First-Party Sets Policy Proposal
W3C Privacy Community Group
August 12, 2021
Anti-tracking policies for the web
How browsers currently define “third-party”
Why “site” or “registrable domain” isn’t sufficient
Website functionality is often deployed across multiple domains, including:
⇨ User journeys/workflows exist across domains that users perceive as the same website or “first-party”
Why First-Party Sets?
Blue and Green sites are in the same First-Party Set
Blue site is third-party to Purple site
How could browsers use First-Party Sets?
Why are we talking about a policy?
FPS Policy Proposal
We propose a three-pronged policy:
Why we need a policy enforcement component for FPS
An independent enforcement entity (aka verification entity) would serve multiple functions: