"Medium Security" in IE8 states that third-party cookies that save information that can be used to contact you without your explicit consent
are blocked.
What is the most broad P3P header that means we do not collect such information, and will not be blocked by IE?
I want to skip the nasty details of the P3P policy, and just set the header that implies the least legal obligations. Its semantic should be:
we collect everything except information that can be used to contact you.
... without specifying anything else.
Note that most P3P headers are inclusive - if they're not present, you're not allowed to use the information for that purpose - so the P3P header I'm looking for should contain a lot of flags.