The DoubleClick Controversy

Details
Case Code:

ITSY014

Case Length:

13

Period:

Pub Date:

2002

Teaching Note:

YES

Price (Rs):

300

Organization:

Doubleclick.com

Industry:

Technology & Communications

Country:

US

Themes:

Data Privacy,Digital Marketing

Abstract

The case examines the Internet media company DoubleClick.com’s legal problems due to its controversial website visitor information collection practices. The company’s attempts to come out of these problems are also discussed. The case also discusses the issue of privacy on the World Wide Web and the legal, technical and ethical aspects involved.

Learning Objectives

The case is structured to achieve the following Learning Objectives:

  • On-line privacy.
Contents
The DoubleClick.com Controversy

“Every time you use the Internet, DoubleClick is placing a bar code on your back - a user I.D. - so that it can identify your interests, habits and preferences. The average consumer has no idea that their on-line movements are being spied upon; this amounts to little more than a secret, cyber wiretap.”

- Jennifer M. Granholm, Attorney General, Michigan State, US, in February 2000.

A SPATE OF LAWSUITS

In January 2000, a suit was filed against the world?s largest Internet advertising company DoubleClick.com (DoubleClick) in the California Superior Court. The media company providing digital marketing and Internet advertising technology and services, was accused of using computer tracking technology to identify Internet users and collect personal information without their consent, while they browsed the World Wide Web. DoubleClick had allegedly 'represented to the general public that it was not collecting personal and identifying information and that it gives privacy interests of Internet users the utmost importance.?

The following month, the US state of Michigan too served a notice of intended legal action against the company over the issue of improper data collection. This was accompanied by the US Federal Trade Commission (FTC) launching a review of some websites accused of inappropriate sharing of personal information of their visitors with third parties. DoubleClick was named in this probe as a third-party. These accusations were accompanied by various privacy and civil liberty groups asking the US government to toughen online privacy norms to make it harder for companies to disseminate user records.

A popular healthcare website, DrKoop.com was one of the websites reported to be sending user details to DoubleClick. DrKoop eventually severed its business relationship with DoubleClick over the issue. Search engine Altavista.com, another partner of DoubleClick, decided to limit the release of user information to the company. Kozmo, a company involved in-home delivery of video/food etc. also decided to end its relationship with DoubleClick. The number of suits against the company soon reached 20 – 13 in Federal courts, five in California and one each in Texas and Illinois state courts. The stock price declined by 86% from $ 107.63 on February 1, 1999 to $15.25 on January 21, 2001(Refer Exhibit I). Alarmed by the above developments, DoubleClick was forced to rethink its controversial data collection practices.

BACKGROUND NOTE

DoubleClick was started as 'Internet Advertising Network' (IAN) in Atlanta, Georgia by two software professionals Kevin O'Connor (Connor) and Dwight Merriman in 1995. The founders developed a technology for delivering targeted ads at websites. In the same year, a California-based marketing firm, Poppe Tyson (later renamed as Modem Media) formed DoubleClick as its new media division to sell ads on the Internet. The company began by selling ad space on a network of sites run by Netscape Communications and Excite. In January 1996, Poppe Tyson acquired IAN and merged it with DoubleClick's network of websites. This merger resulted in the formation of DoubleClick with Connor as its CEO.

In the mid 1990s, companies wanting to advertise online did not have much clue about the dynamics of the business. DoubleClick's pioneering efforts in gathering hundreds of popular sites in a network and then offering the ability to place banner ads1 across all, or some, of the network, thus found immediate acceptance and popularity. DoubleClick's network consisted of six different groups of websites categorized according to the industry – such as DoubleClick Auto – network of automobile sites, DoubleClick Business – network of business and finance sites, DoubleClick Commerce – network of e-commerce and shopping sites, DoubleClick entertainment – Network of entertainment sites, DoubleClick Tech – Network of technology related sites and DoubleClick Travel – Network of travel sites. These groups consisted of many sub-categories as well, based on the user profile. For instance, the DoubleClick entertainment network was divided into five categories – namely college, culture, entertainment, sports and youth.

The company also offered four categories of targeting filters to help advertisers to effectively reach their audience. These filters were categorized as content targeting, user targeting, tech targeting and behavioral targeting. Content targeting allowed advertisers to place their advertising message on a particular site where the advertiser was assured that the message was delivered to an interested audience. For example, car advertisers could deliver their ads through the DoubleClick Auto network to websites focusing on the car industry. Behavioral targeting allowed advertisers to select an audience based on how they used the web. For example, advertisers targeted ads at business people by having their advertisements delivered from Monday to Friday between 9 am and 5 pm and at recreational users by targeting messages in the evening hours.

User targeting allowed advertisers to deliver ads based on geographic location, company name, domain type and industry type. Tech targeting allowed advertisers to deliver ads based on user hardware, software and Internet access provider that included browser type, operating system and service provider. For instance, DoubleClick delivered UNIX-based advertisements for engineers and ads of Macintosh systems that supported graphics and animations for graphic designers. Gradually, many Fortune 500 companies began to give their online advertising accounts to DoubleClick and soon it became the 'one-stop shop for online ads.' By 2000, the company was releasing 1.5 billion banner advertisements per day for its 1800 plus customers through 750 website publishers.

With revenues of $258.3 million for the financial year 1999-2000, DoubleClick established itself as the leader in providing online advertising solutions. About 50% of the company's gross profits came from its technology operations, 25% from the data services business and the remaining from the sale of ads. The company had offices in 40 countries worldwide and worked with 2300 advertisers, 700 of whom were outside the US.

THE CONTROVERSY

To deliver targeted ads, DoubleClick used an advertisement management technology, DART (Dynamic Advertising Reporting and Targeting). DART delivered ads to web pages based on what the user was searching for or information already known about the consumer. DART technology thus targeted and delivered ads to web users based on pre-selected criteria, including the website category, time of day and regional geographic location. If the user responded by 'clicking on the ad,' DoubleClick servers directed him to the advertisers' website for more information. DART provided advertisers feedback on who saw their ads and how viewers responded to them.

Initially, DoubleClick collected non-personally-identifiable information (where the identity of the user was not revealed) such as the user IP address (for identifying the user's geographic location, company, type and size of organization), domain type and standard information (browser type, operating system and Internet service provider). It also included information regarding how users utilized the pages they visited within DoubleClick's advertiser sites (For example, it identified which sections of a particular website the users viewed). Every time a user saw or clicked on DoubleClick's targeted banners, DoubleClick updated its database. It also identified whether the user responded to the ads.

The banner ads place on websites were automatically monitored by DoubleClick cookies4, which tracked the number of people who clicked on them as a percentage of those who just viewed them. This 'click-through rate' offered feedback regarding ads much more accurately than those on TV, print or radio. The click-through technology helped DoubleClick to track individuals as they moved from one site to another. With the advent of web bugs, DoubleClick was able to track browsers even without the banner ads.

Things were by and large fine, although there was some opposition from online privacy advocates regarding the use of cookies by DoubleClick. The company's troubles began soon after it announced its decision to acquire Abacus Direct in June 1999. Abacus managed Abacus Alliance, the largest proprietary database in the US of consumer, retail, business to business, publishing and online transactions used for target marketing purposes. The Abacus database contained information about the individual spending habits of 88 million (about 90% of the total number) US households.

The merger announcement met with opposition from various parties, because the merger brought together online profiles obtained from over 850 million daily Internet advertisements and 2 billion consumer catalog transaction histories. DoubleClick would thus have been able to accurately identify all the 88 million households and track their online behavior. The Electronic Privacy Information Center (EPIC5) filed a complaint with the FTC, charging that the company was indulging in unfair and deceptive trade practices. It said that the proposed merger violated DoubleClick's earlier assurance of keeping the data collected anonymous. The merger was opposed by many other privacy advocates as being potentially harmful to people who had been profiled in the database.

Despite the protests, the merger was formally completed in November 1999. Soon after, DoubleClick created a division called Abacus Online, which formed a co-operative database, Abacus Online Alliance (AOA). The group, comprising various online marketers and publishers, contributed their registered user data to AOA in exchange for access to DoubleClick's data services. By December 1999, AOA had collected records from more than 1700 member companies (including catalogers, retailers and publishers). Using the Abacus database, DoubleClick was able to identify users as follows:

  • DCLK sent a cookie to the browser being used by an individual and gave it a unique ID (identification) number.
  • This ID number was sent to websites on which the users were registered.
  • These websites in turn sent back the data to DCLK, which then looked up the user in the Abacus database, thereby identifying the individual/household.

For instance, a person, who browsed websites related to diabetes treatment in DoubleClick's network, was tracked by DoubleClick's cookie technology, which kept a record of his/her browsing habits and IP address among other things. If he gave out personal information to some member of the Abacus Alliance, DoubleClick could accurately track him, right down to the address and spending habits. DoubleClick could then sell this information to websites or companies offering diabetic care services.

Initially, DoubleClick argued that it was not using the information received to target consumers. DoubleClick and Abacus claimed that they allowed consumers to opt out of their databases, and that they had disclosure policies about the usage of the collected data. Both were members of the Online Privacy Alliance and the Direct Marketing Association and claimed that they had complied with self-regulatory data collection policies. However, critics claimed that in spite of that, many a time, customers did not realize the enormity of the information they were letting out. Also, most of the websites under DoubleClick's network were found to be lacking regarding the enforcement of strict privacy policies.

Jules Polonetsky, Chief Privacy Officer, DoubleClick said, “The company's privacy policy is in no way contradicted by the deployment of web bugs, because names are not linked to sensitive online activities such as health and porn sites. The company has made a commitment that we won't ever use sensitive information to target ads or to build a profile.” However, he added that the policy could change with the development of government standards (Refer Exhibit II for DoubleClick's privacy policy).

However, the company's claims were not accepted by those opposing its data collection practices. Legal charges against the company began and soon acquired significant coverage in the media, giving rise to heated debates over the issue of a company's right to improve its business as against the rights of individual to privacy. 

 

THE DEBATE

The use of customer databases has become an integral part of building better customer relationships through electronic commerce. With constant advances in technologies associated with building databases and analyzing them, data mining6 and customer profiling have acquired a better-defined role. This is because of the ability of commercial Internet sites to collect newer forms and greater quantities of customer data than in the pre-Internet days.

As the use of cable modems, high-speed DSL lines and unlimited usage of Internet service packages increased, the number of computers, which are online all the time also increased. This, coupled with the increasing technological capabilities of companies seeking to track browsers, has made the issue of online privacy extremely important. Even reputed companies like barnesandnoble.com and amazon.com have admitted to using covert data collection tactics.

Companies adopt various measures to collect information about their consumers. A way of doing it would be to provide questionnaires on the websites, which customers can choose to fill or ignore. The question of legality arises when companies seek to collect data without the knowledge of consumers. This can be done via collating the routine information a web browser routinely sends out with each request, (for instance the originating computer's IP address and the operating system) or via hidden HTML tags7 (in e-mails as well as web pages), cookies or web-bugs. If a browser reads an e-mail with HTML tags with HTML-capable software, the website
administrators can know that a particular user has read the email.

Cookies are extremely helpful in letting a web server know what the user purchased through the Internet, what the user looked at and how long the user stayed on the web site. Cookies can be used in e-commerce transactions to store users' buying pattern information, to personalize web search engines and web portals and other interactive actions that require repeated user recognition. Thus, a company can record all the websites a particular user has clicked on, as the cookie would be the same for all the clicks. This in turn, can be used to give tailored advertisements to a user browsing a particular genre of websites.

Though users have an option of disabling cookies, it is not of much use because, in the latest versions of popular browsers such as Netscape and Internet Explorer, those websites with pages based on Microsoft's ASP technology8, appear as a collection of broken links unless the cookies are turned on. A web bug refers to a computer code, quite similar to the code written to place a picture or a banner ad on a website. The difference between usual banner ads and the web bug is that the latter is extremely small and invisible to the naked eye.

Advocates of online privacy were opposed to the covert manner in which companies collected information. They argue that individuals have a right to know what information is being collected about them, how it is being used and how they can prevent its unlawful usage. They also negated companies' claim that clandestine data collection is an industry-wide practice stating that the widespread usage of an illegal practice does not make it legal under any circumstances. They claim that customers have to be granted the right to decide the extent of data collection regarding them. According to analysts, besides self-regulation, violation of online privacy can be tackled either through legal intervention or technological solutions only. On the legal side, the European Union had in place the European Data Collection Directive (EDCD), which controlled the gathering and dissemination of information by granting the consumer rights to refuse collection, to know how the information is to be used, and control and change information after it has been collected. According to EDCD, 'in order to be lawful, the processing of personal data must in addition be carried out with the consent of the data subject.'

There are also certain industry bodies, such as the US based TRUSTe, which is an independent, non-profit organization whose mission is to build trust and confidence in the Internet by promoting the use of fair information practices. TRUSTe certifies and polices the privacy policies of websites. Its members are required to tell their visitors what information is gathered about them and how that information is used. However, after TRUSTe refused to audit Microsoft, one of its biggest donors, analysts started to question its credibility.

A few technological solutions have also been devised to solve privacy problems. These include the Platform for Privacy Preferences (P3P), developed by the World Wide Web consortium (W3C). P3P is a standardized set of multiple-choice questions, covering all the major aspects of a website's privacy policies. Taken together, they reveal how a site handles personal information about its users. P3P-enabled websites make this information available in a standard, machine-readable format, which is read by P3P enabled browsers and compared to the consumer's own set of privacy preferences.

The system is designed to let consumers tell their browsers how much information they are willing to give out. The websites would then disclose how much and what information is being collected. The browser warns a user if there is a discrepancy between the site's expectations and users preferences. However, it would take time before P3P becomes an internationally accepted standard. Microsoft's browser, Internet Explorer 6.0 released in August 2001 has features that require third parties that set cookies to deliver P3P 'compact cookie policies' with their cookies. The browser evaluates cookies from those websites that do not have these policies, to see if they meet user preferences or not. If they do not meet user preferences, the browser blocks these cookies.

THE FUTURE

Amidst growing public outcry, DoubleClick announced a five-point initiative to silence its critics. The company released full-page advertisements in major newspapers, announcing various measures to deal with the allegations leveled against it. DoubleClick decided to appoint a privacy officer and a privacy advisory board and strengthen the mechanism to let people opt out of its services through notification by a 'pop-up' box whenever personal data was sought from them. DoubleClick also said that it would do businesses only with companies that had strict privacy policies. It also decided to launch an Internet ad campaign with up to 50 billion banner ads educating Internet users about privacy.

The company hired PricewaterhouseCoopers as external auditors to confirm that it was following all rules and regulations. It started a new privacy portal called 'Privacychoices.org' through which users could opt out of DoubleClick's network. It also decided to provide detailed information about its privacy policy, opt-out procedure and general information about online advertising and privacy (Refer Exhibit II for DoubleClick's privacy policy).

DoubleClick seemed to have realized that it had taken its privacy violation technologies too far this time. Commenting on the issue, Connor said, “I made a mistake.” He admitted that the company should have waited for industry-wide privacy standards to be established before undertaking such an initiative.

In May 2000, DoubleClick appointed a seven-member independent privacy advisory board. It included Privacy Advisor TRUSTe chairwoman Lori Fena, PlanetOut.com co-founder David Stazer and Stewart Baker, a former general counsel for the national security agency. In June 2000, DoubleClick declared that it had dropped plans to track Internet users by their personal information.

In July 2000, the FTC entered into a deal with Network Advertising Initiative, a consortium of DoubleClick and other online marketers, to uphold a strict set of self-regulatory data-privacy standards. DoubleClick also committed to disclose more information regarding several of its practices in the next iteration of its privacy policy, including the use of web bugs.

In January 2001, the FTC's Bureau of Consumer Protection ruled that DoubleClick had 'never used or disclosed consumers' personal data for purposes other than those disclosed in its privacy policy.' FTC sources said, “DoubleClick has always maintained that they haven't merged any non-personally identifying information with personally identifying information. The FTC has conducted the most thorough investigation possible and has given them a clean bill of health.” Though DoubleClick managed to emerge a winner in the legal battle, its image had taken a severe beating. With the global information technology industry slowdown in the early 21st century and increasing competition in the Internet advertising business, the company seemed to be bracing itself for a tough time ahead. Analysts commented that the company had to write off a substantial amount as goodwill impairment for the year ended December 31, 2000, to a certain extent due to the privacy violation controversy (Refer Exhibit III for DoubleClick's financials).

Meanwhile, FTC's clean chit to DoubleClick was severely criticized by many parties. They continued to argue that though the company had not used the data for any fraudulent practices till now, the potential dangers associated with data tracking could not be ignored. Analysts added that if online business was made safer, there would be more number of customers who will take to e-commerce, thereby boosting the business at the global level.

 

QUESTIONS FOR DISCUSSION

1. What were the accusations against DoubleClick? Why did the merger announcement with Abacus Direct attract opposition from various parties?

2. Explain the main features of DoubleClick?s corporate policy on privacy and comment on the initiatives taken by the company to restore the confidence of Internet users.

3. 'The practice of collecting data without the consent of the customers is completely unjustifiable, even if the companies involved do not put to use such data.? Critically comment on the above statement highlighting the economic, social and moral aspects involved in the issue of covert tracking of customer information using the Internet. 

EXHIBITS

Exhibit I

DoubleClick Share Price Movement - (March 1999 to February 2002)
Exhibit I

Source: www.bigcharts.com

 

Exhibit II
DoubleClick – Privacy Policy

NOTICE
Consumers usually interact with DoubleClick when they visit Web publishers or advertisers using DoubleClick technology. DoubleClick asks those website operators to disclose their relationship with us by providing notice to consumers about the DoubleClick technologies they use. See “Internet Ads”, “Marketing Scores”, “Email”, “Surveys”, “Sweepstakes”, “Cookies” and “Clear GIFs” for a detailed description of the information collected and how it is used by our various services. DoubleClick also asks website operators to link from their privacy policy to ours to allow consumers to opt out of the DoubleClick cookie.

CHOICE
DoubleClick believes that Internet consumers should be able to control the use of their data. DoubleClick provides Internet users the choice not to have online information collected about them from their browsers by providing an anonymous cookie. DoubleClick also provides email customers the ability to control the use of information collected about them through email delivered by DoubleClick. DoubleClick also provides choice in the offline world. In addition to honoring the Direct Marketing Association's Mail List Preference Service, Double-Click's Abacus division respects your choice to not receive offline marketing (such as catalogs). To opt out of the Abacus catalog database, please write to Abacus, P.O. Box 1478, Broomfield, CO 80038 or call 1-800-518-4453. Please include your full name (including any middle initial), your current address (and previous address if you have been at your current address fewer than six months). When you opt out, your record will be suppressed from the Abacus Master File, ensuring your Abacus household record is not selected from the Abacus Database.

ACCESS
In most cases, when DoubleClick collects personal information online, we do so on behalf of another company (as an agent or processor). To request access to this information, please contact the company to which you provided it. When DoubleClick collects personal information from you for our own purposes (such as to process an employment application on this site), DoubleClick will provide you with reasonable access to that information.

SECURITY
DoubleClick has implemented generally accepted standards of technology security in order to protect information from loss, misuse and unauthorized access, disclosure, alteration or destruction. Only authorized DoubleClick personnel and agents are provided access to personal information and certain databases containing non-personal information, and these employees have agreed to ensure confidentiality of this information.

ENFORCEMENT
We will do our best to address your concerns. In addition, DoubleClick is a member of the Network Advertising Initiative and abides by the NAI's Self-Regulatory Principles on Online Preference Marketing, which were developed in conjunction with the Federal Trade Commission in July 2000. DoubleClick is also a licensee of TRUSTe. Our employees are made aware of and are accountable for compliance with our privacy policies and for any changes to those policies.

DATA RETENTION
DoubleClick currently retains data in the chronological 'log file' of the advertisements we serve and events that we process on behalf of clients for accounting and data backup. However, those log files are not in an easily searchable format. DoubleClick purges these log files on a two year schedule. Marketing score data 'decays' or falls out of the database on average basis of 45 days. That means that if you have not visited any sites in the DoubleClick group of sites that are sharing data for the creation of a marketing score in the past 45 days, your cookie will likely not have any scores associated with it, and your browser will see advertisements based on other information.

POLICY CHANGES
As DoubleClick introduces and acquires new products and changes are made to existing products, DoubleClick reserves the right to amend this policy at any time. All privacy policies are dated with the effective date (the date on which the policy was posted to this website, www.doubleclick.net). Information collected about you by us under a particular policy is used in the manner disclosed to you at the time it was collected, unless DoubleClick obtains your consent to use your information in a different way. If you want to be notified about changes to this policy, DoubleClick will maintain an email notification list.

SENSITIVE DATA
DoubleClick acts as an agent or processor for a wide variety of companies that may have sensitive information. For example, a user might visit a health information website and may click on an ad we have placed on that site. Thus our log files may reflect the activities of a computer browser on sites that could be deemed sensitive, but DoubleClick does not use such information in a marketing score to deliver ads to you when you are on other Web sites. DoubleClick does not develop marketing scores that  indicate a user's individual health condition, detailed financial information, sexual orientation or behavior, information that appears to relate to children under 13, information of racial and ethnic origin, political opinions, religious or philosophical opinions or beliefs, and trade union membership or information about visits to websites outside of the United States.

DoubleClick understands the importance of protecting the privacy of children's personal information, especially in an online environment. It is DoubleClick's policy to not knowingly collect or maintain personal information about anyone under the age of 13. DoubleClick encourages parents and guardians to use the Internet with their children and encourages children not to provide personally identifiable information on the Internet without their parents' or guardians' consent.

CHANGES IN CORPORATE STRUCTURE
If all or part of the company is sold, merged or otherwise transferred to another entity, the data, whether personally identifiable  or otherwise, associated with the services provided by that part of the company may be transferred as part of that transaction.  However, DoubleClick takes steps to ensure that the data is used for the purposes collected and in the manner contemplated under the privacy policy associated with that data.

DISCLOSURE OF INFORMATION
DoubleClick may transfer information to a company that provides services that assist DoubleClick in its business. Those companies act as our agents and are bound to use the data only for the purposes for which DoubleClick has shared the data. If DoubleClick  transfers information to third parties for other purposes, those parties are required to apply the same notice and choice principles to which DoubleClick adheres. However, please note that information is subject to disclosure pursuant to judicial or other government subpoenas, warrants or orders.

Source: www.doubleclick.com

 

Exhibit III
DoubleClick – Financial Statements

Exhibit III

Source: www.doubleclick.com

Keywords

Internet, media company, DoubleClick.com, legal problems, website, visitor information, collection practices, privacy, World Wide Web, legal, technical, ethical

Move to top