LINDDUN privacy threat model for a customer-data store
You are adding a new customer-data warehouse. The privacy team wants a LINDDUN-go privacy threat model: linkability, identifiability, non-repudiation, detectability, disclosure of information, unawareness, non-compliance — per data flow.
How the gateway answered
Captured 14 May 2026 — a point-in-time run; corpora and tools have been updated since.
Build a LINDDUN-go privacy threat model for the following data flow: SaaS app → ETL service → customer warehouse → BI tool. Show threats per LINDDUN category, mitigations, and cite GDPR / ePrivacy / DPA guidance where relevant.
search(query="linkability identifiability profiling automated decis…" frameworks=[GDPR] limit=8)→ 8 results: GDPR Art. 22, 13, 14, 15, 20, 21, 47 + Recital 71search(query="electronic communications privacy confidentiality coo…" frameworks=[EPRIVACY] limit=6)→ 6 results from ePrivacy Directive — Art. 5 + Recitals 4, 6, 21, 33, 46search(query="data protection impact assessment large-scale systema…" frameworks=[GDPR] limit=6)→ 6 results: GDPR Art. 35, 37 + Recitals 72, 90, 91, 97LINDDUN-go threat model — SaaS app → ETL → customer warehouse → BI tool
Four pipeline stages, seven LINDDUN-go categories. Each row maps a privacy threat to the cited control. The GDPR coverage in this run is strong; ePrivacy is relevant only at the SaaS-collection edge.
L — Linkability
Distinct records can be tied back to the same person across the pipeline even when no direct identifier is present.
| Stage | Threat | Cited control |
|---|---|---|
| SaaS app | Session IDs + IP + UA fingerprint sufficient to re-identify | GDPR Art. 5 (data minimisation, storage limitation) |
| ETL | Join keys exposed across previously isolated datasets | GDPR Art. 35 (DPIA for systematic large-scale evaluation) |
| Warehouse | Cross-table joins enable singling-out | GDPR Recital 91 (DPIA explicitly required for systematic + extensive profiling) |
| BI | Small-cohort filters reveal individuals | Aggregation thresholds (k-anonymity); no on-point gateway citation in this run |
I — Identifiability
A pseudonymous record becomes identifiable.
| Stage | Threat | Cited control |
|---|---|---|
| SaaS app | Email + name collected when not needed | GDPR Art. 5 (purpose limitation, minimisation) |
| … |
Every claim traces to a source you can open
A typical AI assistant invents a citation that looks plausible. Ansvar retrieves the real one. Every finding above rests on one of these 10 sources — official legislation — linked wherever the source is publicly reachable; catalog rows served through the gateway are quoted as fetched. No citation is fabricated — every source was retrieved through Ansvar and can be checked.
- GDPR Article 5 — Principles relating to processingEU · regulation · gdpr-info.eu
- GDPR Article 13 — Information at collectionEU · regulation · gdpr-info.eu
- GDPR Article 14 — Information when data not from subjectEU · regulation · gdpr-info.eu
- GDPR Article 15 — Right of accessEU · regulation · gdpr-info.eu
- GDPR Article 21 — Right to objectEU · regulation · gdpr-info.eu
- GDPR Article 22 — Automated decisions including profilingEU · regulation · gdpr-info.eu
- GDPR Article 35 — DPIAEU · regulation · gdpr-info.eu
- GDPR Article 37 — DPO designationEU · regulation · gdpr-info.eu
- GDPR Recitals 71, 72, 91, 113 — Profiling and DPIA rationaleEU · regulation · gdpr-info.eu
- ePrivacy Directive 2002/58/EC Article 5 — Confidentiality of communicationsEU · regulation · eur-lex.europa.eu
Run this on your own data
This is available as a service: Threat Model as a Service. Bring your own documents and scope, and we'll run it end-to-end — every finding cited and validated by the expert who delivers it.
See the coverage behind this run on the Privacy & data protection sector page.