skip to content

LINDDUN Privacy Threats

LINDDUN's seven types - linking, identifying, non-repudiation, detecting, data disclosure, unawareness, non-compliance - map onto a DFD. Interviewers probe why non-repudiation is a threat here.

on this pageshow

questions

4

What are the seven LINDDUN threat types, and which privacy property does each one break?

level: middleimportance: must knowfreq 72%

answer

  1. Seven types, one per privacy property
  2. Each letter negates something you wanted
  3. Two different N's, don't merge them
  4. Existence hidden versus content hidden
  5. One type sits on the person, not a component

basics

~10 s

LINDDUN covers Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness and Non-compliance. Each names the failure of a privacy property: unlinkability, anonymity, plausible deniability, undetectability, confidentiality, user awareness, and policy compliance.

solid answer

~40 s

LINDDUN is a privacy threat modeling method whose seven letters are threat types, each the negation of a privacy property. Linkability breaks unlinkability: you can tell two items concern the same person. Identifiability breaks anonymity: you can pin an item to a named individual. Non-repudiation breaks plausible deniability: someone cannot deny having acted. Detectability breaks undetectability: you can tell a record exists even without reading it. Disclosure of information breaks confidentiality. Unawareness breaks the subject's understanding and control of what is shared about them. Non-compliance breaks the system's own stated policy for how data is handled. Current LINDDUN material relabels several of these as Linking, Identifying, Detecting, Data Disclosure and Unawareness & Unintervenability, but the seven categories are the same. The list is a categorisation of threats, not a severity rating.

go deeper

for a junior

Be able to say LINDDUN is the privacy counterpart to a security threat-category method, and that it has seven threat types aimed at protecting the person whose data is processed rather than the system.

for a middle

Expect to list all seven and name the privacy property each negates, and to explain the pairs people confuse: linkability versus identifiability, and detectability versus disclosure.

for a senior

Show that you use the list to drive a real design conversation — which types actually bite on the system in front of you, and why the ones that survive encryption are usually the interesting ones.

for a principal

Own the framing question: what does adopting a privacy threat taxonomy commit the organisation to, given it produces categorised threats but no ratings and no legal conclusions, and who consumes that output.

## What LINDDUN is LINDDUN is a privacy threat modeling methodology developed by the DistriNet research group at KU Leuven. Structurally it works the way STRIDE does: you take a model of the system, walk its elements, and ask a fixed list of threat categories against each one. What changes is the asset. A security pass protects the system and its owner; LINDDUN protects the **data subject** — the person whose data the system processes — and the party you are modeling against may be someone with entirely legitimate access. The acronym is seven **threat types**. Each is the mirror image of a privacy property, so the fastest way to remember the list is to remember the properties and negate them. | Threat type | Property it breaks | Reading in one line | | --- | --- | --- | | **L**inkability | Unlinkability | Two items can be told to concern the same subject, without necessarily knowing who | | **I**dentifiability | Anonymity / pseudonymity | An item can be tied to a specific individual | | **N**on-repudiation | Plausible deniability | A person cannot credibly deny having done something | | **D**etectability | Undetectability / unobservability | The existence of an item can be distinguished, even if its content stays hidden | | **D**isclosure of information | Confidentiality | The content itself is exposed to someone not entitled to it | | **U**nawareness | Content awareness and intervenability | The subject does not understand, or cannot control, what is shared about them | | **N**on-compliance | Policy and consent compliance | Processing departs from the policy the system itself states | ## The distinctions that get probed **Linkability versus identifiability.** Linkability is the weaker, earlier condition: given two records you can say "same person" without knowing the name. Identifiability is the stronger one: you can say *which* person. Most real privacy failures are a linkability chain that ends in identifiability, because a pseudonym only survives until something joins it to an identified record. Treating them as one category is the most common mistake — the interesting mitigation decisions usually sit on linkability, before identity is ever established. **Detectability versus disclosure.** Disclosure is about content. Detectability is about the *existence* of a record. Knowing that a person has a file in a patient register, an asylum caseload, or a whistleblower system can be the whole harm even if the file's contents remain encrypted. Candidates who collapse detectability into disclosure lose exactly the threats that encryption does not fix. **The two N's.** Non-repudiation and non-compliance are unrelated, and mixing them up is a giveaway. Non-repudiation is about a person being irrefutably bound to an action — a threat here, because for some flows the subject needs to be able to deny. Non-compliance is about the system's handling of data diverging from what it claims: retaining beyond a stated period, processing for a purpose it never declared, ignoring a stated consent state. **Unawareness is about the person, not the system.** It covers a subject oversharing because the interface never made the consequence visible, and a subject unable to see, correct, or stop what is held. It is the one type that sits on the human rather than on a component. ## What LINDDUN does not do The seven types are **categories of threat** — things that could go wrong. They are not vulnerabilities (the concrete flaw that permits the threat), not risks (the rated consequence), and not controls. LINDDUN itself carries no scoring model; you enumerate first and prioritise afterwards with whatever rating scheme the organisation already uses. A candidate who answers "LINDDUN tells you the severity" has confused enumeration with assessment. It is also not a legal checklist. The non-compliance type asks whether the system does what its own stated policy says; it does not tell you which lawful basis applies or what a data-subject request must contain. ## Naming versions Recent LINDDUN material uses gerunds and clearer labels — Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness & Unintervenability, Non-compliance. The count and the meanings are unchanged; the renaming mostly removes the awkward noun forms and makes explicit that unawareness includes the subject's inability to intervene. Either vocabulary is acceptable in an interview as long as you can list seven and say what property each one negates.

  • How does linkability differ from identifiability?
    Linkability means you can tell that two items concern the same subject without knowing who that subject is — two taps on the same card, two sessions with the same device fingerprint. Identifiability means you can attach the item to a specific person. Linkability is the precursor: build a large enough linked set and one joining record turns it into an identified profile. Mitigations usually have to land at the linkability stage, because once identity is established there is nothing left to protect.
  • Which LINDDUN type is the odd one out, and why?
    Unawareness. The other six describe properties of data or of system behaviour; unawareness describes the data subject's state — they share more than they realise, or cannot see and correct what is held about them. That is why it is analysed against the person in the model rather than against a store or a flow, and why its mitigations are about transparency and control rather than about protecting a component.
  • Does LINDDUN tell you how severe a privacy threat is?
    No. LINDDUN is an enumeration method: it produces a categorised list of what could go wrong. Rating and prioritisation are a separate step, done with whatever scheme the organisation already uses, weighing the impact on the individual rather than on the service. Candidates who claim the method scores threats have confused threat elicitation with risk assessment — the same distinction that separates naming a threat from rating a risk.

Think of a set of privacy promises — you can't be linked, named, pinned to an act, noticed, read, kept in the dark, or handled off-policy. LINDDUN is that list of promises written as the seven ways each one breaks.

saying these in an interview costs you the question

  • Says LINDDUN has six types, mirroring STRIDE
  • Merges linkability and identifiability into one idea
  • Treats detectability as a synonym for disclosure
  • Confuses non-repudiation with non-compliance
  • Calls unawareness a system logging problem
  • Claims LINDDUN outputs a severity score

context

open as a page

Why does LINDDUN treat non-repudiation as a privacy threat when security treats it as a goal?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Non-repudiation destroys plausible deniability. Where a person must be able to deny acting, such as a whistleblower filing a report, evidence that irrefutably binds them to the act is itself the harm, so LINDDUN treats it as a threat.

open as a page

Running a per-element LINDDUN pass over a transit card tap ledger, which threats dominate and where?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Linkability on the tap ledger dominates, escalating to identifiability. A per-element pass applies six LINDDUN types to the flow, store and analytics process, but only linkability, identifiability and unawareness to the rider, whose card number is a pseudonym, not anonymity.

open as a page

When would you run LINDDUN GO instead of a full per-element LINDDUN pass, and what do you give up?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

LINDDUN GO is the lightweight card-based form: a deck of prompting cards worked against a rough system sketch with non-specialists. It trades the full method's exhaustive per-element coverage and its defensible record for speed and reach.

open as a page