I had a much longer comment, but it eventually detracted from this point: you can't guarantee where that data goes, how it's stored through its life, etc.
Inappropriate usage of PII can lead to severe consequences in most western countries.
Facebook still being around shows this is just wishful thinking.
We can clearly see where the incentives are aligned.
Also, be careful, the concept of "ethical frameworks" is used by companies to become their own judges and jury.
Sure, it's definitely a security risk.
However there is a strong line betweeen a first party spyware that collects data to sell, and the malware discussed in this article, that was specifically places there to try to steal your credit card or banking info for criminals.
I'm fine with legal penalties for the manufacturers in both cases though.
From a consumer POV, they are indistinguishable, are they not?
At least third party malware works silently and efficiently. First party hateware puts ads in the start menu.
From a security perspective they’re totally different. Malware can be used to perform arbitrary code execution compromise my machine, pivot to my work computer compromise my aws keys, spin up $100k/mon infrastructure to run unrelated scams, syphon down my customer database ransomware it / post it on the dark web.
Telemetry is unlikely to do the above. If it does it gets reclassified as malware. The distinction is valid and useful.
Claiming otherwise is either ignorant in the extreme or deliberately deceptive. Which are you?