Guide to improving privacy in Windows 10 and 11

  • Windows 10 and 11 collect necessary and optional data, but you can significantly limit telemetry by disabling advanced diagnostics and personalized experiences.
  • Privacy is enhanced by adjusting location, activity history, app permissions, and advertising identifier, as well as managing what syncs with your Microsoft account.
  • Microsoft's Privacy Dashboard and diagnostic data erasure allow you to control and delete much of the information already collected linked to your account and devices.
  • Choosing the right edition of Windows and, in professional environments, applying group policies and privacy baselines helps to further reduce the data sent to Microsoft.

Privacy guide for Windows 10 and 11

In recent years, Windows 10 and Windows 11 have become packed with connected features , assistants, cloud backups, and "smart" tools that, while useful, also mean the system sends a lot of data to Microsoft. If you're worried your PC is revealing too much about you, it's a good idea to take a moment, review your settings , and make the system a little more discreet.

The good news is that you don't need to be a computer expert to strengthen privacy in Windows or install unusual versions of the system: practically everything can be adjusted from the Settings app or, in professional environments, with Group Policy and MDM. In this guide, we'll take a step-by-step look at what data Windows collects, what can be disabled, and how to make the system as "inquisitive" as possible without losing essential functions.

What data do Windows 10 and 11 collect and why does it affect your privacy?

Privacy settings in Windows

The first thing to understand is that Windows will always collect a minimum amount of information . Microsoft distinguishes between required (mandatory) diagnostic data and optional diagnostic data (which you can choose to send or not). According to Microsoft, the required data is used to keep the system up to date, check computer compatibility, and ensure basic security.

This mandatory section primarily collects technical data about the device and system : hardware model, Windows version, installed components, update status, potential critical errors, etc. In theory, this is anonymized information that shouldn't directly identify you, and there's no setting to completely disable it in the home and professional editions.

The real privacy problem arises with optional data and connected features and services that run on top of the system: online searches, cloud services, cross-device synchronization, personalized suggestions, advertising based on your activity, and so on. This includes, for example, your browsing history in Edge, your app usage preferences, typing and voice data, precise location, and device activity history.

Windows also relies on a number of cloud-based applications and services (Windows Search, Windows Spotlight, Mobile Link, Windows Insider, custom dictionary, OneDrive, among others). Many of these require additional data to function: authentication, certificates, network information, advanced device settings, or fairly detailed usage data. In particular, some cloud services require special handling of metadata and compliance with regulations, as explained in guides on managing metadata in Office and Windows.

It's worth noting that Windows 10 from version 1903 onwards and Windows 11 share the same basic data collection policy , so upgrading from one version to the other doesn't, in itself, represent a greater invasion of privacy. What makes the difference is how you configure those options and to what extent you accept personalized experiences and optional telemetry.

Difference between required data and optional data

To properly organize the settings, it's very helpful to clearly distinguish between what Windows considers essential for operation and what are extras for telemetry and personalization.

On one hand, we have the necessary diagnostic data . This includes compatibility information for updates, system status, critical failures, and basic details of the hardware and installed software. It's used to detect problems, release patches, and ensure that updates don't break your PC. It can't be disabled through the standard settings and, in principle, isn't the most sensitive privacy issue for the average user. If you need more context on how to protect your computer, consult guides on how to protect your privacy in Windows 10.

On the other hand, there's optional diagnostic data . This includes much more detailed information: app usage, advanced performance, deeper device settings, browsing history if you use Edge, usage patterns of Microsoft products and services, typing, and voice data used to improve suggestions, and even metrics to refine ads and recommendations.

This optional data can be disabled with just a few clicks , and unless you absolutely need the highest level of diagnostics for a highly controlled corporate environment, the wisest course of action for home use is to turn it off: you gain privacy and barely lose any relevant functionality. For practical settings on permissions and apps that affect this telemetry, see how to change app permissions.

In addition to the required/optional distinction, some connected experiences have their own data requirements that you can't be too granular about: you either accept those conditions and use the service, or you forgo the feature altogether. This is the case with certain cloud tools, Windows Autopatch, advanced reports from Windows Update for Business, and some advanced compatibility components in enterprise environments.

How to check privacy settings from Windows Settings

The most straightforward way for a typical user to adjust their shared data with Microsoft is through the Settings app. The menu changes slightly between Windows 10 and 11, but the basic idea is the same.

In Windows 10, you can go to Start > Settings > Privacy . In Windows 11, the typical path is Start > Settings > Privacy & security . From there, you'll see several sections: General, Speech, Typing and inking personalization, Activity history, Feedback and diagnostics, App permissions (location, camera, microphone, etc.), among others.

The core of telemetry is found in the Feedback and Diagnostics section. There you can disable the sending of optional diagnostic data , personalized experiences based on that data, handwriting/typing enhancement, and the Diagnostic Data Viewer if you don't need them. To better understand the impact of telemetry and how to protect your computer from data leaks, it's advisable to read materials on online security and how to secure your Windows system.

If you ever activated that viewer, it's a good idea to use the option to delete the saved diagnostic data . It's a small detail, but it helps minimize the historical information that has already accumulated on Microsoft's servers; in practical examples, you'll see steps to delete and resolve privacy issues.

When using Settings to adjust privacy, also check if you see the message "Your organization manages or hides some options ." This means the device is under the policies of a company or educational institution, and some settings can only be changed by an administrator, either through Group Policy, MDM, or tools like Configuration Manager and Intune.

Turn off location and app permissions panel

One of the first things to check is the device's location , especially if you use a laptop or tablet that you take everywhere. Windows can use your location to show the weather, maps, or find the device if you lose it, but many users prefer not to leave a constant trail of their movements.

In Windows 10 and 11, you can go to Settings > Privacy and security > App permissions > Location . From there, you can completely turn off system location services with a simple toggle switch. If you prefer a less drastic approach, you can keep location services enabled but disable access for specific apps that you don't think need to know your location.

In the same app permissions section, you'll find settings for camera, microphone, contacts, calendar, calls, emails, and notifications . Each of these sections lets you decide which apps can use that resource and which can't. For privacy, it's best to grant access only to trusted apps and revoke it for the rest, especially apps you never use. If you use chats or other messaging apps, check out guides on messaging privacy in Windows.

Another feature to consider is "Find My Device ." This can be helpful if you lose your laptop, as it uses location data to try to show you where it is. However, this means the system periodically saves the location when there's an internet connection. You can disable this feature in Settings > Privacy and security > Find My Device if you'd rather not take that risk. For general advice on privacy practices, you can review articles with essential online privacy tips.

In corporate environments, access to location and other sensors can be centrally blocked or limited using group policies or MDM, so that the user can only choose within a range controlled by the administrator.

Activity history and timeline synchronization

Windows activity history records which applications you use, which files you open, and which websites you visit (when integrated with Microsoft browsers and services). This information can be used for features like the old Timeline, which let you return to past tasks or sync activities across devices.

If you prefer that the system not saves everything you do , you can disable this feature. Go to Settings > Privacy and security > Activity history and uncheck the option "Store my activity history on this device." Then, tap the Clear history button to delete anything that has been saved up to that point.

In versions that still allow cloud synchronization of these activities, there is also a specific policy to prevent the device from uploading activity history to the online profile. This is controlled via Group Policy with "Allow user activity upload," and via MDM with the option to enable or disable the activity feed.

The result of these measures is that Windows stops building a kind of "log" of your computer usage , reducing the amount of metadata that could be exploited by both Microsoft and an attacker who gains access to the device.

Advertising, ad identifier, and personalized experiences

Like many other systems, Windows associates your profile with a unique advertising identifier , designed to help apps show more relevant ads based on your activity. Optional diagnostic data is also used to deliver personalized experiences: suggestions, app recommendations, in-system promotional content, and more.

If you want to reduce this tracking, go to Settings > Privacy and security > Windows permissions > General . There you can uncheck the option that allows apps to use your advertising identifier to show personalized ads. You'll still see ads, but they'll be less targeted because they won't be based on your usage history within Windows.

On that same screen, you'll see other checkboxes related to suggestions based on how you use the system and recommendations within the Settings app. Disabling anything you don't consider essential reduces the amount of data Microsoft uses to build usage profiles.

In the diagnostics section, you can disable the option to use diagnostic data for personalized experiences , preventing this data from being used to show you ads or content tailored to your activity. At the corporate level, there's even a specific group policy to prevent these telemetry-based personalized experiences.

All of this won't eliminate advertising completely, but it does break some of the correlation between your behavior and the ads you receive , which is an important step for anyone trying to reduce tracking.

Diagnostic data: fine-tuning and monitoring tools

At the heart of the privacy settings is the diagnostic data and feedback section . Here you define the telemetry level, decide whether to send optional data, and control certain transparency tools.

For the average user, the key step is to disable the sending of optional diagnostic data from the Settings app. This limits what is sent to Microsoft to the minimum set considered necessary for Windows to function, receive updates, and maintain a basic level of security.

You can also turn off the option to improve handwriting and typing . This prevents samples of your typing or handwriting from being collected to improve algorithms. Similarly, you can disable the Diagnostic Data Viewer if you're not actively using it, as it can reserve around 1 GB of storage for local copies.

If you want to go a step further, you can use the Diagnostic Data Viewer (DDV), available from the Microsoft Store. This app shows you what diagnostic data is being recorded and sent in real time, organized by category. It's useful for getting a clear picture of the kind of information coming out of your computer.

System administrators, for their part, can query and manage diagnostic data using PowerShell , employing specific commands to view, export, or delete information collected from specific devices. This is essential for organizations that must comply with regulations such as GDPR and require much stricter traceability and control.

Voice recognition, handwriting and handwriting input

Windows' "smart" voice and typing features rely on collecting snippets of what you dictate or type to further refine the models that generate suggestions and improve language recognition. It's convenient, but it does mean that some of your content passes through Microsoft's servers.

If you don't like it, you can disable it from Settings > Privacy and security > Voice , where you have the option to turn off online speech recognition . You'll still be able to use basic local recognition in some cases, but your full dictations won't be sent to the Microsoft cloud for processing.

Regarding handwriting and keyboard input, the settings are usually found in the Writing or Handwriting section within your privacy settings. Disabling the collection of linguistic data prevents samples of your writing style, common errors, and corrections from being saved to feed the algorithms.

In enterprise environments, these functions can be controlled with specific group policies that prevent the collection of write data at the organization level. This prevents potentially sensitive information from ending up in training datasets.

Aside from the improved user experience, the reality is that few people critically depend on these features for their daily work , so turning them off is usually an acceptable trade-off if you prioritize the confidentiality of what you type or dictate.

Microsoft account, synchronization, and shared experiences

One of the biggest privacy decisions in Windows 10 and 11 involves using a Microsoft account versus a local account . With a cloud account, you get synchronized settings, automatic access to OneDrive, the Microsoft Store, and other services, but it also centralizes much more information on the company's servers.

In Windows 11, especially in the Home editions, creating a local account during installation is becoming increasingly complicated . The wizard pushes you to sign in with Microsoft, and there have even been automatic changes, such as enabling OneDrive backups by default without making it very clear. In Pro and Enterprise, you can still use local accounts, although the option is better hidden.

In addition to the account itself, there are features like shared experiences and cross-device syncing , which allow you to transfer activities from one device to another, share apps, or quickly send files and links. These features use your Microsoft account and generate additional data about your activity on each associated device.

If you prefer to limit it, you can go to Settings > Apps > Advanced app settings > Share between devices and use the Turn Off button to disable that integration. It's also a good idea to review your account sync options in Settings > Accounts, disabling anything you don't need (theme, passwords, history, etc.).

In organizations where the Windows diagnostic data processor configuration is enabled , things go a step further: the administrator can assume the role of data controller under the GDPR, associating telemetry with Microsoft Entra (formerly Azure AD) user IDs and managing requests for access, export, or deletion of data for specific employees.

Microsoft Privacy Dashboard and control over data already collected

Even if you adjust everything now, Microsoft has likely already collected a significant amount of information linked to your account: browsing history in Edge, search activity, locations used, Cortana data, app usage, and more. To keep this under control, there's the Microsoft Privacy Dashboard on the web.

From your browser, access the Microsoft Privacy Dashboard , sign in with your account, and you'll see several sections: location activity, browsing history, search history, app and service activity, and even data from products like Xbox or Office if you use them.

In each category, you can review, delete specific entries, or clear the entire history . It's a good habit to check in occasionally, take a look, and clean up anything you don't want stored. This doesn't prevent data from being generated in the future, but it does reduce the amount of historical data associated with your account.

This web panel complements the options within Windows, such as the "Delete diagnostic data" button in the Diagnostics and Comments section, which erases the telemetry sent from the device. Together, they allow you to take action both on the computer and in the cloud account.

For advanced users or administrators, Microsoft also offers diagnostic data export tools and formal mechanisms to address data subject rights (DSRs) under GDPR or CCPA, such as exporting what is saved about a specific user or requesting deletion linked to the closure of corporate accounts.

Windows editions and privacy limits by version

Not all editions of Windows are on the same page when it comes to comprehensive telemetry control and advanced security features . The Home version, which is the most common on home computers, falls short in some key areas.

For example, the Enterprise editions are the only ones that allow the most restrictive level of data sent to Microsoft via telemetry. They also add features such as advanced device management options, centralized privacy controls, and more aggressive security templates to limit connections to Microsoft services.

Windows Pro is, in practice, the most balanced option for demanding users : it incorporates almost all the security features that are of interest (BitLocker, Hyper-V, Windows Sandbox, etc.), and although it does not allow the extreme telemetry cut-off of Enterprise, it does offer much more leeway than Home to adjust configurations through local group policies.

Students and teachers can obtain Education licenses (equivalent to Enterprise or Pro, depending on the case) through their educational institution, typically via portals like OnTheHub or Azure for Education. In terms of privacy and security, these editions are no worse than the commercial ones; on the contrary, they give administrators more flexibility to limit data transmission.

What is strongly discouraged is opting for modified versions of Windows created by third parties , which promise "zero telemetry" at the cost of disabling updates and offering weaker protection against current threats. The result is usually an increasingly vulnerable system with outdated antivirus software and unpatched security holes.

Further reduce telemetry with commands and policies

If you want to go beyond graphical configuration, there are specific Windows telemetry services that can be disabled using commands. One common approach is to disable the DiagTrack and dmwappushservice services.

To do this, open the Start menu, search for "CMD", right-click on Command Prompt , and choose "Run as administrator". In the window that opens, you can use commands to change the startup settings for those services to disabled . Later, if needed, you can simply revert the value to enabled.

In environments with many machines, the ideal approach is to use Group Policy (GPO), MDM, or tools like Configuration Manager to apply these and other privacy settings centrally. Microsoft even offers a "limited functionality baseline" that groups recommendations for minimizing connections to its services, at the cost of sacrificing certain features.

That baseline and other reference documents explain which Windows connection points are used , what happens if they are blocked (for example, loss of compatibility reports, disabled suggestions, problems with some connected experiences), and how to configure every detail according to the organization's needs.

The key is to find a reasonable balance between privacy and functionality : in a home environment you might be able to be aggressive in blocking, while in a company that relies on compatibility reports from Windows Update, Autopatch or Intune, it is advisable to keep certain connections active.

Connected services, Windows in the cloud, and related products

Beyond Windows itself, there are a number of Microsoft services that live around the system and also use diagnostic data: Windows Update for Business, update reports in Intune, Surface Hub, Windows Autopatch, among others.

Windows Server, from 2016 onward, largely shares the same personal data management mechanisms as Windows 10 and 11, so many privacy guidelines apply directly to servers. On special devices like Surface Hub, the device identifier is collected for diagnostics but is not linked to individual users , and privacy options are primarily managed through MDM rather than traditional GPOs.

Windows Update for Business reports, Windows Autopatch, and the update dashboards in Intune all draw on Windows diagnostic data to build metrics for compatibility, patch status, and driver issues. Minimizing this telemetry means sacrificing some of these reporting capabilities and a degree of convenience in remote management.

From a legal standpoint, Microsoft states that it complies with applicable data protection laws and regulates international transfers according to its Privacy Statement. For devices configured with the diagnostic data processor option, the administrator gains the ability to enforce user rights (access, rectification, deletion, export) with respect to this specific data.

If you manage a large environment, it's worth delving into the official documentation on managing connections from Windows components to Microsoft services , which details what is sent to each connection point, how to restrict it, and what effects doing so has on daily functionality.

With all these settings carefully reviewed, Windows 10 and 11 can become considerably less intrusive while remaining fully functional . Disabling optional telemetry, reducing personalized advertising, turning off unnecessary location tracking, clearing your activity history, and controlling what you sync with your Microsoft account makes a significant difference. Furthermore, by choosing the appropriate Windows edition and, in professional environments, taking advantage of advanced management policies and tools, you can maintain a reasonable balance between convenience and privacy, allowing your PC to do its job without unduly intruding on your life.

What is a decentralized VPN and how to use it on Windows to improve your privacy
Related article:
What is a decentralized VPN and how to use it on Windows to gain privacy

Add as preferred source in Google