ISSUE-152: Write up logged-in-means-out-of-band-consent

Updated Proposed Text:


"User registration and login often are bundled with a set of sign-up flow notices, Terms of Service, and Privacy Policy by which a 1st party will operate.  If these notices directly address interactions with users off of the 1st parties direct web site, such as through Widgets or other interactions with a user in a logged-in state, in an open and transparent manner, then this is considered an out-of-band user consent.  If a party claims it supports DNT, they MUST claim their out-of-band consent in DNT response headers or well-known URIs (direction TBD) - including a link to instructions for the user to alter a previously granted out-of-band consent if they so desire.  If a service that employs registration (logged-in) is silent on how their service interacts with DNT (we honor it, we don't, you're providing consent to our service to ignore your DNT setting, etc.), then it should be assumed that party is not honoring DNT.  If on the other hand a service states they comply with the DNT standard, they would need to articulate what this means for their registration services.  If a party both states they support DNT and is silent on how this interacts with their registration services, then that party MUST continue to honor DNT despite a user logged-in status."

Received on Tuesday, 10 April 2012 17:06:57 UTC