Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why is 1P identity implied to be essential for analytics and ad servers? #15

Open
arvind-m opened this issue Jul 30, 2020 · 2 comments
Open

Comments

@arvind-m
Copy link

Section "Third Parties can be allowed access to a first-party identity" says:

This recognizes that composability is central to the Web — for example, it is unreasonable to expect 1p's to implement their own analytics or ad servers.

While this is a reasonable statement in isolation, it doesn't seem to fit into a section with this title, i.e. it seems to imply that 3p analytics and 3p ad servers can be [generally] allowed access to first-party identity.

Suggest deleting this, unless there is a better example for composability that requires first-party identity in 3p context.

I could be missing something, in case please update text to avoid similar confusion in other readers.

@michaelkleber
Copy link
Owner

I tried to address this question in the very next bullet point:

  • The intent is to let the first party retain control over identity on their site. A 3p who builds a per-1p user profile should be in the same position as any other company with whom the 1p chooses to share its user data.

We've heard in the Web Advertising Business Group that building a "per-1p user profile" is a core operation for analytics, to answer questions like "How long do visitors spend on my site?", or for ads, to make choices about what ad to show, or for frequency capping, etc.

The point is not that "3p analytics and 3p ad servers can be [generally] allowed access to first-party identity", but rather that if a 1p wants to give that access to a 3p, they can do so ("as long as that delegated identity remains sharded by 1p", as I said).

If in-house analytics were able to answer "How long do visitors spend on my site?" but 3rd-party analytics were not able to answer such questions, then the composability of the web would be dramatically harmed.

@arvind-m
Copy link
Author

arvind-m commented Aug 3, 2020

Thanks for the explanation, this helps.

What is an example of appropriate (meaning privacy-preserving) use of "per-1p user profile" to make "choices about what ad to show"? Which specific proposals could we refer to as exemplifying this use case?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants