The document presents a novel approach to privacy-preserving delegated access control in public clouds through two layers of encryption, where the data owner performs coarse-grained encryption and the cloud performs fine-grained encryption. This method minimizes the overhead on data owners by delegating most of the access control enforcement to the cloud while ensuring data confidentiality and user privacy. The paper also addresses challenges in decomposing access control policies (ACPs) and proposes optimization algorithms for efficient policy management.