Earlier quoted context omitted.
They have access to IP+time, your search query, and cookies for correlation to other requests. It's valuable information and Google openly documents that they are keeping and using it, along with anything else you leak to them: http://www.google.com/policies/privacy/ IP+time is enough to get your personal identity information from your ISP (physical location of the endpoint, billing information), I have no idea if Go…
> They have access to IP+time, your search query, and > cookies for correlation to other requests. It's > valuable information Valuable for blackmail, but not really useful for anything else; the commercial value of information rapidly degrades over time. Knowing I want to buy a new fridge today is very valuable, knowing I wanted to buy one last month is nearly worthless. > IP+time is enough to get your personal iden…
My ISP, Time Warner/RoadRunner, claims that they will do so. It's kind of ambiguous because their declaration combines several services and kinds of data covered by different laws. I think the applicable part for their cable ISP service is:
In the course of providing Time Warner Cable Services
to you, we may disclose your personally identifiable
information to [...] consumer and market research firms,
credit reporting agencies and authorized representatives
of governmental bodies.
Selling their DHCP logs and customer records to a commercial data aggregator (who could then sell it to anyone) appears to be compliant with their privacy policy.