I have P3P on my Web site. Why do users who already have my sites cookies on their systems get the privacy icon when they upgrade to Internet Explorer 6 or Windows XP?
Cookies that exist on a computer prior to an upgrade are bound to first-party use only. That is, they are sent as usual on HTTP requests in the first-party context, but they are not sent on HTTP requests in the third-party context. When the cookie is suppressed in that third-party context request, the privacy icon displays to inform the user of this protection. This helps to protect the user’s privacy from the very beginning of using Internet Explorer 6. Any site that appears in a first-party context can retrieve those legacy cookies and exercise their relationship with their user. Sites can delete legacy cookies to keep the privacy icon from appearing.