NEWS

How to Build a Privacy-First Setup on Windows in 2026

Windows 11 is more privacy-conscious than all previous versions of the desktop operating system. However, 11 still has privacy-invasive default features. If you leave the system on default, youโ€™re giving Windows access to significant telemetry, diagnostic data, and usage information. You can easily tighten and limit all default features in 10-15 minutes. To limit data collection, you should review the settings related to diagnostics, personalization, location, app permissions, and network activity.

1. Limit Windows Diagnostic Data

Go to Settings > Privacy & security > Diagnostics & feedback
Select โ€œRequired diagnostic dataโ€.

You can also turn off โ€œSend optional diagnostic dataโ€, โ€œTailored experiencesโ€, and โ€œImprove inking and typingโ€. By limiting diagnostic data, you stop Microsoft from tracking optional telemetry, device usage details, and crash logs. Microsoft still receives the data it needs for security and troubleshooting. However, limiting diagnostic data means less usage data leaves your computer. The average device generates only around 6 MB of Windows diagnostic data per day. While it may seem insignificant, diagnostic data can still reveal a lot about your device, settings, and usage patterns.


2. Disable the Advertising ID

Go to Settings > Privacy & security > General

Switch off โ€œLet apps show me personalized ads by using my advertising IDโ€. As a Windows account holder, youโ€™ll have an advertising ID assigned to your profile. The code allows different developers to recognize you and associate specific information with that identifier. By recognizing you, the developers can launch targeted and personalized ads.

Disabling the advertising ID reduces intrusive targeted ads. It also prevents third parties from building in-depth profiles based on your online activities and data. You can also switch off โ€œLet websites show me locally relevant content by using my language listโ€. By doing so, you will prevent websites from determining your region based on your language settings.


3. Turn Off Unnecessary Location Access

Go to Settings > Privacy & security > Location

You can switch โ€œLocation servicesโ€ off at the top of the page. By doing so, youโ€™ll prevent all applications from knowing your location.
Under โ€œLet apps access your locationโ€, you can specify which apps receive location data and which ones donโ€™t. You can leave location on for apps you require location for โ€” for example, trusted maps and weather apps. You can turn off location permissions for apps that never need location access.

Location is useful for some applications and when completing certain tasks. However, if youโ€™re security-conscious, you can switch off your location access entirely. Hackers frequently target location data. At the start of 2025, hackers successfully stole over 10 terabytes of location data from apps like Spotify.


4. Remove Unnecessary Permissions

Go to Settings > Privacy & security

Donโ€™t stop at location settings. In โ€œPrivacy & securityโ€, you can review the various other permissions each app has by default. Specifically, review permissions such as:

  • Camera
  • Videos
  • Microphone
  • Contacts
  • Calendar
  • Account info
  • Documents
  • Notifications

If the app doesnโ€™t need permission for the specific function, you should remove it. For example, a video conferencing app needs camera and microphone access. However, an image converter does not require these functions. Revoking permissions reduces the amount of access potential hackers gain. Theyโ€™ll only be able to access the information and features that youโ€™ve allowed the app to use.


5. Turn Off Activity History

Go to Settings > Privacy & security > Activity history

Here, select โ€œClear activity historyโ€, which will delete all the data thatโ€™s currently stored locally. Next, switch off โ€œStore my activity history on this deviceโ€ to prevent Microsoft from recording data going forward. Turning off activity history prevents Microsoft from keeping a local log of your daily computer habits.


6. Use Private DNS and Secure Your Network

Windows settings donโ€™t protect you fully โ€” specifically, they canโ€™t control what happens between your computer and the internet.
You should consider using a reputable and encrypted Domain Name System (DNS) provider. An encrypted DNS provider protects your queries from interception.

You should also avoid public Wi-Fi. You leave yourself prone to attacks when you connect to an open airport, hotel, or public transport Wi-Fi. Bad actors use public Wi-Fi to perform man-in-the-middle attacks and intercept private data. If you need to use your computer on the go, it would be safer to connect to your mobile hotspot. Or, to add another layer of protection, you could use a Virtual Private Network. A VPN allows you to safely and securely access files remotely. It also masks your IP address and allows you to browse privately, which is essential for creating a privacy-first setup.


Regularly Review Your Default Settings

Building a privacy-first setup isnโ€™t a one-time thing. Whenever you install a new application on Windows, be sure to review the default settings. Remove unnecessary permissions such as location access. Additionally, limit your diagnostic data, disable the advertising ID, and switch off activity history. Use an encrypted DNS and a VPN to further secure your setup.

You may also like

Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted