Privacy-Preserving Techniques
Privacy-preserving techniques are methods designed to protect the privacy of individuals while still allowing data to be used, analysed, or shared. They generally aim to reduce the risk that a person can be identified from data, or to keep sensitive information hidden even while it is being processed. Common examples include modifying data so individuals cannot be readily identified, and encrypting data during use or storage.
Privacy-preserving techniques refer to a broad set of methods and technologies used to advance data privacy and security objectives while still enabling data processing, analysis, or model training. Reported examples in the evidence include data anonymisation (modifying personal information so individuals cannot be readily identified), encryption, federated learning, homomorphic encryption, and secure computation methods; privacy-preserving machine learning specifically describes training, tuning, and inference on models without exposing the underlying sensitive data. The evidence characterises these techniques with reference to technical parameters such as plaintext and ciphertext size. Note that these techniques vary widely in the degree and type of protection they provide, and their effectiveness is context-dependent; the source evidence does not specify how any given technique maps to GDPR concepts such as anonymisation, pseudonymisation, or 'appropriate technical and organisational measures', and readers should assess each technique's legal status against the current regulatory position rather than assuming any technique renders data non-personal.
Why it matters
Privacy-preserving techniques matter because they address a recurring tension in data-driven work: organisations often need to analyse, share, or train models on data, while remaining subject to obligations to protect the individuals that data may relate to. By reducing the risk that a person can be identified, or by keeping sensitive information hidden even during processing, these techniques can support a controller's efforts to implement appropriate technical and organisational measures and to apply data protection by design and by default. They are therefore frequently discussed as tools that may help manage privacy risk rather than as a single guaranteed compliance outcome.
That said, the techniques vary widely in the degree and type of protection they provide, and their effectiveness is context-dependent. The source evidence does not establish how any given technique maps onto GDPR concepts such as anonymisation, pseudonymisation, or 'appropriate technical and organisational measures'. This distinction is significant in practice: genuinely anonymous data generally falls outside the scope of the GDPR, whereas pseudonymised data typically remains personal data and stays in scope. Whether a particular technique achieves anonymisation in the legal sense is a matter of assessment against the current regulatory position and relevant guidance, and regulators may take differing views.
Readers should therefore treat privacy-preserving techniques as a category of risk-reducing measures whose legal status depends on how, and how robustly, they are implemented in a specific processing context. A technique that reduces identifiability in one dataset may not do so in another where additional data could enable re-identification. The prudent approach is to assess each technique's actual effect on identifiability and residual risk rather than assuming any technique automatically renders data non-personal or delivers full compliance.
Who it's relevant to
Inside PPTs
Common questions
Answers to the questions practitioners most commonly ask about PPTs.