Library Header Image Library Header Image

Why Privacy-Enhancing Technologies, Why Now


Posted on in Videos

Data has never been more valuable—or more exposed. As organizations push to extract more value from their data, regulatory scrutiny and breach risk are climbing right alongside it. This episode opens a new series on privacy enhancing technologies (PETs) by framing that core tension and introducing the toolkit built to resolve it: differential privacy, homomorphic encryption, federated learning, confidential computing, synthetic data, and zero-knowledge proofs.

Kristie Chon Flynn, Data Protection Officer, Google, and John Elliott, Author Fellow, Pluralsight and RSA Conference Program Committee Member, break down each category in plain terms—what it actually does, where it fits, and why it matters right now—without assuming you're already a cryptography expert. Rather than a shallow survey, this conversation sets the foundation the rest of the series builds on.

If your organization is weighing how to unlock more value from data without expanding its exposure, this is the place to start.

To watch Kristie's session on privacy enhancing technologies (PETs) from RSAC 2026 Conference, you can find the recording here.


Video Transcript

Hello, everyone, and welcome to this first episode in this series on privacy enhancing technologies. We're excited to be joined today by Kristie Chon Flynn and John Elliott, who will be talking about why PETs, why now? And without further ado, I will turn it over to my guests to introduce themselves and get started.

Thanks, Kristie. I'm John Elliott. I'm a member of the RSAC conference program committee for the data security, privacy, and data protection track, and I'm a Pluralsight author fellow. I'm joined today by Kristie Chon Flynn from Google. Kristie, would you like to introduce yourself?

Yes. Hi, everyone. Thanks, John. I'm Kristie Chon Flynn, and I'm Google's data protection officer. I also lead a global team of privacy engineers focused on building technical privacy policies as well as privacy by design capabilities, including privacy enhancing technologies.

And prior to Google, I was the Chief Privacy Officer for PayPal and held numerous data governance, risk management leadership positions in, different consumer as well as B2B companies, including American Express and HCL Technologies.

Wow. That's a heck of a career. I guess we should start by well, it sounds pretty impressive to me, you know.

Oh, thank you.

So you know.

I've been doing it for a while.

Frankly, being being the DPO so well, like, Google must be an an amazingly fun and challenging job. Was slightly envious of it, but I suppose we should start by making sure we're talking about the same thing, privacy enhancing technologies or pets. Obviously, you have something to do with privacy. So let's start there. What do we mean?

You know, you can think about privacy as analogous to, if and who and why you let somebody into your home.

So think about, you know, if you for example, if your sink is broken and you need a plumber, you are asking the plumber to come to your house to fix the broken sink.

Your expectation is that the plumber comes to your house, fixes the sink, and doesn't need to go into any other space in your house, doesn't need to look at any other things, for example, in your bedroom, or take anything, right, outside of the activity that he's there to do. I think if you translate that into companies, companies are, building privacy programs to ensure that we understand the types of data that is collected, how individuals' data is used and it flows through the various different systems for processing, as well as making sure that we're honoring customer and user choices around how their data gets used and also retained and deleted. And so making sure that all of that gets wrapped around in showing accountability. How do companies show that, there is appropriate governance associated with, managing and protecting personal data?

Great.

So if that's what privacy is, let's try and put that in terms of PETS, privacy enhancing technologies. So how can technology enhance privacy?

You know, I talked a little bit about the the data side and then the accountability side. So I'll I'll maybe touch on both. Technology has come a long way, and I think we've been using technology to, automate and, demonstrate governance process. So, for example, how do you actually show that you are doing the right type of risk assessments to understand the data that's collected, how it's used, and how we are honoring user choices?

That kind of technology, I think, helps companies to scale, especially in the era of multi domain compliance.

And it helps us to think about how do we evolve, right, as different frameworks and regulatory requirements across the globe upon companies to demonstrate accountability on. That is overarching. And then you think about privacy enhancing technologies, which is a set of technologies I'm personally really, really passionate and excited about, which are tools in a toolkit that could help to reduce risk around personal data and, this is the key part, maximize and actually enable data utility. I think if you think about privacy governance and privacy in the historical sense, it's a lot to do with regulatory requirements, compliance checks, and being able to show that you're protecting the user data.

But with, AI, and especially deployment of AI as a lot of companies are thinking about these days, there's a tremendous amount of data that goes into deploying, AI models. And the accuracy and the quality and the protection of how that data gets used and processed becomes even more critical. Right? So I'll give you an example.

An example of a privacy enhancing technology is differential privacy. And differential privacy is, almost like a mathematical solution where you're able to inject noise into a data set. So therefore, the actual raw data of let's say personal data doesn't need to be shared or known by anyone because it gets injected with the noise. But it actually produces the same utility. If we bring that into a concrete example, I don't know if you use, Google Maps, but if you use Google Maps, you'll know that if you look for a restaurant. What's your favorite restaurant, John?

Oh, see, the problem is if I tell you my favorite restaurant in London, lots of people will know my favorite restaurant in London. And every time I look at Google Maps, I won't be able to get a table to go there. But actually, you will take this. You might come to you might come to London. My favorite restaurant is a restaurant called Noise in London. It's it's amazing. There we go.

That's a well, and that's an exact that's a great example. Noise, if I look up Noise, I would know the busy times and the busy days of noise without necessarily knowing, without knowing actually, where, let's say, John goes to noise maybe every Thursday at a certain time. Without that information, it provides an incredible utility to the product users of knowing what business factors are or even traffic, right? And so this is a great example of where differential privacy in combination with other technologies gets used to be able to inject noise and so that the system does not need to know the individual data, individual name, address, location to be able to determine, a great utility, which is for a business. You would also know, how to staff, right? And as an individual consumer, I would know to avoid Noise at, you know, Friday evenings at seven o'clock.

Sure. And is that the same technology that because one of things I love about Google Maps is actually when I'm driving somewhere is to be able to see the the traffic patterns. Like, is is this road gonna be very busy? And can it reroute me sometimes? Is that the same technology?

Yes. Exactly. So that's also understanding traffic patterns. And the way that that we do that is is to, again, using differential privacy in combination with other technologies, inject noise to only know and only collect the actual utility of phone A is moving at ten miles per hour or maybe kilometers per, an hour for your commute.

And that phone B is also moving at ten kilometers per hour. And so thereby, knowing that certain street is very busy at a certain time, without knowing exactly who is on the road, where you're going, and the exact points around the actual personal data. And, you know, I'm talking about differential privacy as an example, but there are a lot of pets. And what's exciting is that this is a really interesting time where historically pets have been a little bit more on the research and academic side.

And I'm really excited to see that we've come a long way in seeing the advancements of pets and also the combination of use of pets. So another example that I could, give is, we're now seeing a lot of use cases of unlocking data utility in otherwise, areas that we weren't able to, enable. So fraud prevention is one thing that comes to my mind where, Google Cloud and Swift has partnered to really do analysis on the data in a federated system. So Bank A, Bank B, Bank C would have logic and insight into the different ways that, you know, let's say fraud detection can be analyzed, right?

And, we're able to then only using signals to be able to share the almost like intelligence around the patterns so that individual bank data is not shared with, other banks or other system providers. And so enabling this, what I call almost like a really great data collaboration in a responsible way without compromising or sharing, corporate data or individual data to enable the greater good, right? That is, one of the other ways that I'm seeing, lots of great use cases be unlocked by privacy enhancing technologies.

And what technology are you using to do that? Is that another differential privacy example or is that something else?

This is actually federated learning in combination with trusted execution environment.

And so, you know, I'm talking through various different pets examples and the types of pets. But think about pets as almost as there isn't one sort of meta list. There isn't like a website we can go to and say, hey, give me a total, all the list of pets. You can see different lists.

And you can also see the evolution. And I think the key point here is don't it's not one pet use for a particular use case that's almost like a silver bullet. That doesn't exist. Because every use case, I think, can and depending on the lifecycle of where you are, at what stage do you apply the PETS, I think that'll really, sort of, change the utility the against the data sort of mitigation as you apply the different privacy enhancing technologies.

I'm incredibly disappointed there isn't a website like, I don't know, pets dot com, for instance, where you could go and find out all the different sorts of pets.

I think we are going to get to a state of where, you know, this is a good list. These are available pets. And also, I'd love to share that, as companies do more research and as companies invest in more pets, especially for enterprise use, there is open source libraries that are available in places like GitHub. But I'm a true believer that the more we research and the more we learn, being able to share with the rest of the ecosystem is really important, right, through blog posts and through, other, channels of publication because this is a growing area of research and application and utility.

Yeah. I mean, and I say sitting on the program committee for data privacy and data protection, every year we see more submissions of proposals for new uses of pets. We all we all, you know, we it used to just be almost homomorphic encryption was all we saw, and now we're seeing lots of different types of of uses of pets coming in as session presentations.

Yeah. And I think one thing to note there is different pets have, in a way, different costs. Right? Some pets are really expensive to implement. Some pets actually cause more latency than others.

Some pets, take up more capacity, right? And so that's why I keep on reminding, everyone I speak to that use case starting out with a very, very specific use case is really important because depending on what that use case is, there might be other pets or other combinations of pets that can work, to produce a much better outcome than, let's say, using another pet.

That's great. Pets, obviously, have got some privacy benefits we've talked about. But what are some of the security benefits of using them?

Yeah. You know, when I started with describing privacy using a house analogy, right, if privacy is about determining if and who you let in your house and for what reason, I sort of think about security as making sure you have all the structural foundations, the deadbolts, the framing, everything in place to ensure that no bad actors can sort of get in your house. Right? And so if you start with that analogy, pets are really great risk mitigants around making sure that if you actually got into the house that there is nothing really, really valuable to steal because we've already, either masked through encryption. We've already put noise in it so that it looks blurry instead of the actual raw data.

And so the sensitivity around the data set gets reduced. And so I think if you think about it, it reduces the, attack surface around, the really sensitive, attributes and data that could potentially be compromised. Having said that, I think the really greater benefit to both the security and the privacy community is being able to actually use PETS for, data utility and maximizing and being able to unlock, data use. If you think you know, I remember historically the privacy teams and the security teams were always sort of, oh my gosh, you can't do this because.

Name the danger, right? Name the risks or name the regulatory challenges. But now I am seeing a lot more conversations around how can privacy and security professionals enable responsible data use through, leveraging technologies, like you know, the ones I mentioned, privacy enhancing technologies. Sometimes I think it's a little bit of maybe we need a different PR brand.

You know, maybe we should call it, you know, data utility technologies or data, know, data use data use technologies. What do you think?

I think dud duds doesn't sound very good, whereas pets sounds like You prefer pets.

Friendly, doesn't it? I like pets, to be honest.

And I love the idea that pets dot com would actually just be a list of privacy enhancing that's a maybe that's a good idea for us to think about.

Yeah. I know. I I think someone's probably got that domain even though it was a classic of the god, the little dog saying I wanna play with a pussycat twenty years ago now. Maybe more than that actually. Look Christy, we've gone on quite a while. Thank you for making time to talk to to me and to the RSAC community today. Do you do you have a final thought you'd like to leave with people?

I'd say, you know, right now, I think it's it's an incredible moment for privacy security data governance professionals to really play a critical role in innovation and innovating responsibly. And so investing in and understanding what technologies like privacy enhancing technologies can do to be able to innovate responsibly, I think that is where I would leave the audience to continue to think about.

That's great. Thank you, Christy, and thank you all for joining. In the RSAC library, which I'm sure everyone's a member of, you'll find a really good talk given at the last RSA conference in twenty twenty six by Christie and by Robert Pisacek from Oblivious on the practical use of pets, which I thought was a really great presentation.

As I think either Katie or I said at the beginning, this is the first in a series dedicated to pets. So episode two is coming up soon. It's looking at implementation, and that will be available in the library where this was pretty soon. Thank you very much indeed.

Contributors
Kristie Chon Flynn

Data Protection Officer, Google

John Elliott

Author Fellow, Pluralsight


Share With Your Community

Related Videos