sencha.com, activestate.com, sandisk.com, clustrix.com, and about 2000 others use LandLander. I checked the privacy policies of those four sites and none of them say they are giving away your personal information. On the contrary, they all explicitly say they aren't.
"We do not share any information about you or your company to unaffiliated third parties, except as necessary to administer the communications we offer and as permitted by law. We may use a third party service provider to for communications; that company is prohibited from using our users’ personally identifiable information for any other purpose. If you follow us on Twitter, Facebook or on other social media services, we may use information provided by these services to customize our communications to you. We will not share the personally identifiable information you provide with other third parties unless we give you prior notice and choice." - http://www.sencha.com/legal/privacy/
Nearly every company using LeadLander is breaking the law because their posted privacy policies do not state that they are giving a third party your personal information, and that third party is giving it to others.
Edit: It looks like http://formalyzer.com/formalyze_call.js is the specific js file that uploads personal information. Of the sites I listed only clustrix.com is loading that (on the contact form). The other sites seem to be using LeadLander without the form tracking.
As I understand it, in the US the FTC enforces privacy policy violations. If you don't promise your customer anything, then you're more or less off the hook (as far as I know). But if you do have a privacy policy, and you violate it, then you're misleading consumers.
And then it says: "that company is prohibited from using our users’ personally identifiable information for any other purpose."
It turns out that sencha.com might not be sending personal information. clustrix.com appears to be, their privacy policy says:
"The Personal Information we collect is not shared, rented, or sold to any third-parties. We may provide your Personal Information to companies that provide services to help us with our business activities such as shipping your order or offering customer service. These companies are authorized to use your personal information only as necessary to provide these services to us." - http://www.clustrix.com/privacy-policy
I'm not a lawyer, but as a normal native English speaker I read that as they are not going to send my name, email, and phone number to another company, who will in turn share it with with anyone who pays them. But that's what they are doing. They are selling your personally identifiable information.
Marketo has done company-level tracking for years[0], and if you click through from an email or fill out a form they can keep tracking you as well as back-fill any previously anonymous visits you made (depending on your browser cookie settings, of course). Once it's in the system, they partner with a number of companies, some of whom can help populate contact data[1], eg: "over 1.5 billion opt-in email addresses" -- how plausible is that? They have as customers a few companies[2] you're likely familiar with (eg: VMware).
No, that's the wrong solution. The traffic still tells them that there is still interest to monetize, they just may need to stoop to new lows to get to it.
Loudly tell them that their spying is unacceptable, then actually follow up on that statement. Ghostery is awesome, but that's a proactive measure. We're talking about appropriate reactions.
While I agree with your count-point, it's worth pointing out that Ghostery blocks Google Analytics, too. So they might actually not notice the traffic if they're only looking at Google Analytics (or other blocked analytics tools). [1]
But anyways, I agree with what you're saying. If we care about privacy, we have to be loud about it. I just thought it was worth pointing out that facet of Ghostery.
[1] Yes, you can still see the traffic in the web server logs, but I don't see evidence of many companies still doing that. Google Analytics and the like seem to have completely replaced server logs for traffic analysis.
If they only use Google Analytics (or Piwik, or anything else) and not fact-check this with server logs, they deserve to feel "low on traffic".
But Ghostery is not able (correct me if I am wrong) to disable the server from logging you. And automatically reading server-logs is not so difficult at all.
The most funny thing here is, that in Germany, you should anonymize an IP-address, when tracking, because of the law, that is concerned with privacy.
But the server logs your full IP non the less.
On the original post:
The technology advertised to the author would be totally illegal in Germany. And if I would ever encounter (via Ghostery) a site that uses them and has a German base, I would inform the authorities against them.
I just hate this philosophy of bending/breaking the law/common sense, just because it is possible and might bring in some Bucks. And just because pressure from users might change the regulators minds in the future. It just feels so totally wrong, so disrespectful against fellow human beings, that imho everybody, that has something to do with things like this should be deported to somewhere like North Korea, or the likes. Or like in the middle ages should stand in the pillory (and not in a virtual one).