Live data from Hacker News

Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

blogs.microsoft.com

31–40 of 82 posts

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#31

Here's a question I haven't seen asked or answered: Can I now (in 4 days time), ask Microsoft for all the data it's hoovered up from my Windows 10 installation? I've only seen people talking about GDPR as it applies to websites, but as far as I'm aware, it applies to all software.

The GDPR applies to any processing of personal data, regardless of whether it's a website, software or even paper records.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#32
post #24
post #15

Earlier quoted context omitted.

There is an option to delete all diagnostic data collected (Windows 10 1803). You can find it under Settings->Privacy-> Diagnostics & feedback-> Delete diagnostic data. As others have mentioned you can access and manage it using the portal that is linked.* * I work at Microsoft.

Would that delete the data that has already been transferred to Microsoft? And as others mentioned: the portal is useless for people without MS account. What about those?

That's exactly what this option does. It deletes everything that has been collected up until that point.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#33
post #4

Ok so there’s a privacy policy on this website and a standard “we use cookies” header but where is the consent management platform that’s supposed to let me review all the purposes and vendors used on the site so I can choose which ones I want to give consent to and which ones I don’t. The https://github.com/appnexus/cmp appnexus cmp is the only cmp I’ve found that’s open source and provides a clear reference to what…

Yes I have, for a medical company I recently did DD on. It was done pretty good actually and they are considering fielding it as a separate (whitelabel) product for others.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#34
post #25

Earlier quoted context omitted.

Microsoft is reinventing itself. You can disable those ads. You can remove apps like Skype. Manually or with an app such as O&O Shut Up. I also use Classic Shell instead of the new start menu.

Microsoft is reinventing itself. Really? I though that was just standard corporate marketing.

They are changing, that still doesn’t mean that all things they do are good things.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#35
post #4

Ok so there’s a privacy policy on this website and a standard “we use cookies” header but where is the consent management platform that’s supposed to let me review all the purposes and vendors used on the site so I can choose which ones I want to give consent to and which ones I don’t. The https://github.com/appnexus/cmp appnexus cmp is the only cmp I’ve found that’s open source and provides a clear reference to what…

Here's a marvelous example I've stumbled upon yesterday: https://juro.com/policy.html

The entire privacy policy is very well done (and beautifully designed, I may add). Clear options, transparency over who gets your data, ability to use the product without providing PII and all sorts of other goodies.

Specific quotes related to consent:

> If you have previously given consent to our processing your data you can freely withdraw such consent at any time. You can do this by emailing us at support@juro.com. If you do withdraw your consent, and if we do not have another legal basis for processing your information, then we will stop processing your personal data.

Disclaimer: I'm not affiliated with Juno nor am I their user. I just randomly stumbled upon their privacy policy.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#36
post #18
post #9

Privacy: ability to opt out of all data collection. Microsoft privacy: inability to opt out of all data collection unless you pay for enterprise edition. This makes a mockery of any policy.

Also ads for Candy Crush in you operating system. Microsoft is scum. They have not changed from the 90s, they are just better at hiding it.

Hatera gonna hate

What about Guitar Hero crap boundled with every Mac?

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#37
post #18

Earlier quoted context omitted.

Also ads for Candy Crush in you operating system. Microsoft is scum. They have not changed from the 90s, they are just better at hiding it.

Hatera gonna hate What about Guitar Hero crap boundled with every Mac?

What Guitar Hero crap? Honestly asking, I have never seen anything related to Guitar Hero on my Mac.

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#38

Earlier quoted context omitted.

Hatera gonna hate What about Guitar Hero crap boundled with every Mac?

What Guitar Hero crap? Honestly asking, I have never seen anything related to Guitar Hero on my Mac.

Probably means Garage Band, which is free multi-track recording software.

How dare they ship privacy respecting productivity software with their OS instead of Candy Crush!

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#39

Earlier quoted context omitted.

Hatera gonna hate What about Guitar Hero crap boundled with every Mac?

What Guitar Hero crap? Honestly asking, I have never seen anything related to Guitar Hero on my Mac.

GarageBand

Re: Microsoft’s commitment to GDPR, privacy and customers’ control of their own data

#40
post #4

Ok so there’s a privacy policy on this website and a standard “we use cookies” header but where is the consent management platform that’s supposed to let me review all the purposes and vendors used on the site so I can choose which ones I want to give consent to and which ones I don’t. The https://github.com/appnexus/cmp appnexus cmp is the only cmp I’ve found that’s open source and provides a clear reference to what…

Don't forget that 'consent' is only one of the bases to collect data. Where the data is vital to the ability to run the service, it will be being collected on the basis of contractual agreement, not consent.

I've seen a lot of privacy policies include lines like "we collect your activity data on the website, so we can improve your experience" or "we use cookies to gauge how to improve our services" or "we collect usage data to improve our marketing across other sites and platforms", which are both horribly vague and certainly not vital to run the service.

I took those lines basically verbatim (translated from Danish) from Just-Eat's Danish website. I am pretty sure they're violating GDPR, based on what they say in their privacy policy. Collecting usage data and sending data to third-party marketing companies is not vital to running a food ordering website. A ToS is not a legally binding contract, and I have not been asked for direct consent to their use of my data.

Post reply on HN