Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Google Asks Chrome Extensions to Post Privacy Policies

Google this week announced an update to its Chrome store policies that requires all extensions to be explicit about the collection and use of user data.

The changes, which will be enforced in January 2021, follow previous policies that require extensions to only request those permissions they need to implement their features.

Google this week announced an update to its Chrome store policies that requires all extensions to be explicit about the collection and use of user data.

The changes, which will be enforced in January 2021, follow previous policies that require extensions to only request those permissions they need to implement their features.

Now, Google is limiting what developers are allowed to do with the user data they collect, and the new policy requires developers to be clear about their extension’s privacy practices, directly on the Chrome Web Store listing.

“Starting January 2021, each extension’s detail page in the Chrome Web Store will show developer-provided information about the data collected by the extension, in clear and easy to understand language. Data disclosure collection is available to developers today,” Google says.

To limit the manner in which extension developers use collected data, Google now requires that the use of or transfer of user data is “for the primary benefit of the user and in accordance with the stated purpose of the extension.”

Furthermore, Google does not allow extension developers to sell user data, and prohibits the use/transfer of that data for personalized advertising, or for creditworthiness or any form of lending qualification.

“The item listing page will also display whether the developer has certified that their extension complies with this new policy,” the company explains.

The new policy requires developers looking to publish or update an extension to provide information on data usage from the privacy tab of the developer dashboard, including details on what data is being collected and certification of compliance with the new Limited Use policy.

Advertisement. Scroll to continue reading.

“The disclosure form is grouped by category to make it simpler for developers, and maps exactly to the disclosures that will be displayed to Chrome users. Most of this information will be consistent with existing privacy policies that developers have provided to the Chrome Web Store,” the Internet giant says.

Google has already released the data disclosures collection to developers and will display them on the Chrome Web Store listing starting January 18, 2021. To inform users, starting that day, a notice will be shown on the store listings of developers who haven’t provided privacy disclosures.

Related: Chrome 86 Starts Blocking Abusive Notification Permission Requests

Related: Google Axes 500 Chrome Extensions Exfiltrating User Data

Related: Chrome Extensions Policy Hits Deceptive Installation Tactics

Related: Google Tightens Rules for Chrome Extensions

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

Tabitha Craig has been named the CISO of the Congressional Budget Office (CBO).

Life360 has appointed Vari Bindra, former Amazon cybersecurity lead, as Chief Information Security Officer.

Forcepoint has appointed Guy Shamilov as CISO, Bakshi Kohli as CTO and Naveen Palavalli as CPO and CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.