Coming soon · Guided evidence dossier

AUIA · Anonymisation and Utility Impact Assessment

Prove anonymity.
Preserve utility.

The AUIA guides and records the evidence needed to show whether a defined data asset is anonymous for a named recipient, then measures whether the least risky release or access arrangement still supports the stated lawful task.

One asset. One recipient context. One task. One evidence record.

Anonymise first.

Measure what remains.

Choose the least risky route.

Record why.

The problem

Too risky to share. Too damaged to use.

Data-access projects often drift towards a false choice. One route preserves useful detail but leaves identification risks unresolved. The other suppresses so much information that the intended research, competition, analytics or AI task no longer works.

The failure usually begins earlier. Teams remove obvious identifiers and call the result anonymous. They ask contracts, clean rooms or access restrictions to perform the legal transformation. They measure usefulness before they have established the data-status threshold. They approve a static artefact even though recipients, auxiliary data and attack capabilities will change.

Anonymity is not a label. Utility is not an excuse. Both require evidence.

01

Identifier removal is not enough

Names and account numbers may disappear while distinctive language, behaviour, geography, timing or combinations still support identification.

02

Context changes the risk

The same artefact may present different risks for a named independent recipient, a processor, a public release or a recipient with rich auxiliary information.

03

Controls cannot do everything

Contracts, logs, ring-fencing and clean rooms may reduce residual risk. They do not turn a still-identifying artefact into anonymous data.

04

Usefulness needs its own test

An artefact can satisfy a privacy threshold yet fail the task. Utility must be measured against the defined function, not assumed from data volume.

What it is · what it is not

One focused method. One bounded release decision.

The AUIA is

A structured anonymity and utility evidence dossier.

  • A defined assessment of one versioned artefact, recipient or recipient class, lawful task and access modality.
  • A connected legal, technical and operational record of transformations, threats, tests, controls and residual risk.
  • A two-gate process that establishes anonymity before measuring task-specific utility.
  • A lifecycle record with approval conditions, review dates and material reassessment triggers.
  • The evidence layer from which a bounded TRACE Passport can be produced.

The AUIA is not

An anonymisation engine, certificate or universal badge.

  • It does not transform or anonymise raw data by itself.
  • It does not declare an artefact anonymous for every actor, purpose or future use.
  • It does not allow utility, contractual promises or commercial need to lower the anonymity threshold.
  • It does not replace a DPIA, independent audit, specialist privacy testing, regulatory decision or legal opinion.
  • It does not treat a clean room or controlled API as an anonymiser.

The AUIA does not trade privacy for utility. It identifies the least risky candidate artefact or access route that preserves the defined function.

How it works

Two gates. Seven modules. One reasoned route.

The order controls the method. The anonymity gate comes first. Utility cannot rescue an artefact that remains identifiable in the relevant context.

Gate 1

Legal and evidential threshold

Has anonymity been demonstrated?

Test the exact artefact against the realistic means available to the relevant recipient and other actors whose capabilities must form part of the assessment.

  • Singling out and record isolation
  • Linkage and auxiliary information
  • Source-specific inference
  • Active influence and reconstruction
  • AI-assisted extraction or re-identification

If the answer is no or unresolved, stop, transform or narrow the route.

Gate 2

Operational value test

What useful function remains?

Measure the artefact against the defined lawful task and compare safer artefacts or access arrangements before approving release.

  • Task-specific benchmarks
  • Performance and degradation curves
  • Minimum sufficient information
  • Alternative artefacts and modalities
  • Stop conditions and acceptable loss

Utility guides the choice among anonymous options. It never lowers Gate 1.

The seven modules

Each module produces evidence another team can inspect.

01

Data inventory and transformation

Define the artefact, source fields, schema, sensitivity, version and every removal, generalisation, binning, replacement, noise addition, aggregation or suppression.

Output: field map, schema and transformation record
02

Persons, actors and recipient context

Identify whom the data concerns, who holds relevant information, the recipient’s role, access, purpose, auxiliary data and realistic capacity to distinguish or treat a person differently.

Output: actor, perspective and responsibility map
03

Threat model

Assess singling out, linkage, inference, membership, active attacks, recipient-held data and AI-assisted extraction, reconstruction or re-identification.

Output: attack tree and residual-risk register
04

Technical measures and calibration

Record the reasoning, evidence and test results behind thresholds, cohorts, bins, allowlists, location cells, session rules, suppression classes and privacy parameters.

Output: parameter, calibration and test record
05

Task-specific utility

Measure what the transformed artefact can still achieve for the stated task, identify unacceptable degradation and compare the minimum information needed to preserve the function.

Output: benchmark and degradation report
06

Recipient controls and access architecture

Record what the recipient may access, join, train, derive, store, share and delete, together with roles, logging, lineage, output checks, retention and onward-transfer boundaries.

Output: access and control architecture
07

Red-team evidence and lifecycle

Test realistic adversaries, record failures and remediation, define approval conditions, and set dates and events that renew, narrow, suspend or revoke reliance.

Output: red-team log, decision and review schedule

Outcomes

Five practical routes. No black-box score.

The AUIA records a route, the evidence supporting it and the conditions that limit it.

Stop

Anonymity not demonstrated

Do not release the artefact as anonymous through the proposed route. Assess any continued use under the applicable personal-data framework.

Transform

Further treatment required

Change the artefact, parameters or evidence before retesting Gate 1.

Narrow

Use a safer route

Move to aggregation, a more restricted dataset, controlled access or privacy-tested output.

Approve

Bounded release

Approve the defined artefact for the named recipient, task, modality and period.

Suspend

Reassessment triggered

Pause reliance after a material change, control failure, misuse or new technical capability.

An artefact may pass the anonymity gate but fail the utility test. The answer is to redesign the artefact or access route, not to weaken anonymity.

Outputs

One dossier. Evidence another team can inspect.

The AUIA creates a connected record rather than a generic dashboard. A reader can trace the conclusion back to the asset, recipient, threat assumptions, transformations, technical tests, utility evidence and controls.

01

Confidential AUIA dossier — the full seven-module evidence record, assumptions, gaps, tests and decision.

02

Executive decision record — the route, reasons, conditions, owners and unresolved work.

03

Non-confidential summary — a controlled explanation for recipients, auditors, regulators or governance bodies.

04

TRACE Passport export — an optional bounded summary that travels with the approved artefact.

What the dossier contains

  • Field and transformation map
  • Actor and recipient-context map
  • Attack tree and residual-risk register
  • Technical calibration and test evidence

What the decision layer contains

  • Utility benchmark and degradation analysis
  • Access and control architecture
  • Red-team findings and remediation
  • Approval, expiry and reassessment triggers

Users and use cases

Built for teams that must release value without inventing a privacy fiction.

The method joins expertise that organisations often keep in separate files. Legal and data-protection teams define the threshold and actors. Privacy engineers and data scientists supply transformation and attack evidence. Product, research and competition teams define the task. Security, audit and governance teams test the controls and lifecycle.

Data holdersIndependent recipientsDPOsPrivacy engineersData scientistsLegal teamsResearch consortiaData-space operatorsAuditorsRegulators
Data access

Competition and statutory sharing

Assess record-level data, aggregates, APIs and controlled-access models under a defined recipient and purpose.

Research

Scientific and public-interest collaboration

Document privacy threats and task utility for research data, secure environments and cross-organisational projects.

AI

Models, embeddings and outputs

Attach the assessment to the actual artefact and interface, then test extraction, membership, memorisation and reconstruction risks.

Data economy

Data spaces and PET programmes

Compare transformations and access modalities so privacy-enhancing technology preserves a useful and reviewable function.

Technical details

Simple to use. Inspectable underneath.

The first release is being designed as a local-first browser application. It will structure the assessment and evidence without requiring an organisation to send confidential project material to DigiData.

ProcessingOn the user’s device

No assessment back end required for the core workflow.

Raw dataNot required by default

The dossier records test evidence and references rather than ingesting the source dataset.

Decision logicDeterministic and inspectable

Versioned branching rules, gates and conclusion language.

EvidenceLocal attachments and manifest

Planned browser storage, file references and SHA-256 evidence hashes.

PortabilityJSON, PDF and TRACE

Local project export, print-ready report and optional Passport summary.

AI dependencyNone in the core result

No generative model determines the outcome or substitutes for evidence.

Important technical limit

The AUIA is an assessment and evidence system, not a transformation engine. Version 1 will not anonymise a dataset, run every privacy attack automatically or prove anonymity from a file upload. Technical teams must perform the relevant tests and supply the evidence. The AUIA structures, challenges and records that evidence.

Proposed launch model

Explore it. Use it once. Build it into the programme.

The AUIA remains in development. Online purchasing is not open. The proposed licence fees position the product above generic templates and below broad enterprise privacy platforms.

Public demonstration

Free

Explore a complete fictional data-access scenario and see how the two gates and seven modules connect.

  • Pre-loaded sample facts
  • Interactive evidence pathway
  • Watermarked sample report
  • No real organisational decision
Request launch notification

Single assessment

£695 + VAT

Complete one AUIA for one named organisation and one bounded assessment object.

  • One versioned artefact
  • One recipient or recipient class
  • One defined task and up to three candidate access modalities
  • Local save, JSON and full report
  • Optional TRACE Passport export
  • 180-day completion period
Register interest

Professional review remains separate. An expert review of a completed AUIA would start from £3,500 + VAT. Group-company, adviser, consultancy, external-client, white-label and regulator licences require separate terms.

These prices remain proposed until DigiData finalises the workflow, security model, support scope and licence terms.

Origin and legal context

Born in Article 6(11). Built to travel.

Dr M.R. Leiser developed the AUIA through DigiData’s intervention on Google Search data sharing under Article 6(11) of the Digital Markets Act. The submission proposed a formal evidence pack that demonstrates anonymity in the recipient context before explaining the utility retained for concrete search tasks.

The European Commission adopted binding Google Search data-sharing specification measures on 16 July 2026. The final regime combines significant technical alteration with complementary contractual and organisational safeguards, pre-access verification, annual independent audits and biennial review. The Commission describes that package as ensuring anonymisation. The AUIA preserves the distinction between what changes the artefact and what constrains the recipient, and records both. It remains an independent DigiData method; the Commission did not adopt or mandate it by name.

The pre-release rule pack also takes account of the EDPB’s draft Guidelines 02/2026 on Anonymisation. DigiData will version the methodology against final guidance and later legal developments before commercial reliance.

Evidence baseline for this page: 14 August 2026.

Relationship with TRACE

AUIA holds the evidence. TRACE carries the result.

The AUIA is the complete assessment and decision dossier. TRACE is the portable, versioned summary that can travel with the approved artefact and state the scope, actors, controls, evidence, review date and trigger events.

Explore the TRACE Passport
01Legal baselineApplicable test and perspective
02AUIA dossierFull evidence and decision
03TRACE PassportBounded portable summary

Frequently asked questions

The boundaries are part of the product.

A credible assurance method must explain what it cannot establish as clearly as what it can record.

Does the AUIA certify that data is anonymous?

No. It structures and records the evidence supporting a bounded conclusion. It does not bind a regulator, court, auditor or recipient, and it cannot make weak evidence conclusive.

Does the AUIA anonymise or redact data?

No. It is not a transformation engine. The organisation’s technical team or specialist provider must apply and test the relevant transformations. The AUIA records the methods, parameters, results, limitations and residual risk.

Can strong utility justify a lower anonymity standard?

No. The anonymity gate comes first. Utility helps the organisation choose among artefacts or access arrangements that have already met the applicable threshold.

Is a clean room or controlled API enough?

No. A controlled environment may reduce operational, combination or output risks and may form part of the recipient context. It does not make still-identifying data anonymous merely by restricting access.

Does the AUIA replace a DPIA?

No. A DPIA addresses high-risk processing of personal data. An AUIA examines the evidence for anonymity and retained utility. A project may require both, particularly while personal data remains in the source or transformation process.

What exactly does one assessment cover?

One defined and versioned artefact, one recipient or recipient class, one stated task and one release decision. The standard single licence may compare up to three candidate access modalities, but the final conclusion attaches to the selected modality and decision context. A material change to any of those elements may require reassessment.

Can the method assess models, embeddings and outputs?

Yes, provided that the assessment attaches to a defined version and interface and uses form-specific tests such as membership, extraction, memorisation, inversion, reconstruction and prompt-based disclosure.

What information leaves the browser?

The planned core workflow processes assessment content locally. Standard web hosting may still generate ordinary server logs when the page loads. Users should not enter real confidential information into the public demonstration.

When should an AUIA be reassessed?

After material changes to fields, transformations, recipient classes, purposes, auxiliary information, access modalities, AI capabilities, attack methods, control performance, evidence of misuse or the utility benchmark.

Is the AUIA only for Article 6(11) DMA?

No. Article 6(11) supplied the original problem and discipline. The same two-gate structure can support research, data spaces, PET programmes, competition remedies, analytics and model or output release where anonymity and useful function both require evidence.

Legal and methodological boundary

No badge. No legal fiction. No false certainty.

The AUIA provides structured decision support. It does not provide legal advice, certification, an audit opinion or a universal determination of data status. Any result remains conditional on the facts, evidence, recipient context, technology, law and method version recorded at the assessment date.

Organisations remain responsible for selecting qualified assessors, performing adequate technical testing, meeting applicable legal duties and deciding whether independent review or regulatory engagement is required.

Coming soon

Start with one real data-access decision.

Identify the artefact, intended recipient, lawful task, proposed access route and decision timetable. DigiData can then assess whether an early pilot, sector profile or organisational licence fits the problem.