Conflicting guidelines on Web 'cookies' spur confusion

Contradictory guidelines about whether federal agencies may use software "cookies" on their Web sites has led to confusion among departments and a frequent failure to meet the privacy principles government agencies promote for the private sector, two officials from the General Accounting Office and the Commerce Department's chief information officer said Monday.

Citing two memos and one letter of clarification from the Office of Management and Budget, GAO Senior Attorney David Plocher said OMB had put federal agencies into a bind by simultaneously encouraging them to comply with the FTC's fair-information principles--which are not mandated by law--and requiring them to comply with the 1974 Privacy Act.

That act--which applies only to the federal government's collection of records about individuals--places specific obligations on agencies even though it allows numerous exceptions so long as an agency publishes its proposed rules in the Federal Register.

According to a study of federal privacy policies conducted by Linda Kontz, GAO's director of information management issues, seven agencies used cookies without disclosing their use--a clear violation of a June 2000 memorandum issued by former OMB Director Jacob Lew.

Koontz also cited a study released last week by Senate Governmental Affairs Committee Chairman Fred Thompson, R-Tenn., finding that 64 government sites used Web-tracking text files known as cookies even though they had not obtained permission from the head of the agency--also a violation of the June memorandum.

But Plocher said much of the blame stems from contradictions between the memo, a subsequent clarification issued in September 2000, and a June 1999 memo requiring agencies to post privacy policies informing Web site visitors about what information the agency collects, why it collects it and how it is used.

"OMB was trying to prod agencies to comply with the spirit [of privacy protection] but not trying to raise the bar with compliance of the [Privacy Act]," Plocher said. "It seemed to us that the OMB guidance is problematic."

"The effort to conform to broad privacy principles, while limiting requirements to those of the Privacy Act, introduces confusing terms and may send mixed messages about basic compliance requirements," he continued. "The attempt to narrowly address pressing problems, such as press accounts of cookie use, while avoiding overly prescriptive directives resulting in fragmented and unclear guidance for agencies."

Roger Baker, the Commerce Department's CIO and chairman of the Federal CIO Council's Privacy Subcommittee, said federal agencies should not use cookies "unless you absolutely have to." He also said Commerce had prohibited the use of "Web bugs," or pieces of software that help Web-site operators track a user's movements on the Internet.

Stay up-to-date with federal news alerts and analysis — Sign up for GovExec's email newsletters.
Close [ x ] More from GovExec

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Sponsored by G Suite

    Cross-Agency Teamwork, Anytime and Anywhere

    Dan McCrae, director of IT service delivery division, National Oceanic and Atmospheric Administration (NOAA)

  • Data-Centric Security vs. Database-Level Security

    Database-level encryption had its origins in the 1990s and early 2000s in response to very basic risks which largely revolved around the theft of servers, backup tapes and other physical-layer assets. As noted in Verizon’s 2014, Data Breach Investigations Report (DBIR)1, threats today are far more advanced and dangerous.

  • Federal IT Applications: Assessing Government's Core Drivers

    In order to better understand the current state of external and internal-facing agency workplace applications, Government Business Council (GBC) and Riverbed undertook an in-depth research study of federal employees. Overall, survey findings indicate that federal IT applications still face a gamut of challenges with regard to quality, reliability, and performance management.

  • PIV- I And Multifactor Authentication: The Best Defense for Federal Government Contractors

    This white paper explores NIST SP 800-171 and why compliance is critical to federal government contractors, especially those that work with the Department of Defense, as well as how leveraging PIV-I credentialing with multifactor authentication can be used as a defense against cyberattacks

  • Toward A More Innovative Government

    This research study aims to understand how state and local leaders regard their agency’s innovation efforts and what they are doing to overcome the challenges they face in successfully implementing these efforts.

  • From Volume to Value: UK’s NHS Digital Provides U.S. Healthcare Agencies A Roadmap For Value-Based Payment Models

    The U.S. healthcare industry is rapidly moving away from traditional fee-for-service models and towards value-based purchasing that reimburses physicians for quality of care in place of frequency of care.

  • GBC Flash Poll: Is Your Agency Safe?

    Federal leaders weigh in on the state of information security


When you download a report, your information may be shared with the underwriters of that document.