4.2 Privacy Threat Models: LINDDUN and MITRE PANOPTIC
Key Takeaways
LINDDUN's seven threat types are Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness and Unintervenability, and Non-compliance.
LINDDUN's first five threat types are hard privacy threats (anonymity, unlinkability, confidentiality); unawareness and non-compliance are soft privacy threats (transparency, control, compliance).
LINDDUN comes in variants: LINDDUN GO (a card-based workshop method), LINDDUN PRO (systematic analysis of each DFD element), and LINDDUN MAESTRO (in-depth analysis).
MITRE PANOPTIC (Pattern and Action Nomenclature Of Privacy Threats In Context) combines Contextual Domains with Privacy Activities made up of privacy threat actions.
PANOPTIC was built from real non-breach privacy cases, counts inactions such as missing notice or consent as threats, and treats the system itself as a possible threat agent.
4.2 Privacy Threat Models: LINDDUN and MITRE PANOPTIC
Quick Summary: A threat model is a structured catalog of what can go wrong. Security teams use STRIDE or MITRE ATT&CK; the CIPT BoK names two privacy threat models: LINDDUN, from KU Leuven, which walks through a system design element by element, and MITRE PANOPTIC, which describes how real privacy attacks unfold in context. Both treat privacy harms that are not security breaches as first-class threats.
Risk frameworks (Section 4.1) tell you how to manage privacy risk; threat models help you find the risks in a specific system. A privacy threat model has to cover things security models ignore: the organization's own processing, people who do not know what is happening to their data, and failures to act, such as never giving notice.
LINDDUN: Seven Privacy Threat Types
LINDDUN was first published in 2011 by researchers at KU Leuven's DistriNet group and has been revised several times. Its acronym lists seven threat types, using the current names:
| Threat Type | What Goes Wrong | Example |
|---|---|---|
| Linking | Data items or actions can be linked to the same person, even without knowing who that person is | Two "anonymous" app sessions are linked because both send the same device fingerprint |
| Identifying | A person's identity can be learned from data or actions | A rare combination of ZIP code, birth date, and sex points to one patient |
| Non-repudiation | A person cannot deny having done something, where deniability matters | A whistleblowing portal logs signed, timestamped submissions tied to user accounts |
| Detecting | Someone can tell whether a person or item of interest exists, without seeing its content | A login form responds faster for registered email addresses than unregistered ones |
| Data Disclosure | Personal data is disclosed to parties who should not have it | An API returns full profiles to any authenticated caller |
| Unawareness and Unintervenability | People are not informed about, or cannot influence, how their data is processed | No dashboard to see or delete inferred interests |
| Non-compliance | Processing does not follow legislation, regulation, or policy | Data kept far beyond the retention period in the published notice |
Older study materials use the earlier names Linkability, Identifiability, Detectability, Disclosure of information, and Unawareness. The meaning is the same; the current version renamed them as actions and folded "unintervenability" (the inability to intervene) into the sixth category.
Hard and Soft Privacy
LINDDUN groups its types into two families:
- Hard privacy threats (linking, identifying, non-repudiation, detecting, data disclosure) concern properties such as anonymity, unlinkability, plausible deniability, undetectability, and confidentiality. Mitigations tend to be technical: pseudonyms, anonymous credentials, encryption, noise.
- Soft privacy threats (unawareness and unintervenability, non-compliance) concern transparency, user control, and compliance. Mitigations tend to combine design and governance: notices, dashboards, consent and rights tooling, retention enforcement.
How LINDDUN Is Applied
LINDDUN starts from a data flow diagram (DFD) of the system, made of external entities, processes, data stores, and data flows. Analysts walk through each element and ask which threat types apply, using threat trees that break each type into concrete conditions. Section 16.4 walks through this process step by step, including the classic mapping table of threat types to DFD elements.
LINDDUN offers three variants to fit different teams:
- LINDDUN GO: a lightweight, card-based method for workshops. Each card describes a common threat; teams walk through the cards against a whiteboard sketch.
- LINDDUN PRO: a systematic method that analyzes each DFD element (or each flow) against the threat trees.
- LINDDUN MAESTRO: the most in-depth variant, for detailed, high-assurance analyses.
LINDDUN also pairs threats with mitigation strategies and privacy-enhancing technologies, such as pseudonymous identifiers against linking or differential privacy against detecting.
MITRE PANOPTIC: Privacy Threats in Context
PANOPTIC stands for Pattern and Action Nomenclature Of Privacy Threats In Context. MITRE released it publicly in late 2023, and version 2.0 followed in 2024. Where LINDDUN starts from a system design, PANOPTIC starts from how privacy attacks actually happen: it was built by deconstructing hundreds of documented non-breach privacy cases, mostly U.S. Federal Trade Commission and Federal Communications Commission matters, and cataloging their components. It plays a role for privacy similar to the one MITRE ATT&CK plays for cyberattacks, but its structure is different.
PANOPTIC combines two taxonomies:
- Contextual Domains (Environment, Distribution, Interaction, Engagement, and Data Type) describe the circumstances of an attack, such as whether it happens in a physical store or online and whether it involves location, biometric, or health data.
- Privacy Activities describe the attack itself. Version 2.0 lists Notice, Consent, Collection, Insecurity, Identification, Quality Assurance, Manageability, Aggregation, Processing, Sharing, Use, Retention and Destruction, and Deviations. Each activity contains specific privacy threat actions with identifiers (for example, an absent notice, an out-of-sequence consent request, or profiling).
What Makes PANOPTIC Different
- Actions and inactions. A privacy attack can be something an organization fails to do, such as never giving notice or offering no opt-out. Security threat models rarely treat inaction as an attack.
- The system as threat agent. The organization's own system, operating as designed, can be the source of the threat.
- Benign and malicious intent. Privacy harm can result from well-intentioned actions.
- No duplication of security models. PANOPTIC deliberately leaves out attacks covered by cybersecurity threat models, such as breaches of confidentiality, and focuses on privacy harms beyond them.
Example: MITRE's tutorial maps the FTC's case against Nomi Technologies, which tracked shoppers' phones inside retail stores. The context includes a physical environment and location data; the activities include collection by tracking, aggregation into reports for retailers, and a notice failure, because the promised in-store opt-out did not exist.
Uses of PANOPTIC
- Privacy threat assessment of systems and environments, integrated into the systems engineering life cycle.
- Privacy risk modeling, combining threats with vulnerability and consequence models (most privacy risk models only address consequences).
- Privacy red teaming, emulating privacy adversaries to find gaps before real ones do.
LINDDUN and PANOPTIC Side by Side
| Dimension | LINDDUN | MITRE PANOPTIC |
|---|---|---|
| Starting point | The system's data flow diagram | Real-world privacy attacks and their context |
| Structure | Seven threat types with threat trees | Contextual Domains plus Privacy Activities and threat actions |
| Typical use | Design-time threat elicitation by engineering teams | Threat assessment, risk modeling, and privacy red teaming |
| Inactions | Covered indirectly (unawareness, non-compliance) | Explicitly modeled as threat actions |
| Origin | KU Leuven DistriNet (academic) | MITRE (empirical, from FTC and FCC cases) |
The two are complementary: LINDDUN helps engineers ask the right questions about a specific design, while PANOPTIC reminds them how similar systems have actually harmed people.
A privacy technologist conducts a LINDDUN privacy threat modeling session on a microservice architecture and maps identified threats against the system's Data Flow Diagram (DFD). Which LINDDUN threat category is architecturally applicable ONLY to External Entity DFD components?
Linkability
Data Disclosure
Unawareness
Detectability
A privacy team wants a threat model built from documented real-world privacy cases that explicitly counts failures to act, such as never providing notice, as threat actions. Which model fits best?
The CIA triad, because availability failures include missing notices
LINDDUN GO, because its threat cards are derived directly from FTC and FCC enforcement actions
STRIDE, because its repudiation category covers organizations that fail to act or give notice
MITRE PANOPTIC, because it combines contextual domains with privacy activities and models both actions and inactions
In LINDDUN, which threat types are classified as soft privacy threats?
Detecting and data disclosure
Non-repudiation and detecting
Linking and identifying, because they concern who the person is
Unawareness and unintervenability, and non-compliance
Sections you finish are checked off in the contents.