Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Richard Stallman calls Windows “malware” in a broad, political sense: he argues that proprietary software gives its developer power over users and can include behavior—such as collecting data—that users cannot independently inspect or remove. He is not simply claiming Windows is a conventional virus. Microsoft, meanwhile, documents diagnostic-data collection and controls for Windows, as well as built-in security protections. Those are different questions: privacy and user control are not the same as protection from malicious software.

What Stallman means by “malware”

In ordinary technical usage, malware is software designed to harm, disrupt, or gain unauthorized access to a device or its data. Stallman uses the term more broadly to criticize software he considers hostile to users’ interests. His central concern is who controls the program: users and their community, or a company that can set its terms and add features users cannot independently inspect, change, or remove.

In his 2018 essay “What sort of laws would give us real privacy?”, Stallman wrote: “If it is the non-free software of Apple, Google or Microsoft, it spies on you regularly (see https://gnu.org/malware/).” This is Stallman’s categorical assertion and reflects his wider free-software argument. It should not be mistaken for a regulator’s or court’s technical ruling that Windows is a virus or that every Windows data practice is covert surveillance.

For Stallman, the issue is not only whether a particular feature is harmful. It is also that with proprietary software, the developer retains control while users lack the freedom to study and modify the program themselves. His talk at Microsoft provides further context for his criticism of proprietary software.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Microsoft says Windows collects

Microsoft’s Windows privacy compliance guide describes diagnostic data collected through different user interactions and divides it into required and optional categories. Required diagnostic data includes information about a device, its settings and capabilities, its readiness for updates, and whether it is functioning properly. Optional diagnostic data includes more detailed information; choosing to send it also sends required diagnostic data.

Microsoft says it uses diagnostic data to keep Windows secure and up to date, troubleshoot problems, and improve its products. These are the purposes Microsoft gives for the data—not independent proof of every practice or of the company’s motives. The guide covers specified Windows 10 and Windows 11 editions and versions; available settings and management options depend on the device and applicable policies.

What privacy controls do—and do not—do

Microsoft’s diagnostics and privacy support page explains how users can choose optional diagnostic-data settings and use the Diagnostic Data Viewer to see diagnostic data. On a device managed by an employer or school, administrators may determine or hide some controls.

Viewing diagnostic data is not the same as preventing all collection. Microsoft says deleting device diagnostic data does not delete information associated with a Microsoft account and does not stop further diagnostic data from being sent. A setting or deletion action therefore should not be described as turning off every kind of Windows data collection.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why Windows security features do not settle the dispute

Windows also includes documented protections against threats. Microsoft says Windows Security real-time protection monitors for potential threats, including viruses, malware, and spyware.

That protection addresses the risk of malicious software attacking a device. It does not answer Stallman’s separate questions about what data the operating system collects, who controls its code, or whether users can independently inspect and change it. Conversely, the presence of diagnostic-data collection does not by itself establish that every category is covert surveillance or that Windows is a conventional malware payload.

How to assess the claim fairly

  • Clarify the meaning of “malware.” Stallman uses the term as a broader criticism of software he sees as harmful to user freedom; that differs from the narrower technical sense of a malicious payload.
  • Separate the kinds of evidence. Stallman offers an ethical and political argument. Microsoft’s pages describe its own product, data categories, settings, and stated purposes; they do not independently resolve Stallman’s value judgment.
  • Check the specific Windows setup. Data categories and available controls vary by Windows release, edition, and whether an organization manages the device.
  • Keep privacy and security distinct. Threat protection can be valuable without answering concerns about data collection or software control.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.