1. Privacy by Design advanced

    On 20 March 2023 a change to OpenAI's servers spiked Redis request cancellations, a redis-py bug returned another user's cached reply on a pooled connection, and chat titles plus payment details of roughly 1.2% of active ChatGPT Plus subscribers were exposed during a nine-hour window. Which design decision turned a client-library bug into a personal-data breach?

    3 min answer openaicacheconnection-poolbreach
  2. Privacy by Design advanced

    What does privacy by design mean architecturally rather than as a policy statement, and which decisions must be made first?

    2 min answer jupiterprivacyminimisationdefaults
  3. Privacy by Design advanced

    What does privacy by design mean concretely at the point of designing a system, rather than as a principle?

    1 min answer privacyminimisationdesigndefaults
  4. Privacy-Enhancing Technologies advanced

    A product lead at a super-app of Tencent/WeChat's shape says the new on-device keyboard model can ship without a consent flow because federated learning means the data never leaves the phone. You have ten minutes at the architecture review board. What do you say and what would you actually build?

    3 min answer federated-learningsecure-aggregationdifferential-privacyon-device-ml
  5. Privacy-Enhancing Technologies advanced

    A statistics team wants to publish counts from a sensitive dataset under differential privacy. Working from the way the US Census Bureau ran its 2020 disclosure avoidance system, estimate how the privacy budget constrains what can be published and which choice dominates the accuracy you end up with.

    3 min answer differential-privacycensusepsilonbudget
  6. Privacy-Enhancing Technologies advanced Multiple choice

    Two retailers want the size of their shared customer overlap and the average basket of that overlap group without either seeing the other's customer list. Which technique fits the requirement as stated?

    2 min answer psidifferential-privacyclean-roomhomomorphic-encryption
  7. Privacy-Enhancing Technologies advanced

    What do privacy-enhancing technologies actually enable, and what do they cost in practice?

    2 min answer privacy-techdifferential-privacyfederated-learninghomomorphic
  8. Pseudonymisation advanced

    A travel metasearch of Expedia's shape replaces every traveller email with a deterministic HMAC token before the data reaches the analytics warehouse and before any file goes to an advertising partner. Two years later an audit finds that one partner can name individual travellers. The token vault was never breached. What failed?

    3 min answer pseudonymisationtokenisationlinkabilityre-identification
  9. Pseudonymisation advanced

    On 4 August 2006 AOL published about 20 million search queries from more than 650,000 users over three months, with usernames replaced by random numbers. Within days the New York Times had identified user 4417749 as a named individual from the content of her searches alone. What failed, which design assumption made it possible, and what would have prevented it?

    3 min answer aolre-identificationquasi-identifiersanonymisation
  10. Pseudonymisation advanced

    Pseudonymisation reduces regulatory obligations. What does it actually provide, and where is it commonly overstated?

    2 min answer pseudonymisationanonymisationre-identificationkey-separation
  11. Records Retention & Legal Hold advanced

    A regulated fintech must prove every customer-facing balance can be reconstructed from an audit trail. Compare event sourcing, CDC into an immutable log, and conventional tables with a triggered audit log.

    3 min answer nubankevent-sourcingcdcaudit
  12. Records Retention & Legal Hold advanced

    Litigation requires preserving all records relating to a matter, overriding normal retention. How is that implemented?

    2 min answer legal-holdretentionpreservationdiscovery