Privacy-Enhancing Technologies
Privacy-enhancing technologies (PETs) are tools, techniques, and practices designed to protect individuals' privacy while still allowing data to be collected, analyzed, or shared. In practice, they aim to let organizations work with sensitive information without exposing the personal details of the people the data describes. As commonly presented, they can keep a person's information private even from the company handling the data.
Privacy-enhancing technologies (PETs) comprise a set of technologies, tools, and methods that enable the collection, analysis, and sharing of information while protecting data confidentiality and privacy. They are typically characterized by their ability to allow entities to access, share, and analyze sensitive data without exposing the underlying personal information, and in some configurations can prevent even the processing party from learning who a given data subject is or the content of protected communications. The precise scope of what qualifies as a PET varies across sources and application contexts; the evidence here does not enumerate specific techniques (such as cryptographic or statistical methods), so the term should be treated as an umbrella category rather than a single defined technique. Regulatory and standards treatment of PETs is jurisdiction- and context-dependent and is not established by the sources cited here.
Why it matters
Privacy-enhancing technologies address a recurring tension in AI and data-driven work: organizations often need to collect, analyze, or share sensitive information, yet doing so can expose the personal details of the individuals that data describes. PETs matter because they are commonly presented as a way to reconcile these competing pressures, enabling data to be used for analysis or collaboration while reducing the exposure of underlying personal information. For teams building or governing AI systems that rely on personal data, this makes PETs a relevant category of controls when balancing utility against privacy obligations.
The practical significance is heightened by the fact that, in some configurations, PETs can prevent even the party processing the data from learning who a given data subject is or the content of protected communications. This shifts the privacy posture from trusting an organization's internal handling practices toward technical measures that limit what any handling party can observe. That distinction can be material for compliance, contractual, and risk-management decisions, though the extent and reliability of such protections depend heavily on the specific technique and its implementation.
It is important to treat PETs as an umbrella category rather than a single guaranteed safeguard. The sources here do not enumerate specific techniques, and PETs vary widely in the protections they provide; describing a system as using a PET does not by itself establish what privacy risk is reduced or to what degree. Regulators including the U.S. Federal Trade Commission have signaled attention to the accuracy of privacy claims associated with these technologies, underscoring that stated protections should correspond to actual technical behavior. PETs reduce or manage privacy risk within their design limits rather than eliminate it.
Who it's relevant to
Inside PETs
Common questions
Answers to the questions practitioners most commonly ask about PETs.