In many organizations, Data innovation and Privacy are still treated as mutually exclusive. On one side, product and innovation teams push for AI, new digital services, partnerships, and Data ecosystems. On the other, legal, compliance, and security teams are tasked with preventing harm and controlling risk. The prevailing narrative is simple: to innovate, organizations must accept greater Privacy risk; to protect Privacy, they must slow down innovation.
This perception largely stems from how Data environments are structured. Data remains siloed by department, geography, and partner. Every new use case triggers fresh negotiations, new Data Protection Impact Assessments, and additional layers of complexity. The result is friction at every step: friction in accessing Data, sharing it, and combining it across entities or jurisdictions.
Privacy-Enhancing Technologies (PETs) including federated learning, secure multiparty computation, synthetic Data, and related approaches aim to shift this dynamic by enabling meaningful computation without directly exposing Data. This is not science fiction. PETs are grounded in cryptography, Privacy engineering, and statistics, and regulators increasingly reference them as tools to reduce risk while enabling responsible Data reuse.
That said, “without compromise” is more of an aspiration than a guarantee. PETs do not eliminate trade-offs, they reshape them. Organizations must still navigate tensions such as Privacy versus performance, or cost versus scalability. The real question is whether PETs can offer a better, measurable alternative that allows innovation, legal, and engineering teams to make informed decisions together.
To assess the audience’s initial mindset, we conducted a poll asking: “Do you believe Privacy-Enhancing Technologies can be a core enabler of innovation in your organization, or are they simply a compliance or technical add-on?”
🔹 Aymeric Pontvianne: From an innovation perspective, can Privacy and Compliance be considered enablers?
Regulation imposes strict limits on how Data can be used, creating a need to innovate in order to meet both compliance requirements and computational demands. PETs emerge precisely from this tension: they enable new methods that respect legal constraints while still allowing meaningful Data processing. In this sense, regulatory pressure becomes a driver of innovation.
🔹 Sophie Stalla-Bourdillon : Do PETs change the legal qualification of Data, or only how it is considered in a given context?
To assess whether PETs change the legal status of Data, we must examine the specific technique used and its impact on identifiability. The answer also depends on the context of Data release: has the Data been pseudonymized or transformed into synthetic or aggregated outputs? What technical and organizational safeguards are in place such as key separation, access controls, audit logs, contractual limits, or restrictions on onward transfers to prevent re-identification?
This brings us back to cases like the SRB decision, where the analysis hinges on “who holds the Data” and what means are realistically available. For now, assessments remain case by case, as there are no harmonized European operational guidelines on PETs or identifiability thresholds. While the UK ICO frames PETs as Data minimization techniques, evolving EU policies (such as the Omnibus package) may reshape expectations and enforcement practices.
🔹 Maarten Everts : What is the biggest misconception about PETs?
There are two extremes. Some believe PETs are a form of magic that allows organizations to bypass regulations like the GDPR, which is incorrect. Others think PETs are ineffective or purely theoretical, which is equally false.
Technologies such as homomorphic encryption allowing computation on encrypted Data and secure multiparty computation enabling decentralized processing without revealing inputs are already operational. However, PETs do not remove legal obligations; they change the technical conditions under which Data is processed and can reduce exposure when properly designed.
One key limitation is that many PETs distribute Data across multiple locations. As a result, exploratory analysis becomes more difficult, since no single party has full visibility over the Dataset. This often requires a shift toward “query-by-design,” where objectives and features must be defined in advance. In this context, governance, orchestration, and output controls become just as critical as the underlying cryptography.
🔹 Aymeric Pontvianne: How do PETs enable new market models?
PETs challenge traditional business models based on exclusive Data ownership and bilateral sharing. Instead, they promote collaborative approaches closer to open-source models, where value is created through trusted participation and shared outcomes rather than raw Data exchange.
They also enable safer collaboration around sensitive Data, which can stimulate competition and lower barriers to entry for new market participants. Finally, PETs support interoperability across ecosystems, though true interoperability requires shared standards and governance frameworks such as those envisioned in the European Health Data Space.
Adoption ultimately depends on aligned technical interfaces, assurance mechanisms (such as auditability and measurable Privacy), and clear accountability rules. While current adoption remains limited, it is likely to grow as regulatory pressure and ecosystem initiatives intensify.
🔹 Emmanuel P. : When do synthetic Data enable innovation, and when do they distort reality?
Synthetic Data should not be seen as perfectly replicating reality, but rather as a model-based approximation shaped by the assumptions, constraints, and sampling properties of both the source Data and the generation process. They offer an alternative lens on real-world Data.
Synthetic Data enable innovation when they provide safe and scalable access for exploration, testing, and sharing for example, simulating cohorts that do not yet exist, adapting Datasets to specific needs, or increasing sample sizes for rare conditions.
However, they must be validated against real Data using both utility metrics (such as distributional similarity, predictive performance, and edge-case coverage) and Privacy metrics (such as inference and linkage risks). When used correctly, synthetic Data can even reveal biases or gaps in real Datasets, acting as a diagnostic tool rather than a replacement for ground truth.
🔹 Sophie Stalla-Bourdillon : Where do PETs reduce or eliminate risk?
Zero risk is an illusion. PETs do not eliminate risk; they redistribute and mitigate it across the Data lifecycle. They are most effective in reducing the risk of unauthorized disclosure of sensitive information, particularly in contexts such as Data sharing or cross-border collaboration.
Certain PETs, such as differential privacy or homomorphic encryption offer formal, mathematically defined guarantees under specific threat models. However, these guarantees depend heavily on correct parameterization, implementation, and governance.
🔹 Rafa Gálvez Vizcaíno : What is the current state of PET research?
Applied research increasingly evaluates PETs in real-world deployments, but results are often context-dependent and not easily transferable. Differences in Data distributions and operational constraints mean that findings from one domain may not generalize to another.
A major challenge is composition: we cannot yet reliably predict how different PETs interact when combined, or how the configuration of one impacts overall Privacy, utility, and robustness. This creates a need for standardized benchmarks, interoperable threat models, and reproducible evaluation frameworks.
On the regulatory side, authorities seek strong assurances of effectiveness, while PETs inherently depend on assumptions and correct implementation. Bridging this gap requires both empirical evidence and formal validation.
💬 Q&A
What is the common definition of PETs? The term “Privacy-Enhancing Technologies” is broad and can be misleading. A more practical definition is: techniques that measurably reduce Privacy risk for a given use case and threat model while preserving a target level of utility. Their effectiveness depends on context, architecture, and governance.
Federated learning illustrates this ambiguity. While often classified as a PET, its primary purpose is collaborative model training not Privacy per se. Without proper safeguards such as secure aggregation and encryption in transit, it can still introduce risks.
Who is responsible if synthetic Data are misused? Responsibility depends on the role of each actor. The Data generator is responsible for the quality and documented limitations of the dataset. However, misuse especially beyond the intended scope shifts responsibility to the user.
Can PETs be certified by authorities? Certification typically validates specific claims made by developers (e.g., a quantified residual risk). However, certification does not guarantee that every implementation is secure. Configuration, deployment, and evolving threat landscapes all impact effectiveness, making continuous monitoring essential.
How can organizations be encouraged to adopt PETs in healthcare? By emphasizing tangible benefits: reduced transaction costs, faster access to Data, and improved collaboration. What matters is not the label “PET,” but the demonstrated effectiveness, cost efficiency, and ability to accelerate research while maintaining trust.
Do PETs always increase complexity? Often, yes but not always. In some architectures, PETs can actually simplify legal and compliance considerations. For example, federated analytics or secure enclaves allow Data to remain in place, reducing exposure and limiting cross-border transfers.
Author: Gregory Collet