Secure multi-party computation use.
Secure Multi-Party Computation (SMPC) Use
Secure Multi-Party Computation (SMPC) is a privacy-enhancing technology that allows two or more parties to jointly calculate a result from their respective private data without revealing the underlying data to each other. The European Data Protection Supervisor describes SMPC as enabling organisations to obtain joint insights while keeping their underlying datasets confidential.
For example, two companies may want to know how many employees they have in common without either company revealing its complete employee database. SMPC can be designed so that only the agreed result—such as the number of common employees—is revealed.
1. Meaning and Working of SMPC
SMPC generally involves:
- Multiple data holders – each party possesses confidential information.
- Cryptographic protection – data is transformed or distributed using cryptographic techniques.
- Joint computation – the parties collectively perform a computation.
- Limited disclosure – parties do not receive the other parties' raw input data.
- Output generation – only the authorised result is disclosed.
The central principle is “compute together without revealing the underlying inputs.”
2. Uses of SMPC
A. Employment and HR
SMPC can allow different employers to conduct joint analysis without exchanging complete employee records.
Examples include:
- identifying duplicate employment records;
- calculating industry-wide salary statistics;
- comparing workforce demographics;
- analysing attrition patterns;
- checking conflicts of interest;
- conducting recruitment analytics;
- comparing benefits or compensation structures.
This can be particularly relevant where employee information contains personal or confidential data.
B. Financial Services
Banks and financial institutions can jointly detect patterns of fraud or financial crime without giving another institution unrestricted access to their customer databases.
C. Healthcare
Hospitals and research institutions can jointly analyse datasets for research while limiting disclosure of individual patient information.
D. Government and Public Administration
Different government departments can potentially calculate statistics across databases while reducing unnecessary disclosure of citizens' underlying information.
E. Competition and Market Analysis
Competitors may use privacy-preserving computation for certain legitimate statistical or compliance purposes where sharing complete commercially sensitive datasets would create unnecessary confidentiality risks.
3. Importance for Data Protection
SMPC can support the principle of data minimisation because an organisation may obtain the particular result it needs without necessarily obtaining the entire underlying dataset.
This is especially significant in India because the Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) recognised privacy as a constitutionally protected right and discussed informational privacy and control over personal information.
The Aadhaar litigation also specifically raised questions concerning the collection, storage, retention and use of personal data and the protection of collected information.
SMPC therefore can be considered as one technological measure for reducing unnecessary exposure of personal information, although using SMPC does not automatically make a processing activity legally compliant.
4. Legal and Case-Law Framework
There are relatively few Indian reported judgments specifically deciding the legality of SMPC itself. Therefore, the following cases are important for the privacy, proportionality, confidentiality, electronic-data and surveillance principles within which SMPC may be deployed.
Case 1: Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1
The nine-judge Constitution Bench recognised privacy as a fundamental right under the Constitution.
The judgment is foundational for informational privacy and protection of personal data. It is relevant to SMPC because privacy-preserving technologies can reduce unnecessary disclosure of personal information.
Principle: Collection and processing of personal information must be considered in light of constitutional privacy protections.
Case 2: K.S. Puttaswamy (Retd.) v. Union of India — Aadhaar Judgment, (2018) 8 SCC 1
The Supreme Court considered the constitutional validity of the Aadhaar framework, including questions concerning collection, storage and use of demographic and biometric information.
The Court's analysis demonstrates that the architecture through which personal information is collected and processed can itself have privacy implications.
Relevance to SMPC: Privacy-preserving computation can be considered when designing systems where organisations need information derived from sensitive datasets without unnecessarily centralising or exposing the underlying data.
Case 3: Anuradha Bhasin v. Union of India, (2020) 3 SCC 637
The Supreme Court examined restrictions on communications and the relationship between constitutional rights and digital communications.
The case is relevant to privacy-preserving technologies because it illustrates the constitutional importance of digital information systems and communications.
Principle: Restrictions affecting digital communications must satisfy constitutional standards rather than being treated as technologically neutral matters.
SMPC relevance: Organisations implementing privacy-preserving computational systems should similarly consider the legal purpose, necessity and proportionality of the processing involved.
Case 4: People's Union for Civil Liberties (PUCL) v. Union of India, (1997) 1 SCC 301
The Supreme Court dealt with telephone interception and laid down safeguards concerning interception of communications.
The case is significant because it established that technological access to private communications cannot be treated as completely unrestricted merely because the information is technically accessible.
SMPC relevance: SMPC addresses a related technological concern from the opposite direction—it is designed to reduce unnecessary access to underlying information during computation.
Case 5: Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1
The Supreme Court addressed the admissibility and authentication of electronic records.
The Court emphasised safeguards concerning the source and authenticity of electronic evidence and held that the statutory requirements governing electronic records had to be followed.
SMPC relevance: A system using SMPC should maintain reliable records concerning computation, inputs, authorisation, integrity and outputs where those records may subsequently become relevant in legal proceedings.
Case 6: Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473
The Supreme Court established important principles concerning electronic evidence and the statutory requirements for proving electronic records.
The Court recognised the particular problems associated with electronic information, including risks of alteration and questions concerning authenticity. These principles were subsequently considered in Arjun Panditrao Khotkar.
SMPC relevance: Privacy protection should not come at the expense of auditability and evidentiary reliability. An SMPC implementation should therefore have appropriate mechanisms for demonstrating that the computation was performed correctly.
Case 7: K.S. Puttaswamy (Retd.) v. Union of India, Aadhaar Proceedings, 2017 Interim Order
During the Aadhaar proceedings, the Supreme Court considered restrictions concerning the use and linking of Aadhaar information while the larger constitutional proceedings were pending.
The proceedings demonstrate the importance of controlling the purposes for which personal information is used rather than treating collected data as freely reusable.
SMPC relevance: Even if an organisation uses SMPC, the organisation must still have a legitimate purpose and appropriate legal basis for the underlying processing.
5. SMPC in Employment Law
SMPC can be particularly useful for HR analytics.
For example:
Company A: 10,000 employee records
Company B: 8,000 employee records
Both companies want to determine:
“How many employees have previously worked for both companies?”
Normally, each company could be required to disclose its employee database.
With an appropriately designed SMPC protocol, the parties could jointly calculate the intersection while limiting disclosure of their individual employee lists.
Similarly, multiple employers could potentially calculate:
- average salary;
- number of employees within particular salary bands;
- workforce turnover;
- aggregate diversity statistics;
- training participation rates;
- benefit utilisation;
- recruitment statistics.
The output can be restricted to the specific statistic required.
6. SMPC and Employee Privacy
Employers increasingly process:
- employee identifiers;
- salary information;
- attendance information;
- performance data;
- recruitment information;
- location information;
- disciplinary records;
- benefits information.
Giving all such information to another organisation merely because a joint analysis is required may create unnecessary privacy and confidentiality risks.
SMPC can provide a technical architecture where the computation is shared but the raw datasets remain compartmentalised.
However, it is important to distinguish:
Privacy-enhancing technology ≠ automatic legal compliance.
An organisation must still consider applicable privacy, employment, contractual, cybersecurity and data-retention requirements.
7. Advantages of SMPC
Privacy protection
Raw datasets can remain with their respective owners.
Reduced data transfer
There may be less need to create large central databases containing information belonging to multiple organisations.
Confidentiality
Commercially sensitive information can potentially remain confidential.
Controlled disclosure
The system can be designed to reveal only the agreed output.
Collaborative analytics
Organisations can obtain useful combined statistics without unrestricted data sharing.
Reduced breach impact
Where raw datasets are not centrally combined, the consequences of a compromise may potentially be reduced, although SMPC itself does not eliminate cybersecurity risks.
8. Limitations and Risks
SMPC is not a complete solution to every privacy problem.
1. Implementation complexity
SMPC protocols can be technically complicated and may require specialist cryptographic expertise.
2. Performance
Some computations may require significant processing and communication resources.
3. Input manipulation
If one participant supplies false or manipulated data, the resulting computation may still be incorrect.
4. Output leakage
Even if raw data is protected, repeated queries or highly detailed outputs can sometimes allow information to be inferred.
5. Collusion
The security model must identify what happens if participating parties cooperate improperly.
6. Legal compliance remains necessary
SMPC does not remove obligations relating to lawful processing, purpose limitation, transparency, retention, security or employee rights.
9. Compliance Framework for Organisations
An organisation implementing SMPC should consider:
- Identify the purpose of the computation.
- Identify the data categories involved.
- Determine the lawful basis for processing.
- Minimise the output to what is actually required.
- Define participating parties and responsibilities.
- Conduct security and privacy risk assessments.
- Document the cryptographic protocol and security assumptions.
- Control access to computation results.
- Maintain appropriate audit records.
- Establish retention and deletion procedures.
- Address incident-response procedures.
- Periodically test the implementation.
Conclusion
Secure Multi-Party Computation is a privacy-enhancing technology that enables multiple parties to obtain a common computational result without necessarily revealing their underlying datasets to one another. Its potential applications include HR analytics, healthcare research, financial fraud detection, government data analysis and confidential business collaboration.
Indian privacy jurisprudence—particularly Puttaswamy—makes minimising unnecessary exposure of personal information an important consideration. At the same time, Anvar P.V. and Arjun Panditrao Khotkar demonstrate the importance of authenticity, integrity and procedural safeguards when electronic information becomes relevant to legal proceedings.
Thus, SMPC should be viewed not as a substitute for legal compliance, but as a technical privacy and confidentiality measure that can support responsible data processing when properly designed and governed.

comments