Skip to Content

A window into PETs use cases, organizational concerns

During an IAPP web conference, stakeholders outlined how the benefits of privacy-enhancing technologies can only be realized with appropriate application and sufficient awareness to their availability.

Published
Subscribe to IAPP newsletters

Contributors:

Lexie White

Staff Writer

IAPP

Privacy-enhancing technologies have long provided companies with opportunities to access and analyze sensitive data while reducing privacy risks. The value of PETs ranges, allowing for privacy-protected analysis of location information, financial fraud detection and health research advancements.

The trouble with adoption and application isn't the techniques themselves, but the general awareness to their availability. A recent IAPP web conference hosted by IAPP Senior Fellow for Privacy Engineering Dylan Gilbert sought to offer an introduction to PETs and their benefits.

Future of Privacy Forum Vice President for U.S. Policy Matthew Reisman told webcon attendees that PETs "deliver so much more than a compliance function" while "unlocking the value of data." He added PETs are "best thought of as a tool in the toolkit for unlocking business value and research value in non-commercial contexts as well from things like health and education insights that we would not be able to unlock otherwise because of the privacy risk symbol."

The event coincided with the launch of the IAPP's PETs resource repository, which carries original IAPP reporting, curated external papers and reports, official regulatory guidance for using PETs, open-source tools, educational materials, and sandbox testing and research. The aim is to support education, deployment and continued maturity of PETs from research to practice.

PETs use cases

Google Group Data Protection Officer Kristie Chon Flynn highlighted the company's use of differential privacy tools to provide insights through Google Maps.

The application to Google Maps helps provide information about how busy a location may be without identifying the individual users at the location. According to Flynn, the feature works by "aggregating and anonymizing data from users who opt-in to Google Timeline" to provide broader insights into activity.

The company uses similar methods to measure traffic analytics by aggregating data from devices to determine traffic patterns and provide users with alternate routes.

Reisman noted organizations are also using PETs to analyze financial information. The Future of Privacy Forum recently released its case study on Mastercard's use of fully homomorphic encryption to protect consumers' sensitive personally identifiable data and prevent fraud.

The encryption layer aims to allow organizations to check individual bank account numbers against databases while keeping source data encrypted and localized.

"This is not saying that data transfer rules no longer apply, and indeed, different jurisdictions have spoken about it in different ways," Reisman said. "But one thing that is clear is that you're greatly enhancing the protections that apply to that data while in transit."

Flynn also highlighted Google Cloud's partnership with SWIFT, which uses federated learning and trusted execution environments to detect financial fraud.

By using a combination of PETs, financial institutions are looking to train fraud detection models "within each bank's secure firewall," Flynn said. Federated learning tools embedded within secure systems could also allow organizations to share and collect "insightful anomalies and patterns that other banks can leverage to combat fraud while keeping the data safe and secure."

Researchers are using similar measures to protect sensitive information as they increase innovation and collaborative analysis.

Mitchell Technology Consulting Principal Curtis Mitchell, CIPT, discussed the use of differential privacy, federated learning and trusted execution environments during his time as the U.S. Census Bureau's Emerging Technology Fellow. Those techniques were applied toward studies on global pediatric cancer research alongside the National Institute of Standards and Technology and various health organizations.

"Our project was trying to look at rare pediatric cancers. So, by the very nature of that class of diseases, these are small populations," Mitchell said. "If anybody gets access to those datasets, they could potentially re-identify those patients, and because it's genetics, they could also impact the patients' families as well."

He added the bureau used federated learning tools "because these different data sets were held by different institutions in different countries. That particular PET allows them to keep their data where it is and then provide updates from local model training to a central server."

Case-by-case assessment is key

Benefits of PETs can only be realized once an organization determines the proper technology required to address the specific risks and business needs at hand, the panel noted.

"For each of the PETs or combination of PETs, and for use cases where PETs are leveraged, it's really important to think about the balancing act of utility," Flynn said. "What is the outcome that you really want, balancing that with cost, privacy and other factors. This goes to the point of it's not a silver bullet, but it is a set of tools."

To assess risks and address compliance obligations, organizations must ensure they are addressing privacy, legal and technical needs before implementation.

Flynn stated that without universal auditing standards for PETs, organizations should "work across industry sort of consortiums and forums to be able to establish almost like benchmarking and technical operational standards that may work."

Industry collaboration could help determine "where the true operational and technical data and benchmarking can connect to the policy layer and hopefully regulation," she added. "I think that is a really great, healthy way to go about operationalizing and leveraging the technical solutions and benchmarking to ultimately get to the policy layer."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Lexie White

Staff Writer

IAPP

Tags:

Data securityPrivacy-enhancing technologyRisk managementPrivacy engineeringPrivacy

Related Stories