Privacy Enhancing Technologies (PETs) are a family of cryptographic and systems-engineering techniques designed to minimise the collection, use, and disclosure of personal data while still enabling legitimate data processing for analytics, machine learning, and regulatory compliance. The family encompasses Zero-Knowledge Proofs, Differential Privacy, Homomorphic Encryption, Secure Multi-Party Computation, Trusted Execution Environments, anonymisation pipelines, pseudonymisation, and synthetic data generation. PETs implement the data-minimisation and privacy-by-design principles mandated by frameworks such as GDPR and the UK Data Protection Act 2018. They are increasingly deployed by financial institutions, healthcare providers, and government agencies to unlock the utility of sensitive data without exposing individual records, and are recognised by the UK ICO, European Data Protection Board, and US NIST as essential infrastructure for trustworthy data ecosystems.
Content
- The term Privacy Enhancing Technologies was coined by a Canadian/Dutch joint report in 1995, originally covering anonymisation and pseudonymisation techniques. The field has since expanded dramatically to encompass cryptographic proofs of correct computation. Zero-Knowledge Proofs (SNARKs, STARKs) let a prover convince a verifier of a statement’s truth — for instance, that a user is over 18 or holds a valid credential — without disclosing the underlying data. ZKP systems are deployed in digital identity (age verification, KYC-free authentication) and privacy-preserving blockchain transactions.
- Differential Privacy, pioneered by Cynthia Dwork et al. (2006), provides a mathematically rigorous privacy guarantee: the probability of any output from a query is nearly identical whether or not any specific individual’s data is included, bounded by a parameter epsilon. Apple, Google, and the US Census Bureau use differential privacy to release population statistics from device telemetry and census microdata. Federated learning combined with differential privacy enables model training across devices without raw data ever leaving the user’s hardware.
- Homomorphic Encryption (HE) allows a cloud server to compute functions (addition, multiplication) directly on encrypted data and return an encrypted result that the data owner can decrypt. While fully homomorphic encryption (FHE) is computationally intensive, levelled and bootstrapping techniques continue to reduce overheads. Secure Multi-Party Computation (MPC) achieves similar goals via a different mechanism: multiple parties jointly evaluate a function using secret shares, with no party learning another’s input. MPC is used in privacy-preserving analytics consortia, confidential auctions, and threshold signature schemes.
- The UK Information Commissioner’s Office (ICO) and the European Data Protection Board have both published guidance explicitly endorsing PETs as means of compliance with GDPR obligations, particularly data-minimisation and purpose-limitation principles. Regulatory sandboxes for PET deployment (e.g. the UK Digital Sandbox) allow financial institutions to pilot PET-based data-sharing arrangements under supervisory oversight, accelerating adoption in health, financial crime prevention, and transport planning.