# SP-039 Client-Side Encryption and Data Privacy

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: Pattern for implementing client-side encryption to protect sensitive user data before it reaches the server. Covers browser-based cryptography via Web Crypto API, key lifecycle management, data anonymisation for aggregates, and the architectural separation of private encrypted data from shareable plaintext.
Use when: This pattern is indicated for any application that handles sensitive user data where the service operator should not -- or does not need to -- read the data. Specific indicators include: applications storing personal health information (patient journals, symptom trackers), financial data (personal budgets, portfolio analysis), security assessments (maturity scores, vulnerability data), personal notes and diaries,...
Not when: Applications requiring server-side search, sorting, or filtering of encrypted data cannot use this pattern without additional cryptographic techniques (searchable encryption, order-preserving encryption) that significantly increase complexity and may weaken the security model.

## Controls (28, NIST SP 800-53 ids)
- Critical (7): AC-04, PT-04, SA-08, SC-12, SC-13, SC-28, SI-07
- Important (12): AC-03, AC-21, AT-02, AU-02, CP-09, PM-25, PT-02, PT-03, SA-10, SC-08, SC-23, SR-03
- Standard (9): AU-03, AU-06, CM-03, CM-06, IA-05, IR-04, IR-06, SC-07, SC-17

## What each critical control mitigates (7)
- AC-04 Information Flow Enforcement: T-CE-002
- PT-04 Consent: none of the threats below
- SA-08 Security and Privacy Engineering Principles: none of the threats below
- SC-12 Cryptographic Key Establishment and Management: T-CE-001, T-CE-005, T-CE-008, T-CE-009, T-CE-011
- SC-13 Cryptographic Protection: T-CE-001, T-CE-007, T-CE-008, T-CE-010, T-CE-011
- SC-28 Protection of Information at Rest: T-CE-001, T-CE-002, T-CE-008, T-CE-009
- SI-07 Software, Firmware, and Information Integrity: T-CE-003, T-CE-004, T-CE-010, T-CE-012

## Threats and the controls that mitigate them (12)
- T-CE-001 Server-side data breach exposing user data at rest: SC-12, SC-13, SC-28
- T-CE-002 Rogue insider with database access reading sensitive records: AC-03, AC-04, SC-28, AU-02
- T-CE-003 Cross-site scripting (XSS) exfiltrating encryption key from localStorage: SI-07, SC-07, SC-23
- T-CE-004 Compromised JavaScript delivery replacing encryption code: SI-07, SA-10, SC-08
- T-CE-005 Key loss from browser data clearing or device loss: SC-12, CP-09, AT-02
- T-CE-006 Metadata analysis inferring sensitive information from access patterns: PM-25, PT-02, AU-03
- T-CE-007 Man-in-the-middle intercepting encrypted payload in transit: SC-08, SC-13, SC-23
- T-CE-008 Lawful compulsion or government demand for user data: SC-12, SC-13, SC-28, PT-02
- T-CE-009 Cloud provider or hosting infrastructure accessing stored data: SC-28, SC-12, AC-03
- T-CE-010 Ciphertext manipulation or corruption altering encrypted records: SC-13, SI-07, AU-06
- T-CE-011 Weak key derivation from user passphrase in multi-device scenarios: SC-12, SC-13, IA-05
- T-CE-012 Supply chain attack injecting malicious code into cryptographic dependencies: SA-10, SI-07, SR-03

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-039/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-039/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 32 KB: /api/v1/patterns/SP-039
- Page for people: /patterns/sp-039/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-013 Data Security Pattern; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-029 Zero Trust Architecture

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
