it or something, and it's not in there. So I'm just curious if you could talk about the history, the decisions, or you don't think that's interesting?
Justin Brookman: No, I think it's been interesting. We talked about it, we still talk about it. We talked about it in W3C, I think Google's made that point. We should try to solve... There's a lot of privacy problems that this might solve. And again, it's not just companies like NOYB, who is a European based, probably well thought as very aggressive, Max Schrems. They have worked on an extension that is a lot more complicated, that you can make fine grain privacy choices. I guess one, because people don't have time for that. Again, I mean, site-by-site, certainly not, but I think it's still hard to... I mean, I remember Explorer used to have that. You can pick what your... Do you want high, medium, or low privacy? And even that's a lot for people to process and they shouldn't have to, and so I like the binary choice. And then the other thing is fingerprinting, right? I mean, we've talked about that. Turning on DNT or GPC, even just being binary, is a fingerprinting signal. If you make it a lot more extensible and you can do 15 settings at once and suddenly it maybe becomes very identifying. And especially in the jurisdictions where GPC is not legally binding, it might perversely actually make it a lot easier to track you. And that is something that we have definitely talked and thought a lot about, and one reason for keeping it simple.
Brian Kardell: This is definitely not a criticism as much as a question about why, especially in the JSON, it felt like there was an opportunity there. And when you go, look, it says, 'No, we intentionally chose to not do that.' I think to your point and to actually a lot of the points in this chat have somehow circled around what I think is, you say, ain't nobody got time for that. But I don't know that it's time as much as it's even the ability to make the decision in a lot of cases. I don't think that anybody understands what they're doing. Even when you get these cookie banners, I don't know if you look at some of them, but it's like if they have two check boxes, one of those options might be, 'It's okay for us to share your data with our 25,000 partner.' That's literally a thing that I have seen on not obscure websites. You know? That's a 25,000 partners, that's the same origin policy doesn't allow you to share with a subdomain. You know what I mean? It doesn't allow you to be like HTTP and HPS. No, those are completely different things. You know? Two different ports, what? Are you crazy? But 25,000 other partners, I don't think people understand what they're accepting. And to the earlier point of there probably is some less binary choice that people would be okay with, but how do they understand it in the first place is a big problem. You know? And I think it's good to let people experiment with the UI around that and use this sort of simple blunt instrument as the mechanism for it, and let governments figure out their own thing with a single signal that people are probably trying to express like, 'Just don't be gross and track me, just, please.' So, I actually am pretty keen on it. I think it's pretty cool. I would like to hear if anybody in our audience has problems with it, because it seems like a really good idea to me. Like a lot of things, I can imagine potentially technically better answers, but I don't know if they're technically better and can be done. Do you know what I mean? The problem is balancing all of these factors of, can you get it implemented? Can you get laws built around it? Can users understand it? I think the nice thing about this is it walks a really nice line for a lot of those-
Justin Brookman: Yeah. I mean, you want it to get a platonic ideal of people really understanding what's going on and making these granular choices, but it's really difficult. Even explaining first party, third party and you're going to lose people right away. And even though GPC is really a request to turn off third party tracking and it isn't going to stop the site from remembering you. Again, trying to... People are just going online, they want to buy diapers and then to be done. Right? They don't want to be tracked, but they mostly need diapers, so they don't have a lot of time or ability to do that. And we're not going to teach people. I mean, we're not going to try to explain how ad tech works to folks. 10, 15 years ago maybe now, there was a paper called Folk Models of Privacy where they asked normies, 'What do you think happens when you go online and where the data goes and who you share with?' And they all drew these amazing pictures of what they thought was going on. None of which is actually reflected in reality, but it shows people even when they have to think about it, what does it mean? They don't know. And the burden, the labor of trying to find somebody who's not actually that interested is going to be really hard. Now I will say, I'm a little bit sympathetic to the browsers because they maybe do have to be a little more careful about telling folks what it does. And if they offer a tool that doesn't work, especially the big companies who have been sued before on privacy, if they offer a tool like, 'Hey, incognito mode, oh, that's great.' And they rely on it and like, oh, it actually doesn't do what you think it does, that is a legitimate concern to them. So if you do read Google's incognito page, there's a lot more text than Google is normally going to provide about what exactly it does and what it doesn't. And when they offered Do Not Track back in the day, they also would say, 'By the way, Do Not Track is fun, but here's what it's trying to do, but right now no one's really honoring it.' And so that is a tricky part for the company whose job it is to offer the tool and then to say, 'Here, you're telling people to knock it off,' what it might mean, what it might not mean. And it might be disregarded and it's only legally binding in some places. That is a tough thing from a legal point of view to convey when you might be sued for it.
Brian Kardell: I wonder if you had any discussions about whether control was a potentially loaded term in that regard, and whether it should be like global privacy signal or something like that, because that's all it's doing is broadcasting a signal about what you prefer, global privacy, I don't know, indicator.
Justin Brookman: Yeah, no, it's a good point. I mean, we've heard of the Holy Roman Empire was neither Holy nor Roman nor and Empire, right? It's not global because only certain places look for it. It's not necessarily control. It is privacy related, but it doesn't necessarily guarantee your privacy. So we've heard arguments maybe should you change the name, but then at this point, GPC does have, at least among regulators and certain people, we know what it means. Right?And so if we were to rebrand it, that has some costs as well.
Brian Kardell: Sure.
Justin Brookman: But yeah, definitely concerned about over-promising. And again, part of the problem is we're taking advantage of these laws that from my point of view as a privacy advocate, are too weak. I would just assume a lot of stuff be prohibited by default. I think it's the shame that you go to a website and by default, there are 100 other companies there watching what you do who can correlate what you do there with other places as well.
Brian Kardell: 100%.
Justin Brookman: It annoys me further that even when this is turned on, you don't even turn a lot of that off. You just tell them, 'You can only do it for limited purposes, mostly just data sales and target advertising.' But half the other stuff that you do, these people can still watch you, which is why a lot of people still are going to want to block ads and block trackers because these laws, when they allow for GPC, don't turn off what a lot of people are going to want to turn off.
Brian Kardell: I would also submit global thermonuclear privacy control as an option, just as a throwback to War Games.
Justin Brookman: Just file a pull request.
Brian Kardell: Okay.
Nick Doty: I mean, like most web standards, I'm hoping that no user ever sees or is forced to understand these abbreviations or spec names. So I am interested in, yeah, what is the best way we could communicate this? And I have tended to use that preference expression language, but I think signaling is a good thing too. I think there might be more standards work that we're going to do around signaling, because I think there's going to be a lot of privacy things that come up. Not just this, can we exercise a legal right not to have our data sold? But I think there's going to be a lot of privacy things that come up where we can't in the browser block everything, and so we're going to need to signal. Users are going to need to signal to websites, websites are going to need to signal back to users about what's happening with their data downstream or off the web. So, I think there's going to be a lot more of this signaling technology that might be necessary if we're going to have privacy, because I don't think anymore we can rely on, well, we'll just get perfect protection, the perfect system of blocking just on our device or on our browser.
Brian Kardell: I wanted to just thank both of you again for coming on. I think we got to wrap it up, we're about out of time. But this was really, really great and I hope that it helps make more people know about your spec and the effort and we'd love to hear what people think about it.
Eric Meyer: Yeah.
Nick Doty: We're trying to do wide review. So yes, please send us feedback. The privacy working group, this is our first recommendation track deliverable in addition to doing privacy reviews. So, that's also a new experience for us. But yeah, I hope we can also learn from this spec and then maybe there'll be more privacy work to do in the future.
Brian Kardell: Where can people find the privacy working group so that they can file issues and make comments, things like that?
Justin Brookman: Search up global privacy control, a landing page, and this deck is linked there. That's usually how I get there.
Eric Meyer: Okay. So, where should people go if they want to follow you on the socials or follow your work or otherwise get connected?
Justin Brookman: Yeah. I'm still on Twitter. I'm Justin Brookman on Twitter. LinkedIn is probably where I do most of my postings. So Justin Brookman there. Bluesky, occasionally. And then Consumer Reports. I mean, a lot of my work is direct to the states, and so you look at Consumer Reports Advocacy, you see all the stuff we do, all the letters and the testimony we do to try to get privacy and other laws passed around the country to do better consumer protection online.
Nick Doty: And sure, from my side, the Center for Democracy and Technology, that's cdt.org. So I write on the blog there, I have lots of colleagues that work on privacy and free expression and equity in technology. On social media, you can see me, I'm npdoty@techpolicy.social on the Fediverse.
Brian Kardell: Great.
Eric Meyer: Cool.
Brian Kardell: And thanks to both of you and your organizations for doing the work. Appreciate you.
Eric Meyer: Yeah, thank you. Great to meet you.
Nick Doty: Well, and thanks for talking about it. Sometimes the privacy stuff, it can be frustrating or complicated or something, but doesn't get talked about enough. And so, I appreciate it. Let's keep talking about it.