Coming soon

Anonymisation and Utility Impact Assessment

Coming soon: a structured assessment that demonstrates anonymity in the relevant recipient context before it measures the utility that remains for a defined lawful task.

Concept cover for Anonymisation and Utility Impact Assessment
What it is

Anonymisation and Utility Impact Assessment in one paragraph.

The AUIA is a structured, reviewable evidence dossier developed through DigiData’s Article 6(11) DMA work on Google Search data sharing. It addresses a recurring regulatory problem: how to make valuable data access operational without treating privacy safeguards as a fiction. The method first tests whether the proposed artefact has been rendered anonymous for the relevant recipient, taking account of realistic lawful means of identification. Only after that threshold has been met does it assess task-specific utility, compare less risky artefacts or access arrangements, and record the controls and review conditions that govern release.

Intended users. Organisations designing data-access regimes, research environments, competition remedies, data spaces, model or output releases, and other high-value collaborations that require a defensible account of anonymity and retained utility.

Important limitation. The AUIA does not certify anonymity by itself, replace a regulator or court, or allow utility, contracts or commercial need to dilute the applicable anonymisation standard. A controlled environment cannot turn identifying data into anonymous data merely by restricting access.
Origin of the method

Built from the Article 6(11) DMA data-access problem.

Article 6(11) requires access to Google Search ranking, query, click and view data on fair, reasonable and non-discriminatory terms. Personal query, click and view data must first be anonymised. The AUIA was proposed as the evidence layer that makes that sequence demonstrable rather than assumed.

The method rejects a trade-off in which useful data receives a weaker anonymity test. It asks whether the artefact is anonymous in the concrete recipient environment, then measures the utility that remains and selects the least risky modality that preserves the defined function.

Method architecture

What the method is intended to record.

Each module produces evidence that another organisation, auditor or regulator can inspect. The method exposes the assumptions that a simple ‘anonymous’ label would conceal.

01

Data inventory and transformation map

Identifies every field and records what is removed, generalised, binned, replaced, noised, linked or suppressed. The output is a field map, schema, sensitivity classification and transformation record.

02

Personal data, actors and recipient context

Tests whether query or other data may identify the person who generated it, including where the system cannot reliably distinguish data about the end user from data about another person. The output maps relevant actors, information and responsibility.

03

Threat model

Assesses singling out, linkability, inference, active attacks, recipient-held auxiliary data and AI-assisted linkage or reconstruction. The output is an attack tree and residual-risk analysis by recipient profile.

04

Technical measures and calibration

Explains and tests thresholds, bins, allowlists, location cells, suppression classes, session rules and other transformations. The output records parameter choices and calibration by language, market and data class.

05

Task-specific utility testing

Measures what the transformed artefact can still do for the defined lawful function, such as ranking, query understanding, local search, freshness, evaluation or carefully controlled rare-query analysis. Utility never lowers the anonymity threshold.

06

Recipient controls and access architecture

Records what a recipient may join, access, train, derive, store, share and delete, together with permissions, logging, AI lineage, output controls and the chosen release or controlled-access modality.

07

Red-team evidence and lifecycle

Tests whether realistic adversaries can identify, link, infer, extract or reconstruct information, records remediation, and sets review dates and events that trigger reassessment.

Reviewable by design

A living evidence record, not a one-off score.

The Article 6(11) proposal requires an AUIA before release, periodic review, and revision after material changes. A confidential dossier can support scrutiny by a regulator, supervisory authority or trusted auditor, while a non-confidential summary can explain the basis and limits of access to eligible recipients.

The same lifecycle logic can support other data-sharing, model-release and research settings where anonymity depends on the recipient, auxiliary information, technical capabilities and the form in which an artefact circulates.

Proposed licence options

Proposed access options for the forthcoming AUIA.

Online purchasing is not currently available. The indicative options and pricing remain visible while the guided workflow, terms, support model and release timetable are finalised.

Single use licence
£100one-off

Designed for one completed AUIA concerning one defined artefact, access arrangement or release decision.

Best for: A discrete anonymisation, data-access, model or output-assurance question.

Monthly licence
£1,000per month

Designed for repeated AUIA use by one named organisation during a monthly licence period.

Best for: A focused research, competition, data-space or product-development project.

What the proposed licence would include

  • A guided evidence dossier for a defined artefact, recipient context and access modality
  • Field-level risk, technical calibration, threat-model and task-utility templates
  • Review gates, reasoned reporting outputs and material-change reassessment triggers

Terms still to be finalised

  • Whether access is per user, per organisation, per project or per artefact
  • Updates, implementation support and professional review
  • VAT treatment, renewal, cancellation and refund conditions
  • Reliance, permitted use, redistribution and audit rights
Research foundation

From a competition remedy to a reusable assurance method.

The Article 6(11) submission supplies the legal sequence, field-level modules, access-tier logic and proposed AUIA clause. From Sticker to Passport develops the wider case for carrying evidence, scope, expiry and review conditions with contextual data-status claims.

Coming soon

The AUIA is being converted into a practical professional product.

DigiData is developing a guided workflow, evidence templates, review gates, reporting outputs and reassessment controls. Organisations may discuss an early pilot or register interest before release.