Differential privacy limits one person's influence
Differential privacy adds carefully calculated noise so that the result barely changes whether or not any single person is in the dataset.
That gives a mathematical guarantee about what can be inferred about an individual, which is a much stronger claim than "we removed the names". It costs accuracy, and the trade is explicit and tunable, which is the appealing part: for once the privacy guarantee is a number rather than a judgement.
More on Privacy engineering
- Anonymisation is about re-identification riskThe name was the easy part
- Consent interfaces can undermine genuine choiceBoth answers, very different distances
- Purpose limitation prevents silent mission creepThe pipe was laid for one thing
- Privacy by design moves decisions earlierA line on the plan, or a hole in the wall
- A privacy notice does not create permissionTelling is not asking
- Data subject rights depend on finding the dataThe right ends where the index does
