Follow the recommendations here: http://www.w3.org/P3P/details.html
You must create your own P3P policy.
As an example, if you add this to your Global.asax, it works in IE8:
protected void Application_BeginRequest(object sender, EventArgs e) { HttpContext.Current.Response.AddHeader("p3p", "CP=\"IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT\""); }
BUT!!! don't just copy the example above, as the policy should reflect your actual privacy policy on your website. Otherwise, this may have consequences later when the browsers confirm your content / behavior compared to what you specified.
Nobody wants to get blacklisted from certain browser providers, right?
source share