3 ms·
Just to add to the nice responses from lomereiter and georgefox, I think the common response to > For official statistics and scientific research this is often
by dp_throw 6y ago
Just to add to the nice responses from lomereiter and georgefox, I think the common response to
> For official statistics and scientific research this is often not an acceptable tradeoff
is that differential privacy is the best known method for rigorously accounting for privacy risks. It's possible to argue that differential privacy is too strong (and plenty of people have), but to the best of my knowledge, systems that say "you don't need DP - we'll answer lots of database queries without DP and still prevent deanonymization" usually end up getting broken. A good example of this is the (repeated) breaking of Diffix [1], a system that attempts to provide privacy without using differential privacy.
So differential privacy is, I think, a good starting point if privacy is critical to your application. It does not offer much guidance for when you should decide privacy is critical, or when the utility of an application outweighs the need for privacy.
For example, many social science researchers have criticized the US Census for using differential privacy in the 2020 census. It's consistent to say "it's way more important to have accurate counts for all of the decisions made using census data -- let's not try too hard to be private". It's also consistent to say "privacy is important, so we should use a rigorous notion like differential privacy". It's not consistent to say "private is important, but let's just use some heuristics and hope for the best", which is what the census had largely been doing until 2020.
[1] https://differentialprivacy.org/diffix-attack/ https://differentialprivacy.org/diffix-attack/