Back to Frameworks

ENISA Data Protection Engineering - From Theory to Practice

European Union (ENISA)
vMultiple reports released between 2020 and 2024 (each report has its own publication date)
7 domains
28 controls

ENISA's primary report on the practical engineering of data protection (the umbrella PET / privacy-enhancing-technology document for the EU). 'Data Protection Engineering - From Theory to Practice' (January 2022) sets the connection from Data Protection by Design (GDPR Art.25) to engineering practice via the DPIA process, and surveys the main PETs and their applicability to data protection principles: anonymisation and pseudonymisation, differential privacy, homomorphic encryption, secure multiparty computation, trusted execution environments, private information retrieval, synthetic data, end-to-end encryption, proxy/onion routing, privacy-preserving storage, attribute-based credentials, zero-knowledge proofs, privacy policies/icons/sticky policies, privacy preference signals, privacy dashboards, consent management, and mechanisms for exercising data subject rights of access, erasure and rectification. Complementary ENISA PET works are referenced in the report (Pseudonymisation techniques 2019, Advanced Pseudonymisation 2021, Engineering Personal Data Sharing 2023, Engineering Personal Data Protection in EU Data Spaces 2023).

Verified

ENISA Data Protection Engineering - From Theory to Practice is a compliance framework from European Union (ENISA) with 7 domains and 28 controls that map to 2 other frameworks. The largest domains are ENISA DPE - Transparency, Intervenability and User Control (8 controls), ENISA DPE - Privacy-Preserving Computation (5 controls), ENISA DPE - Anonymisation and Pseudonymisation (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

ENISA DPE - Access, Communication and Storage

3 controls
Controls in the ENISA DPE - Access, Communication and Storage domain of ENISA Data Protection Engineering - From Theory to Practice3 controls
CodeTitle
ENISA-DPE-5.1Communication channels (end-to-end encryption, proxy/onion routing)
ENISA-DPE-5.2Privacy-preserving storage
ENISA-DPE-5.3Privacy-enhancing access control and authorisation (ABC, ZKP)

ENISA DPE - Anonymisation and Pseudonymisation

4 controls
Controls in the ENISA DPE - Anonymisation and Pseudonymisation domain of ENISA Data Protection Engineering - From Theory to Practice4 controls
CodeTitle
ENISA-DPE-3.1Anonymisation
ENISA-DPE-3.2Pseudonymisation
ENISA-DPE-3.3Differential privacy
ENISA-DPE-3.4Selecting an anonymisation scheme

ENISA DPE - Conclusions and Assurance

3 controls
Controls in the ENISA DPE - Conclusions and Assurance domain of ENISA Data Protection Engineering - From Theory to Practice3 controls
CodeTitle
ENISA-DPE-7.1Defining the most applicable technique
ENISA-DPE-7.2Establishing the state of the art
ENISA-DPE-7.3Demonstrate compliance and provide assurance

ENISA DPE - Engineering Data Protection

3 controls
Controls in the ENISA DPE - Engineering Data Protection domain of ENISA Data Protection Engineering - From Theory to Practice3 controls
CodeTitle
ENISA-DPE-2.1From DPbD to data protection engineering
ENISA-DPE-2.2Connection with the Data Protection Impact Assessment
ENISA-DPE-2.3Privacy-Enhancing Technologies (overview and taxonomy)

ENISA DPE - Introduction and Data Protection by Design

2 controls
Controls in the ENISA DPE - Introduction and Data Protection by Design domain of ENISA Data Protection Engineering - From Theory to Practice2 controls
CodeTitle
ENISA-DPE-1.1Data Protection by Design
ENISA-DPE-1.2Scope of data protection engineering

ENISA DPE - Privacy-Preserving Computation

5 controls
Controls in the ENISA DPE - Privacy-Preserving Computation domain of ENISA Data Protection Engineering - From Theory to Practice5 controls
CodeTitle
ENISA-DPE-4.1Homomorphic encryption
ENISA-DPE-4.2Secure multiparty computation (MPC)
ENISA-DPE-4.3Trusted execution environments (TEEs)
ENISA-DPE-4.4Private information retrieval (PIR)
ENISA-DPE-4.5Synthetic data

ENISA DPE - Transparency, Intervenability and User Control

8 controls
Controls in the ENISA DPE - Transparency, Intervenability and User Control domain of ENISA Data Protection Engineering - From Theory to Practice8 controls
CodeTitle
ENISA-DPE-6.1Privacy policies
ENISA-DPE-6.10Exercising the rights to erasure and rectification
ENISA-DPE-6.2Privacy icons
ENISA-DPE-6.3Sticky policies
ENISA-DPE-6.4Privacy preference signals
ENISA-DPE-6.5Privacy dashboards
ENISA-DPE-6.6Consent management (gathering and systems)
ENISA-DPE-6.9Exercising the right of access

Maps to 2 other frameworks

28 total controls
GDPR
21 source controls mapped|6 target controls covered
75%
NIST Cybersecurity Framework 2.0
3 source controls mapped|3 target controls covered
11%

What is ENISA Data Protection Engineering - From Theory to Practice and who does it apply to?

ENISA Data Protection Engineering - From Theory to Practice is a compliance framework from European Union (ENISA) with 7 domains and 28 controls. ENISA's primary report on the practical engineering of data protection (the umbrella PET / privacy-enhancing-technology document for the EU). 'Data Protection Engineering - From Theory to Practice' (January 2022) sets the connection from Data Protection by Design (GDPR Art.25) to engineering practice via the DPIA process, and surveys the main PETs and their applicability to data protection principles: anonymisation and pseudonymisation, differential privacy, homomorphic encryption, secure multiparty computation, trusted execution environments, private information retrieval, synthetic data, end-to-end encryption, proxy/onion routing, privacy-preserving storage, attribute-based credentials, zero-knowledge proofs, privacy policies/icons/sticky policies, privacy preference signals, privacy dashboards, consent management, and mechanisms for exercising data subject rights of access, erasure and rectification. Complementary ENISA PET works are referenced in the report (Pseudonymisation techniques 2019, Advanced Pseudonymisation 2021, Engineering Personal Data Sharing 2023, Engineering Personal Data Protection in EU Data Spaces 2023). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ENISA Data Protection Engineering - From Theory to Practice actually require?

ENISA Data Protection Engineering - From Theory to Practice has 28 controls organised across 7 domains. The largest domains are ENISA DPE - Transparency, Intervenability and User Control (8 controls), ENISA DPE - Privacy-Preserving Computation (5 controls), ENISA DPE - Anonymisation and Pseudonymisation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ENISA Data Protection Engineering - From Theory to Practice do I already cover?

ENISA Data Protection Engineering - From Theory to Practice maps to 2 other compliance frameworks. The top mapping partners are GDPR (75% coverage), NIST Cybersecurity Framework 2.0 (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ENISA Data Protection Engineering - From Theory to Practice?

Start your ENISA Data Protection Engineering - From Theory to Practice compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ENISA Data Protection Engineering - From Theory to Practice requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required