Google Inc. this week announced Google Dashboard, which the company claims will provide transparency, choice and control over the vast amounts of data it collects about its users.
"Many people rely on a host of Google products and services in their daily lives," said Erica Newland, a privacy analyst at the Center for Democracy & Technology. "Until now, there's been no easy way to keep track of which Google products you are using, not to mention a way to comprehensively manage the information you share with Google across its different products. By creating a dashboard that unites this information and provides clear links to relevant privacy settings, Google has helped give people a little more control over their online identities."
Google Dashboard joins a number of online resources, including:
- Privacy Center, which provides users with online privacy policies for each service.
- Data Liberation Front, which allows users to move data in and out of Google.
- A control panel for "interest-based advertising," which allows users to customize which ads they see.
When users view the list of Google services using the dashboard, they might be surprised just how much data Google is aggregating about online activity. Such information includes Google Docs, Gmail, Spreadsheets, Chat, Tasks and Voice. This creates high expectations for data protection and privacy from individuals or businesses that have entrusted their personal or proprietary data to the cloud. What may be more provocative to many, however, is the history of user searches displayed in the dashboard, including maps, images, products, books or news.
How long does Google hold search data?
Aggregated search data is the crux of the online privacy issue for Google, which makes the bulk of its profit from advertising against search results. Alan Davidson, director of public policy and government affairs at Google, spoke at a panel on privacy earlier in the week at the Center for American Progress in Washington, D.C.
Privacy is an "ethical and business imperative," Davidson said. "Users are increasingly finding value in sharing personal information online."
One example of this trend, he said, is cloud computing, like Google, Hotmail or Yahoo email, Facebook or Google search. "People are doing this because they find it to be a compelling way to access things they couldn't access on their desktop," he said, "like converting a document from Mandarin to English for free."
Davidson alluded to the relevance of aggregating data to the future of newspapers, noting that "being able to provide advertising that is useful to users and is well targeted is going to be an important mechanism in the online world."
He suggested that companies can provide people with tools to control their information, including telling them what data is aggregated, offering them choices for control, and ensuring that information is kept secure. One example is interest-based advertising, or behavioral-based advertising, in which ads are served to users based on search or browsing histories.
Jeffrey Rosen, a professor of law at The George Washington University Law School and moderator of the panel, asked Davidson if the solution is to delete data. After Yahoo turned over search data to the U.S. government, Rosen pointed out, deleting these logs became one mechanism to prevent having to turn over the search history of users to government agents on request.
Davidson said the company keeps logs for nine months. "We keep [search data] for a little while because it turns out to be useful," he said. "There's pressure from law enforcement to keep it longer. All we have of that user is an IP address. There's a lot of debate about how identifiable an IP address is."
Could better delivery of health care services or medical therapies ever outweigh the privacy rights of consumers? Davidson raised Google Flu Trends as a "powerful" health tool, "something we were only able to build because we have data for nine months, or longer once we anonymize it."
Davidson said Google is in favor of a "base line" privacy rule. "The basic premise -- that people should know what data is being used for and choices about its being used -- is something we support." Davidson suggested that industry-wide mechanisms are needed, including standards and an ability to opt out. "As much as we'd like this to be something that industry does on its own, it's quite clear that law needs to be involved."
The challenge, as privacy and compliance professionals know, is that there isn't a federal privacy law yet. "Although the dashboard is a step in the right direction," Newland said, "it is clearly no replacement for a national base line consumer privacy law. No such law exists, and consumer privacy violations abound. Consumers ultimately lack the tools to protect their own privacy."