Conflicting guidelines on Web 'cookies' spur confusion

Contradictory guidelines about whether federal agencies may use software "cookies" on their Web sites has led to confusion among departments and a frequent failure to meet the privacy principles government agencies promote for the private sector, two officials from the General Accounting Office and the Commerce Department's chief information officer said Monday.

Citing two memos and one letter of clarification from the Office of Management and Budget, GAO Senior Attorney David Plocher said OMB had put federal agencies into a bind by simultaneously encouraging them to comply with the FTC's fair-information principles--which are not mandated by law--and requiring them to comply with the 1974 Privacy Act.

That act--which applies only to the federal government's collection of records about individuals--places specific obligations on agencies even though it allows numerous exceptions so long as an agency publishes its proposed rules in the Federal Register.

According to a study of federal privacy policies conducted by Linda Kontz, GAO's director of information management issues, seven agencies used cookies without disclosing their use--a clear violation of a June 2000 memorandum issued by former OMB Director Jacob Lew.

Koontz also cited a study released last week by Senate Governmental Affairs Committee Chairman Fred Thompson, R-Tenn., finding that 64 government sites used Web-tracking text files known as cookies even though they had not obtained permission from the head of the agency--also a violation of the June memorandum.

But Plocher said much of the blame stems from contradictions between the memo, a subsequent clarification issued in September 2000, and a June 1999 memo requiring agencies to post privacy policies informing Web site visitors about what information the agency collects, why it collects it and how it is used.

"OMB was trying to prod agencies to comply with the spirit [of privacy protection] but not trying to raise the bar with compliance of the [Privacy Act]," Plocher said. "It seemed to us that the OMB guidance is problematic."

"The effort to conform to broad privacy principles, while limiting requirements to those of the Privacy Act, introduces confusing terms and may send mixed messages about basic compliance requirements," he continued. "The attempt to narrowly address pressing problems, such as press accounts of cookie use, while avoiding overly prescriptive directives resulting in fragmented and unclear guidance for agencies."

Roger Baker, the Commerce Department's CIO and chairman of the Federal CIO Council's Privacy Subcommittee, said federal agencies should not use cookies "unless you absolutely have to." He also said Commerce had prohibited the use of "Web bugs," or pieces of software that help Web-site operators track a user's movements on the Internet.

Stay up-to-date with federal news alerts and analysis — Sign up for GovExec's email newsletters.
Close [ x ] More from GovExec

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Going Agile:Revolutionizing Federal Digital Services Delivery

    Here’s one indication that times have changed: Harriet Tubman is going to be the next face of the twenty dollar bill. Another sign of change? The way in which the federal government arrived at that decision.

  • Cyber Risk Report: Cybercrime Trends from 2016

    In our first half 2016 cyber trends report, SurfWatch Labs threat intelligence analysts noted one key theme – the interconnected nature of cybercrime – and the second half of the year saw organizations continuing to struggle with that reality. The number of potential cyber threats, the pool of already compromised information, and the ease of finding increasingly sophisticated cybercriminal tools continued to snowball throughout the year.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • GBC Issue Brief: The Future of 9-1-1

    A Look Into the Next Generation of Emergency Services

  • GBC Survey Report: Securing the Perimeters

    A candid survey on cybersecurity in state and local governments

  • The New IP: Moving Government Agencies Toward the Network of The Future

    Federal IT managers are looking to modernize legacy network infrastructures that are taxed by growing demands from mobile devices, video, vast amounts of data, and more. This issue brief discusses the federal government network landscape, as well as market, financial force drivers for network modernization.

  • eBook: State & Local Cybersecurity

    CenturyLink is committed to helping state and local governments meet their cybersecurity challenges. Towards that end, CenturyLink commissioned a study from the Government Business Council that looked at the perceptions, attitudes and experiences of state and local leaders around the cybersecurity issue. The results were surprising in a number of ways. Learn more about their findings and the ways in which state and local governments can combat cybersecurity threats with this eBook.


When you download a report, your information may be shared with the underwriters of that document.