At VRM+CRM 2010 Phil Windley gave a talk that included four slides that perfectly framed the history of e-commerce. With his permission, here they are:

As Wikipedia currently puts it,
A cookie, also known as a web cookie, browser cookie, and HTTP cookie, is a piece of text stored on a user's computer by their web browser. A cookie can be used for authentication, storing site preferences, shopping cart contents, the identifier for a server-based session, or anything else that can be accomplished through storing text data.
Handy things, cookies. They've been good enough for all this time because there were no alternatives. Our browsers eat cookies and barf them back at servers because that's the way the system is built. And it's the only one we know. We are like serfs in the middle ages, visiting manors and castles. Equality, democracy, independence... these are not part of the program. If we want something like equality on the Web, we can get our own domains, put up our own websites, publish our own blogs. Which we do.
But even those of us with our own domains, our own stores, our own publications, remain subordinate when we enter the castles of e-commerce sites. And this is not just because those sites bake cookies. It's because subordination of users is built into client-server computing, and (derivatively) into the Web itself. Client-server puts the owners and operators of websites (where the servers are) in the position of sole responsibility for relationships with clients, which are browsers and other applications we use. In client-server terms, our apps (and we) are "service requesters." We request, and the server serves. By this arrangement we are subordinates. Supplicants. Submissives. The dominant parties are all on the server side.
In order to make this system work in the legal dimension, lawyers for site owners long ago came up with the legal mumbo we call "terms of use." For example, here are Google's:
2. Accepting the Terms
2.1 In order to use the Services, you must first agree to the Terms. You may not use the Services if you do not accept the Terms.
2.2 You can accept the Terms by:
(A) clicking to accept or agree to the Terms, where this option is made available to you by Google in the user interface for any Service; or
(B) by actually using the Services. In this case, you understand and agree that Google will treat your use of the Services as acceptance of the Terms from that point onwards.
2.3 You may not use the Services and may not accept the Terms if (a) you are not of legal age to form a binding contract with Google, or (b) you are a person barred from receiving the Services under the laws of the United States or other countries including the country in which you are resident or from which you use the Services.
2.4 Before you continue, you should print off or save a local copy of the Universal Terms for your records.
I've italicized the part that matters. It says use = agreement. Typical agreements like this one also include language like this, also from Google:
19. Changes to the Terms
19.1 Google may make changes to the Universal Terms or Additional Terms from time to time. When these changes are made, Google will make a new copy of the Universal Terms available at http://www.google.com/accounts/TOS?hl=en and any new Additional Terms will be made available to you from within, or through, the affected Services.
19.2 You understand and agree that if you use the Services after the date on which the Universal Terms or Additional Terms have changed, Google will treat your use as acceptance of the updated Universal Terms or Additional Terms.
In other words, they can change their terms, and all they have to do is post them on a Web page. If you continue to use their services, you've automatically agreed to the changes.
Nearly all terms of service (also called "conditions of service," "service terms" and so on) also include a link to a "privacy policy" page. Typically these include language like this, from Second Life:
Linden Lab’s Protection and Disclosure of Your Information
Except under certain limited circumstances set forth here and in our Terms of Service (“Terms of Service”), Linden Lab does not disclose to third parties the personal information or other account-related information you provide us, such as IP address, without your permission. You understand, however, that Linden Lab may disclose your personal or other account-related information under the following circumstances:
- If we believe in good faith that such disclosure is necessary under applicable law, or to comply with legal process served on Linden Lab;
- In order to protect and defend the rights or interests of Linden Lab, Second Life or the users of Second Life;
- In order to report to law enforcement authorities, or assist in their investigation of, suspected illegal or wrongful activity, or to report any instance in which we believe a person may be in danger;
- To service providers with whom we have contracted to assist us with Second Life features or operations (such as anti-fraud functions, billing, collections, registration, customer support, email delivery, age verification or LindeX operations), to fulfill your service requests, offer new content or help us improve our Service. Our contracts with these third parties prohibit them from using any of your personal information for purposes unrelated to the product or service they are providing;
- To other third parties (a) to provide you with services you have requested, (b) to offer you information about our Service (e.g., events or features), or (c) to whom you explicitly ask us to send your information (or about whom you are otherwise explicitly notified and consent to when using a specific service). For instance, we may provide certain information to our payment processor, to credit card associations, banks or issuers (if you are using a credit card), to PayPal (if you are using a PayPal account), or to providers of other services you request. If you choose to use these third parties’ products or services, then their use of your information is governed by their privacy policies. You should evaluate the practices of third party providers before deciding to use their services; and
- To other business entities, should we plan to merge with or be acquired by that business entity. Should such a combination occur, we will require that the new combined entity follow this Privacy Policy with respect to your personal information. If your personal information will be used contrary to this policy, you will receive prior notice.
I've italicized the part that matters here too. While it's nice that they "require" that the new entity follow the old privacy policy, it doesn't matter. They can change that policy just by giving you prior notice.
In fact many (perhaps most) terms of service and privacy policies give site owners the right to do whatever they please with information they get from you directly, or learn about you indirectly, such as by tracking you on the Web and elsewhere, or by purchasing tracking-derived information from other parties. (For details on how creepy all that stuff gets, see The Wall Street Journal's outstanding series called What They Know.)
Both terms of service and privacy policies are full of loopholes like the ones above. That's because they belong to a breed of agreement called contracts of adhesion, standard form contracts, End User Licens Agreements (EULAs), boilerplate contracts, or adhesion contracts. As the Free Dictionary (channeling West's Encyclopedia of American Law) puts it, an adhesion contract is —
A type of contract, a legally binding agreement between two parties to do a certain thing, in which one side has all the bargaining power and uses it to write the contract primarily to his or her advantage.
An example of an adhesion contract is a standardized contract form that offers goods or services to consumers on essentially a "take it or leave it" basis without giving consumers realistic opportunities to negotiate terms that would benefit their interests. When this occurs, the consumer cannot obtain the desired product or service unless he or she acquiesces to the form contract.
In other words, it's a type of contract that nails down the submissive party while the dominant party is free to change whatever it pleases. The Free Dictionary (West's) adds,
There is nothing unenforceable or even wrong about adhesion contracts. In fact, most businesses would never conclude their volume of transactions if it were necessary to negotiate all the terms of every Consumer Credit contract. Insurance contracts and residential leases are other kinds of adhesion contracts.
This does not mean, however, that all adhesion contracts are valid. Many adhesion contracts are Unconscionable; they are so unfair to the weaker party that a court will refuse to enforce them. An example would be severe penalty provisions for failure to pay loan installments promptly that are physically hidden by small print located in the middle of an obscure paragraph of a lengthy loan agreement. In such a case a court can find that there is no meeting of the minds of the parties to the contract and that the weaker party has not accepted the terms of the contract.
West's Encyclopedia of American Law, edition 2. Copyright 2008 The Gale Group, Inc. All rights reserved.
Look up "privacy policy" (with the quotes) on Google and you get more than .9 billion results. In other words, there are close to a billion sites you can do business with, each with their own terms and policies — and each with its own silo'd means for dealing with you. Thanks to both the legal and technical structure of the commercial Web, your relationshps with each of these sites and services are contained within the systems those services provide. You have no common way of dealing with them, beyond their compatibility with your browser or your email client. Your address, your preferences, your history — everything involved in your relationship with them — is silo'd inside their servers. They know who you are when you show up (because they've left a cookie as a reminder in your browser), and that's nice. But the overall system is one where you have no independent existence. To them you exist only within their customer relationship management (CRM) or equivalent system.
We are so accustomed to operating this way that few of us call the system into question, or look for ways around it, or to improve it. When we do, it is usually through some other site- (and therefore silo-) based system.That's what we have with travel sites like Expedia, Travelocity, Kayak, Priceline and Hotwire. While each of those give us ways to deal with multiple airlines, hotels or car rental agencies, our data from one can't easily be moved to another. Again, to them our existence is defined by whatever data we enter into their relationship systems. And they're not about to share that data with a competitor. (Though they might with a third party, as most of their terms of service say.)
There are some browser controls at our end, but they are inconvenient and crude. For example, here's the relevant section of Firefox's privacy prefs pane:

The only real "managment" here is under "Exceptions," where we can "block" or "allow" cookies from a given website. Given the huge number of sites you need to deal with, that's kind of a pain.
Outside the browser there are a few options. For example, Andy Sternberg's Small Print Project at USC's Annenberg School, which grew out of Cory Doctorow's Set Top Cop course there, mophed into reasonableagreement.organ, "where we make mincemeat of End User License Agreements. They do this thorugh the "anti-EULA":

Andy adds,
Frankly, it’s all bullshit. The way the system should work is, you buy something, you own it. The law of the land governs your interactions with the seller. What’s the point of having a consumer-protection law if all it takes to get around it is to announce that you’ve agreed to waive your rights by buying something? If consumer protection laws don't protect people who buy stuff, whom do they protect?
That’s not to say that we can't have reasonable agreements — like when you and your boss sit down and draw up your employment contract, negotiating the terms on which you'll work. But the idea that an agreement can be made by shouting, "By standing there doing nothing, you agree to let me stab you in the eye!" is just dumb.
So how can we make the system work? The short answer is through tools at our end that assert our independent existence, and bring original value to the market's table. The anti-EULA is one. Renee Lloyd, a lawyer and member of the ProjectVRM team, proposes this shorter version:
READ CAREFULLY. The owner of this website is hereby on notice that they do not have my express or implied consent to any and all agreements that are NON-NEGOTIATED including but not limited to licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies (collectively, BOGUS AGREEMENTS) with it, its partners, employees, subsidiaries, licensors, agents and assigns.
But where would it go? The reasonableagreement.org project recommends that individuals include this in e-mail, before signing credit card payments, and so on. But sites have their hearing aids turned off to this kind of thing. They aren't equipped to detect a signal coming from our side unless it comes through systems they provide on their Web pages or through the cookies they give us.
When he was still at Mozilla, Aza Raskin came up with privacy icons:
![]()
While the icons don’t touch on all topics, we do think they significantly move the discussion on privacy, as well as the general level of literacy about privacy, forward. We do not want to let perfection or devotion to taxonomy get in the way of the good.
Keep in mind that the target adopters of Privacy Icons are 2nd-tier sites—the sites where differentiation based on privacy matters to their users. Think about the large number of sites which vehemently promise to never share your email address when you sign up for their service or mailing list. Those are the kinds of sites, which make up a significant fraction of the web, that would adopt Privacy Icons.
These are great, and a huge step forward. They also still operate on the server side, the sell side, of the marketplace. They don't equip the user with tools of their own.
This is why ProjectVRM has come up with the r-button:
![]()
It has two sides. The left one is yours, and the right one is the site's. The symbol is a pair of magnets, open toward each other.
On a browser it might present buttons with pop-downs that look like one this:

In that case nothing is happening. But if you arrive at a site that turns the right button red, like this...

It signals that the site is open to dealing with the user on the user's terms. It doesn't say that the site agrees to those terms. But it's a new kind of signal: one that says "we're open." Or, in somewhat more legal terms, "We're not starting out with an adhesive contract here."
This is a state change for of the first order. It opens a fault line. A tectonic crack. And there's not much to it. All the site needs to get going is some RDFa code that says "light up the right side of this thing."
Basic User-Centric Agreement Terms:
PARTIES: Establishing the parties to the agreement. There is a vast difference between:
1. You are entering into this agreement with ABC Corporation, its direct and indirect affiliates and subsidiaries (ABC).
2. The parties to this agreement are User and ABC Corporation, a Delaware corporation located [insert address] (ABC).Translation: In choice #1, youve entered into an agreement with not just the company but also a host of other individuals and organizations. This language basically makes a traditional third party a quasi first party. In the privacy context this is important because it allows a company to share your information with what would be considered traditional third parties
Review Mozilla Privacy Icons: http://www.azarask.in/blog/post/privacy-icons/
DIGITAL DATA COLLECTION: Provide users with link to information sources such as WSJs: What they Know and establish a tiered terms approach. Value in including a prohibition in the legal terms is that the filter technology will be limited to the current collection tools. A legal prohibition addresses what is known and not yet developed. Technical issue: Terms need to be established prior to tracking taking place. E.g.: At which point in the browser process do cookies get downloaded?
Tier 1:
User Term: All forms of data collection are prohibited.
Vendor Term: Use of digital data collection is permitted solely to enable user verification and access.
Tier 2:
User Term: Data collection is permitted but limited to the following: [E.G. NYTimes Subscription].
Vendor Term: Vendor is limited to the following data collections and use shall be limited as set forth in the Data Use Section
VOLUNTEERED DATA:
DISPOSAL OF OR RETURN OF DATA
User Term: Data shall not be retained. Vendor shall securely dispose of User Data __immediately after consummating transaction; ___months; ___close of account. It shall be returned to User immediately, ___collected Data shall be provided ____[time period].
SALE OF COMPANY: In the event of the sale of the company terms shall bind the succeeding company.
USE OF DATA
[Discuss with Doc]
TRANSACTION SPECIFIC TERMS: Doc I want to see how we can use context automation to capture these terms.
Payment
Product Use