---
title: "LINDDUN, Definition | MedTech Terms"
description: "Privacy threat modeling framework that decomposes privacy threats into seven categories, the privacy counterpart to STRIDE."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/linddun#term",
        "name": "LINDDUN",
        "description": "LINDDUN is a privacy-focused threat modeling methodology developed at KU Leuven. The acronym names seven privacy threat categories: Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness, and Non-compliance. LINDDUN GO (a lightweight card-deck variant) and LINDDUN PRO (a full data-flow-diagram methodology) walk teams through identifying privacy threats in each category against data flows and stores. Output is a prioritized set of privacy threats with mappings to privacy-enhancing technologies (PETs) and controls.",
        "url": "https://medtechterms.com/terms/linddun",
        "termCode": "linddun",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/linddun#article",
        "headline": "LINDDUN",
        "description": "Privacy threat modeling framework that decomposes privacy threats into seven categories, the privacy counterpart to STRIDE.",
        "url": "https://medtechterms.com/terms/linddun",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/linddun"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/linddun#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "LINDDUN, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "LINDDUN privacy threat modeling",
            "url": "https://linddun.org/",
            "publisher": {
              "@type": "Organization",
              "name": "KU Leuven"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "ENISA Privacy and Data Protection by Design",
            "url": "https://www.enisa.europa.eu/publications/privacy-and-data-protection-by-design",
            "publisher": {
              "@type": "Organization",
              "name": "ENISA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/threat-modeling#term",
            "name": "Threat Modeling",
            "url": "https://medtechterms.com/terms/threat-modeling"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/stride#term",
            "name": "STRIDE Threat Model",
            "alternateName": "STRIDE",
            "url": "https://medtechterms.com/terms/stride"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/de-identification#term",
            "name": "De-Identification of Health Data",
            "url": "https://medtechterms.com/terms/de-identification"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/phi-ephi#term",
            "name": "PHI and ePHI",
            "url": "https://medtechterms.com/terms/phi-ephi"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/data-governance#term",
            "name": "Data Governance (AI/ML)",
            "url": "https://medtechterms.com/terms/data-governance"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "LINDDUN",
            "item": "https://medtechterms.com/terms/linddun"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  LINDDUN

[All terms](/terms)

Cybersecurity [AI / ML in Devices](/ecosystems/ai-ml)[Connected & Cyber-Physical Devices](/ecosystems/connected-devices) /lin-don/ 

# LINDDUN

Privacy threat modeling framework that decomposes privacy threats into seven categories, the privacy counterpart to STRIDE.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

LINDDUN is a privacy-focused  [threat modeling](/terms/threat-modeling) methodology developed at KU Leuven. The acronym names seven privacy threat categories: Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness, and Non-compliance. LINDDUN GO (a lightweight card-deck variant) and LINDDUN PRO (a full data-flow-diagram methodology) walk teams through identifying privacy threats in each category against data flows and stores. Output is a prioritized set of privacy threats with mappings to privacy-enhancing technologies (PETs) and controls. 

What the regulation says

Not specifically cited by FDA, but recommended as a privacy  [threat modeling](/terms/threat-modeling) approach by ENISA, referenced in the EDPB Data Protection by Design guidelines, and increasingly cited by notified bodies reviewing EU  [MDR](/terms/mdr-reporting) Annex I privacy and data protection requirements. 

## What this means in practice

For medical devices that process PHI or generate identifiable health data, and especially for cloud-connected  [SaMD](/terms/samd), AI/ML devices that retain inference logs, and  [digital therapeutics](/terms/digital-therapeutics), LINDDUN complements  [STRIDE](/terms/stride) by surfacing threats STRIDE doesn't cover (re-identification of pseudonymized data, inference of sensitive attributes, linkability across datasets). EU GDPR and  [HIPAA](/terms/hipaa) both expect privacy-by-design analysis; LINDDUN is the most rigorous public methodology for it. 

Common pitfalls

-   • Running STRIDE only and assuming privacy is covered, STRIDE addresses security; LINDDUN addresses privacy, and they identify different threats. 
-   • Skipping the PET (privacy-enhancing technology) mapping, without it, LINDDUN produces threats with no controls. 
-   • Limiting LINDDUN to the data layer, privacy threats also arise from UI design (Unawareness) and process design (Non-compliance). 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

De-Identification of Health Data

The HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.





](/terms/de-identification)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

PHI and ePHI

Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.





](/terms/phi-ephi)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)

### More in Cybersecurity

· Same category 

[

Cybersecurity

STRIDE Threat Model(STRIDE) 

A six-category framework for enumerating threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.





](/terms/stride)[

Cybersecurity

Threat Modeling

A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.





](/terms/threat-modeling)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [AI / ML in Devices](/ecosystems/ai-ml)
-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

KU Leuven· 1 ENISA· 1 HSCC· 1 

1.  [1 
    
    LINDDUN privacy threat modeling
    
    Verified 
    
    KU Leuven · linddun.org 
    
    
    
    ](https://linddun.org/)
2.  [2 
    
    ENISA Privacy and Data Protection by Design
    
    Verified 
    
    ENISA · enisa.europa.eu 
    
    
    
    ](https://www.enisa.europa.eu/publications/privacy-and-data-protection-by-design)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=linddun)

Learn in 60 seconds

Card Lesson Quiz

Privacy threat modeling framework that decomposes privacy threats into seven categories, the privacy counterpart to STRIDE.

-   · EU GDPR and HIPAA both expect privacy-by-design analysis; LINDDUN is the most rigorous public methodology for it. 
-   · The acronym names seven privacy threat categories: Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness, and Non-compliance. 
-   · LINDDUN GO (a lightweight card-deck variant) and LINDDUN PRO (a full data-flow-diagram methodology) walk teams through identifying privacy threats in each category against data flows and stores. 

Remember this

Watch out: Running STRIDE only and assuming privacy is covered, STRIDE addresses security; LINDDUN addresses privacy, and they identify different threats.

Related terms

-   [Threat Modeling ](/terms/threat-modeling)
-   [STRIDE Threat Model(STRIDE) ](/terms/stride)
-   [De-Identification of Health Data ](/terms/de-identification)
-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [PHI and ePHI ](/terms/phi-ephi)
-   [Data Governance (AI/ML) ](/terms/data-governance)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [MITRE ATT&CK(ATT&CK) ](/terms/mitre-attack)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [Manufacturer Disclosure Statement for Medical Device Security(MDS2) ](/terms/mds2)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [AAMI TIR97(TIR97) ](/terms/aami-tir97)
-   [MITRE D3FEND(D3FEND) ](/terms/mitre-d3fend)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)