Give the borrower a separate Windows account or guest environment, sign out of accounts they do not need, and lock the private-file vault. Do not rely only on moving files to another folder or hiding windows.
Make and verify a full backup, sign out of accounts, and remove local copies that are not needed for the repair. Keep any private data left on the device encrypted and locked, and remove data drives when the repair does not require them.
Follow organizational rules for access and storage, reduce notifications, previews, and sharing scope during use, lock Windows when leaving, and use appropriate encryption for sensitive files that may be stored locally.
Hiding windows changes only what is visible now; files may still remain on storage or in recent history. Sensitive files need their own BitLocker-protected vault, locked when not in use.
Keep long-term sensitive originals together in an encrypted vault and retain only necessary copies in normal folders. Close files and lock the vault after use, and store recovery material separately.
Save work and lock the vault, check that sensitive files are not scattered across Desktop, Downloads, or sync folders, and sign out of accounts that need not be exposed. Prepare repairs using data minimization.
A trusted device is only a condition for entering the open flow; it is not the vault password. You still enter the BitLocker password so possession of the device alone does not reveal files.