When I’m forced to use windows it’s the LTSC IOT version with telemetry disabled via group policy and a local account. I run O&O shut up after that, then install portmaster. I don’t run it as a daily OS but I think that’s private enough for my limited use case. My only other random recommendations are using either scoop or winget for package management, and komorebi with whkd for tiling window management.
That’s not the case for the newer open source drivers from nvidia. They’re only compatible with the last few generations of cards but they’re performant and the only feature they lack is CUDA to my knowledge. Not talking nouveau here