If he has not your login account details he cannot login in with your windows account and impersonate you, browser searches and registry can be accessed and read if you boot with a usb stick, in fact all data can be accessed.
If you have a TPM chip you don't need to enter the encrypted drive...
If you have a good password it will take a long time to get in but he can without logon access your hard/ssd/nvme drives if not encrypted he just need to boot with a usb stick and then via command prompt enter your drives.
Take a look at this taskbar weather applet GitHub - FelixdelasPozas/TrayWeather: Tray Weather is a simple application to retrieve and show weather information for a given geographic location in a small dialog and in the Windows OS system tray.
I have the same with an HP Elite x2 G2 with a I7-7600 processor, but Microsoft have decided that this processor will not be supported without explanation.
@Shawnlovehorses
Your are missing the future support on your processor called
Virtualization-Based Security (VBS)
Windows 11 raises the bar for security by requiring hardware that can accelerate the performance of Virtualization-Based Security (VBS).
Windows 11 enables Hypervisor-Enforced...
I am 62 and a system engineer working with computers since 1977 (sinclair), great to see so many older as me seniors are active with computers and such related.
At 62 i still play games to keep the brain active, playing Quake and Diabolical everyday.
What i love about Win11 is the new update system, when Windows 11 is tweaked with NTlite (services removed and all Junk) the CU does not override it it leave everything as it is, on Windows 10 it reset everything you tweaked with NTLite.