Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
FPS members must allow technical verification
Make it clear that a site cannot claim first-party set membership and then use ToS or configuration to disallow automated checks by a user agent or independent enforcement entity. An independent enforcement entity may be able to detect that an FPS member domain is handling user data in a manner inconsistent with the shared privacy policy. An FPS in which this occurs may be presumed invalid without waiting to check if other members of the FPS violate their posted policy in the same way. (Many downstream violations of privacy policy, such as email spam and telemarketing, are randomized, or data sets are partitioned. An independent enforcement entity may detect a privacy policy violation by one member of a set but not others that are doing the same thing, and would need to be able to disallow the FPS.) Refs: #43
- Loading branch information