{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"9d711828-e470-4300-8423-ae4201c57786","screeningDate":"2026-08-01T04:33:55.921Z","publicationGate":"published","company":{"id":"9bffb74f-0f91-46a9-a635-74b5e91623e1","name":"Microsoft","slug":"microsoft","industry":"Tech Giant"},"policy":{"id":"5681de09-ab08-4131-9922-34b96d28db2d","name":"Privacy Statement","type":"privacy","jurisdiction":"Global","sourceUrl":"https://www.microsoft.com/en-us/privacy/privacystatement"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T09:39:08.874Z","retrievalChannel":"other","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":1,"sha256":"bf0d42255d66ccdd9b9b1707cc4454904d107469c0ab3627af72d5b6fc3fc8b2","capturedAt":"2026-07-06T09:42:52.770Z"},"current":{"version":2,"sha256":"0d69136f4c89eac5a2a6b57f1c5f81fb68e1acc289f939d66e158406f74ab54e","capturedAt":"2026-08-01T04:33:55.910Z"}},"assessment":{"summary":"Microsoft's updated privacy policy now explicitly allows sharing your age group information with third-party apps, increasing data exposure for age-appropriate experiences.","overallRisk":"High","overallScore":7,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"New clause permits sharing age group data with third-party apps.","textIt":"Nuova clausola consente la condivisione dei dati sull'età con app di terze parti.","deltaScore":-3,"evidenceQuote":"We may share age group information with Microsoft apps and services, as well as third-party apps, so that they can apply appropriate safeguards, tailor experiences, and comply with applicable laws and regulations.","evidenceSide":"new","relatedKpi":"kpiThirdPartySharing","anchorStatus":"verified"},{"icon":"warning","textEn":"Increased potential for broader exposure of sensitive age-related information.","textIt":"Maggiore potenziale di esposizione più ampia di informazioni sensibili sull'età.","deltaScore":-2,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":"kpiDataCollection","anchorStatus":"not-recorded"},{"icon":"info","textEn":"Users may have less direct control over how external parties use their age data.","textIt":"Gli utenti potrebbero avere meno controllo diretto sull'uso dei loro dati sull'età da parte di terzi.","deltaScore":-1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":"kpiConsentMechanism","anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Age group data can now be shared with external third-party applications.","textIt":"I dati relativi alla fascia d'età possono ora essere condivisi con applicazioni di terze parti esterne.","sentiment":"negative"},{"textEn":"This sharing aims to tailor experiences and comply with age-related regulations.","textIt":"Questa condivisione mira a personalizzare le esperienze e rispettare le normative sull'età.","sentiment":"neutral"},{"textEn":"Users should review privacy settings to understand how their age information is used.","textIt":"Gli utenti dovrebbero rivedere le impostazioni sulla privacy per capire come vengono usate le loro informazioni sull'età.","sentiment":"negative"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Enterprises using Microsoft services must ensure their internal policies and consent mechanisms align with this broader data sharing. Compliance with GDPR and the upcoming AI Act for age-related data is critical.","complianceNoteEn":"GDPR, AI Act"},{"region":"EU","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"The explicit sharing of age group data with third parties raises concerns under GDPR, especially for children's data. Users should be aware of potential broader processing.","complianceNoteEn":"GDPR Art. 6, 8, 9"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Global enterprises must update their data governance frameworks to account for this expanded sharing of age data. This includes reviewing data processing agreements with Microsoft.","complianceNoteEn":"Data Governance"},{"region":"Global","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"Globally, users should be aware that their age group data might be shared more broadly. This necessitates proactive management of privacy settings across Microsoft products.","complianceNoteEn":"Global Privacy Norms"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"US enterprises must assess how this change affects their compliance with state-specific privacy laws, especially regarding data shared with third parties. Vendor agreements may need review.","complianceNoteEn":"State Privacy Laws"},{"region":"US","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"This change impacts US users, particularly minors, under state privacy laws like CCPA/CPRA. Increased sharing of age data requires careful review of privacy choices.","complianceNoteEn":"CCPA/CPRA, COPPA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Opt-Out"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiContentModeration","label":"Content moderation","value":"Partial"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Opt-Out"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Privacy Statement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/9d711828-e470-4300-8423-ae4201c57786","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"82f5d8906c90154111f553bd54250099c5818e256a66f0c428c4fb7265deec88"}