"Data is the pollution of the information age. It's a natural byproduct of every computer-mediated interaction. It stays around forever, unless it's disposed of. It is valuable when reused, but it must be done carefully. Otherwise, its after effects are toxic."
I agree with this idea; that's why I prefer the regulation of data collection and storage, rather than use. Allowing companies and governments to collect massive amounts of data about people that they aren't allowed to use in certain ways today is a ticking time bomb. This data is attractive to criminals who aren't bound by laws anyway, and corporate mergers or changing laws can retroactively harm privacy based on data that was previously collected.
I've been toying with a Creative Commons like service, one where as an organization, you can choose the criteria which meet your privacy policy. This would have a "visual vocabulary" akin to the CC badges or nutrition facts on food for different privacy models. It seems like a missing component is clarity and transparency when it comes to understanding the implications of several facets: collection, storage, and use being the big three.
This paper by Irene Pollach [http://portal.acm.org/citation.cfm?id=1284627] delves into some of the details and weaknesses in privacy policies and how legalese can weasel out of a real policy.
Schneier's article makes me even more concerned about storage -- which I think most people dismiss if the use argument is addressed.
I think P3P never gained traction in part because it was too early. I don't remember in 2000-2002 people getting in huffs over privacy policies. They weren't common then. Terms of use were -- deep linking policies. Heh.
One of the major P3P criticisms is the lack of enforceability. While say a Creative Commons license is applied to a work, if a P3P "contract" was applied to a site, how does one enforce it?
I think with the oversight a community provides (Facebook ToS is a recent example), a community or communities could keep companies' policy _more_ honest. I'm currently formulating my thoughts on this; I'm not completely versed in privacy nor previous attempts to clarify, add trust, understanding and accountability, like P3P.
I'm think it is wholly because it is unenforceable and unverifiable when it comes down to it. P3P allows websites owners to assert their privacy policies, and some aspects of the TOS, in "machine readable" formats. This was supposed to allow standardization to allow better filtering automatically when you visit a site. You tell your browser you are only interested in sites that "collect cookies for the purposes of aggregate data collection" and "don't sell personal information to third parties", and the browser was supposed to warn you, or change its functionality, based on your targets with the site's claimed assertions. It doesn't work like that though, for the same reason the Firefox bad certificate screen ended up being more annoying than useful: no one actually cared about security more than using the site. It's easier to override the settings and use the site. And you could never be sure, until after the fact when it's too late because the information is already out there, that the policy was ever followed or not.
And because of that and the way IE's default "internet zone" cookie policy worked, you pretty much had to, as a website, assert policies that were amenable to the IE defaults.
This would only work when there is significant competition between interchangeable and interoperable sites anyway. Facebook asserts policies A, B, and C, while Myspace asserts policies X, Y, and Z. Well, those policy differences don't mean anything if I actually want to use Facebook because that's that's where my friends are. Privacy policies are only a differentiation point if the policies are different and the services are exactly the same, which is actually impossible (and not really in the indivdual sites' best interest anyway).
P3P has some use as a way to monitor the privacy policy and TOS on a site, and have your browser notify you of changes. I don't think this is necessarily better than what happened with Facebook TOS where someone was following it closely, actually read it, and raised hell about it. There's an emotional aspect tied to that, one that doesn't exist when your browser pops up a box with a warning you just want to dismiss and get out of your way.
I agree with this idea; that's why I prefer the regulation of data collection and storage, rather than use. Allowing companies and governments to collect massive amounts of data about people that they aren't allowed to use in certain ways today is a ticking time bomb. This data is attractive to criminals who aren't bound by laws anyway, and corporate mergers or changing laws can retroactively harm privacy based on data that was previously collected.