Learning outcomes
- Distinguish privacy risk from confidentiality breach and map consequences of authorized processing.
- Reduce identity and access data, stable links, traffic metadata, and telemetry to defined purposes.
- Assess pseudonymization, de-identification, inference, differential privacy, and other privacy-enhancing technologies.
- Build and test a privacy threat model across normal, recipient, repeated-release, support, export, and recovery paths.
Scenario
An identity-aware platform sends rich claims to applications and stores years of route, device, and policy telemetry. Teams want fraud detection, support, security investigation, and product analytics without creating a permanent cross-service behavior profile or unsafe de-identified export.
Ordered learning units
Privacy Engineering Objectives
Apply systems engineering to make personal-data processing predictable, manageable, and no more associated with people than the purpose requires.
Privacy Risk
Assess data actions that can create problems for people, then combine likelihood and impact without reducing privacy to breach risk.
Personal Data and Metadata
Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.
Data Minimization and Purpose Limitation
Collect, use, expose, and retain only the data necessary for a stated operational purpose and bounded period.
Linkability and Identifiability
Distinguish connecting events to each other from connecting them to a person, and bound both by observer, dataset, purpose, and time.
Pseudonymization
Replace direct identity with a controlled reference while treating the mapping, stable links, attributes, and auxiliary data as remaining privacy risks.
Minimize Identity and Access Data
Reduce claims, identifiers, device signals, policy inputs, assertions, logs, and retention to the minimum required for each access decision.
Traffic Analysis
Infer participants, relationships, activity, protocol, content class, and events from communication timing, direction, size, frequency, and routes.
Design Privacy-Preserving Security Telemetry
Collect enough access evidence for detection and investigation while limiting identity detail, linkability, sensitive content, recipients, and retention.
Anonymization and Re-Identification
Evaluate whether a release resists identification and sensitive inference under realistic auxiliary data, recipients, repeated releases, and governance.
Inference Attack
Derive protected facts from permitted queries, aggregates, models, correlations, errors, and repeated observations.
Differential Privacy
Bound how much a computation's output distribution can change when one person's contribution is added or removed.
Privacy-Enhancing Technologies
Select minimization, isolation, cryptography, confidential computation, controlled queries, and formal privacy from a precise data-use threat model.
Assess De-Identification and Inference
Test a dataset or query release against linkage, membership, attribute, reconstruction, rare-record, and repeated-release attacks.
Build a Privacy Threat Model
Model data actions, observers, linkability, inference, unawareness, loss of control, and human consequences across a complete system lifecycle.
Data Retention and Secure Deletion
Retain data for a stated need, then remove access across primary storage, replicas, caches, backups, indexes, keys, and media.
Evaluation questions
- Which normal, authorized collection, association, use, disclosure, inference, retention, or decision can create a problem for a person or group?
- Which observer, recipient, stable identifier, metadata, auxiliary data, and repeated release can link or identify records?
- Does each privacy mechanism state its protected entity, threat, parameter, trusted component, output, and residual risk?
- Can the system find, restrict, retain, delete, and verify every raw, derived, logged, exported, backed-up, and modeled copy?
Completion conditions
- Build a complete identity-and-access data map with purpose, recipients, identifier scope, retention, and deletion.
- Remove at least three unnecessary fields, scope one identifier, and redesign one telemetry flow.
- Test one dataset or query service for linkage, membership, attribute, rare-record, and repeated-release inference.
- Complete a privacy threat model with one normal-operation problem, one observer threat, one manageability failure, and verified controls.
