Privacy in Tech
An audio course on privacy engineering and privacy-enhancing technology for technology professionals, with a guide, a one-page map and a self-check for each of its five parts, and a glossary. Written as a companion to our classroom course. Study material, not legal advice.
Listen while driving or commuting: subscribers of the podcast's paid tier get every episode in their podcast app.
5 parts, 18 episodes, 3 h 48 min of audio. Each part also has a guide, a one-page map and a self-check, and the course has a glossary.
Premium Content
Subscribe to unlock this course and all premium privacy training content.
Part I
What are we protecting, and from what?
Covers: What privacy means to an engineer, principles, the data life cycle, privacy harms, risk models and frameworks, values in design.
Episode 1. What privacy means to an engineer
What privacy means, the principles behind it, and how privacy sits beside security and data governance.
14:08Episode 2. The life of a piece of data
Personal data from collection to destruction, with the rule, the main risk and a real case at each stage.
9:21Episode 3. What goes wrong, and how likely it is
Naming privacy problems, weighing risk, and bringing people's values into design.
15:50
- Part I guide (PDF)
- Part I one-page map (PDF)
- Part I self-check (PDF)
Part II
Who does the privacy work, and with what paperwork?
Covers: Roles, turning law into requirements, standards, policies and inventories, contracts, privacy and data protection impact assessments, data flows, threat modelling, incidents.
Episode 1. The technologist in the privacy team
The people who do the privacy work, how law is turned into requirements, and the standards they work to.
14:06Episode 2. Policies, inventories, contracts and assessments
The documents needed before a contract is signed: notice and policy, inventory and classification, contracts, and the impact assessment.
12:16Episode 3. Mapping systems, modelling threats, handling incidents
Mapping systems and data flows, data crossing borders, modelling threats, handling incidents, and measuring the programme.
15:25
- Part II guide (PDF)
- Part II one-page map (PDF)
- Part II self-check (PDF)
Part III
How do we build privacy in?
Covers: Privacy by design principles, the engineering objectives, requirements, design strategies and patterns, usable notices and controls, dark patterns, testing and monitoring.
Episode 1. Principles and objectives
The seven principles of privacy by design, how they became a legal duty and a standard, and the three engineering objectives.
10:11Episode 2. From requirement to design
How a privacy goal becomes a testable requirement, and a requirement becomes a design through strategies, tactics and patterns.
11:14Episode 3. Interfaces people can use
Notices, consent and privacy controls that people can use, and the dark patterns the rules now address.
14:54Episode 4. Testing and watching the live system
Testing a design before launch, and watching the live system every day after it.
9:31
- Part III guide (PDF)
- Part III one-page map (PDF)
- Part III self-check (PDF)
Part IV
Which tools protect the data?
Covers: Encryption and post-quantum migration, identity and authentication, access control and security, de-identification and the law on pseudonymised and anonymous data, privacy-enhancing technologies.
Episode 1. Encryption and its limits
How encryption, keys and certificates protect data in transit, at rest and in use, and the move to post-quantum cryptography.
13:01Episode 2. Who are you? Identity, authentication and access
How little identity a task needs: passwords and passkeys, federation and credentials, age checks, and access control.
12:48Episode 3. Removing the person: de-identification
What identifies a person, the techniques that weaken the link, and the law on pseudonymised and anonymous data.
13:40Episode 4. Using data without seeing it
Privacy-enhancing technologies, from differential privacy to computing on hidden data, what each protects and how to choose one.
12:07
- Part IV guide (PDF)
- Part IV one-page map (PDF)
- Part IV self-check (PDF)
Part V
What does new technology change?
Covers: Online tracking and ad tech, location, cameras and connected devices, machine learning and its privacy attacks, generative AI, retrieval and agents, the rules for AI.
Episode 1. Being followed online
What the network can see, cookies and fingerprinting, the browsers' answers, and consent and privacy signals.
14:33Episode 2. Sensors everywhere
Location, cameras, microphones and drones, and connected devices, cars and cities.
9:59Episode 3. Machine learning and its privacy attacks
Where personal data sits in machine learning, how models give it away, and the limits of unlearning.
9:19Episode 4. Assistants, agents and the law catching up
Assistants and agents, the rules for AI, harms that are not leaks, and the close of the series.
15:26
- Part V guide (PDF)
- Part V one-page map (PDF)
- Part V self-check (PDF)
Glossary
The terms used across the course, each tagged with the part where it is explained.
- Glossary (PDF)