
The BT Phorm trials put customers inside an advertising experiment without telling them. During covert tests in 2006 and 2007, the company treated private browsing as material for a new commercial service. Some customers noticed suspicious behaviour. When The Register asked questions in 2007, BT denied testing and blamed malware. The interference had a rather more familiar supplier.
You paid the postman to deliver the letters. He quietly opened an advertising consultancy inside the fucking envelope. When you noticed something wrong with the post, the explanation pointed back towards your house.
Welcome back to Renting Rubin. Our first BT visit opened the corporate complaints cupboard. Part II followed AI, jobs and office monitoring; Part III examined Openreach’s proposed discounts and Ofcom’s competition concerns. The fourth instalment reached the digital landline switchover, where reassurance needed a battery backup. Number five goes back to an earlier experiment in what a trusted connection could become.
The BT Phorm trials belong to the company’s history. Their significance survives because the relationship remains recognisable: you entrust a company with access, and somebody inside the commercial machinery starts wondering whether access could also mean permission.
Daniel Rubin And The Borrowed Connection
Horsfield Menzies advertises Daniel Rubin’s secondment to BT, alongside Barclays and AstraZeneca. His biography sells experience in strategic change, boardroom disputes, regulatory investigations and projects where “reputation management and investor confidence” matter. BT supplies part of the corporate pedigree beneath that sales pitch.
That is the explicit connection. The profile gives no secondment dates or project details, and the public material examined here provides no evidence that Rubin worked on Phorm. This article examines the company whose name Horsfield Menzies uses to establish his credentials.
A prestigious client list performs a little electrical trick. Current flows from the household name into the professional biography, lighting the reassuring bulbs marked experience, judgement and trust. Renting Rubin follows the wire back through the wall. Sometimes the installation looks considerably less impressive behind the plaster.
BT’s Phorm history is particularly suitable for that inspection. It concerns commercial judgement, communication and the management of an embarrassing discovery. Those subjects sit remarkably close to the expertise Horsfield Menzies wants prospective clients to notice. Once a firm puts a corporate reference in the shop window, the public can reasonably ask what else comes with the fucking display.
The BT Phorm Trials Had Eighteen Thousand Guinea Pigs
Between 23 September and 6 October 2006, BT ran a covert trial involving approximately 18,000 broadband customers. Its technology partner was 121Media, later renamed Phorm. The system then went under the name PageSense. The Register obtained BT’s technical account of the experiment and reported the scale in April 2008.
These were customers using BT’s live network. They had not volunteered for an advertising laboratory. Nevertheless, their browsing helped generate profiles that the system used to select adverts on participating websites. The commercial categories included finance, weight loss and employment, with campaigns for an Egg credit card, Weight Watchers and Monster.com.
The experiment therefore had a thoroughly ordinary destination. All that covert machinery led towards somebody trying to sell a credit card. Intelligence gathering had put on a promotional lanyard and wandered into the broadband exchange.
BT’s report explained that customers did not know about the trial because one aim was “not to affect their experience”. That formulation deserves preservation. After all, informing people would change the conditions under which the company observed them, so the information stayed on the company’s side of the glass.
Of course, an experiment can produce cleaner measurements when its subjects do not know it exists. The ethical problem lives inside that convenience. BT had the network, the equipment and the commercial partner. Its customers paid for broadband and unknowingly supplied the fucking test bench.
The Browser Started Coughing Up The Experiment
The first system left visible fingerprints. Its early design inserted JavaScript into web pages, while customers encountered flickering pages, browser problems and stray code appearing in forum posts. Some suspected viruses or spyware. In its account of the leaked report, WIRED described how the intervention disrupted browsing while users struggled to identify the source.
That is an exceptionally rotten position for a paying customer. Something behaves strangely on your computer, so you start investigating your computer. You inspect the window because you trust the person who fitted it. Meanwhile, the draught originates in an experiment taking place further down the connection.
BT’s report also anticipated a presentation problem. In a passage reproduced by The Register, it recorded that 121Media would take technical and public-relations action to prevent people perceiving the system as a virus, malware or spyware. The appearance of intrusion had become a communications issue before the customers received a meaningful say in the intrusion itself.
Imagine finding a stranger reading your shopping list through the kitchen window, then learning that the outstanding project task concerned how to make him look friendlier. Perhaps a waistcoat would help, or a leaflet about relevance. Either way, the priority would remain stopping the householder using an ugly word for the man at the glass.
Technology could change. The permission problem would remain until somebody asked the person paying for the window.
BT Sent The Suspicion Back Down The Line
In 2007, the story acquired a particularly sour customer-service script. Customers noticed suspicious redirects associated with a Phorm domain. The Register asked BT about the relationship that July. According to the newspaper’s subsequent account, BT denied testing and said the affected customers must have a malware problem.
In March 2008, however, BT confirmed that it had run a small technical trial on one exchange in June 2007. The company said the exercise tested performance and that it had neither processed nor stored nor disclosed personally identifiable information.
Those assurances addressed the experiment’s handling of data. However, they did not make the earlier denial an accurate answer. A customer asking why traffic behaved strangely needed an explanation of what the provider had done. Instead, the explanation sent the customer searching for a different culprit.
The provider occupied both ends of the conversation: it controlled the network intervention and supplied the account of why the network appeared to misbehave. That gives a denial unusual power. Most customers cannot climb inside a broadband exchange to check the fucking story.
Technical trust therefore carried a second burden. Customers relied on BT to explain the very symptoms that BT’s undisclosed activity could help explain. Once the company finally acknowledged testing, its earlier answer looked like a burglar recommending a better fucking locksmith.
Anonymous Does Not Mean Invited
BT defended the experiment through its treatment of data. In its statement confirming the 2006 test, the company said no personally identifiable information had been processed, stored or disclosed. It presented the exercise as a limited check that a prototype worked properly before any deployment.
Network World’s description of Phorm’s later proposed service explained its use of numerical identifiers and advertising-interest categories, rather than customer names. That distinction matters when assessing what the system was designed to retain. It cannot, however, supply the missing invitation to participate.
Imagine, for example, a hotel reassuring guests that the person studying their movements knows them only as Room 214. The number may reduce the information attached to the observation. Nevertheless, it does not answer why somebody started observing them for an additional commercial purpose without asking.
Likewise, a broadband customer can object to profiling even when an advertiser never receives their name. The objection concerns what happens to the communication entrusted to the carrier. A company cannot settle that disagreement merely by explaining that its filing cabinet uses numbers.
This is where the vocabulary starts doing unpaid security work for the business. Anonymous sounds reassuring. Technical sounds necessary. Prototype sounds temporary. Together, they can usher the reader past the absent customer decision with all the confidence of a doorman checking everybody’s invitation except the fucking host’s.
The Man Who Built The Web Objected
Tim Berners-Lee approached the issue from the other end of the cable. In his personal notes for a House of Lords discussion, published in March 2009 under the title “No Snooping”, the web’s inventor argued that internet communications deserved protections comparable to telephone calls and sealed mail.
His concern reached beyond whether an advertising profile contained a name. Browsing can expose intensely private interests and uncertainties. People read when they are frightened, curious, ill or undecided. Consequently, turning that activity into material for commercial observation can change the freedom with which they explore it.
Berners-Lee was examining the power that such access creates and the risks that follow. His central point punctured the cheerful sales language. The act of reading matters before anybody measures its usefulness to an advertiser. Curiosity does not become a commercial concession because somebody else owns the fucking cable.
A library, for instance, would look rather different if the person shelving books also followed readers around, marking possible purchases against their movements. Giving that person a computer and calling the results relevant would hardly improve the atmosphere.
That was the collision Phorm exposed. The web offered space to discover what you thought. An advertising system wanted to discover what it could sell you because you thought it. BT’s position in the connection made that collision possible without the customer installing the commercial machinery themselves.
Customer Support Acquires A Delete Button
By November 2008, the argument had become extensive enough to trouble BT’s own support forums. The Register reported that BT removed Phorm and Webwise discussions stretching back to February. One earlier thread had approached 200 pages before the company closed it; customers continued the discussion elsewhere on the forum.
BT explained that the forums should remain constructive places for customers to exchange technical help. It directed people seeking Webwise information towards the company’s dedicated website. Its chief press officer also argued that the discussions were inappropriate for that venue and that participants had retained copies elsewhere.
There is a legitimate distinction between a technical-support forum and an unrestricted debating chamber. Yet BT had created a controversy about the technical behaviour of its service and the information customers received about it. Calling the resulting discussion unsuitable for technical support required some magnificently selective cable tracing.
First, customers struggled to understand an undisclosed experiment. Later, the company decided where their discussion of the experiment belonged. BT controlled the service, the original disclosure and, on its own platform, the continued visibility of the argument.
Reputation management had therefore found another button on the router. If the signal became uncomfortable, remove the thread and direct everyone towards the approved information desk. Meanwhile, the broadband remained connected as the conversation encountered a carefully administered outage. Apparently, customer support could cope with a broken connection more comfortably than a broken explanation.
Europe Found Holes In The Guardrail
On 14 April 2009, the European Commission opened infringement proceedings against the United Kingdom. Complaints about Phorm had exposed concerns about the UK’s implementation of rules protecting communications. The Commission specifically recorded BT’s admission that it had tested the technology in 2006 and 2007 without informing customers.
Its objections concerned structural gaps. UK law limited the relevant interception offence to intentional conduct and permitted reliance on reasonable grounds for believing consent existed. The Commission also questioned the absence of an independent national authority supervising these interceptions.
The proceedings examined whether Britain’s legal protections met EU requirements. Consequently, the issue had travelled well beyond a provider’s awkward relationship with its customer forum. Brussels was asking whether the national guardrail could actually stop the vehicle. BT’s advertising experiment had helped expose holes in the country’s fence.
When a company can discuss why its experiment was technically sound while citizens struggle to identify who should examine their missing consent, the protection system has a plumbing problem. Every office may possess a respectable nameplate while the complaint circulates through the building without reaching a working tap.
The European Commission eventually closed the case in January 2012 after the UK changed its legislation. That ending matters too: the country altered the framework, and the Commission accepted the changes. The official outcome involved repairing the guardrail. It did not retrospectively turn uninformed customers into volunteers.
The BT Phorm Trials Ended Without A Prosecution
BT’s later trial used invitations, a distinction the European Commission recorded for the October–December 2008 exercise. By July 2009, the company had shelved deployment while retaining an interest in the technology. It explained its decision through competing investment priorities, including next-generation broadband and television.
Then, in April 2011, the Crown Prosecution Service decided that a prosecution would not serve the public interest. Its reasons included an assessment that the companies had not acted in bad faith and could reasonably argue a genuine misunderstanding. It also considered their cooperation and the move towards obtaining consent.
The CPS said the trial data was anonymous, received no human processing and had been destroyed. It agreed with the Information Commissioner’s assessment that there was no evidence of harm to affected customers, and considered that any conviction would probably attract only a nominal penalty.
BT and Phorm therefore faced no prosecution and received no criminal convictions for these trials. Their exit from the criminal process rested on the CPS assessment above.
Equally, declining prosecution leaves room for an elementary judgement about customer trust. The people buying the connection had not received the choice that an invitation would have provided. A public-interest decision explains why prosecutors did not take a case forward. It does not write the missing invitation, deliver it or obtain the customer’s fucking answer.
Reputation Management Needs A Better Filter
Twenty years after the first covert trial, BT presents its purpose as connecting people “for good”. Phorm sits in the company’s past, but that past remains part of the reputation professional biographies borrow. Corporate history cannot become irrelevant whenever somebody wants to use the prestigious bit. The reference comes with wiring behind the logo.
Horsfield Menzies selected BT as evidence of Daniel Rubin’s experience. Renting Rubin has now followed that reference through five different examinations. The BT Phorm trials add a particularly instructive chapter because the failure began with a basic misunderstanding of the relationship: carrying a customer’s activity does not automatically entitle the carrier to recruit it into another business.
The sequence contains its own review of corporate judgement. A covert trial put customers into the experiment. Suspicious behaviour prompted questions. BT initially denied testing when The Register asked about the 2007 activity. Later, its forums lost discussions of the controversy. Investigators and prosecutors reached their own conclusions, while the customer relationship retained a question that technical assurances could not answer.
Who agreed to this? That question should have appeared before the equipment entered the connection. Instead, it followed the experiment into press reports, complaints and arguments about the law. The postman had already opened his advertising consultancy, and the householder was still trying to establish why the envelopes looked odd.
You thought it was a virus. It was BT. The familiar name on the bill was the part your suspicion had failed to scan.
Lee Thompson – Founder, The Cummins Accountability Project
Sources
- Horsfield Menzies – Daniel Rubin’s Professional Profile
- The Register – BT And Phorm Secretly Tracked 18,000 Customers In 2006
- WIRED – Leaked Report Describes Secret Code And Browser Disruption
- The Register – BT Admits Misleading Customers Over Phorm Experiments
- BT – Statement Confirming The 2006 Technical Test
- Tim Berners-Lee – No Snooping
- The Register – BT Removes Phorm Discussions From Customer Forums
- European Commission – Proceedings Against The UK Over Communications Privacy, April 2009
- Network World – BT Shelves Deployment Of Phorm’s Advertising System
- Pinsent Masons – CPS Decision Not To Prosecute BT And Phorm
- MrWeb – European Commission Closes Its UK Privacy Case, January 2012
- BT – Corporate Purpose And Company Overview
- TCAP – Renting Rubin : Barclays And The Markets That Moved Themselves
- TCAP – Renting Rubin : AstraZeneca And The Reputation Management Placebo
- TCAP – Renting Rubin : BT And The Reputation Management Dead Zone
- TCAP – Renting Rubin : Barclays II – They Could Hunt The Whistleblower, Just Not The Fucking Red Flags
- TCAP – Renting Rubin : AstraZeneca II – Patients First, Provided The State Pays More
- TCAP – Renting Rubin : BT II – Come Into The Office So AI Can Watch You Leave
- TCAP – Renting Rubin : Barclays III – £322 Million Through The Back Door
- TCAP – Renting Rubin : AstraZeneca III – The $400 Billion Adverse Reaction
- TCAP – Renting Rubin : BT III – Significant Market Power, Now With £9.50 Off
- TCAP – Renting Rubin : Barclays IV – Your Higher Interest Rate Was Their Commission
- TCAP – Renting Rubin : AstraZeneca IV – The Settlement Cost More Than The Company
- TCAP – Renting Rubin : BT IV – Don’t Put Off The Switch. BT Already Did
- TCAP – Renting Rubin : Barclays V – The Shelf Was Empty. Barclays Sold $17.7 Billion Anyway
- TCAP – Renting Rubin : AstraZeneca V – Follow The Science Out The Fucking Door
- TCAP – The Complete Renting Rubin Series
