DPolicy: Managing Privacy Risks Across Multiple Releases with Differential Privacy
Nicolas K\"uchler, Alexander Viand, Hidde Lycklama, Anwar Hithnawi

TL;DR
DPolicy is a system that manages cumulative privacy risks across multiple data releases using differential privacy, enabling organizations to enforce complex privacy guarantees and improve privacy risk management.
Contribution
It introduces a high-level policy language and a framework for considering multiple DP guarantees simultaneously for organizational privacy risk management.
Findings
DPolicy effectively manages privacy risks across multiple releases.
The system enables formalization of complex privacy guarantees.
Evaluation shows improved privacy risk mitigation.
Abstract
Differential Privacy (DP) has emerged as a robust framework for privacy-preserving data releases and has been successfully applied in high-profile cases, such as the 2020 US Census. However, in organizational settings, the use of DP remains largely confined to isolated data releases. This approach restricts the potential of DP to serve as a framework for comprehensive privacy risk management at an organizational level. Although one might expect that the cumulative privacy risk of isolated releases could be assessed using DP's compositional property, in practice, individual DP guarantees are frequently tailored to specific releases, making it difficult to reason about their interaction or combined impact. At the same time, less tailored DP guarantees, which compose more easily, also offer only limited insight because they lead to excessively large privacy budgets that convey limited…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Privacy, Security, and Data Protection · Information and Cyber Security
