Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Google Asks Chrome Extensions to Post Privacy Policies

Google this week announced an update to its Chrome store policies that requires all extensions to be explicit about the collection and use of user data.

The changes, which will be enforced in January 2021, follow previous policies that require extensions to only request those permissions they need to implement their features.

Google this week announced an update to its Chrome store policies that requires all extensions to be explicit about the collection and use of user data.

The changes, which will be enforced in January 2021, follow previous policies that require extensions to only request those permissions they need to implement their features.

Now, Google is limiting what developers are allowed to do with the user data they collect, and the new policy requires developers to be clear about their extension’s privacy practices, directly on the Chrome Web Store listing.

“Starting January 2021, each extension’s detail page in the Chrome Web Store will show developer-provided information about the data collected by the extension, in clear and easy to understand language. Data disclosure collection is available to developers today,” Google says.

To limit the manner in which extension developers use collected data, Google now requires that the use of or transfer of user data is “for the primary benefit of the user and in accordance with the stated purpose of the extension.”

Furthermore, Google does not allow extension developers to sell user data, and prohibits the use/transfer of that data for personalized advertising, or for creditworthiness or any form of lending qualification.

“The item listing page will also display whether the developer has certified that their extension complies with this new policy,” the company explains.

The new policy requires developers looking to publish or update an extension to provide information on data usage from the privacy tab of the developer dashboard, including details on what data is being collected and certification of compliance with the new Limited Use policy.

Advertisement. Scroll to continue reading.

“The disclosure form is grouped by category to make it simpler for developers, and maps exactly to the disclosures that will be displayed to Chrome users. Most of this information will be consistent with existing privacy policies that developers have provided to the Chrome Web Store,” the Internet giant says.

Google has already released the data disclosures collection to developers and will display them on the Chrome Web Store listing starting January 18, 2021. To inform users, starting that day, a notice will be shown on the store listings of developers who haven’t provided privacy disclosures.

Related: Chrome 86 Starts Blocking Abusive Notification Permission Requests

Related: Google Axes 500 Chrome Extensions Exfiltrating User Data

Related: Chrome Extensions Policy Hits Deceptive Installation Tactics

Related: Google Tightens Rules for Chrome Extensions

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Kim Larsen is new Chief Information Security Officer at Keepit

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...