Ill echo apologies for late comments I share some of the concerns namely: > We do not sell, rent, or share any personally identifiable information supplied by visitors to the web site or subscribers to our community mailing list(s) with unaffiliated third parties This language is quite ambiguous, is there a maintained list of current affiliated third parties that information may be shared with? > Other email addresses, phone numbers, and contact information submitted by visitors in the course of inquiries and comments are used for purposes of taking action in relation to the nature of the inquiry or comment and will not be disclosed unless disclosure is required by law Is there a retention period defined for this (Sensitive) information? Has the IETF considered issuing a transparency report or using a warrant canary to inform participants of legal requests for information? (Not necessary but good practice) I would also note that some areas of this policy may fall below the standards of EU Directive 95/46/EC, mainly not having an opt-out clause on transfer of information to (Affiliated) third parties. Overall its good but I would think that some work may still be needed. -----Original Message----- From: ietf [mailto:ietf-bounces@xxxxxxxx] On Behalf Of S Moonesamy Sent: Sunday, March 22, 2015 7:41 PM To: ietf@xxxxxxxx Subject: Re: Proposed IETF Websites Privacy Policy; Community Input Requested Hello, At 08:52 03-02-2015, IETF Administrative Director wrote: >The IAOC would like community input on a proposed IETF websites Privacy >Policy. > >We are required by California law (and good net citizenship) to have an >accurate privacy policy on our websites. Counsel have reviewed this >statement for compliance with US and EU privacy regulations. [snip] >The IAOC will consider all comments received by 17 February 2015. Apologies for the late response. The proposed privacy policy for the IETF web site is four pages. Most people probably won't read beyond "the Internet Engineering Task Force (IETF) is committed to protecting the privacy and security of the personal information of our participants and of visitors to our site". What is the meaning of the following: "You also consent to our using the information to communicate with you further about your interaction with the site, programs, and services, hat IETF may offer to you, and your relationship with IETF." "If you provide personal data through this site, you acknowledge and agree that such personal data may be transferred from your current location to the offices and servers of the IETF and its affiliates, agents, and service providers located in the United States and in other countries." In simple terms the person is agreeing to his/her personal data to be transferred anywhere in the world and to (unknown) affiliates of the IETF. "When you interact with the site, we strive to make your experience easy and meaningful. We may use cookies and other means to track user activity and collect site data." The above text about cookies sounds like marketing. I suggest explaining that the IETF uses cookies for purposes X, Y, etc and list some information about the cookies for the technically-inclined. "We offer specific opt-in and opt-out options so if you do not wish to receive such mailings, please inform the IETF by email, phone, or postal mail directed to the contact information provided at" Doesn't the IETF use "opt-in" by default? Regards, S. Moonesamy