TL;DR

This EU Joint Research Centre report surveys six privacy-enhancing technology categories — differential privacy, federated learning, SMPC, homomorphic encryption, synthetic data, and TEEs — and provides a decision framework for selecting among them based on data sensitivity, trust model, and GDPR requirements.

Summary

No single privacy technology suits all data-sharing scenarios. This JRC report surveys six PET categories: differential privacy, federated learning, secure multi-party computation, homomorphic encryption, synthetic data, and trusted execution environments. Each is assessed on maturity, use cases, limitations, and GDPR alignment. A decision framework guides practitioners in selecting the appropriate PET based on data sensitivity, trust model, and performance constraints — bridging technical capabilities with regulatory obligations for European practitioners.

Key contributions

  1. Provides a structured survey of six PET categories with consistent assessment criteria across maturity, use cases, and limitations.
  2. Introduces a decision framework mapping data sensitivity and trust model to appropriate PET selection.
  3. Assesses GDPR alignment for each technology, connecting technical controls to legal compliance obligations.
  4. Identifies federated learning and differential privacy as the most mature PETs for production data-sharing deployments.
  5. Demonstrates that hybrid PET architectures can cover individual weaknesses at the cost of increased complexity.

When to cite

  1. When selecting among PETs (differential privacy, FL, SMPC, HE, synthetic data, TEEs) for a data-sharing use case.
  2. When justifying a privacy technology choice against GDPR requirements in a European regulatory context.
  3. When comparing the maturity and practical limitations of homomorphic encryption vs. federated learning for production use.
  4. When arguing that no single PET is sufficient and hybrid privacy architectures should be considered.

PET FL ML