Secondly, however, this statement smells faintly of fluffy language and PR speak:
> When you browse from an O2 mobile, we add the user's mobile number to this technical information, but only with certain trusted partners. This is standard industry practice.
Is it really industry practice? Can anybody in this field confirm this? I can see why it would be useful for billing as they mention, but is this really an effective way to do age verification?
> in addition to the usual trusted partners, there has been the potential for disclosure of customers’ mobile phone numbers to further website owners.
Woah, there's nothing "potential" about it - this was right there in the HTTP headers. Saying "there has been the potential..." implies the website owner would have had to do some hacking to get hold of this information, which is not the case, right?