Online services increased their effort to protect user data, EFF says

The Electronic Frontier Foundation hopes to stimulate transparency and encourage companies to stand up for user privacy

While some online services are stepping up their efforts to protect private user data from government requests, there is plenty room for improvement, the Electronic Frontier Foundation (EFF) said on Thursday. It is time for all companies that hold private user data to make public commitments to defend their users against government overreach, the foundation said.

The EFF measured the commitment of 18 U.S. companies hosting users' personal data, including Amazon, Facebook and Microsoft, to protect that data from U.S. government requests. It examined their privacy policies, terms of service, published law enforcement guides if available, and the track record of companies defending user privacy in courts.

The companies were awarded stars and half stars in four categories. The EFF investigated whether users were informed about government data demands, determined whether the companies were transparent about government data requests, whether they were willing to fight for user privacy in courts, and whether the companies were fighting to protect user privacy in the U.S. Congress.

The EFF said it was pleased that Facebook, Dropbox and Twitter have stepped up their game since last year, when it published its first report on the topic. Twitter was awarded an extra star because it started fighting for user privacy rights in Congress, and showed more effort to fight for users rights in courts, EFF data showed. The microblog service now has 3.5 stars.

Facebook gained half a star for being more transparent about government requests, bringing its total up to 1.5 stars and Dropbox gained two stars for becoming transparent about government requests and telling users about data demands, bringing its total to three out of four stars., an ISP based in California, is the first company to receive a full gold star in each category, the EFF said.

Google maintained its position with two whole and two half stars.

Apple, Microsoft and AT&T still have one star, for fighting for user privacy in Congress, while Comcast picked up its first star for protecting its users' privacy in the courts, according to the EFF data.

Verizon, Myspace and Skype failed to score a star in any of the categories.

"The overall poor showing of AT&T, Verizon and Comcast, who provide Internet connectivity to so many people, is especially troubling," the foundation said.

The EFF added five new companies to the list this year including location based services Foursquare and Loopt. Foursquare was awarded zero stars and Loopt got one for defending privacy in Congress. "We're hopeful that next year we'll see more protections for users from location services providers like Loopt and Foursquare, since location information is so sensitive and increasingly sought by the government," the EFF said.

By publishing the report, the EFF hopes to stimulate companies to improve transparency about what data flows to the government and to encourage the companies to stand for user privacy when it is possible to do so, the foundation said.

Loek covers all things tech for the IDG News Service. Follow him on Twitter at @loekessers or email tips and comments to

Join the CSO newsletter!

Error: Please check your email address.
Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Loek Essers

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place