Privacy technology is the family of techniques that keep data confidential while it is being used rather than only at rest or in transit, and after a decade as a research category it is now shipping first at the identity layer, where the core primitives are being given away free by platforms and regulators.
Summary
Privacy technology, usually called privacy-enhancing technologies (PETs), covers secure multiparty computation (MPC), fully homomorphic encryption (FHE), zero-knowledge proofs (ZKPs), verifiable computing, trusted execution environments (TEEs) and private information retrieval (PIR). The framing that makes the category coherent is simple: in a normal online interaction, data on the device can be encrypted and data moving between device and server is protected by TLS, but data being processed on the server is not protected at all. PETs are the attempts to close that third gap, either cryptographically (MPC, FHE, ZKP) or in hardware (TEEs, marketed as confidential computing) ref ref.
The commercial thesis attached to this stack has been that securing processing unlocks data collaboration between organisations that today cannot legally or commercially share data, creating a new market variously called collaborative computing ref. A related line of argument extends the same primitives into database architecture, where secure enclaves and fast PIR would give a query engine that never sees the query or the data ref.
The parameters that decide it are three. First, performance and engineering integration: as of May 2026 the problem of making cryptographic and hardware PETs interoperable, distributable and cost-optimisable was still the subject of a fresh NSF CAREER award, which tells you the unified stack does not exist yet. Second, demand structure: practitioners interviewed across 2023 consistently located the blocker outside the technology, in culture, incentives, risk asymmetry and the number of internal stakeholders who must agree ref ref ref. Third, value capture: in the one place where PETs have reached consumers, the primitives are being open-sourced by Google and by the European Commission itself, which makes privacy a compliance baseline rather than a product ref.
The practical consequence is that “privacy technology” now needs splitting into two very different things: a shipping, regulator-driven ZK identity layer, and an enterprise secure-analytics market that has been three years away for at least five years.
Viability (3/5)
The general-purpose side is weaker. An NSF CAREER award dated 13 May 2026 funds software abstractions, a distributed fault-tolerant runtime and a cost-based optimiser to make FHE, MPC and TEEs usable in one pipeline, worth $422,683. The existence of that project in 2026 is the clearest available signal that scalable, deployable secure analytics remains unsolved engineering rather than a productisation exercise, consistent with a 2023 practitioner account of why MPC, ZKP and FHE struggle for adoption and why selective rather than blanket encryption is the pragmatic route ref. Sources contain no benchmark numbers, so the size of the remaining performance gap cannot be assessed here.
TLDR: ZK identity works and is in app stores; general secure analytics is still a funded research problem in 2026.
Drivers (3/5)
Demand: eIDAS 2.0 encourages privacy-enhancing technologies including ZKPs in the wallet, which converts the primitive from a differentiator into an expectation, and the EU shipped an age-verification blueprint and app in April 2026 ref. Outside identity, the demand case in the sources is argued rather than demonstrated: more data continues to be a business driver and machine learning is expected to be the main catalyst for data-sharing tools ref; incumbents holding monolithic data estates are said to carry all the data risk, making federation inevitable ref. Counterweight: the same interview series repeatedly identifies data sharing as cultural rather than technical, and expects global data-sharing rules to remain unlikely because of differing values ref ref.
Supply: the constraint is loosening fast in identity, because the platforms and the regulator are both giving the code away, and the stated pattern is that commoditising a layer protects a profit pool above or below it, the same mechanism used when Google donated AP2 to FIDO, Cloudflare put Web Bot Auth into the IETF and Coinbase gave x402 to the Linux Foundation ref. On the analytics side supply is still constrained by scarce cryptography and systems engineering, which is what public research money is being pointed at.
TLDR: Regulation is the only hard demand driver in the sources, and it is concentrated in identity; supply is now free.
Novelty (3/5)
The thing PETs are better than is the status quo of encrypting storage and transport and leaving processing in the clear, which is the whole basis of the category ref. In identity the comparison is sharper: a ZKP-based age attestation replaces handing over a document or a full identity record, and no conventional alternative achieves that, which is why the regulator has written the primitive into its own reference implementation ref. TEEs are a distinct claim again, offering confidentiality and integrity in mainstream cloud hardware rather than through cryptography ref, and one practitioner argues integrity matters as much as confidentiality and that crypto-agility is systematically underrated ref.
What the sources do not provide is magnitude. There are no throughput, latency or cost figures for FHE, MPC or PIR against plaintext computation anywhere in this evidence base, and the fact that a 2026 research project is still building the cost-modelling framework needed to choose between these technologies implies the tradeoff space is not yet even well characterised. The relevant caution from an adjacent interview is that a 5x technical improvement can still lose to the risk and cost of acting on it ref. Novelty is real; the score is held at 3 because it is unquantified here.
TLDR: A genuinely new capability against the encryption-at-rest plus TLS baseline, but the sources quantify none of the improvement.
Diffusion (2/5)
The barriers are unusually well specified in the sources and they are not technical. Selling data collaboration software means convincing five distinct groups inside the buyer ref; the vendor is competing against non-consumption, and even a large performance gain can be refused because the downside risk of sharing data is larger ref; alignment must be reached across legal, compliance, technology and business before a single supplier is onboarded ref; culture is named as the most important driver ahead of technology, with a globally fragmented data economy the expected end state ref. A vertical go-to-market is also argued to be sub-optimal, which removes the usual beachhead strategy ref, while healthcare is expected to need its own infrastructure rather than the general one ref.
The identity path diffuses differently and better, because distribution is the wallet and the mandate comes from eIDAS 2.0 rather than a sales cycle, and because the implementation cost has been driven towards zero by Google’s Apache 2.0 release and the EU’s own blueprint ref. Note that this is diffusion of a capability, not of a business. The score reflects the enterprise case, where five years of sources show diagnosis without resolution.
TLDR: Free primitives will spread through wallets; enterprise adoption is blocked by culture, stakeholder count and risk asymmetry, all documented and none solved.
Impact (3/5)
The upside claim is that securing processing lets organisations combine data across boundaries, maximising the value of data assets for private and public benefit, described as the next trillion-dollar market ref ref. That number is advocacy from the publication’s own thesis and should not be treated as evidence. The nearest independent-ish scale anchor in the sources is a data broker market put at $250bn against a machine-learning market of roughly $40bn, used to argue that data intermediation is the larger prize ref.
TLDR: Large if data collaboration actually unlocks, but the trillion-dollar figure in the sources is the authors’ own thesis, not measured demand.
Timing Now (0-2yr)
Something is shipping now. The European age-verification app was announced on 15 April 2026, its blueprint is open source, Google’s ZKP libraries were released under Apache 2.0, and ZKPassport is already in both app stores across 120-plus countries ref. If you are asking when privacy technology first touches ordinary users at scale, the answer is the current cycle, driven by eIDAS 2.0 rather than by product demand.
The collaborative computing market is on a different and undated clock. It was declared ready for investment around 2022 ref, the obstacles were catalogued through 2023 as cultural and organisational ref ref, and by May 2026 the integration layer was still receiving early-career research funding. The publication’s own hype-cycle test is apposite: the hard part of any inevitable technology is the “now” ref. On this evidence the analytics half fails that test and no responsible date can be put on it.
TLDR: The ZK identity layer is live in 2026; the enterprise secure-analytics market is not, and the sources do not date it.
Overrated or underrated? Overrated
As a capability, privacy technology is real and, in identity, already deployed. As the venture category described in these sources, a trillion-dollar collaborative computing market unlocked by PETs, it is overrated on the evidence available. Two things support that call. First, the timeline: the thesis was declared investment-ready in 2022, the blockers documented in 2023 were cultural, incentive-based and organisational rather than technical, and by 2026 the technical layer that would make the products deployable was still being built with a $422,683 research grant ref ref. Nothing in the sources shows the cultural blockers being cleared.
Second, value capture. In the one segment where PETs reached scale, the primitives were immediately given away by Google, by Microsoft Research and by the European Commission, and the explicit reading is that privacy becomes a regulatory expectation rather than a product differentiator, following the same commoditise-the-layer-below pattern seen with AP2, Web Bot Auth and x402 ref. A specialist selling the primitive into that environment has no moat. The defensible positions the sources point to are elsewhere: selective encryption and workflow-level products ref, confidential computing folded into cloud infrastructure ref, and data governance as a system of record ref. Underrated as infrastructure, overrated as a market.
Prediction
By 31 December 2027, ZKP-based age or identity attestation will be in production in at least one EUDI Wallet deployment built on the EU Age Verification Blueprint or Google’s Apache 2.0 ZKP libraries, while no general-purpose FHE or MPC analytics stack in these sources will have shipped as a mainstream cloud product.
Evidence base
Open questions
- What are the actual performance overheads of FHE, MPC and TEE-based analytics versus plaintext computation, and does the unified stack under NSF development close them enough for production pipelines?
- Does eIDAS 2.0’s encouragement of ZKPs harden into a requirement, and do member state wallets adopt the open-sourced Google or EU implementations rather than building their own?
- If the privacy primitives are free, where does the revenue sit: cloud infrastructure, governance and workflow software, or verticalised data collaboration networks?
- Has any organisation publicly reported a data collaboration deployment that crossed an organisational boundary and produced measurable revenue, as opposed to a pilot?
Assessment drafted 2026-08-31 from up to 18 KB sources using the technology-scorecard framework; scores are a draft read pending review.