Startup idea: Do we value our laundry more than our privacy?
clearsignal.posterous.com
clearsignal.posterous.com
Even if you have a normal ToS and then try to abbreviate it, you have a host of issues: which one would control? You could explicitly say, "the normal ToS controls in the case of a conflict between the ToS and an abbreviated version," but, if people, don't read the normal ToS because there is an abbreviated version, is it really conscionable to say that the normal ToS would control? If the abbreviated controls, there have to be many caveats: like "We own everything you upload... unless you didn't own it to begin with, in which case, we don't own it, and you guarantee to us that you have the right to use it, and you give us the right to use it," or "There are no warranties, except if this statement itself is unenforceable (which is true in some states), in which case we disclaim all warranties to the extent applicable by law, and in the event this is unconscionable or found unenforceable, the rest of this agreement is still enforceable" etc etc. Once you're in that land, you've obviously lost the point of abbreviating it.
There is no legal equivalent to widely used open source libraries where one can go to the parts bin and pull out the functionality one needs and only that functionality. And yet most of the law firms I've worked with do have boilerplate documents that fit their practice. It's a knotty problem; lawyers and programmers operate under different constraints, and things that are obvious to one may be complete mysteries to the other.
If we had a legislature that worked and understood the internet, this sort of thing is exactly what they would be tackling...
The power relationship between a corporation and a user is one of extreme imbalance - the corporation can set the terms, and usually modify them at will, and usually does so to the interest of it and its investors.
Lawyers, by and large, seem to labour under the delusion that if legal matters can be specified precisely enough, then they will compile into reality. This isn't the case, and we have now reached a situation where an individual is required to deal with more agreements than s/he could possibly fairly comprehend. Anything that serves to remedy this situation is fine by me.
The main problem I see is that if these icons are just opt in, why would a company use them if it wasn't respecting a user's privacy? It would be similar to a website having a badge that proudly says "Invalid XHTML".
P3P (http://en.wikipedia.org/wiki/P3P) tries to address a similar problem but in a machine-readable way.
I can promise you that many companies in the wild actively violate their own TOS, knowingly or unknowingly. I can promise you that you will never find out about all of those cases, even after there's a data breach.
Given the legal concerns and the skew that attempting profitability would have, I'd rather just see this adopted by projects voluntarily. But even then, if it becomes mainstream to expect a "privacy ticker", there's still nothing to keep companies from selectively disclosing or straight up lying.