Chapter 5. Securing and Respecting Users’ Privacy
Years ago, when I was young and foolish, I managed the intranet of a well-known company (not Google), and we had a problem. Employees were complaining that some information on our main internal website was difficult to find. So, my team got an idea: capture all the search queries our users entered on the site. We could then identify the most commonly searched topics and make the most relevant articles more visible, which would delight our users. Simple, right? Also, since our company culture was extremely open, we decided to remove all employee names from the query data and make it visible to everyone in the company, because why not? The website was protected behind a firewall, and it would be cool to see what our nameless coworkers searched for. What could possibly go wrong?
Twenty-four hours after our search-tracking feature went live, we shut it down because somebody with actual sense explained the risks to us. Even on a work-related website, it turns out, employees search for intimately personal topics such as maternity leave and medical benefits for cancer. Collecting and viewing this information was a serious violation of personal privacy. Worse, our decision to make these search terms visible to others, even with the searcher’s name removed, was potentially perilous. Imagine what could happen if an employee were laid off shortly after they searched for maternity leave. They could say (accurately) that their anonymous searches ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access