For some months now the campaigners at nodpi who are working to prevent widespread adoption of deep packet inspection such as that implemented by Phorm have been seeking clrification of why the BBC use cookies to send of records of your IP address, your Post Code*, and what parts of their website (e.g. iPlayer videos) you've been viewing off to a third party company in the USA. This third party is Omniture, formerly known as Visual Sciences. The BBC say this is in order to monitor usage of their website. Response is here; the whole thread can be viewed here. Interestingly, such transfer of personal data seems to be legal under EU legislation, as indicated in this quotation from the FOI response Dephormation finally received:
To the extent that the bbc.co.uk homepage is capturing IP addresses and post code data for anonymous statistical reporting purposes, the BBC confirms that the BBC treats both IP addresses and post code data as “personal data” within the meaning of the Data Protection Act 1998, despite the currently uncertain legal position around IP addresses in particular. Given its position, the BBC does not permit the transfer of IP addresses and user post code data to countries outside of the European Economic Area (“EEA”) unless those countries have “adequate data protection standards” and/or there are strong contractual data protection provisions in place with the data processor. It is correct that Omniture is a USA company and therefore operates outside the EEA. However, Omniture do satisfy the European Union's Directive on Data Protection’s requirements by demonstrating “adequate data protection standards” by registering with the US Department of Commerce’s safe harbour framework.