The DoubleClick Controversy
Details
ITSY014
13
2002
YES
300
Doubleclick.com
Technology & Communications
US
Data Privacy,Digital Marketing
Abstract
The case examines the Internet media company DoubleClick.com’s legal problems due to its controversial website visitor information collection practices. The company’s attempts to come out of these problems are also discussed. The case also discusses the issue of privacy on the World Wide Web and the legal, technical and ethical aspects involved.
Learning Objectives
The case is structured to achieve the following Learning Objectives:
- On-line privacy.
Contents
The DoubleClick.com Controversy
“Every time you use the Internet, DoubleClick is placing a bar code on your back - a user I.D. - so that it can identify your interests, habits and preferences. The average consumer has no idea that their on-line movements are being spied upon; this amounts to little more than a secret, cyber wiretap.”
- Jennifer M. Granholm, Attorney General, Michigan State, US, in February 2000.
A SPATE OF LAWSUITS
In January 2000, a suit was filed against the world?s largest Internet advertising company DoubleClick.com (DoubleClick) in the California Superior Court. The media company providing digital marketing and Internet advertising technology and services, was accused of using computer tracking technology to identify Internet users and collect personal information without their consent, while they browsed the World Wide Web. DoubleClick had allegedly 'represented to the general public that it was not collecting personal and identifying information and that it gives privacy interests of Internet users the utmost importance.?
The following month, the US state of Michigan too served a notice of intended legal action against the company over the issue of improper data collection. This was accompanied by the US Federal Trade Commission (FTC) launching a review of some websites accused of inappropriate sharing of personal information of their visitors with third parties. DoubleClick was named in this probe as a third-party. These accusations were accompanied by various privacy and civil liberty groups asking the US government to toughen online privacy norms to make it harder for companies to disseminate user records.
A popular healthcare website, DrKoop.com was one of the websites reported to be sending user details to DoubleClick. DrKoop eventually severed its business relationship with DoubleClick over the issue. Search engine Altavista.com, another partner of DoubleClick, decided to limit the release of user information to the company. Kozmo, a company involved in-home delivery of video/food etc. also decided to end its relationship with DoubleClick. The number of suits against the company soon reached 20 – 13 in Federal courts, five in California and one each in Texas and Illinois state courts. The stock price declined by 86% from $ 107.63 on February 1, 1999 to $15.25 on January 21, 2001(Refer Exhibit I). Alarmed by the above developments, DoubleClick was forced to rethink its controversial data collection practices.
BACKGROUND NOTE
DoubleClick was started as 'Internet Advertising Network' (IAN) in Atlanta, Georgia by two software professionals Kevin O'Connor (Connor) and Dwight Merriman in 1995. The founders developed a technology for delivering targeted ads at websites. In the same year, a California-based marketing firm, Poppe Tyson (later renamed as Modem Media) formed DoubleClick as its new media division to sell ads on the Internet. The company began by selling ad space on a network of sites run by Netscape Communications and Excite. In January 1996, Poppe Tyson acquired IAN and merged it with DoubleClick's network of websites. This merger resulted in the formation of DoubleClick with Connor as its CEO.
In the mid 1990s, companies wanting to advertise online did not have much clue about the dynamics of the business. DoubleClick's pioneering efforts in gathering hundreds of popular sites in a network and then offering the ability to place banner ads1 across all, or some, of the network, thus found immediate acceptance and popularity. DoubleClick's network consisted of six different groups of websites categorized according to the industry – such as DoubleClick Auto – network of automobile sites, DoubleClick Business – network of business and finance sites, DoubleClick Commerce – network of e-commerce and shopping sites, DoubleClick entertainment – Network of entertainment sites, DoubleClick Tech – Network of technology related sites and DoubleClick Travel – Network of travel sites. These groups consisted of many sub-categories as well, based on the user profile. For instance, the DoubleClick entertainment network was divided into five categories – namely college, culture, entertainment, sports and youth.
The company also offered four categories of targeting filters to help advertisers to effectively reach their audience. These filters were categorized as content targeting, user targeting, tech targeting and behavioral targeting. Content targeting allowed advertisers to place their advertising message on a particular site where the advertiser was assured that the message was delivered to an interested audience. For example, car advertisers could deliver their ads through the DoubleClick Auto network to websites focusing on the car industry. Behavioral targeting allowed advertisers to select an audience based on how they used the web. For example, advertisers targeted ads at business people by having their advertisements delivered from Monday to Friday between 9 am and 5 pm and at recreational users by targeting messages in the evening hours.
User targeting allowed advertisers to deliver ads based on geographic location, company name, domain type and industry type. Tech targeting allowed advertisers to deliver ads based on user hardware, software and Internet access provider that included browser type, operating system and service provider. For instance, DoubleClick delivered UNIX-based advertisements for engineers and ads of Macintosh systems that supported graphics and animations for graphic designers. Gradually, many Fortune 500 companies began to give their online advertising accounts to DoubleClick and soon it became the 'one-stop shop for online ads.' By 2000, the company was releasing 1.5 billion banner advertisements per day for its 1800 plus customers through 750 website publishers.
With revenues of $258.3 million for the financial year 1999-2000, DoubleClick established itself as the leader in providing online advertising solutions. About 50% of the company's gross profits came from its technology operations, 25% from the data services business and the remaining from the sale of ads. The company had offices in 40 countries worldwide and worked with 2300 advertisers, 700 of whom were outside the US.
THE CONTROVERSY
To deliver targeted ads, DoubleClick used an advertisement management technology, DART (Dynamic Advertising Reporting and Targeting). DART delivered ads to web pages based on what the user was searching for or information already known about the consumer. DART technology thus targeted and delivered ads to web users based on pre-selected criteria, including the website category, time of day and regional geographic location. If the user responded by 'clicking on the ad,' DoubleClick servers directed him to the advertisers' website for more information. DART provided advertisers feedback on who saw their ads and how viewers responded to them.
Initially, DoubleClick collected non-personally-identifiable information (where the identity of the user was not revealed) such as the user IP address (for identifying the user's geographic location, company, type and size of organization), domain type and standard information (browser type, operating system and Internet service provider). It also included information regarding how users utilized the pages they visited within DoubleClick's advertiser sites (For example, it identified which sections of a particular website the users viewed). Every time a user saw or clicked on DoubleClick's targeted banners, DoubleClick updated its database. It also identified whether the user responded to the ads.
The banner ads place on websites were automatically monitored by DoubleClick cookies4, which tracked the number of people who clicked on them as a percentage of those who just viewed them. This 'click-through rate' offered feedback regarding ads much more accurately than those on TV, print or radio. The click-through technology helped DoubleClick to track individuals as they moved from one site to another. With the advent of web bugs, DoubleClick was able to track browsers even without the banner ads.
Things were by and large fine, although there was some opposition from online privacy advocates regarding the use of cookies by DoubleClick. The company's troubles began soon after it announced its decision to acquire Abacus Direct in June 1999. Abacus managed Abacus Alliance, the largest proprietary database in the US of consumer, retail, business to business, publishing and online transactions used for target marketing purposes. The Abacus database contained information about the individual spending habits of 88 million (about 90% of the total number) US households.
The merger announcement met with opposition from various parties, because the merger brought together online profiles obtained from over 850 million daily Internet advertisements and 2 billion consumer catalog transaction histories. DoubleClick would thus have been able to accurately identify all the 88 million households and track their online behavior. The Electronic Privacy Information Center (EPIC5) filed a complaint with the FTC, charging that the company was indulging in unfair and deceptive trade practices. It said that the proposed merger violated DoubleClick's earlier assurance of keeping the data collected anonymous. The merger was opposed by many other privacy advocates as being potentially harmful to people who had been profiled in the database.
Despite the protests, the merger was formally completed in November 1999. Soon after, DoubleClick created a division called Abacus Online, which formed a co-operative database, Abacus Online Alliance (AOA). The group, comprising various online marketers and publishers, contributed their registered user data to AOA in exchange for access to DoubleClick's data services. By December 1999, AOA had collected records from more than 1700 member companies (including catalogers, retailers and publishers). Using the Abacus database, DoubleClick was able to identify users as follows:
- DCLK sent a cookie to the browser being used by an individual and gave it a unique ID (identification) number.
- This ID number was sent to websites on which the users were registered.
- These websites in turn sent back the data to DCLK, which then looked up the user in the Abacus database, thereby identifying the individual/household.
For instance, a person, who browsed websites related to diabetes treatment in DoubleClick's network, was tracked by DoubleClick's cookie technology, which kept a record of his/her browsing habits and IP address among other things. If he gave out personal information to some member of the Abacus Alliance, DoubleClick could accurately track him, right down to the address and spending habits. DoubleClick could then sell this information to websites or companies offering diabetic care services.
Initially, DoubleClick argued that it was not using the information received to target consumers. DoubleClick and Abacus claimed that they allowed consumers to opt out of their databases, and that they had disclosure policies about the usage of the collected data. Both were members of the Online Privacy Alliance and the Direct Marketing Association and claimed that they had complied with self-regulatory data collection policies. However, critics claimed that in spite of that, many a time, customers did not realize the enormity of the information they were letting out. Also, most of the websites under DoubleClick's network were found to be lacking regarding the enforcement of strict privacy policies.
Jules Polonetsky, Chief Privacy Officer, DoubleClick said, “The company's privacy policy is in no way contradicted by the deployment of web bugs, because names are not linked to sensitive online activities such as health and porn sites. The company has made a commitment that we won't ever use sensitive information to target ads or to build a profile.” However, he added that the policy could change with the development of government standards (Refer Exhibit II for DoubleClick's privacy policy).
However, the company's claims were not accepted by those opposing its data collection practices. Legal charges against the company began and soon acquired significant coverage in the media, giving rise to heated debates over the issue of a company's right to improve its business as against the rights of individual to privacy.
THE DEBATE
The use of customer databases has become an integral part of building better customer relationships through electronic commerce. With constant advances in technologies associated with building databases and analyzing them, data mining6 and customer profiling have acquired a better-defined role. This is because of the ability of commercial Internet sites to collect newer forms and greater quantities of customer data than in the pre-Internet days.
As the use of cable modems, high-speed DSL lines and unlimited usage of Internet service packages increased, the number of computers, which are online all the time also increased. This, coupled with the increasing technological capabilities of companies seeking to track browsers, has made the issue of online privacy extremely important. Even reputed companies like barnesandnoble.com and amazon.com have admitted to using covert data collection tactics.
Companies adopt various measures to collect information about their consumers. A way of doing it would be to provide questionnaires on the websites, which customers can choose to fill or ignore. The question of legality arises when companies seek to collect data without the knowledge of consumers. This can be done via collating the routine information a web browser routinely sends out with each request, (for instance the originating computer's IP address and the operating system) or via hidden HTML tags7 (in e-mails as well as web pages), cookies or web-bugs. If a browser reads an e-mail with HTML tags with HTML-capable software, the website
administrators can know that a particular user has read the email.
Cookies are extremely helpful in letting a web server know what the user purchased through the Internet, what the user looked at and how long the user stayed on the web site. Cookies can be used in e-commerce transactions to store users' buying pattern information, to personalize web search engines and web portals and other interactive actions that require repeated user recognition. Thus, a company can record all the websites a particular user has clicked on, as the cookie would be the same for all the clicks. This in turn, can be used to give tailored advertisements to a user browsing a particular genre of websites.
Though users have an option of disabling cookies, it is not of much use because, in the latest versions of popular browsers such as Netscape and Internet Explorer, those websites with pages based on Microsoft's ASP technology8, appear as a collection of broken links unless the cookies are turned on. A web bug refers to a computer code, quite similar to the code written to place a picture or a banner ad on a website. The difference between usual banner ads and the web bug is that the latter is extremely small and invisible to the naked eye.
Advocates of online privacy were opposed to the covert manner in which companies collected information. They argue that individuals have a right to know what information is being collected about them, how it is being used and how they can prevent its unlawful usage. They also negated companies' claim that clandestine data collection is an industry-wide practice stating that the widespread usage of an illegal practice does not make it legal under any circumstances. They claim that customers have to be granted the right to decide the extent of data collection regarding them. According to analysts, besides self-regulation, violation of online privacy can be tackled either through legal intervention or technological solutions only. On the legal side, the European Union had in place the European Data Collection Directive (EDCD), which controlled the gathering and dissemination of information by granting the consumer rights to refuse collection, to know how the information is to be used, and control and change information after it has been collected. According to EDCD, 'in order to be lawful, the processing of personal data must in addition be carried out with the consent of the data subject.'
There are also certain industry bodies, such as the US based TRUSTe, which is an independent, non-profit organization whose mission is to build trust and confidence in the Internet by promoting the use of fair information practices. TRUSTe certifies and polices the privacy policies of websites. Its members are required to tell their visitors what information is gathered about them and how that information is used. However, after TRUSTe refused to audit Microsoft, one of its biggest donors, analysts started to question its credibility.
A few technological solutions have also been devised to solve privacy problems. These include the Platform for Privacy Preferences (P3P), developed by the World Wide Web consortium (W3C). P3P is a standardized set of multiple-choice questions, covering all the major aspects of a website's privacy policies. Taken together, they reveal how a site handles personal information about its users. P3P-enabled websites make this information available in a standard, machine-readable format, which is read by P3P enabled browsers and compared to the consumer's own set of privacy preferences.
The system is designed to let consumers tell their browsers how much information they are willing to give out. The websites would then disclose how much and what information is being collected. The browser warns a user if there is a discrepancy between the site's expectations and users preferences. However, it would take time before P3P becomes an internationally accepted standard. Microsoft's browser, Internet Explorer 6.0 released in August 2001 has features that require third parties that set cookies to deliver P3P 'compact cookie policies' with their cookies. The browser evaluates cookies from those websites that do not have these policies, to see if they meet user preferences or not. If they do not meet user preferences, the browser blocks these cookies.
THE FUTURE
Amidst growing public outcry, DoubleClick announced a five-point initiative to silence its critics. The company released full-page advertisements in major newspapers, announcing various measures to deal with the allegations leveled against it. DoubleClick decided to appoint a privacy officer and a privacy advisory board and strengthen the mechanism to let people opt out of its services through notification by a 'pop-up' box whenever personal data was sought from them. DoubleClick also said that it would do businesses only with companies that had strict privacy policies. It also decided to launch an Internet ad campaign with up to 50 billion banner ads educating Internet users about privacy.
The company hired PricewaterhouseCoopers as external auditors to confirm that it was following all rules and regulations. It started a new privacy portal called 'Privacychoices.org' through which users could opt out of DoubleClick's network. It also decided to provide detailed information about its privacy policy, opt-out procedure and general information about online advertising and privacy (Refer Exhibit II for DoubleClick's privacy policy).
DoubleClick seemed to have realized that it had taken its privacy violation technologies too far this time. Commenting on the issue, Connor said, “I made a mistake.” He admitted that the company should have waited for industry-wide privacy standards to be established before undertaking such an initiative.
In May 2000, DoubleClick appointed a seven-member independent privacy advisory board. It included Privacy Advisor TRUSTe chairwoman Lori Fena, PlanetOut.com co-founder David Stazer and Stewart Baker, a former general counsel for the national security agency. In June 2000, DoubleClick declared that it had dropped plans to track Internet users by their personal information.
In July 2000, the FTC entered into a deal with Network Advertising Initiative, a consortium of DoubleClick and other online marketers, to uphold a strict set of self-regulatory data-privacy standards. DoubleClick also committed to disclose more information regarding several of its practices in the next iteration of its privacy policy, including the use of web bugs.
In January 2001, the FTC's Bureau of Consumer Protection ruled that DoubleClick had 'never used or disclosed consumers' personal data for purposes other than those disclosed in its privacy policy.' FTC sources said, “DoubleClick has always maintained that they haven't merged any non-personally identifying information with personally identifying information. The FTC has conducted the most thorough investigation possible and has given them a clean bill of health.” Though DoubleClick managed to emerge a winner in the legal battle, its image had taken a severe beating. With the global information technology industry slowdown in the early 21st century and increasing competition in the Internet advertising business, the company seemed to be bracing itself for a tough time ahead. Analysts commented that the company had to write off a substantial amount as goodwill impairment for the year ended December 31, 2000, to a certain extent due to the privacy violation controversy (Refer Exhibit III for DoubleClick's financials).
Meanwhile, FTC's clean chit to DoubleClick was severely criticized by many parties. They continued to argue that though the company had not used the data for any fraudulent practices till now, the potential dangers associated with data tracking could not be ignored. Analysts added that if online business was made safer, there would be more number of customers who will take to e-commerce, thereby boosting the business at the global level.
QUESTIONS FOR DISCUSSION
1. What were the accusations against DoubleClick? Why did the merger announcement with Abacus Direct attract opposition from various parties?
2. Explain the main features of DoubleClick?s corporate policy on privacy and comment on the initiatives taken by the company to restore the confidence of Internet users.
3. 'The practice of collecting data without the consent of the customers is completely unjustifiable, even if the companies involved do not put to use such data.? Critically comment on the above statement highlighting the economic, social and moral aspects involved in the issue of covert tracking of customer information using the Internet.
EXHIBITS
Exhibit I
| DoubleClick Share Price Movement - (March 1999 to February 2002) |
![]() |
Source: www.bigcharts.com
Exhibit II
DoubleClick – Privacy Policy
|
NOTICE CHOICE ACCESS SECURITY ENFORCEMENT DATA RETENTION POLICY CHANGES SENSITIVE DATA DoubleClick understands the importance of protecting the privacy of children's personal information, especially in an online environment. It is DoubleClick's policy to not knowingly collect or maintain personal information about anyone under the age of 13. DoubleClick encourages parents and guardians to use the Internet with their children and encourages children not to provide personally identifiable information on the Internet without their parents' or guardians' consent. CHANGES IN CORPORATE STRUCTURE DISCLOSURE OF INFORMATION |
Source: www.doubleclick.com
Exhibit III
DoubleClick – Financial Statements
![]() |
Source: www.doubleclick.com
Keywords
Internet, media company, DoubleClick.com, legal problems, website, visitor information, collection practices, privacy, World Wide Web, legal, technical, ethical
Related Case Studies
| Case Title | Details |
|---|---|
|
Case Title SMS AdvertisingCase Code: MKTG043 |
Details |
|
Case Title Fabmart’s e - Tailing ModelCase Code: ITSY024 |
Details |
|
Case Title Google.com - The World’s Number One Internet Search EngineCase Code: ITSY019 |
Details |
|
Case Title BEA Weblogic - Personalizing the World Wide WebCase Code: ITSY017 |
Details |
|
Case Title SciQuest.com’s B2B e-marketplaceCase Code: ITSY008 |
Details |

