Share on LinkedInShare on LinkedIn

ARTICLE · 30 NOVEMBER 1999

Web Bugs - Ten Steps You Should Take

United StatesIntellectual Property

Internet advertisers are collecting detailed information about the online behavior of consumers. Consumers may not be aware this is happening. Web site operators need to notify consumers of the information collection practices associated with their pages (whether these practices are controlled by third-party advertisers or the web site itself) and give consumers a reasonably-accessible method for opting out.

What’s a web bug?

A web bug (sometimes called a "clear gif" by the advertising industry) is an inconspicuous graphic loaded on a web page, usually from a different server than that used for the rest of the page. Web bugs are often invisible because they are extremely small. They are placed on a page to allow the source to record "hit" information about visitors to that page. (A "hit" is the retrieval of any item, like a page or a graphic, from a web server.) This hit information is reported to the advertising networks who have a relationship with the site.

What information does a web bug report?

A web bug gathers the Internet Protocol (IP) address of the computer that produced the hit. (An IP address is the unique numeric identifier for a computer attached to the Internet.) It also reports the Universal Resource Locator (URL) of the page on which the web bug was placed (e.g., www.quicken.com); the URL for the web bug graphic or image (which usually comes from a different server); the time the web bug was viewed; the kind of browser (e.g., Internet Explorer) the user is using; and information about any "cookie" set by the web bug. (A "cookie" is a piece of information stored on the user’s disk drive when the web browser accesses a server. The browser stores the information in a text file, and this information is sent back to the particular server each time the browser retrieves a page from that server. Cookies are used to identify unique users.) Because each advertising company has relationships with a network of sites, information gathered from multiple web bugs hit by a single user can help the advertising network build a detailed profile of what sites a particular person is visiting, and their activities on those sites.

Why should you care?

On November 8, the Department of Commerce and the Federal Trade Commission held a joint public meeting on online profiling - the creation of numeric profiles of users’ online activity by advertising agencies and others. At this meeting, representatives of the Internet advertising industry and consumer groups discussed advertisers’ practice of placing "web bugs" that collect information about users’ activity on a particular site. Consumer groups expressed strong opposition to this practice.

During the afternoon portion of the meeting, a group of Internet advertising networks (24/7 Media, AdForce, AdKnowledge, Adsmart, DoubleClick, Engage, Flycast, Matchlogic, and RealMedia) announced the formation of a self-regulatory group called the Network Advertising Initiative (www.networkadvertising.org). These companies have agreed to provide notice to consumers of their profiling practices; to provide an easy-to-use opt out method; to educate users about profiling (through their web site); to require publishers to provide a link to their disclosure statements about their practices; and (eventually) to agree to a third-party audit to enforce these agreements. The Network Advertising Initiative has promised that users will be able to opt out of all use of personally-identifiable information. Additionally, users will be able to opt out of all collection of advertisement delivery data concerning them - but users won’t be able to opt out of the collection of aggregate "reach" data (data on the overall numbers of users viewing particular advertisements), which the companies termed essential to the "infrastructure" of the Internet.

The Federal Trade Commission has announced that it intends to examine the impact of web bugs on consumer privacy.

What’s the problem?

Consumers don’t know about web bugs or online profiling. Many people feel very uncomfortable once they learn that their actions are being closely monitored. If a consumer curious about web bugs looks at a site’s privacy policy, the policy will likely say nothing about what third-party advertising networks are doing through the site. This could lead to claims that many privacy policies, drafted with a view to the practices of the web site owner (not the entire network of sites using an ad placement service) are misleading.

Ten things operators of web sites can do:

1. Find out what the advertising networks are learning about your visitors. (Consider whether advertisers’ access to information about visits to particular pages on your site might be viewed as especially sensitive.)

2. Make sure that your privacy policy clearly discloses to visitors what information is being gathered about them by advertising networks through your site.

3. Provide a link in your privacy policy to the disclosures of the advertising networks placing web bugs on your pages.

4. Educate yourself about the opt-out options being provided to your visitors by the advertising networks with whom you have relationships.

5. Make sure that your privacy policy clearly discloses to visitors how they can opt out of the collection of information about them by the advertising networks.

6. Consider eliminating the use of non-advertising, invisible web bugs on your pages (web bugs that are not associated with actual advertising on which users affirmatively click).

7. Educate yourself about the access your visitors will be provided to the profiles being built about them by the advertising networks.

8. Find out whether your visitors will be allowed to erase inaccurate information about themselves from online profiles.

9. Make sure that your privacy policy clearly discloses to visitors what access they will have to the online profile information prepared about them by the advertising networks.

10. Ensure that any advertising network with whom you have a contractual relationship has agreed to be part of a self-regulatory program agreed to be part of a self-regulatory program (like the Network Advertising Initiative) and a third-party seal program (like bbbOnline or TrustE) that will enforce their privacy promises.

By David R. Johnson and Susan P. Crawford

This memorandum is for general purposes only and does not represent our legal advice as to any particular set of facts, nor does this memorandum represent any undertaking to keep recipients advised as to all relevant legal developments.

See more popular content from