Whats the scope of a P3P policy?
As we have seen in question II.13 P3P has very flexible means to address the range of pages and servers which are addressed by a policy. In addition, policies identify the data recipients, and make a variety of other disclosures including information about dispute resolution, and the address of a site’s human-readable privacy policy. P3P policies must cover all relevant data elements and practices (but note that legal issues regarding law enforcement demands for information are not addressed by this specification; it is possible that a site that otherwise abides by its policy of not redistributing data to others may be required to do so by force of law). P3P declarations are positive, meaning that sites state what they do, rather than what they do not do.