Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement discloses that Windows generates an advertising ID for each user that can be accessed and used by Microsoft, third-party app developers, and advertising networks for personalized advertising and experiences. Users can disable the advertising ID through Windows Settings.
This analysis describes what Microsoft Azure's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that a persistent identifier enabling cross-app tracking is generated by default in Windows and made available to third-party developers and advertising networks, which may require evaluation under CCPA's opt-out requirements for targeted advertising and GDPR's consent requirements for tracking technologies.
Microsoft now discloses that it may contact you by phone for marketing using automated dialers and AI-generated voices if you have consented to marketing communications, which represents a new disclosure of contact method and technology type. The company has also reorganized its data retention policy to state it retains data for broader business purposes including improving products and protecting systems, while removing previous specific examples and retention criteria, making it less clear exactly how long specific types of your data will be kept. You should review your consent settings for marketing communications and verify what contact methods you have authorized, particularly if you have concerns about automated or AI-generated calls.
View change record →Microsoft's privacy policy now provides a less detailed explanation of how long your data is retained. Previously, the policy included specific examples, such as how long deleted emails remain in your system before final deletion, and listed criteria for deciding retention periods. Now those details are consolidated into a more general statement pointing readers to separate product documentation. This means you'll need to consult multiple documents to understand retention timelines for specific services, which reduces transparency at the point of reading the main privacy policy.
View change record →Microsoft's updated retention policy provides greater specificity about how long your data persists and under what conditions it is deleted. The policy now explicitly states that deleted items from OneDrive and Outlook.com may remain in Microsoft's systems for up to 30 days before permanent removal, even after you empty the Deleted Items folder. Additionally, the updated terms clarify that retention periods depend on whether you have an expectation that Microsoft will keep the data until you actively remove it, and whether automated controls exist to let you access and delete data yourself. You can review Microsoft's privacy dashboard to exercise available deletion controls and understand which services retain your data under these criteria.
View change record →The agreement discloses that Windows generates an advertising ID for each user that third-party apps and advertising networks can access for personalized advertising purposes, subject to their own privacy policies. Users can disable the advertising ID in Windows Settings, though the statement notes this control does not apply to other methods of personalized advertising such as website cookies.
Cross-platform context
See how other platforms handle Windows Advertising ID and Third-Party App Tracking and similar clauses.
Compare across platforms →Monitoring
Microsoft Azure has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Windows generates an advertising ID for each user on a device, which Microsoft, third-party apps, and advertising networks can use to provide relevant ads and personalized experiences on apps and across the web, similar to how websites use cookies. App developers and advertising networks can also use it for their own purposes, subject to their own privacy policies and the controls described below. The advertising ID setting applies to Windows apps using the Windows advertising identifier. You can turn off use of the advertising ID in the Windows Settings app.Excerpt from Microsoft Azure's Microsoft Privacy
1. REGULATORY LANDSCAPE: The Windows advertising ID functions as a persistent tracking identifier and its use by third-party apps implicates CCPA's opt-out requirements for cross-context behavioral advertising, as well as GDPR's requirements for consent to non-essential tracking technologies under the ePrivacy Directive. The FTC Act applies to the adequacy of disclosures about the advertising ID and the scope of third-party access to it. 2. GOVERNANCE EXPOSURE: Medium. The advertising ID is generated for each user by default, and the statement discloses that third parties can use it for their own purposes subject to their own privacy policies, which means the scope of downstream data use is not fully governed by this privacy statement. The limitation that disabling the advertising ID does not affect other personalized advertising methods may reduce the practical effectiveness of the control. 3. JURISDICTION FLAGS: California residents have CCPA opt-out rights for cross-context behavioral advertising that may apply to advertising ID-based tracking. EU and EEA users are subject to ePrivacy Directive requirements for consent to tracking technologies. The default-on nature of the advertising ID may require evaluation against opt-in consent requirements in EU jurisdictions. 4. CONTRACT AND VENDOR IMPLICATIONS: App developers distributing applications on Windows and accessing the advertising ID are subject to their own privacy policies, which creates a fragmented privacy governance landscape for Windows users. Developers should assess their own compliance obligations when using the Windows advertising ID, including whether their use constitutes a sale or sharing of personal information under CCPA. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the default generation of an advertising ID accessible to third parties satisfies GDPR consent requirements for tracking technologies in EU deployments. Organizations managing Windows devices should evaluate whether enterprise configuration options to disable the advertising ID satisfy applicable employee privacy obligations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that a persistent identifier enabling cross-app tracking is generated by default in Windows and made available to third-party developers and advertising networks, which may require evaluation under CCPA's opt-out requirements for targeted advertising and GDPR's consent requirements for tracking technologies.
The agreement discloses that Windows generates an advertising ID for each user that third-party apps and advertising networks can access for personalized advertising purposes, subject to their own privacy policies. Users can disable the advertising ID in Windows Settings, though the statement notes this control does not apply to other methods of personalized advertising such as website cookies.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Microsoft Azure.