Shostack + Friends Blog Archive

 

Podtrac.com and Listener Privacy

It turns out that it’s very hard to subscribe to many podcasts without talking to Podtrac.com servers. (Technical details in the full post, below.) So I took a look at their privacy statement:

Podtrac provides free services to podcasters whereby Podtrac gathers data specific to individual podcasts (e.g. audience survey data, content ratings, measurement data, etc). This podcast data is not considered personally identifiable information and may be shared by Podtrac with member advertisers. (“Podtrac Client Privacy Statement,” [link to http://podtrac.com/about/privacy-clients no longer works] undated, unversioned.)

It’s not clear to me who doesn’t consider what they collect to be personal data, because the passive voice is annoyingly used. So I’ll ask: precisely what data is collected? And under what set of laws or even perspectives is the data they’re collecting is not considered personally identifiable? For example, are they collecting IP addresses, which I understand are PII in the EU?

Enquiring minds with privacy officials might want to ask those officials.

So on to the technical details. Let’s use The Onion Radio news as an example. The subscription URL is http://feeds.theonion.com/OnionNewsNetwork. If you download that file, you get chunks like this:

<feedburner:origEnclosureLink>
http://www.podtrac.com/pts/redirect.mp4/track.theonion.com/podcast_redirect.mp4?
file=http://videos.theonion.com/onion_video/auto/26741/high-unemployment-linked-to-increasing-number-of-f-podcast-5602.mp4
&amp;amp;
title=High%20Unemployment%20Linked%20To%20Increasing%20Number%20Of%20Face%20Tattoos
&amp;amp;issue=0
</feedburner:origEnclosureLink>

It also links to DoubleClick and Feedburer, both Google businesses.