Skip to main content

If you don't have an IBM ID and password, register here.

By clicking Submit, you agree to the developerWorks terms of use.

The first time you sign into developerWorks, a profile is created for you. This profile includes the first name, last name, and display name you identified when you registered with developerWorks. Select information in your developerWorks profile is displayed to the public, but you may edit the information at any time. Your first name, last name (unless you choose to hide them), and display name will accompany the content that you post.

All information submitted is secure.

The first time you sign in to developerWorks, a profile is created for you, so you need to choose a display name. Your display name accompanies the content you post on developerworks.

Please choose a display name between 3-31 characters. Your display name must be unique in the developerWorks community and should not be your email address for privacy reasons.

By clicking Submit, you agree to the developerWorks terms of use.

All information submitted is secure.

The cranky user: Respecting user privacy, Part 1

Earn their trust with a clearly-written, straightforward policy

Photo of Peter Seebach
Peter Seebach has been having trouble navigating through badly designed pages since before frames and JavaScript existed. He continues to believe that, some day, pages will be designed to be usable, rather than being designed to look impressive.

Summary:  Last time we talked about why it's dangerous to be overly dependent on JavaScript in your Web pages. This time, we'll look at why privacy is a much-abused buzzword. The e-commerce industry has failed miserably to produce consumer confidence; not because we haven't tried to do so, but because we've done it through dog-and-pony shows, rather than real respect for personal data. It is particularly crucial to note, in this context, that not everything that is legal is acceptable. We discuss the basic principles of an effective privacy policy: It must be short and readable, and the customer must like it.

View more content in this series

Date:  24 Apr 2001
Level:  Introductory

Comments:  

In your face

What is privacy? Privacy is a big buzzword these days. Sites have long, involved privacy policies -- many of them 15 to 20 paragraphs long. The Federal Trade Commission is talking about a need for legislation to correct problems with online privacy.

The fact is, privacy is something that has great importance to most consumers, and negative importance to all too many marketers. The moment we agree not to call, not to fax, not to spam the customer into next week, we have given up "eyeballs." Marketing is all about eyeballs, all about buzz, all about getting in the consumer's face, right up close so they can see our pores.

Privacy is anathema to these in-your-face marketing models. Privacy means leaving customers alone, not selling everything we can to them. Privacy means not selling the "eyeballs" we have to our would-be marketing partners. Privacy, the way consumers' rights advocates go on about it, seems to imply a kind of distant, formal relationship -- not one where you can keep in touch.

This is simultaneously true and false. Modern marketing is surprisingly close to stalking. We collect data. We analyze it. We predict. One British grocery store chain experimentally sent out pamphlets to women reminding them that it was about time for them to stock up on feminine products; the campaign was dropped quickly. The fact is, the marketing instinct tells us we need to know about people, and we want to find out about them, whether the people tell us themselves or we collect the data from "partners." At the same time, we give those partners the juiciest tidbits we can find.

The end result is that consumers are, justifiably, terrified of us. They know that a phone number given "for questions about your order" will quickly turn into dinnertime sales pitches. They know that a street address given for shipping today will receive piles of glossy pamphlets next week. And they want it to stop. So, they avoid us -- because we're trying to get too close, without any concern for what they want. If we give them a little space, we may find we have closer, and more willing, relationships with them!

So, with this in mind, let me walk you through a few key points that may help you understand what privacy policies are really about, how to write a good one, and why it matters.


The finer things

The first order of business is this: People hate fine print. Really. They hate it. There's an urban legend about an insurance company that once put a paragraph on page 17 of a policy saying, "If you read this paragraph, call our corporate offices at (800 number) and we'll pay you $100.00." No one tried to collect. None of them read that far; the state law mandating the "full disclosure" was irrelevant. (This was, supposedly, why the insurance company put the paragraph there; they wanted to show that the law was irrelevant.)

What that means is that, if you have a truly comprehensive privacy policy, chances are that none of your customers have read it. So, anything you do that fails to meet their expectations will come as a shock. Companies get used to saying, "Well, our policy is just an industry norm," but many customers aren't aware of the "industry norm," and that means they won't be expecting it when you follow through on that policy.

Some companies try to capitalize on this: They hide the most odious terms near (but not quite at) the end of the document, and disguise them behind confusing double and triple negatives. They say things like, "If you decide that you no longer wish not to be excluded from our mailing list, you may send a request stating your preference to...". Most people don't notice -- and thus, are offended when you try something funny. The ones that notice will never trust you.

So, if your policy is going to do you any good, it must be short, and it must be in clear language. It has to be unambiguous, and it has to be easy to understand.


Warm fuzzies

Secondly, the policy actually has to be a good one. The reason we write such long, wordy policies is that we know customers won't like it if they understand it. As soon as we commit to writing a policy the customer can understand, we have committed to writing a policy the customer will like. Would you write a clear, comprehensible, policy, if you knew the customer would hate it?

Your policy, then, has to provide warm fuzzies. If you're writing in clear language, that means you have to make some promises that will probably terrify your marketing department. Promises like: "If you provide an e-mail address for order confirmation, it will be used only for correspondence related to your orders. It will not be used for marketing or promotional material, and it will not be shared with third parties unless you ask us to share it." Read that little passage again; it's a paraphrase of the policy that got me hooked on the bookstore I've used for all my online book shopping in the last few years (see Resources). Having read that, wouldn't you feel safe handing out your real e-mail address, not just a throwaway Hotmail account, to this company, knowing that you won't be deluged with spam?

This week's action item: Read your company's entire privacy policy -- every paragraph. Talk about it with someone. See if there are any terms you aren't sure of. Do you redefine common terms in surprising ways? Does your policy contradict itself? Most do.


Resources

About the author

Photo of Peter Seebach

Peter Seebach has been having trouble navigating through badly designed pages since before frames and JavaScript existed. He continues to believe that, some day, pages will be designed to be usable, rather than being designed to look impressive.

Report abuse help

Report abuse

Thank you. This entry has been flagged for moderator attention.


Report abuse help

Report abuse

Report abuse submission failed. Please try again later.


developerWorks: Sign in

If you don't have an IBM ID and password, register here.


Forgot your IBM ID?


Forgot your password?
Change your password


By clicking Submit, you agree to the developerWorks terms of use.

 


The first time you sign into developerWorks, a profile is created for you. This profile includes the first name, last name, and display name you identified when you registered with developerWorks. Select information in your developerWorks profile is displayed to the public, but you may edit the information at any time. Your first name, last name (unless you choose to hide them), and display name will accompany the content that you post.

Choose your display name

The first time you sign in to developerWorks, a profile is created for you, so you need to choose a display name. Your display name accompanies the content you post on developerWorks.

Please choose a display name between 3-31 characters. Your display name must be unique in the developerWorks community and should not be your email address for privacy reasons.

(Must be between 3 – 31 characters.)


By clicking Submit, you agree to the developerWorks terms of use.

 


Rate this article

Comments

Help: Update or add to My dW interests

What's this?

This little timesaver lets you update your My developerWorks profile with just one click! The general subject of this content (AIX and UNIX, Information Management, Lotus, Rational, Tivoli, WebSphere, Java, Linux, Open source, SOA and Web services, Web development, or XML) will be added to the interests section of your profile, if it's not there already. You only need to be logged in to My developerWorks.

And what's the point of adding your interests to your profile? That's how you find other users with the same interests as yours, and see what they're reading and contributing to the community. Your interests also help us recommend relevant developerWorks content to you.

View your My developerWorks profile

Return from help

Help: Remove from My dW interests

What's this?

Removing this interest does not alter your profile, but rather removes this piece of content from a list of all content for which you've indicated interest. In a future enhancement to My developerWorks, you'll be able to see a record of that content.

View your My developerWorks profile

Return from help

static.content.url=http://www.ibm.com/developerworks/js/artrating/
SITE_ID=1
Zone=Web development
ArticleID=11511
ArticleTitle=The cranky user: Respecting user privacy, Part 1
publish-date=04242001
author1-email=crankyuser@seebs.plethora.net
author1-email-cc=htc@us.ibm.com

Tags

Help
Use the search field to find all types of content in My developerWorks with that tag.

Use the slider bar to see more or fewer tags.

For articles in technology zones (such as Java technology, Linux, Open source, XML), Popular tags shows the top tags for all technology zones. For articles in product zones (such as Info Mgmt, Rational, WebSphere), Popular tags shows the top tags for just that product zone.

For articles in technology zones (such as Java technology, Linux, Open source, XML), My tags shows your tags for all technology zones. For articles in product zones (such as Info Mgmt, Rational, WebSphere), My tags shows your tags for just that product zone.

Use the search field to find all types of content in My developerWorks with that tag. Popular tags shows the top tags for this particular content zone (for example, Java technology, Linux, WebSphere). My tags shows your tags for this particular content zone (for example, Java technology, Linux, WebSphere).