Re: [User Context] Spec Privacy Assessment (SPA) review from Privacy Interest Group (PING)

James Craig <jcraig@apple.com> wrote:
> 
> I've reviewed the Specification Privacy Assessment (SPA) document [1] and
> still believe we should request an assessment from the Privacy Interest
> Group (PING). I do not believe there is any additional work for us in the
> IndieUI User Context spec until we hear back from them.

I agree. There may be additional work thereafter. In particular, the SPA
document is concerned with the flow of personal data, which we don't directly
address other than by controlling it at the boundary between user agent and
content script.

We may need to give additional advice to Web application authors, for instance
to avoid transferring the user's preferences to the server, where practicable,
and not to retain them after the user's session terminates without strong
reasons for doing so.

Received on Tuesday, 20 May 2014 01:44:27 UTC