Internet privacy — regulating cookies and web bugs

Sharon Nye

Until the introduction of the Privacy Amendment (Private Sector) Act 2000 (Cth), the Australian information economy had burgeoned on almost unfettered use of technology to collect information. The central argument of this article is that the Privacy Act 1988 (Cth) as amended (the Act), with its stated policy of encouraging Australian online commerce, has, in reality, the effect of permitting the continuation of such unfettered collection, only providing illusory privacy protection for the individual.

The discussion will centre on the use of cookies and web bugs in a typical internet marketing network to demonstrate how, by combination of characteristics in the National Privacy Principles (NPPs) and pro-business policy bias, the rules can be read restrictively by courts to permit cookie and web bug surveillance. Given the limited scope, the discussion will only focus on the gateway pillars of the NPPs under the Act, particularly NPP 1, which are most significant in first line defence and also the most tested by the new technologies. NPP 1 provides:

1. Collection

1.1 An organisation must not collect personal information unless the information is necessary for one or more of its functions or activities.

1.2 An organisation must collect personal information only by lawful and fair means and not in an unreasonably intrusive way.

1.3 At or before the time (or, if that is not practicable, as soon as practicable after) an organisation collects personal information about an individual from the individual, the organisation must take reasonable steps to ensure that the individual is aware of:
(a) the identity of the organisation and how to contact it; and

(b) the fact that he or she is able to gain access to the information; and

(c) the purposes for which the information is collected; and

(d) the organisations (or the types of organisations) to which the organisation usually discloses information of that kind; and

(e) any law that requires the particular information to be collected; and

(f) the main consequences (if any) for the individual if all or part of the information is not provided.

1.4 If it is reasonable and practicable to do so, an organisation must collect personal information about an individual only from that individual.

1.5 If an organisation collects personal information about an individual from someone else, it must take reasonable steps to ensure that the individual is or has been made aware of the matters listed in subclause 1.3 except to the extent that making the individual aware of the matters would pose a serious threat to the life or health of any individual.

First, the meanings of ‘collection’, ‘personal information’ and ‘fairness’ will be examined to find that, notwithstanding prima facie broad protection construed by the Privacy Commissioner, the principles often apply awkwardly to the technology and are inched along further towards restrictive application by explicit judicial intention to claw back privacy. Second, discussion of the meaning and application of ‘necessary’ will reveal not only that NPP 1 has limited ability to curb the privacy invasiveness of cookies and web bugs as their functionality now stands, but that the requirement of being ‘necessary’ as ,a floating standard has the ability to permit future developments in the privacy invasiveness of the technologies.

Cookies and web bugs in a typical internet organisational relationship and the potential that courts will apply NPPs to give weak privacy protection

The typical website privacy policy only discloses the use of cookies in a simple request-reply interaction between the user’s browser and the website’s server to facilitate the display of the webpage and any transactions that occur therein.[1] In such a two party interaction, it is still within the intuitive awareness of the user that information is being passed along to the server to facilitate the operation of the website, even though the server is invisible to ,the user.

Controversy lies in the use of cookies and web bugs by third parties: the user assumes that the information is being passed on to the party facilitating the interaction, when in fact the information is also being passed on to a party uninvolved in the transaction and whose existence is unknown to the user. This occurs in the common internet marketing relationship between four players: the user, the company who wishes to advertise its products on third party host websites, the advertisement hosts whose website displays the advertisements, and the intermediary network advertiser who serves the ads on behalf of the company.[2] The user may believe that he or she could only receive cookies from the website that ,he or she is immediately viewing, but in fact the user is also receiving cookies and hence being ‘tracked’ from the network advertiser serving the ads ,on the host website.

Cookies have been defined as ‘a piece of information that the internet website sends to your browser’[3] and web bugs as ‘1x1 clear gifs’.[4] The function of the technologies defies simple definition and will be revealed progressively in the discussion of NPP application. One preliminary distinction must be made however; the type of web bug pertinent to the advertisement context is the ,Type 1 web bug that relays machine information to the server in the downloading process, rather than more malicious types that execute files within the user’s computer itself to directly access personal information.[5]

The central contention of this article is that the NPPs do not decisively curb the privacy invasive potential of cookies and web bugs. The NPPs are a set of high level principles that do not specify what is required for compliance and therefore have elasticity to accommodate interpretation for stringent or weak privacy protection.[6] While the Privacy Commissioner’s Guidelines infer stronger protection to catch technological breaches, because ,no distinction is made between requirements for strict compliance and mere best practice,[7] the courts have some scope to claw back protection afforded by the NPPs. Internet business organisations using cookies and web bugs could rely on s 55A(5) of the Act to force a court hearing and avoid a ‘pro-privacy’ Commissioner’s determination.[8]

The NPPs give courts leeway to roll back protection by a combination of technological neutrality that creates ambiguity in application, and a pro-business bias that gives the opportunity to construe the ambiguity against the consumer.[9] The NPPs are worded generally[10] and do not specifically address the privacy implications of ,21st century technology. As a result, technological innovation in e-commerce that redefines interaction with information will find loopholes in the static broad brushstrokes of the NPPs.[11] Furthermore, Attorney-General Daryl Williams has made it clear that the legislative intent of the Privacy Amendment (Private Sector) Act is not to protect privacy from the moral perspective of absolute human right[12] but to provide protection only insofar ,as is necessary to achieve the optimal advantage for Australian ,e-commerce.[13] Therefore, the stated object of the Act limits the scope of the NPPs by weighing privacy against business efficiency,[14] and downplaying its moral force in rights discourse, for example, by balancing an individual’s ‘interest’ in privacy against the ‘right’ ,of business efficiency.[15] Privacy will therefore have to fight for survival against profit maximisation in the information economy. American courts are already forcing big entertainment companies to monitor customer use of intellectual property online.[16] By analogy, the ‘big money’ interest[17] in network advertising would force the hand of the courts to take the restrictive approach to privacy when given half the chance. Indeed, the following discussion reveals many such chances in NPP 1.

NPP 1 examined

Meaning of ‘collection’

The NPPs only apply where there has been collection of information, and requirements for lawful collection are stated in NPP 1 (reproduced above). ‘Collection’ is defined broadly by the Federal Privacy Commissioner to mean to ‘gather’, ‘acquire’ or ‘obtain’ personal information from any source.[18] Despite the apparent breadth of these words, restriction arguably lies in the lowest common denominator of the synonyms that strongly suggests ‘gain’[19] by positive action,[20] connoting first, acquisition of information not previously held and second, a distinction between direct extraction and passive inference. To correctly assert that a cookie or web bug has ‘collected’, these requirements must be fulfilled by the technology within its operational transaction.

Cookies do not functionally fulfil these requirements within the immediate transaction wherein they operate. Upon receiving the request for a page from ,the user’s browser, the web page server sends back not just the requested page but also an HTTP header[21] with an additional ‘set-cookie: name=value’ line. The browser complies with the header and a cookie of a certain name and assigned value[22] is stored in the user’s browser. The value can be a random number that ‘identifies’ the user’s computer to the server[23] when the browser returns this cookie in the next visit.[24] Strictly speaking, what is actually extracted by the server is the existence of the identifier that the server itself set, and therefore there is no incremental ‘gain’ in information from the immediate cookie transaction. Any information about the user’s location is passively and subsequently inferred by matching the existence of the identifier with the URL of the web page viewed,[25] which is information collected by a web bug outside of the cookie transaction.[26] Granted, a convincing refutation would be to consider the location of the identification number to be sufficiently proximate to the user’s computer that subsequent inferences could be deemed ‘collected’ within the immediate cookie transaction.[27] However, even a slight lapse in the nexus[28] gives courts the opportunity for restriction.

Whether or not the use of a web bug would be deemed sufficiently proximate depends on its specific functionality. In our marketing scenario, the general rule is that the user’s browser will only return cookie information to the domain where the cookie originated, implying that only the host website’s server which set the cookie can recognise the user’s computer.[29] The first functionality of ,the Type 1 web bug[30] is to circumvent this rule by permitting the third party network to set cookies.[31] This potentially stretches the proximity loophole to allow surveillance by unknown third parties outside the web page domain.[32] The second point to make about ‘collection’ is the apparent requirement for some ‘active’ request; in this case, the apparent requirement for some ‘act’ the bug actively ‘gaining’ information by establishing a conduit between the user’s browser and the network advertiser’s server.[33] When the browser is triggered automatically to send an HTTP request to the network advertiser to place an ad in the pre-set banner space of the web page, other information is also sent along this conduit to enable the transaction, such as the user’s IP address, browser and operating system type and version, and the address of the host web page.[34]

Even if web bugs can be said to ‘gain by positive action’ the URLs required to match with cookie identifiers, this may still be permitted through the ambiguity of ‘solicitation’. As analogous to the situation in Harder,[35] web bugs may not involve a solicitation or request, but can be equated to an open telephone line as the user’s browser automatically divulges information during the process of downloading web pages.

Gunning suggests that the requirement of solicitation can be implied into collection because NPP 1.1 ‘necessity’ and NPP 2.1 ‘purpose’ envisage collection with a preconceived objective, which is arguably a mental element ,that cannot exist prior to or during accidental receipt of unsolicited information.[36] Greenleaf disagrees with this construction; according to him the operation of s 16B of the Act postpones collection until such time as information is included in a record, therefore postponing also the critical time for the mental element of purpose to exist until point of inclusion.[37] However I would argue, contrary to Greenleaf, that unsolicited information included in a record is not ‘collected’;[38] Gunning is correct to emphasise the importance of purpose at the point of reception as a requirement distinct from subsequent s 16B retention. The NPP 1.3 requirement that collection of information be ‘from the individual’ does not necessarily require solicitation, because information can be collected from an individual even though it was not requested.[39] But in conjunction with NPP 1.3(c) arguably there is a requirement of a request for information because it envisages the formulation of purpose before collection for retention so that the individual can be informed of the purpose — preferably at or before collection for retention.

Personal information

While it is recognised that cookies ,can store other information in the name=value pair,[40] such as an email address or search string that has been divulged to the website by the user during registration or search,[41] this discussion will only focus on personal information collected by the covert operation of the technologies.[42] The information that can be received by covert use of web bugs are a user’s IP address, browser and operating system type and version, the address of the host web page, and any identification numbers stored on the advertiser’s cookies. The only information that can be ‘collected’ by covert use of cookies is the cookie identification number.[43]

Personal information has been given ,a broad conceptualisation by Bygrave, who perceives the cruxial criterion to ,be identifiability or the ability to distinguish a person by unique characteristics, not necessarily by name.[44] The concept of personal information can be restricted however, first by sub-issues of identifiability, second by the additional requirement in s 6 of the Act that the information be ‘about an individual’, and third by the judicial gloss of intention to identify.

First, the Privacy Commissioner considers that s 6’s use of the phrase ‘reasonably be ascertained’ construes ,a primary piece of information as personal if identity can be ‘fairly easily’ ascertained by the use of auxiliary information.[45] This prima facie permissive use of auxiliary information could mean that an IP address could be linked to a name in an internet log file or a cookie identifier linked to an email address to make such information personally identifiable.[46] The IP address-name link could be defeated ,by ‘ease’ of identity if the IP address ,is dynamic[47] or if there is no extant accessible log file.[48] The Act’s use of ,the term ‘reasonably’ arguably poses a higher standard than ‘fairly easily’, requiring lawful linkage to defeat the auxiliary use of email addresses collected by planting web bugs in ,email (which is possibly outlawed under the Cybercrime Act 2001 (Cth)).[49] Concomitantly, lack of individuation could extinguish the ‘personal’ quality of the link where the IP address and cookie identification attach to a machine with multiple users.[50]

While these issues are not necessarily fatal to successful qualification as personal information, they do pose obstacles. On the one hand, case law is not always a reliable guide, as it may ,be coloured by a court’s consideration of underlying policies pertinent to a particular case. For example, the New Zealand Privacy Act Casenote 12582[51] ruling that telephone numbers lack ‘personal’ quality because they fail ,to uniquely identify individuals was influenced by the Court’s desire to avoid the possibility of jeopardising the privacy of other innocent users of the phone in question if the number were ,to be disclosed. On the other hand, whether or not information crosses the obstacles to become ‘personal’ is a matter of fact; so, for example, information can be more easily linked ,if IP addresses become static with the technological evolution towards DSL;[52] information can potentially be linked lawfully if the advertiser purchases a profiling agency;[53] and linkage of a telephone number or IP address to an individual is generally not difficult, for example if the person is the subject of ,a police inquiry.[54]

The above ambiguities create the possibility of construing cookie identifiers and IP addresses as personal information, but if ‘reasonably be ascertained’ is given the meaning of probability of identification rather than the difficulty of identifying, then even ,if there is no intention to use the information as personal identification, the mere capacity to do so will render the information personal.[55] Restriction of the identification element can come with the second element of idiosyncratic connection. Section 6(1) of the Act prima facie conflates the requirement that information be about an individual with identifiability, because the meaning of ‘about’ is not specified other than by qualification of the latter.[56] However, Harder and Provincial Section Order 23 interpret the New Zealand and Ontario counterpart definitions[57] respectively to operate with ‘about an individual’ as a separate narrower element requiring some idiosyncratic connection. So in Harder, Ms C’s denial of possessing unspecified chattels was not personal information because even though she was identified in the information, no ‘statement’ was made in relation to ,her as an individual.[58] In Order 23, estimated market value combined with a municipal address was held not to ,be information about the inhabitants, but merely about the property.[59] By analogy, arguably, an IP address or cookie identifier — even linked to ,a name — lacks an idiosyncratic relationship with the user because the information is about an inanimate browser or computer, not the individual. Conversely, a cookie identifier linked with the web page URL can constitute personal information about a person’s browsing tastes and therefore has the potential to be sensitive information if inferences can be made to intimate idiosyncrasies.[60] ,C v ASB is a decision which prohibited the use of auxiliary information to establish the idiosyncratic link that the information is about the individual.[61] (A small compromise was made that if the auxiliary information appears in the same document and the personal information is not intelligible without ,it, then the link will be permitted.)[62] Auxiliary use of web bug collected web page URLs would fall outside the purview of this concession for lack of proximity with the cookie transaction. There is a weaker argument here that the result was driven by a tangential policy of refusal to lift the corporate veil,[63] because the Court explicitly stated that its rejection of auxiliary information was grounded in the need to maintain the integrity of the definitional boundaries of personal information.[64]

This brings me to the third point —courts, attempting to restrict the reach of privacy protection,[65] can impose a judicial requirement which is not prima facie present in the legislation. Eastweek posed a radical constriction of requiring an intention to identify,[66] possibly to the extent of requiring an intention to identify by name.[67] This would exempt the combined use of an IP address and web page URL to personalise advertisements, because arguably the result of personal interaction with the user can be achieved without an intention to identify by name, relying instead upon identification by idiosyncratic browser behaviour. However, the decision in Equifax Europe Ltd v The Data Protection Registrar put the brakes on Eastweek’s radicalism by concentrating on the intention to find out about the individual rather than identification, which would catch a combination use of the IP and URL accessed.[68]

NPP 1.2: an organisation must only collect information by fair means

According to the Guidelines, a crucial element of fairness is lack of deception, interpreted broadly to include prima facie all forms of covert collection.[69] The American Federal Trade Commission (FTC) does not consider ‘deceptive practice’ to be mere covert collection of data without consent, but holds there must be the additional element of engaging in practices that betray the reliance placed by users on represented collection practices in the website privacy policy.[70] The Hong Kong Privacy Commissioner, New Zealand Privacy Commissioner and the recent UK Campbell case also adopt ,this reasoning of reliance — not on the parameters of the privacy policy, but on the illusion of being unwatched so the individual divulges information where otherwise he or she would have remained reticent.

In New Zealand Case Note 16479[71] and Hong Kong Case 199804574,[72] covert recording was held to be unfair because were it not for reliance on the fact the conversation was off the record the respondent would have answered differently. Similarly in Campbell, the clandestine nature of filming was unfair because the subject was disempowered from taking alternative action.[73]

The interpretation of the FTC has been criticised for not taking into account what can be achieved in practice.[74] For example, in the use of web bugs and cookies, the collection process begins upon downloading the web page, because this is the moment the cookie is set onto the user browser and the user’s browser divulges information to the server through the web bug. This makes the question of whether continued browsing is in reliance of the privacy policy irrelevant, since by the time the policy can be viewed the collection has been completed.

Even in the case of persistent cookies, it is difficult to assert that continued browsing resulted from reliance upon ,a privacy policy, because general consumer practice is to ignore such notices.[75] If the interpretation of the Commonwealth countries is adopted, it could be argued that consumers would divulge information even if they knew cookies and web bugs were operating. This is because the potential privacy invasion from the technology in surveillance and personalisation is intimately tied to the technical capability of the website. For example, without cookies, shopping carts will not work properly, and without web bug collection of URLs, some graphics cannot be downloaded.[76] Although it could be argued that persistent cookies are not strictly necessary for the immediate function of the website, ,some consumer opinion suggests that personalised advertising is coming to ,be expected as integral to the internet experience. This would mean disclosure is not based upon a lack of expectation.[77]

NPP 1 collection: what is necessary?

NPP 1.1 states that an organisation must not collect personal information unless the information is necessary ,for one or more of its functions or activities. Article 8 of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR) states that there ,shall be no interference by a public authority with the exercise of the right to privacy except where this is ‘necessary’ in a democratic society.[78] ‘Necessary’ in art 8 of the ECHR has been interpreted by the Court of Human Rights to create a high standard, requiring pressing social need and proportionality to the legitimate aim pursued.[79] ‘Necessary’ has also been interpreted to mean pressing commercial need.[80] Interpretation of the ‘necessary’ criterion in art 8 of the ECHR by the Court of Human Rights is relevant to defining ‘necessary’ in the European Directive and therefore also in the ,data protection legislation of European party states.[81]

Therefore, in Europe, use of persistent cookies[82] to prolong the tracking of user habits long after the original session has ended may be considered unnecessary for the function of the website or personalisation of the browsing experience during any one immediate session; hence it would not qualify as a pressing commercial need.[83] Arguably, web bugs may be permitted as a pressing commercial need because the internet advertising industry is heavily dependent upon the revenue generated by personalised advertising[84] and the internet culture of free access that has popularised the online information economy would be jeopardised without subsidies flowing on from advertising revenue.[85]

However, the covert use of cookies and web bugs could be considered as use for illegitimate purposes if the arguments surrounding the ‘side effects’ of personalised advertising gain widespread acceptance. Such ‘side effects’ include:

However, it is contended that this argument has no interpretative application to the Australian NPPs; first, because without the refractory effect of the Directive, the focus of art 8 on public authorities means it is not directly applicable to the private sector; second, because although the ECHR may be influential on the UN Human Rights Committee in its interpretation of the International Covenant on Civil and Political Rights (ICCPR) to which Australia is a party, the ICCPR counterpart art 17 does not include ,the term ‘necessary’, thereby severing the link of interpretation;[90] and third, even if it could be correctly asserted that the European ‘necessary’ standard has force as customary international law,[91] or at least constitutes an extrinsic interpretative aid under s 15AB of the Acts Interpretation Act 1901 (Cth),[92]because the Australian Act explicitly creates a conflicting lower standard,,be applied.[93]

Arguably the Australian Act creates a lower standard because it will only raise the standard of privacy protection given by the courts if it is incidental to achieving the apparent overall objective of the legislation of securing Australian economic advantage. Despite political rhetoric invoking Australia’s human rights obligation regarding privacy under ICCPR art 17,[94] the Attorney General’s Department and the Australian Law Reform Commission consider the ICCPR to be only an indication of international best policy and expressly deny that it creates any legally binding obligation which must be implemented through the Act.[95] Indeed, it is questionable if any ‘international obligation’ attaches to ,the ICCPR at all, as the Explanatory Memorandum only discusses obligations under the EU Directive.[96] Despite Australia’s clear concern ,with the EU trade barrier, the Government has displayed a US style hesitation in applying sweeping EU privacy standards,[97] as evidenced ,by the inclusion of the small business exemption in the Act despite the risk that this compromises Australia’s chances of being held to have met ,the EC Directive’s requirement of ‘adequacy’.[98]

Left to Australian judicial consideration, the meaning of ‘necessary’ varies from an absolute imperative, to a relative term of reasonably required,[99] to merely the exclusion of collection as a ‘fishing expedition’,[100] depending entirely upon judicial intention — which, in the case of the Act, has favoured the lower threshold. ‘Reasonably required’ could mean that alternative modes of collection that are less privacy invasive need not be considered, and certainly the breadth of ‘reasonably’ is such ,that the stated purpose is virtually unrestricted. If the stated purpose is future marketing in anticipation of the user returning to the site, then the use of persistent cookies would be ‘reasonable’.

The Privacy Commissioner’s interpretation raises the standard so that necessary qualifies ‘legitimate’ functions or activities, rather than merely functions and activities.[101] I would argue that this is to no avail. Because ,the NPPs establish no absolute immutable right, but rather initiate a negotiation between interest in privacy and the right to business efficiency, then what constitutes ‘legitimacy’ is a floating standard, contingent upon changing social acceptance of the technology.[102] Already, some consumers socialised into an acceptance of surveillance on the internet scoff at the ‘hype’ surrounding cookie and web bug usage.[103] Arguably, not only is the floating standard no inhibition to present privacy invasive technologies that have become accepted, but it also gives the Act elasticity to encompass currently unacceptable technological applications that through socialisation may eventually become acceptable. At present the use of cookies and web bugs within the organisational relationship of a network advertiser and a web page host extends the privacy invasiveness of the technology by hiding the network advertiser as a collecting party.[104] However, developments are afoot that would take the problem to new heights by increasing the magnitude of surveillance exponentially and increasing the exposure of disclosed information to countless intermediate collectors. I am referring to KaZaa’s use of Gnutella’s peer sharing topology to permit the harnessing of personal home computers to the network advertiser hub[105] so that the individual surfer also becomes a collector. While presently controversial, this process has the potential to slip ,into internet culture because it promises even more efficient advertising[106] and potential remuneration for private party collectors.[107] Its ‘legitimacy’ is just one small step down the slippery slope to total privacy compromise.


Cookies and web bugs have a good chance of surviving the privacy legislation and, indeed, there is potential for the Act to allow even more intrusive privacy invasive practices. The economic imperative has seen the cutting back of fair use exemptions in anti-circumvention legislation in favour of powerful media interests, and it would seem that the law/technology divide in the privacy legislation will also be dominated by the colour of money. l

Sharon Nye is a student researcher at the Baker & McKenzie Cyberspace Law Centre at the University of New South Wales. This article was first submitted as an essay for the elective course Data Surveillance and Information Privacy Law in the LLM program at UNSW.

