Microsoft Store policy 10.5.1: fixing a privacy policy certification failure

Microsoft Store certification fails under policy 10.5.1 when a product handles personal information without a privacy policy, or when the link does not lead to one. Here is what the policy says, which apps always need a policy, and how to fix a failed submission.

Published by Legiflare. General information, not legal advice.

What policy 10.5.1 says

Policy 10.5 of the Microsoft Store Policies covers personal information, which Microsoft defines as "all information or data that identifies or could be used to identify a person, or that is associated with such information or data." Policy 10.5.1 then says:

"If your product accesses, collects or transmits Personal Information, or if otherwise required by law, you must maintain a privacy policy. You must provide users with access to your privacy policy by entering the privacy policy URL in Partner Center when you submit your product."

The policy can also be included in or linked from the product itself, and it "must be kept up-to-date as you add new features and functionality to your product." This article is based on version 7.20 of the Store Policies.

Apps that always need a privacy policy

Microsoft adds a rule that catches many desktop developers:

"Product types that inherently have access to Personal Information must always have privacy policies. These include, but are not limited to, Desktop Bridge and Win32 products."

So if you publish a Win32 app, a packaged desktop app or a game built that way, you need a privacy policy even if you believe it collects nothing.

Common causes of a 10.5.1 failure

  1. No URL in Partner Center. The privacy policy field is empty.
  2. The link doesn't lead to a privacy policy. It points to your home page, a download page or a page that no longer exists.
  3. The policy is too thin. It doesn't cover what Microsoft lists, such as how data is stored and secured or what controls users have.
  4. The policy is out of date. You added sign-in, telemetry or cloud sync, but the policy still describes the old version.

Fix checklist

  1. Publish a privacy policy on a public page that loads without a login and is titled as a privacy policy. See free hosting options.
  2. Make sure it covers every item in the next section.
  3. In Partner Center, open your app's submission, go to the Properties page and enter the URL in the privacy policy field.
  4. Optionally link the policy from your app's About or Settings screen.
  5. Resubmit the product for certification.

What the policy must include

Policy 10.5.1 says your privacy policy must:

  • tell users what personal information your product accesses, collects or transmits;
  • explain how that information is used, stored and secured;
  • indicate the types of parties to whom it is disclosed;
  • describe the controls users have over the use and sharing of their information, and how they can access it;
  • comply with applicable laws and regulations.

If your product publishes customers' personal information to an outside service or third party, policy 10.5.2 also requires opt-in consent in the product's interface and a way to withdraw it later.

The privacy policy template covers each of these points.

Frequently asked questions

Does a free Windows utility with no accounts need a privacy policy?

If it is a Win32 or Desktop Bridge product, yes: Microsoft says these product types must always have one. Other products need one when they access, collect or transmit personal information, or when the law requires it.

Can the privacy policy live inside the app?

It can be hosted within or linked from the product, but you still have to enter a privacy policy URL in Partner Center when you submit.

Does the privacy policy have to be on my own website?

No. The policy asks for a URL that leads to your privacy policy. Any public page that loads it reliably works.

Get a privacy policy URL for Partner Center

Publish a complete policy on a permanent link and pass certification. Free.