Trustmark Schemes Struggle to Protect Privacy (2008)

7. Coverage

The limited coverage of privacy trustmarks has been a major concern for consumers. Despite the grand sounding names, such as privacy seal, certified privacy seal or verified privacy seal, most trustmarks only cover a very small area of an organisation’s activity.

For example, the TRUSTe privacy seal states:

The privacy statement and practices of have been reviewed by TRUSTe for compliance with our strict program requirements.

The BBB Online Privacy Seal stated:

The seal does not reflect the past practices or policies of any particular seal participant, or practices pertaining to information collected other than online.

These restrictions have been strictly and severely enforced in practice.

In the Microsoft Global UID case, TRUSTe stated that its seal covered only Microsoft's website – not its software – and that the data Microsoft gathered was not transmitted to Microsoft's website.[67] But consumer groups argued that Microsoft's privacy page (prominently displaying the TRUSTe seal) also discussed online registration of software products, and noted that the ‘personal profile’ from their software registration appears on the website and is editable from the website. That page appeared to claim that registration was covered by the TRUSTe certification.[68]

Similar arguments were used to justify the lack of action in the RealNetworks case and the AOL case.

In the RealNetworks case TRUSTe claimed that the ‘music-listening software works via the Internet, but only indirectly through a Web site visit’.

In the AOL case TRUSTe claimed that the seal only covers ‘’ and not ‘’. This means that if you visit (which is covered by the seal) and you decide to join you are sent to which is not covered by the TRUSTe seal, and you lose your protection.[69]

These three decisions are questionable. Taken together they are one of the chief causes of TRUSTe’s poor reputation.[70] The AOL decision is particularly galling, and makes TRUSTe look like they were happy for AOL to lure people into paying for a service based on a privacy promise that is then withdrawn once the money is handed over.

