Evidence Domain

Privacy Engineering

What it studies

The technical and architectural implementation of privacy: data minimisation, aggregation, anonymisation and its limits, consent architectures, suppression, access control and privacy-by-design as an engineering discipline rather than a policy statement.

Why it matters

Workplace evidence is people data, and the entire evidence enterprise stands on its legitimacy: one surveillance scandal poisons every stream for years. Privacy engineering is what makes the evidence architecture trustworthy by construction — cohort thresholds that hold, consent that is real and revocable, aggregation that resists re-identification. It is not the compliance layer on the platform; it is the condition of the platform's licence to exist.

Questions it answers
  • What is the minimum data this decision actually requires?
  • Do the aggregation and suppression controls genuinely prevent identification — including by combination?
  • What does meaningful consent require in an employment relationship, where power is asymmetric?
  • Where are the re-identification and function-creep risks in this evidence architecture?
Evidence sources
  • Privacy engineering research and privacy-by-design frameworks
  • Re-identification and anonymisation-limits literature (aggregation is harder than it looks)
  • GDPR and employment-context data protection guidance
  • The governance record: consent rates, suppression events, access logs
Design and policy implications

Data minimisation as the default posture — collect for decisions, not for optionality; cohort thresholds (minimum five) enforced technically, not procedurally; individual-level data only with explicit, revocable, consequence-free consent; purpose limitation engineered so function creep requires deliberate governance rather than quiet drift; the negative guarantees published and kept.

Related methods
Common misuse

Anonymisation optimism: 'the data is anonymised' claimed for datasets that re-identify trivially by combination (team, floor, day). The engineering literature is clear that aggregation and suppression require actual design; privacy claims that rest on intention rather than architecture fail exactly when tested.

Further research

Meaningful consent under employment power asymmetry remains genuinely unresolved — legally, ethically and practically. It is the workplace evidence field's hardest honest question.