help me!!!

"Nguyen Viet Ha" <[email protected]> Fri, 14 Apr 2006 19:41:35 +0700
Newsgroups gmane.comp.web.p3p.devel
Message-ID <2AAB52AC4DF8FB4B801C5B174D3BA2FB1F3BC4@fsoft-email03.fsoft.fpt.vn>
This is a multi-part message in MIME format.

------_=_NextPart_001_01C65FC0.C3D16898
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

I have been trying to understand what is involved with P3P and I was
dubious about whether a single line of code in a header would solve any
problem, and even worse, if its insertion would open a whole can of
compliance worms. =20

=20

>From what I've read regarding P3P there are 3 levels of policy:

=20

1.	Compact policy - that can be inserted into a header for example
- I think this is what eGS have suggested.=20
2.	XML policy for machine reading (which can be referenced on each
page, modified for each page, or modified for sections)=20
3.	Text policy for human readability=20

=20

I understand that P3P is good practice and not a technical nor legal
requirement, but,

What needs clarification is=20

-          I understand that even though our system is JSP we can still
include the required HTTP declaration in a header. - is that right?

-          Is there a genuine technical requirement to have a P3P
policy, compact or otherwise, ie: will it be a significant benefit to
our system?

-          Can a compact policy statement code in a header stand alone
as the privacy policy in an application, or it will need the other XML
and text policies to reference to?

-          If a line of code can stand alone in the headers - what
should that code be? (verify the code Gareth Boden has suggested)

-          Will the line of code impact in others ways - new
accessibility issues for eg: other browser problems / user agents.  How
much back testing will be involved?

=20

=20


------_=_NextPart_001_01C65FC0.C3D16898
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:Arial;
	color:windowtext;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:719213420;
	mso-list-template-ids:914901750;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>I have been trying to understand =
what is
involved with P3P and I was dubious about whether a single line of code =
in a
header would solve any problem, and even worse, if its insertion would =
open a
whole can of compliance worms.&nbsp; </span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>&nbsp;</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>From what I&#8217;ve read regarding =
P3P
there are 3 levels of policy:</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>&nbsp;</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<ol style=3D'margin-top:0in' start=3D1 type=3D1>
 <li class=3DMsoNormal style=3D'color:navy;mso-list:l0 level1 =
lfo1'><font size=3D2
     color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial'>Compact
     policy - that can be inserted into a header for example &#8211; I =
think
     this is what eGS have suggested.</span></font> <span =
lang=3DEN-GB><o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'color:navy;mso-list:l0 level1 =
lfo1'><font size=3D2
     color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial'>XML
     policy for machine reading (which can be referenced on each page, =
modified
     for each page, or modified for sections)</span></font> <span =
lang=3DEN-GB><o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'color:navy;mso-list:l0 level1 =
lfo1'><font size=3D2
     color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial'>Text
     policy for human readability </span></font><span =
lang=3DEN-GB><o:p></o:p></span></li>
</ol>

<p class=3DMsoNormal style=3D'margin-left:.25in'><font size=3D2 =
color=3Dnavy
face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>&nbsp;</span></fo=
nt><span
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>I understand that P3P is good =
practice and
not a technical nor legal requirement, but,</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>What needs clarification is =
</span></font><span
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in;text-indent:-.25in'><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>-</span></font><font size=3D1 color=3Dnavy><span =
style=3D'font-size:7.0pt;
color:navy'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></font><font
size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>I understand that even though our system is JSP we can still
include the required HTTP declaration in a header. &#8211; is that =
right?</span></font><span
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in;text-indent:-.25in'><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>-</span></font><font size=3D1 color=3Dnavy><span =
style=3D'font-size:7.0pt;
color:navy'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></font><font
size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>Is there a genuine technical requirement to have a P3P =
policy,
compact or otherwise, ie: will it be a significant benefit to our =
system?</span></font><span
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in;text-indent:-.25in'><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>-</span></font><font size=3D1 color=3Dnavy><span =
style=3D'font-size:7.0pt;
color:navy'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></font><font
size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>Can a compact policy statement code in a header stand alone =
as the
privacy policy in an application, or it will need the other XML and text
policies to reference to?</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in;text-indent:-.25in'><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>-</span></font><font size=3D1 color=3Dnavy><span =
style=3D'font-size:7.0pt;
color:navy'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></font><font
size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>If a line of code can stand alone in the headers &#8211; =
what
should that code be? (verify the code Gareth Boden has =
suggested)</span></font><span
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in;text-indent:-.25in'><font =
size=3D2
color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>-</span></font><font size=3D1 color=3Dnavy><span =
style=3D'font-size:7.0pt;
color:navy'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></font><font
size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:10.0pt;font-family:Arial;
color:navy'>Will the line of code impact in others ways &#8211; new
accessibility issues for eg: other browser problems / user agents.&nbsp; =
How
much back testing will be involved?</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>&nbsp;</span></font><span =
lang=3DEN-GB><o:p></o:p></span></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'><o:p>&nbsp;</o:p></span></font></p>

</div>

</body>

</html>

------_=_NextPart_001_01C65FC0.C3D16898--