Thursday, December 31, 2009

The case for User-specified TOS and Privacy Policies

Every service provides its own Terms of Service and Privacy Policy, and the users are supposed to accept it to make use of the service.
But, I can see some reasons for the case for a User-specified Terms-Of-Service (UTOS) and User-specified Privacy Policy (UPP):
Every user indicates in some simple syntax a UTOS and UPP, and services needs to conform to them to be able to provide a service to the user. I think it is time to take away the privacy policy from the lawyers to the computer scientists.

Here are some components of a UPP:

InfoletActions[Predicates]
Biographical InformationRetainfor 30 days
Sharewith <n'th level of Social Graph, Other Services/Apps>
Service Usage InformationRetainfor 90 days
Sharewith <no one>
User-generated InformationRetainforever, unless explicitly deleted
Sharewith <Provide Settings to control>

If a service either violates the policy, or does not support some components of the policy, the user could easily decide to provide an exception and sign up or quit. Some services provide very good privacy policies in the beginning, and slowly start diluting them. It becomes impossible for humans to keep track of legalese english to see if something is amiss. This gets hard for the less popular sites which do not get media attention. The above policy specification if standardized could address user anxiety better I think.

No comments:

Post a Comment