Skip to main content

Privacy Engineering Objectives

Apply systems engineering to make personal-data processing predictable, manageable, and no more associated with people than the purpose requires.

Privacy as a system property

Privacy engineering applies systems methods to reduce problems that data processing can cause for individuals and groups. It addresses what data a system observes, how it associates events with people, who can use it, which inferences it enables, how long it persists, and whether affected people can form reliable expectations and exercise available controls.

Engineering objectives

Predictability lets people, owners, and operators form reliable assumptions about data processing. Manageability supports granular access, alteration, deletion, selective disclosure, and policy change. Disassociability lets the system process data or events without linking them to people or devices beyond operational need.

Translate these into requirements for each flow, store, computation, output, and actor. A notice alone does not create the required system capability.

Lifecycle and evidence

Map collection, derivation, identity binding, use, sharing, storage, backup, analytics, support, export, retention, deletion, and recovery. Record purpose, data owner, data subject or group, recipients, legal and organizational policy inputs, and technical controls.

Test actual outputs and copies. Evidence includes schemas, configuration, access decisions, data lineage, retention jobs, deletion checks, privacy tests, and review of changes and new uses.

Failure and residual risk

Security can be correct while privacy fails through excessive authorized collection, unexpected reuse, correlation, surveillance, or harmful inference. Minimization can reduce analytics utility. User controls can be unusable or misleading. Third parties can combine a narrow release with data the system owner never sees.

Privacy is contextual. A stable identifier useful for account security can create cross-service linkability. State the purpose and observer before claiming a mechanism is privacy preserving.

Pomerium boundary

Pomerium processes identity and access data needed for configured routes and evidence. Operators define identity claims, device context, policy inputs, logs, destinations, access, retention, and downstream correlation. Pomerium does not control every copy held by identity providers, upstream applications, analytics, or support systems.

Evaluation checklist

  • Can affected people and accountable owners form accurate expectations about each data use and recipient?
  • Can the system locate, restrict, alter, retain, delete, and selectively disclose every relevant copy?
  • Which processing can occur without a stable person or device association?
  • What authorized correlation, inference, secondary use, or group harm remains after security controls pass?
  • Does deployed evidence prove the stated privacy behavior across backup, export, analytics, and recovery?

Sources and further reading

Keep learning

Privacy Engineering

Privacy Risk

Assess data actions that can create problems for people, then combine likelihood and impact without reducing privacy to breach risk.

Learn this term
Platform and Component SecurityAuthorization and Policy

Information Flow Control

Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo