Translation Service
What They Say
Microsoft's privacy policy is one of the longest documents the Bureau has reviewed, which we interpret as thoroughness rather than concealment — though the distinction is philosophically unstable. They commit to transparency about what Windows collects via diagnostics and telemetry, describe how enterprise and consumer data is separated, and provide a dedicated privacy dashboard. The policy uses the word "control" 47 times, which the Bureau finds notable.
What They Mean
Windows is telemetry software that also runs your applications. The 'Basic' diagnostics setting, which sounds minimal, still sends device identifiers, installed software lists, error reports, and usage metadata to Microsoft servers. The 'Full' setting — which is the default — includes browsing history from Edge, Cortana interactions, and detailed application usage patterns. This data persists across Windows reinstalls via your Microsoft account. The LinkedIn acquisition means Microsoft now cross-references your professional identity with your device behaviour, which is the kind of data synthesis that should have its own policy category.
Worst Clause — Exhibit A
"We use the data we collect to provide you with rich, interactive experiences. In particular, we use data to keep our services up-to-date, secure, and operating as expected, to detect and prevent fraud, to develop new features, to generate and derive inferences and insights, and to advertise and market to you."
Bureau Translation:
'Generate and derive inferences' means Microsoft builds predictive models from your behaviour to determine things you have not told them — income level, health status, purchasing intent. 'Advertise and market to you' means Bing, MSN, and the Windows Start menu are all advertising surfaces serving ads informed by your device data. The Bureau notes that 'rich, interactive experiences' is the most optimistic description of targeted advertising it has encountered.
Evidence Tags — Data Collected
Bureau Verdict
"Microsoft's policy is the best-organised document in our archive, which is not a compliment to the others and is not fully a compliment to Microsoft. The telemetry collection is extensive and the LinkedIn data merger is underexplained. Grade C-: points for structure and the genuine privacy dashboard, points deducted for the sheer volume of collection that 'Basic' diagnostic mode represents."
Overall Grade
Structurally Impressive, Spiritually Hollow
Frequently Asked Questions
Dark Patterns Documented
See the full Dark Pattern Encyclopedia for documentation of each technique.
Audited: 2026-03-20