Page Content | Main Menu | Section Menu | Support Us | Contact Us
Center for Democracy and Technology
Working for Democratic Values in a Digital Age
Support CDT
Contact Us
PolicyBeta - Digital Policy in Process
This Section

Does Phorm Fit?

May 30th, 2008 by Paul Otto

Last week, the European Commission issued an answer to several queries regarding Phorm, a U.K. company that uses Internet traffic data to serve targeted advertisements. Phorm has proposed partnerships with some of the United Kingdom’s largest ISPs that allow Phorm to use deep packet inspection (DPI) to create profiles of individual consumers’ Web habits. Several members of the European Parliament asked the European Commission whether Phorm’s actions constitute an invasion of privacy contrary to European Union privacy protections.

In its response to these questions, the European Commission explained how the Phorm system intersects with the EU ePrivacy Directive. The Commission declared that, under the directive, the Web traffic information collected by Phorm is “traffic data� and the content of search queries intercepted by Phorm constitutes “communication,� both of which are protected from interception or surveillance without consumer consent.

The Commission noted that the U.K. Information Commissioner’s Office (ICO) — which enforces U.K. data privacy laws — is responsible for monitoring Phorm’s actions. In a review of Phorm’s DPI plans, the ICO said that Phorm’s system “does not appear to be� harming consumers. The ICO will be scrutinizing Phorm’s actions, however, to ensure that the company delivers on its promises to not violate consumer privacy rights.

The Commission itself is also taking ICO’s wait-and-see attitude, promising to remain vigilant in continuing to observe the situation and to “take appropriate action, should the need arise.�

The European Commission’s comments come on the heels of recent inquiries in Canada and the United States into ISPs using DPI for network monitoring and targeted advertising. The Canadian Internet Policy and Public Interest Clinic (CIPPIC) filed a complaint with Canada’s Privacy Commissioner in early May regarding broadband provider Bell Canada’s alleged use of DPI to monitor network traffic. And as we discussed in a recent blog post, two members of the United States Congress have sent a letter to broadband provider Charter Communications’ CEO about the legality of its proposed business relationship with NebuAd, an advertising company similar to Phorm. As ISPs continue to negotiate with DPI-based targeted advertising companies, such government oversight may intensify given the privacy and legal concerns with intercepting customers’ Internet traffic.


This entry was posted on Friday, May 30th, 2008 at 3:08 pm and is filed under CDT, Consumer Privacy, International. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

About the Blog

    PolicyBeta is a forum for CDT experts to discuss news and developments in the technology policy arena. Visitors are encouraged to comment on the blog or email the authors.

    Our goal with PolicyBeta is to foster thoughtful discussion regarding technology policy as it relates to civil liberties and democratic values. While we encourage comments, we must insist that they be focused, relevant and written in a tone that is respectful of other posters. For more information, please feel free to contact PolicyBeta editor Brock Meeks.

    Check the main CDT site for complete, up-to-date information on CDT initiatives and activities.

Search Blog
       Top
Privacy Policy | Feedback