What LINDDUN Threat Modelling Actually Does
Two versions of the same acronym circulate in study materials, which trips people up before they reach the substance. The older expansion reads linkability, identifiability, non-repudiation, detectability, disclosure of information, unawareness and non-compliance. The current framework uses shorter nouns: linking, identifying, non-repudiation, detecting, data disclosure, unawareness, non-compliance. LINDDUN means the same seven things in both. Recognise either wording and move on.
The seven privacy threat types
LINDDUN came out of the DistriNet research group at KU Leuven and now appears in privacy engineering syllabuses across Europe. The Open University’s privacy engineering course sets out each LINDDUN category with worked examples. It makes one point worth carrying into the exam. Organisations notice data disclosure and non-compliance. The other five rarely reach a design review at all.
Linking, identifying and detecting
Linking joins data points together to reveal more about a person or a group. Harm arrives without identification. Learning someone’s preferences well enough to target them is already a privacy problem.
Identifying learns who someone is in a context where they expected anonymity. It runs directly, by demanding a verified phone number before access. It also runs indirectly, by re-identifying records in a badly anonymised dataset.
Detecting sits close to both and works without reading the data. Knowing that a record exists is enough. A login page returning a welcome message for a registered address tells an attacker something the account holder never disclosed.
Non-repudiation, data disclosure and the rest
Non-repudiation inverts a security goal. Security teams want users unable to deny their actions. In privacy terms, plausible deniability sometimes protects someone whose search history could later become evidence against them.
Data disclosure covers the traditional breach and reaches further. Excessive collection counts. An organisation collecting location continuously without needing it is itself the threat actor, whatever the state of its firewalls.
Unawareness and unintervenability covers cases where users lack information about their privacy or control over it. One overlooked version: a poorly informed user causes harm to somebody else. Non-compliance is the one category pointing at the organisation rather than the individual, covering unlawful processing and weak data governance.
How the LINDDUN method runs
The European Data Protection Supervisor set out the LINDDUN method in its preliminary opinion on privacy by design. That is worth knowing, because it puts a regulator’s description on the record. Four moves make up the approach.
First, build a data flow diagram from a high-level description of the system. Second, map the threat categories onto the elements of that diagram: entities, data flows, data stores and processes. Third, find the elements where a mapped threat poses real risk. Work through the threat trees the framework supplies, then prioritise. Fourth, choose mitigation strategies and privacy-enhancing technologies for the threats that survived prioritisation.
The gap the framework leaves open
Here is the detail worth remembering. LINDDUN does not tell you how to assess risk. The EDPS says so directly: the criteria driving prioritisation belong to the organisation applying the method. That is flexibility rather than an oversight, and it explains why LINDDUN pairs naturally with a separate risk methodology.
It also explains a common misreading. Running LINDDUN does not produce a risk score. It produces a structured list of privacy threats with somewhere to look for each. Deciding what counts as serious stays with the organisation.
LINDDUN in the CIPT exam
The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Privacy risk models and threat models sit in Domain I, the privacy technologist’s role. LINDDUN appears there by name, beside contextual integrity and the harms taxonomies.
Exam items generally describe a situation and ask which category it illustrates. Recognition beats deep application. Two pairs catch people: linking against identifying, and detecting against data disclosure. Drill those four until the distinction is instant. Our piece on the three privacy engineering objectives covers the NIST vocabulary sitting beside LINDDUN in the same domain. The piece on dark patterns in interfaces shows interference threats in a product setting.
One exercise beats rereading the list. Take a system you already understand, sketch its data flow diagram, and walk all seven types across every element. Twenty minutes of that fixes the categories in place. The CIPT Exam Question Masterclass at €195 picks up the recognition drill afterwards.
