Cookies Having Independent Partitioned State
   HOME

TheInfoList



OR:

The Privacy Sandbox is an initiative led by
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
to create
web standards Web standards are the formal, non-proprietary standards and other technical specifications that define and describe aspects of the World Wide Web. In recent years, the term has been more frequently associated with the trend of endorsing a set of st ...
for
website A website (also written as a web site) is any web page whose content is identified by a common domain name and is published on at least one web server. Websites are typically dedicated to a particular topic or purpose, such as news, educatio ...
s to access user information without compromising
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
. Its core purpose is to facilitate
online advertising Online advertising, also known as online marketing, Internet advertising, digital advertising or web advertising, is a form of marketing and advertising that uses the Internet to promote products and services to audiences and platform users. ...
by sharing a subset of user private information without the use of
third-party cookie Third-party cookies are HTTP cookies which are used principally for web tracking as part of the web advertising ecosystem. While HTTP cookies are normally sent only to the server setting them or a server in the same Internet domain, a web page may ...
s. The initiative includes a number of proposals, many of these proposals have bird-themed names which are changed once the corresponding feature reaches general availability. The technology include Topics API (formerly
Federated Learning of Cohorts Federated Learning of Cohorts (FLoC) is a type of web tracking. It groups people into "cohorts" based on their browsing history for the purpose of Targeted advertising, interest-based advertising. FLoC was being developed as a part of Google's ...
or FLoC), Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage and Fenced Frames as well as other proposed technologies like IP Protection, Related Website Sets, CHIPS, and Bounce Tracking Mitigation. The project was announced in August 2019. On September 7, 2023, Google announced general availability of Privacy Sandbox APIs, naming explicitly Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage and Fenced Frames, meaning these features were enabled for more than half of Google Chrome users. Privacy Sandbox features were also made available on Android around the same time. The initiative has been described as
anti-competitive Anti-competitive practices are business or government practices that prevent or reduce competition in a market. Antitrust laws ensure businesses do not engage in competitive practices that harm other, usually smaller, businesses or consumers. ...
and has generated an
antitrust Competition law is the field of law that promotes or seeks to maintain market competition by regulating anti-competitive conduct by companies. Competition law is implemented through public and private enforcement. It is also known as antitrust l ...
response due to concerns that the introduced proposals limit tracking through traditional methods and push advertisers to use Google as a middleman in order to show advertisements.


Model

Proposals in the Privacy Sandbox follow the idea of
k-anonymity ''k''-anonymity is a property possessed by certain anonymized data. The term ''k''-anonymity was first introduced by Pierangela Samarati and Latanya Sweeney in a paper published in 1998, although the concept dates to a 1986 paper by Tore Dalen ...
and are based on advertising to groups of people called cohorts instead of tracking individuals. They generally place the
web browser A web browser, often shortened to browser, is an application for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's scr ...
in control of the user's privacy, moving some of the data collection and processing that facilitates advertising onto the user's device itself. There are three focuses within the Privacy Sandbox initiative: replacing the functionality of cross-site tracking, removing third-party cookies, and mitigating the risk of
device fingerprint A device fingerprint or machine fingerprint is information collected about the software and hardware of a remote computing device for the purpose of identification. The information is usually assimilated into a brief identifier using a fingerprint ...
ing.


Proposals

In January 2020, Google invited advertising technology companies to join the
Improving Web Advertising Business Group The Improving Web Advertising Business Group (IWABG) is a subcommittee of the World Wide Web Consortium with a focus on online advertising. In January 2020, Google encouraged advertising technology companies to join the group as a way to partici ...
(IWABG) of the
World Wide Web Consortium The World Wide Web Consortium (W3C) is the main international standards organization for the World Wide Web. Founded in 1994 by Tim Berners-Lee, the consortium is made up of member organizations that maintain full-time staff working together in ...
(W3C) as a way to participate in the proposal process for the Privacy Sandbox.


Testing

On March 31, 2022,
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
announced the start of a single origin trial, for the Topics, FLEDGE and Attribution Reporting APIs. It allows sites to run unified experiments across the APIs. In October 2022 RTB House published its findings of actively testing FLEDGE by adding users to interest groups.
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
and
Criteo Criteo S.A. is an advertising company that provides online display advertisements. The company was founded and is headquartered in Paris, France. History Criteo was founded in Paris, France, in 2005 by Jean-Baptiste Rudelle, Franck Le Ouay and Ro ...
, also ran tests. The report highlighted that, while positive, the FLEDGE origin trials were limited in scope. It noted that a number of essential features of FLEDGE, specifically k-anonymity requirements, were not available for testing, and will require adjustments after industry feedback. The scale of tests is increasing.
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
aims to dedicate H1 of 2023 to developer testing, and make FLEDGE available for the entirety of Chrome users in H2 of 2023. In November 2022 the
Competition and Markets Authority The Competition and Markets Authority (CMA) is the principal competition regulator in the United Kingdom. It is a non-ministerial government department in the United Kingdom, responsible for promoting competitive markets and tackling unfair beh ...
released a report on Google’s quantitative testing of its Sandbox technologies that highlighted the importance of the industry adopting a common testing framework so that performance tests can be conducted more widely across multiple testing entities. Google is developing such a framework in cooperation with the CMA and is seeking to drive engagement with market participants on the design of testing between now and at least the beginning of General Availability in Q3 2023.


Criticism

Google's proposals during Privacy Sandbox surrounding
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
preserving ads have garnered significant pushback. Concerns have been raised that the proposals are anticompetitive and privacy compromising. Google's initial proposal for privacy preserving ads under the Privacy Sandbox umbrella (codenamed FLoC) received significant opposition from browser vendors.
Mozilla Mozilla is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, publishes and supports Mozilla products, thereby promoting free software and open standards. The community is supported institution ...
, the company that makes
Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements curr ...
, released a statement committing to not implementing FLoC or other related web advertising proposals.
Apple An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
, the makers of
Safari A safari (; originally ) is an overland journey to observe wildlife, wild animals, especially in East Africa. The so-called big five game, "Big Five" game animals of Africa – lion, African leopard, leopard, rhinoceros, African elephant, elep ...
took a negative position against the proposal.
Chromium Chromium is a chemical element; it has Symbol (chemistry), symbol Cr and atomic number 24. It is the first element in Group 6 element, group 6. It is a steely-grey, Luster (mineralogy), lustrous, hard, and brittle transition metal. Chromium ...
derivatives like
Brave Brave(s) or The Brave(s) may refer to: Common meanings *Brave, an adjective for one who possesses courage * Braves (Native Americans), a Euro-American stereotype for Native American warriors Film and television * ''Brave'' (1994 film), a concept ...
,
Vivaldi Antonio Lucio Vivaldi (4 March 1678 – 28 July 1741) was an Italian composer, virtuoso violinist, impresario of Baroque music and Roman Catholic priest. Regarded as one of the greatest Baroque composers, Vivaldi's influence during his lif ...
and
Microsoft Edge Microsoft Edge is a Proprietary Software, proprietary cross-platform software, cross-platform web browser created by Microsoft and based on the Chromium (web browser), Chromium open-source project, superseding Edge Legacy. In Windows 11, Edge ...
disabled the feature by default on their browsers. Concerns were raised that the FLoC's proposal could allow websites to track users in new ways that were previously not possible through
third-party cookies Third-party cookies are HTTP cookies which are used principally for web tracking as part of the web advertising ecosystem. While HTTP cookies are normally sent only to the server setting them or a server in the same Internet domain, a web page may ...
, the technology that FLoC was meant to replace. Multiple media outlets and privacy advocacy groups criticised Google's decision to enable the feature by default for all users during the testing phase. This led to Google to withdrawing the proposal in early 2022. Google's replacement for FLoC, known as the Topics API, faced similar criticism from various groups. Mozilla pointed out flaws in the Topics API's design, highlighting that it could allow large
advertising network An online advertising network or ad network is a company that connects advertisers to websites that want to host advertisements. The key function of an ad network is an aggregation of ad supply from publishers and matching it with the advertiser' ...
s to reidentify and track users by aggregating their interests across numerous websites. Apple echoed similar concerns, also noting that the proposal contradicted efforts made by other browsers to partition data on a per-site basis. Furthermore, when the proposal was initially announced, there were uncertainties about how Google or other browser vendors would establish a taxonomy of topics, a critical aspect of the API that was left underspecified. Alongside the Topics API, Google's other proposals within the Privacy Sandbox, such as
Client Hints Client Hints is an extension to the HTTP protocol that allows servers to ask the client (usually a web browser) for information about its configuration. This helps the server tailor its responses to the client; for example, a server can choose ...
, have also sparked significant privacy concerns among other browsers. These concerns primarily revolved around the potential for Client Hints to expand the surface area for passive
fingerprinting A fingerprint is an impression left by the friction ridges of a human finger. The recovery of partial fingerprints from a crime scene is an important method of forensic science. Moisture and grease on a finger result in fingerprints on surfa ...
on browsers. Due to Google's ownership of the browser with the largest market share, concerns have been raised about the
anticompetitive Anti-competitive practices are business or government practices that prevent or reduce competition in a market. Antitrust laws ensure businesses do not engage in competitive practices that harm other, usually smaller, businesses or consumers. T ...
nature of its proposals. Consequently, in January 2021, the
Competition and Markets Authority The Competition and Markets Authority (CMA) is the principal competition regulator in the United Kingdom. It is a non-ministerial government department in the United Kingdom, responsible for promoting competitive markets and tackling unfair beh ...
(CMA) in the
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Northwestern Europe, off the coast of European mainland, the continental mainland. It comprises England, Scotlan ...
announced plans to investigate the Privacy Sandbox initiative, with a focus on its potential impacts on both publishers and users. CMA subsequently accepted legally binding commitments offered by Google concerning its proposals to remove third party cookies on Chrome and develop the Privacy Sandbox. The formal acceptance of these commitments by the CMA resulted in the closure of the investigation, with no decision on whether the
Competition Act 1998 The Competition Act 1998 (c. 41) is the current major source of competition law in the United Kingdom, along with the Enterprise Act 2002. The act provides an updated framework for identifying and dealing with restrictive business practices and a ...
was infringed. CMA reported that Google was complying with its legally-binding commitments between July 2022 and September 2022. In March 2021, 15
attorneys general In most common law jurisdictions, the attorney general (: attorneys general) or attorney-general (AG or Atty.-Gen) is the main legal advisor to the government. In some jurisdictions, attorneys general also have executive responsibility for law enf ...
of
U.S. state In the United States, a state is a constituent political entity, of which there are 50. Bound together in a political union, each state holds governmental jurisdiction over a separate and defined geographic territory where it shares its so ...
s and
Puerto Rico ; abbreviated PR), officially the Commonwealth of Puerto Rico, is a Government of Puerto Rico, self-governing Caribbean Geography of Puerto Rico, archipelago and island organized as an Territories of the United States, unincorporated territo ...
amended an
antitrust Competition law is the field of law that promotes or seeks to maintain market competition by regulating anti-competitive conduct by companies. Competition law is implemented through public and private enforcement. It is also known as antitrust l ...
complaint filed the previous December; the updated complaint says that Google Chrome's phase-out of third-party cookies in 2022 will "disable the primary cookie-tracking technology almost all non-Google publishers currently use to track users and target ads. Then ..Chrome, will offer ..new and alternative tracking mechanisms ..dubbed Privacy Sandbox. Overall, the changes are anticompetitive". The lawsuit suggests that the proposed changes in the Privacy Sandbox would effectively require advertisers to use Google as a middleman in order to advertise.


References


External links

* {{Google LLC Google Web standards