| Sumario: | The article presents a method for preserving the privacy of individuals while simultaneously making data sets containing their private information available for statistical analysis. The concept of differential privacy is said to offer a means of achieving statistical disclosure control, by randomizing responses in a way which preserves the accuracy of the data while dissociating it from the identity of any given individual. The hazards of auxiliary data, which can be used to indirectly ascertain redacted information, are noted, and the usefulness of pan-private algorithms is discussed.
|