1. Any post-processing algorithm that violates differential privacy can be run by a distinguishing adversary, thus allowing the adversary to break DP, which should be impossible. Hence post-processing preserves DP. 2. Users can add noise to their inputs before sending them to the central aggregating servers. The downside of this is that the accuracy of the aggregated result decreases.