through its AdWords system and watches the advertisers through AdWords auctions
that determine the value of advertising topics. Content providers track the value of
those advertising topics to determine which sorts of content to publish. The advertisers
use the AdWords system as a stateless form of market research to target consumers
without knowing anything about them. Content providers watch consumers to determine which sorts of content generate the most interest. All this monitoring happens in
real time. Google adjusts the placement of ads in real time according to the current
results of an ad auction; content providers watch the profitability of their content
in real time and make adjustments to attract more ad-clicking customers; advertisers
adjust their bids and update their ads in real time to attract more users. The effect of
the system is continuous but stateless market research that is constantly adjusting to
the current interests of users rather than the historical interests over time tracked by
user profiling organizations like comScore, Phorm, and NebuAd.
Google and other service providers only have access to data that is sent directly to
them over the network: the client address, the request itself, and any content explicitly
submitted by the user. All these server-collected data, other than the client address,
may be encrypted while traveling over the network, giving the end server access to
some data that are not available on the network. For Web servers, the protocol data
may include cookies, which are often used to assign a pseudonymous identity that persists between separate requests. Users voluntarily (and knowingly, at least in theory)
submit vast amounts of such data to Internet servers. Users are aware that they are submitting names, addresses, and credit card numbers to Amazon when buying merchandise, personal e-mail to Microsoft through Hotmail, and movie preferences to Netflix
when renting videos.
What determines the risk of privacy intrusions—and what ties this case to the narrative of online surveillance—is not just the collection of data but rather what the actors
controlling the servers do with the data, with whom they share the data, and how the
data are combined with other data. The act of collecting a credit card number to execute a purchase for a user is presumably acceptable and necessary in the modern global
economy. But using the credit card number to request data about a user’s purchase history from the credit card company in order to target advertising at him may not be so
acceptable. Likewise, it is fine for Microsoft to collect personal e-mails through Hotmail, but it would become a concern if Microsoft were to sell its users’ e-mail content
to a consumer research company. And Netflix seems innocuous when using video preference information for its own recommendation engine, but many users would be uncomfortable if they found out Netflix was combining its users’ video rental history
with (even public) information from users’ social networking pages to make video
recommendations.
The issue of combining data is particularly relevant (but not unique) to server-based
surveillance because, in comparison to network and client surveillance, the domain of
the data collected is generally much more limited. However, these domains of data can
The EU Data Retention Directive in an Era of Internet Surveillance
43
that determine the value of advertising topics. Content providers track the value of
those advertising topics to determine which sorts of content to publish. The advertisers
use the AdWords system as a stateless form of market research to target consumers
without knowing anything about them. Content providers watch consumers to determine which sorts of content generate the most interest. All this monitoring happens in
real time. Google adjusts the placement of ads in real time according to the current
results of an ad auction; content providers watch the profitability of their content
in real time and make adjustments to attract more ad-clicking customers; advertisers
adjust their bids and update their ads in real time to attract more users. The effect of
the system is continuous but stateless market research that is constantly adjusting to
the current interests of users rather than the historical interests over time tracked by
user profiling organizations like comScore, Phorm, and NebuAd.
Google and other service providers only have access to data that is sent directly to
them over the network: the client address, the request itself, and any content explicitly
submitted by the user. All these server-collected data, other than the client address,
may be encrypted while traveling over the network, giving the end server access to
some data that are not available on the network. For Web servers, the protocol data
may include cookies, which are often used to assign a pseudonymous identity that persists between separate requests. Users voluntarily (and knowingly, at least in theory)
submit vast amounts of such data to Internet servers. Users are aware that they are submitting names, addresses, and credit card numbers to Amazon when buying merchandise, personal e-mail to Microsoft through Hotmail, and movie preferences to Netflix
when renting videos.
What determines the risk of privacy intrusions—and what ties this case to the narrative of online surveillance—is not just the collection of data but rather what the actors
controlling the servers do with the data, with whom they share the data, and how the
data are combined with other data. The act of collecting a credit card number to execute a purchase for a user is presumably acceptable and necessary in the modern global
economy. But using the credit card number to request data about a user’s purchase history from the credit card company in order to target advertising at him may not be so
acceptable. Likewise, it is fine for Microsoft to collect personal e-mails through Hotmail, but it would become a concern if Microsoft were to sell its users’ e-mail content
to a consumer research company. And Netflix seems innocuous when using video preference information for its own recommendation engine, but many users would be uncomfortable if they found out Netflix was combining its users’ video rental history
with (even public) information from users’ social networking pages to make video
recommendations.
The issue of combining data is particularly relevant (but not unique) to server-based
surveillance because, in comparison to network and client surveillance, the domain of
the data collected is generally much more limited. However, these domains of data can
The EU Data Retention Directive in an Era of Internet Surveillance
43
