Privacy in Windows 10 sounds like a joke. But the French National Data Protection Commission (CNIL) doesn't seem to find it funny at all.
Thus, in an official announcement dated July 20, 2016, it asks Microsoft to comply with the French Data Protection Law within three months.
Why? Microsoft's Windows 10 operating system is being used to "collect large amounts of data and track users' browsing without their consent."
In addition, the Commission is asking Microsoft to “ensure the security and confidentiality of user data.”.
A working group analyzed Microsoft's Windows 10 operating system and privacy policy from April to June 2016 to ensure that Windows 10 complies with French Data Protection legislation.
The working group identified the following issues during its research:
Unnecessary or excessive data is collected: The CNIL states in its report that Microsoft collects data that is not required “for the operation of the service.” Microsoft collects Windows Store usage data, for example, and according to the CNIL, this is not necessary for the operation of the operating system.
Lack of security: Windows 10 users can log in with a PIN (a four-digit code) used for authentication. This PIN provides access to the operating system, but also to Windows Store account data. The operating system does not limit the number of attempts to enter the PIN.
Lack of individual consent: Windows 10 uses an advertising identifier by default that can be used by applications, and third parties. Thus, Microsoft “tracks users’ browsing to offer targeted advertising, without obtaining users’ consent.”
Lack of information and no option to block cookies: Microsoft uses advertising cookies as “terminals” of users, without having “properly informed them in advance and without allowing them to do anything else”.
Data is still transferred outside the EU to a “safe harbor”: Personal data is transferred to a “safe harbor” of the United States, but it should not be so since “the judgment is issued by the Court of Justice of the European Union on October 6, 2015.”
The CNIL is giving Microsoft a three-month period to correct these issues. Failure to comply could result in sanctions against Microsoft.
