Differential privacy limits one person's influence

Differential privacy adds carefully calculated noise so that the result barely changes whether or not any single person is in the dataset.

That gives a mathematical guarantee about what can be inferred about an individual, which is a much stronger claim than "we removed the names". It costs accuracy, and the trade is explicit and tunable, which is the appealing part: for once the privacy guarantee is a number rather than a judgement.

More on Privacy engineering