This Windows 10 privacy guide is a work in progress. We will add new information and make adjustments once they become available.
Yes, that is lots of text even if you only read the summaries that Microsoft provides. Please note that the two documents are not exclusive to Windows 10 but apply to Microsoft. You do find "Windows" listed under the privacy statement however.
There you find the following key information:
- Microsoft creates a unique advertising ID for each user on a device running Windows 10. This can be turned off in the Privacy Settings.
- What you say or type may be processed by Microsoft, for instance by the operating system's Cortana service or by providing spelling correction.
- Windows supports a location service that allows apps and services, such as Find My Device, to request your location in the world. This can be turned off in the Privacy settings.
- Microsoft syncs some Windows settings automatically when you sign in to a Microsoft account. This is done to provide users with a personalized experience across devices. Data that gets synced includes installed apps and their settings, web browser history and favorites, passwords and wireless network names, and addresses of shared printers.
- Telemetry data is collected by Microsoft. This includes installed software, configuration data and network and connection data. While some of it can be turned off in the Settings, not all can.
Core Windows 10 Privacy Settings
You find Privacy settings that Microsoft makes available under Settings. The page is surprisingly large and while it provides you with lots of options, does not give you full control over what is collected and submitted.
Open the Privacy settings with a tap on the Windows-key and the selection of Settings when Start opens. If Settings is not listed there, type Settings and hit enter.
Switch to Privacy once the Settings window opens. There you find listed all privacy related settings. Suggests are in brackets)
- Let apps use my advertising ID for experiences across apps (turning this off will reset your ID). (Off)
- Turn on SmartScreen Filter to check web content (URLs) that Windows Store apps use. (Off, but note that this may reduce security on the system. If you are inexperienced, leave this on.)
- Send Microsoft info about how I write to help us improving typing and writing in the future. (Off)
- Let websites provide locally relevant content by accessing my language list. (Off)
- Turn location on or off. Apps or services that you allow may access location-based data if on. (Off, unless you rely on apps that require it to be on, e.g. the weather app)
- Location History. If you have turned location services off, you may want to clear the location history on the device as well.
Camera and Microphone
- Let apps use my camera. (Off)
- Let apps use my microphone. (Off)
Switch these to off if you don't want apps to use the cam or microphone on your device. You may need it for select services, Cortana for instance or the Skype application.
Speech, inking & typing
- Windows and Cortana can get to you know your voice and writing to make better suggestions to you. We'll collect info like contacts, recent calendar events, speech, and handwriting patterns, and typing history. (Off, unless Cortana is used. This will turn off Cortana and dictation).
- Let apps access my name, picture, and other account info. (Off, unless you require this for select applications. Then leave it on and set permissions per application instead).
Contacts and Calendar
- Choose applications that may access your contacts or calendar. There are three by default for the Contacts, and two for the Calendar (the first two): App connector, Mail and Calendar and Windows Shell Experience. (Off, unless required).
- Let apps read or send messages. (Off if you are on the desktop and don't require apps to send text or MMS).
- Let apps control radios. This enables apps to use radios, such as Bluetooth. (Off, unless you use apps that require this).
- Sync with devices. This setting syncs data with Microsoft and other devices you own. If you only use a single device, you may want to disable it. Note that syncing may come in handy when you set up the system anew. (Off)
- Let apps use trusted devices. (Off, unless required).
Feedback and Diagnostic
- Send your device data to Microsoft. If you are an Insider, you cannot switch from Full(Recommended). If you are not, you may switch the setting to Enhanced or Full. It does not seem possible to turn this off completely.
What is transferred if you switch the setting to Basic is listed in the FAQ (when you click on the learn more link):
Basic information is data that is vital to the operation of Windows. This data helps keep Windows and apps running properly by letting Microsoft know the capabilities of your device, what is installed, and whether Windows is operating correctly. This option also turns on basic error reporting back to Microsoft. If you select this option, we’ll be able to provide updates to Windows (through Windows Update, including malicious software protection by the Malicious Software Removal Tool), but some apps and features may not work correctly or at all.
- Select which applications may run in the background (Turn off all that you don't require. If you use Mail for instance, you may want it to run in the background while you may not want the same for "Get Office", "Photos" or "Xbox".
Settings > Update & Security > Windows Update
- Click advanced options.
- Defer Upgrades (Enable, only available in Pro and Enterprise editions)
- Select "choose how updates are delivered".
- Download Windows updates and apps from other PCs in addition to Microsoft. (Off).
Advanced Windows 10 privacy settings
Changing the Telemetry value using the Group Policy Editor or Windows Registry
This setting is identical to the Feedback & diagnostics setting. There is one difference however which only applies to Enterprise customers. Enterprise customers may turn this off completely, while Home and Pro users may set it to basic only as the lowest level.
To make the change in the Group Policy, do the following:
- Tap on the Windows-key, type gpedit.msc and hit enter.
- Navigate to Computer Configuration > Administrative Templates > Windows Components > Data Collection (It may be listed as Data Collection and Preview Builds).
- Set Allow Telemetry to Off if you are using an Enterprise account, to Basic if you are not.
To make the change using the Windows Registry, do the following:
- Tap on the Windows-key, type regedit and hit enter.
- Confirm the UAC prompt if it comes up.
- Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection.
- Set the value of AllowTelemetry to 0 if you are on Enterprise, to 1 if you are not.
Use a local account
Windows 10 supports two account types: Microsoft accounts and local accounts. Microsoft accounts are used by default and if you select that option, you sign in to the operating system using your account's credentials (usually email and the password).
You may use a local account instead for day to day activies. This can be arranged in the Settings under Accounts > Your account.
If you use a local account, you will notice that you cannot use certain features of the operating system. Windows Store and certain applications become unavailable for instance, and account data is not synced across devices.
Misc Group Policy Settings
The following settings are provided in the Group Policy Editor.
Computer Configuration > Administrative Templates > Windows Components > OneDrive
- Prevent the usage of OneDrive for file storage.
Computer Configuration > Administrative Templates > Windows Components > Online Assistance
- Turn off Active Help.
Computer Configuration > Administrative Templates > Windows Components > Search
- Allow Cortana.
- Allow indexing of encrypted files.
- Allow search and Cortana to use location.
- Do not allow web search.
- Don't search the web or display web results in Search.
- Don't search the web or display web results in Search over a metered connection.
- Set what information is shared in Search (Switch to Anonymous info)
Computer Configuration > Administrative Templates > Windows Components > Sync Your Settings
- Disable all syncing or the synchronization of specific settings, for instance Start, browser or passwords.
Computer Configuration > Administrative Templates > Windows Components > Windows Error Reporting
- Configure Error Reporting (do not collection additional files, do not collect additional machine data).
- Disable Windows Error Reporting.
- Disable logging.
- Do not send additional data.
Computer Configuration > Administrative Templates > Windows Components > Windows Update
- Configure Automatic Updates (Set to Notify for download and notify for install. May want to set the scheduled install day as well. This allows you to block updates from being installed)
- Defer Upgrade (Pro and Enterprise only, may defer upgrades til next upgrade period)
- Turn on Software Notifications ("Enhanced notification messages convey the value and promote the installation and use of optional software").
- Allow signed updates from an intranet Microsoft update location.
Additional resources of interest
- Microsoft Edge Forensics - Detailed analysis of the browser's data collection.
- Setting your preferences for Windows 10 services - Official Microsoft guide
Now You: We need your help to make this guide as complete as possible. Got other tips? Please share them in the comment section below.