Account gekoppeld aan het volgprofiel
Bij het inloggen gaat de accountaanduiding van de dienst naar een partij die al een profiel van dezelfde browser had.
- Familie
- Keten
- Status
- actief
- Geldt voor
- web, mobile-app
Wat er gebeurt
Before sign-in a third party recognises the browser or the device by an identifier of its own. At the moment of authentication the operator hands that same party its own account identifier: a user number, a customer number, a hashed address, sometimes the address itself. From then on the profile that was pseudonymous has a name attached. Everything recorded before the sign-in and everything recorded after it, on any device where the person signs in, belongs to one identified person.
Waarom het ertoe doet
The step is invisible and it cannot be undone. A profile built from browsing can be argued about as long as it is pseudonymous; once joined to an account it is a dossier about a named person. Clearing cookies no longer separates the two, because the next sign-in joins them again.
Veelvoorkomende oorzaken
- a user identifier configured as a custom dimension or user property in a measurement tag
- an advertising tag firing on the login event with the account identifier as a parameter
- an identity feature of the measurement product, enabled as soon as a user identifier is available
- the same identifier used in the application and in the tag, because it was the value at hand
Dit is het níet
Two third parties exchanging identifiers so their profiles can be matched is Identifier synchronisation between parties. Here the value comes from the operator itself and names the account. An operator writing its own user identifier into its own store is not this entry either: the value has to reach a party that also holds an identifier of its own for that browser. An address used as the key, hashed or not, is Email address as a cross-service identifier: there the value is computable by both sides from something the person gave, here it is an internal account identifier that only the operator can mint.
Hoe je het vaststelt
Indicator
Differential over accounts. Sign in twice in the same browser profile with two accounts you control: a request to a host under a different registrable domain carries a value that changes with the account while that host's own identifier stays the same. The reverse check confirms it, in that the same account in a fresh profile yields the same account-dependent value against a new host identifier.
Methode
differential
Kwaliteit van de detectie
95 van 100
De grenzen van deze bevinding
Wat dit patroon zou weerleggen
- The account-dependent value changes on every sign-in of the same account, so it identifies a session rather than an account.machinaal te toetsende bevinding vervalt
- The receiving host is under the operator's own registrable domain.machinaal te toetsende bevinding vervalt
- The receiving party holds no identifier of its own for this browser, so there is nothing to join to.machinaal te toetsende bevinding wordt zwakkerThen the account identifier is being disclosed, which is a transfer question, without the joining that makes this entry what it is.
- The recipient acts on the operator's instruction only and is barred from using the value for its own purposes.niet uit de meting af te leidende bevinding wordt zwakker
Wat dit patroon níet vaststelt
- harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
- severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
- unlawfulness; that is for a supervisory authority or a court
- intent; a fault is usually a build decision, not a plan
- absence: not finding it in one capture is not evidence that it is not there
Reproduceren
- manual
METHOD.mdno dedicated reproduction exists yet; follow the general method and the indicator above
Juridisch kader
Bepalingen
Veelgehoorde tegenwerpingen
We only send an internal number, not a name.
The number is the join. The recipient does not need the name to know that this browser and that account are one person, and the operator can resolve the number to a name whenever it likes.
It improves measurement across devices.
That is the purpose stated plainly, and it is exactly the processing nobody was asked about. A benefit to the operator is not a ground.
The person is logged in, so they know we know them.
They know the operator knows them. This is about a third party, and the sign-in screen says nothing about it.
The identifier is hashed before it is sent.
A hash that is stable per account works as an account identifier. What matters is that the value is the same on every visit and different per person.
Geldt wanneer
to-processing