Aggregation can reduce detail while preserving insight
Most analysis does not need individual records. It needs counts, averages and trends.
Aggregating early removes the personal data from everything downstream while keeping what the question actually required. The catch is that aggregates over small groups can still identify people, which is why statistical bodies suppress small cells, and why "it is only a summary" is not automatically safe.
More on Privacy engineering
- Anonymisation is about re-identification riskThe name was the easy part
- Differential privacy limits one person's influenceOne person cannot move the needle
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Purpose limitation prevents silent mission creepThe pipe was laid for one thing
- Privacy by design moves decisions earlierA line on the plan, or a hole in the wall
- A privacy notice does not create permissionTelling is not asking
