
Windows 11 is more privacy-conscious than all previous versions of the desktop operating system. However, 11 still has privacy-invasive default features. If you leave the system on default, youโre giving Windows access to significant telemetry, diagnostic data, and usage information. You can easily tighten and limit all default features in 10-15 minutes. To limit data collection, you should review the settings related to diagnostics, personalization, location, app permissions, and network activity.
1. Limit Windows Diagnostic Data
Go to Settings > Privacy & security > Diagnostics & feedback
Select โRequired diagnostic dataโ.
You can also turn off โSend optional diagnostic dataโ, โTailored experiencesโ, and โImprove inking and typingโ. By limiting diagnostic data, you stop Microsoft from tracking optional telemetry, device usage details, and crash logs. Microsoft still receives the data it needs for security and troubleshooting. However, limiting diagnostic data means less usage data leaves your computer. The average device generates only around 6 MB of Windows diagnostic data per day. While it may seem insignificant, diagnostic data can still reveal a lot about your device, settings, and usage patterns.
2. Disable the Advertising ID
Go to Settings > Privacy & security > General
Switch off โLet apps show me personalized ads by using my advertising IDโ. As a Windows account holder, youโll have an advertising ID assigned to your profile. The code allows different developers to recognize you and associate specific information with that identifier. By recognizing you, the developers can launch targeted and personalized ads.
Disabling the advertising ID reduces intrusive targeted ads. It also prevents third parties from building in-depth profiles based on your online activities and data. You can also switch off โLet websites show me locally relevant content by using my language listโ. By doing so, you will prevent websites from determining your region based on your language settings.
3. Turn Off Unnecessary Location Access
Go to Settings > Privacy & security > Location
You can switch โLocation servicesโ off at the top of the page. By doing so, youโll prevent all applications from knowing your location.
Under โLet apps access your locationโ, you can specify which apps receive location data and which ones donโt. You can leave location on for apps you require location for โ for example, trusted maps and weather apps. You can turn off location permissions for apps that never need location access.
Location is useful for some applications and when completing certain tasks. However, if youโre security-conscious, you can switch off your location access entirely. Hackers frequently target location data. At the start of 2025, hackers successfully stole over 10 terabytes of location data from apps like Spotify.
4. Remove Unnecessary Permissions
Go to Settings > Privacy & security
Donโt stop at location settings. In โPrivacy & securityโ, you can review the various other permissions each app has by default. Specifically, review permissions such as:
- Camera
- Videos
- Microphone
- Contacts
- Calendar
- Account info
- Documents
- Notifications
If the app doesnโt need permission for the specific function, you should remove it. For example, a video conferencing app needs camera and microphone access. However, an image converter does not require these functions. Revoking permissions reduces the amount of access potential hackers gain. Theyโll only be able to access the information and features that youโve allowed the app to use.
5. Turn Off Activity History
Go to Settings > Privacy & security > Activity history
Here, select โClear activity historyโ, which will delete all the data thatโs currently stored locally. Next, switch off โStore my activity history on this deviceโ to prevent Microsoft from recording data going forward. Turning off activity history prevents Microsoft from keeping a local log of your daily computer habits.
6. Use Private DNS and Secure Your Network
Windows settings donโt protect you fully โ specifically, they canโt control what happens between your computer and the internet.
You should consider using a reputable and encrypted Domain Name System (DNS) provider. An encrypted DNS provider protects your queries from interception.
You should also avoid public Wi-Fi. You leave yourself prone to attacks when you connect to an open airport, hotel, or public transport Wi-Fi. Bad actors use public Wi-Fi to perform man-in-the-middle attacks and intercept private data. If you need to use your computer on the go, it would be safer to connect to your mobile hotspot. Or, to add another layer of protection, you could use a Virtual Private Network. A VPN allows you to safely and securely access files remotely. It also masks your IP address and allows you to browse privately, which is essential for creating a privacy-first setup.
Regularly Review Your Default Settings
Building a privacy-first setup isnโt a one-time thing. Whenever you install a new application on Windows, be sure to review the default settings. Remove unnecessary permissions such as location access. Additionally, limit your diagnostic data, disable the advertising ID, and switch off activity history. Use an encrypted DNS and a VPN to further secure your setup.







