Feeds

Facebook revises privacy policy

Plain English update

Securing Web Applications Made Simple and Scalable

Facebook has published a simpler, easier to understand privacy policy which removes complicated technical and legal terms in the previous document without changing much of substance.

Less than 7,000 people commented on the social networking site's proposals to change its privacy policy. This allows the company to adopt the revised scheme without a public vote. If more than 7,000 people had commented on the policy during a week long consultation period, then a vote would have been triggered. In the event only 453 commentards weighed into the debate before the 5 November deadline.

The revised policy advises users to make full use of the social network's privacy settings and application settings to control how much information they share, and with who they share this information with. Facebook provides controls, but it is up to individuals to check and ensure that appropriate settings are in place.

Facebook is supported by ads but it promises users that it "will not share your information with advertisers without your consent", though it will allow advertisers "to select characteristics of users they want to show their advertisements to and we use the information users share with us to serve those advertisements".

One significant difference is that advertisers will be given more details about how their adverts perform. User data related to this will be "anonymised", Facebook promises.

The new policy was completely rewritten, so any changes are not marked as such. Based on user feedback, Facebook promised to publish a redline version with any future revision so users can more easily see what changes have been made in future editions of the policy.

One of the most significant threats to user data comes from malicious applications. A statement of "Rights and Responsibilities" associated with the revised Facebook privacy policy again puts most of the emphasis on surfers to be careful. "We require applications to respect your privacy settings, but your agreement with that application will control how the application can use the content and information you share," Facebook explains.

Users who set their profile as viewable by everyone (the default setting) can expect search engines to index any content they upload.

Users who upload video or pictures to Facebook hand over "non-exclusive, transferable, sub-licensable, royalty-free, worldwide" license, the statement further explains. Up until recently, Facebook only allowed users to "deactivate" their accounts so that their profile was left dormant and no longer visible rather than deleted. This Hotel California policy policy was changed last year, so that users can remove their profile, a point reaffirmed by the revised privacy policy. The new policy also aims to address concerns on this and related privacy policy raised by the Canadian Privacy Commission back in July

More information on the revised policy can be found on the site governance section of Facebook's website here.

In related news, Facebook came under fire on Wednesday over allegations it had failed to implement child safety measures. Jim Gamble of the Child Exploitation and Online Protection Centre criticised Facebook and MySpace for failing to follow Bebo's lead in including Ceop's "Report button" on pages, so that illegal content or online abuse might be more easily reported. Facebook said it already had a robust reporting system in place. The issue is covered in greater depth in our earlier story here. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Boffins build FREE SUPERCOMPUTER from free cloud server trials
Who cares about T&Cs when there's LIteCoin to mint?
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.