AUIA · Anonymisation and Utility Impact Assessment
Prove anonymity.
Preserve utility.
The AUIA guides and records the evidence needed to show whether a defined data asset is anonymous for a named recipient, then measures whether the least risky release or access arrangement still supports the stated lawful task.
One asset. One recipient context. One task. One evidence record.
Anonymise first.
Measure what remains.
Choose the least risky route.
Record why.
The problem
Too risky to share. Too damaged to use.
Data-access projects often drift towards a false choice. One route preserves useful detail but leaves identification risks unresolved. The other suppresses so much information that the intended research, competition, analytics or AI task no longer works.
The failure usually begins earlier. Teams remove obvious identifiers and call the result anonymous. They ask contracts, clean rooms or access restrictions to perform the legal transformation. They measure usefulness before they have established the data-status threshold. They approve a static artefact even though recipients, auxiliary data and attack capabilities will change.
Anonymity is not a label. Utility is not an excuse. Both require evidence.
Identifier removal is not enough
Names and account numbers may disappear while distinctive language, behaviour, geography, timing or combinations still support identification.
Context changes the risk
The same artefact may present different risks for a named independent recipient, a processor, a public release or a recipient with rich auxiliary information.
Controls cannot do everything
Contracts, logs, ring-fencing and clean rooms may reduce residual risk. They do not turn a still-identifying artefact into anonymous data.
Usefulness needs its own test
An artefact can satisfy a privacy threshold yet fail the task. Utility must be measured against the defined function, not assumed from data volume.
What it is · what it is not
One focused method. One bounded release decision.
The AUIA is
A structured anonymity and utility evidence dossier.
- A defined assessment of one versioned artefact, recipient or recipient class, lawful task and access modality.
- A connected legal, technical and operational record of transformations, threats, tests, controls and residual risk.
- A two-gate process that establishes anonymity before measuring task-specific utility.
- A lifecycle record with approval conditions, review dates and material reassessment triggers.
- The evidence layer from which a bounded TRACE Passport can be produced.
The AUIA is not
An anonymisation engine, certificate or universal badge.
- It does not transform or anonymise raw data by itself.
- It does not declare an artefact anonymous for every actor, purpose or future use.
- It does not allow utility, contractual promises or commercial need to lower the anonymity threshold.
- It does not replace a DPIA, independent audit, specialist privacy testing, regulatory decision or legal opinion.
- It does not treat a clean room or controlled API as an anonymiser.
The AUIA does not trade privacy for utility. It identifies the least risky candidate artefact or access route that preserves the defined function.
How it works
Two gates. Seven modules. One reasoned route.
The order controls the method. The anonymity gate comes first. Utility cannot rescue an artefact that remains identifiable in the relevant context.
Legal and evidential threshold
Has anonymity been demonstrated?
Test the exact artefact against the realistic means available to the relevant recipient and other actors whose capabilities must form part of the assessment.
- Singling out and record isolation
- Linkage and auxiliary information
- Source-specific inference
- Active influence and reconstruction
- AI-assisted extraction or re-identification
If the answer is no or unresolved, stop, transform or narrow the route.
Operational value test
What useful function remains?
Measure the artefact against the defined lawful task and compare safer artefacts or access arrangements before approving release.
- Task-specific benchmarks
- Performance and degradation curves
- Minimum sufficient information
- Alternative artefacts and modalities
- Stop conditions and acceptable loss
Utility guides the choice among anonymous options. It never lowers Gate 1.
The seven modules
Each module produces evidence another team can inspect.
Data inventory and transformation
Define the artefact, source fields, schema, sensitivity, version and every removal, generalisation, binning, replacement, noise addition, aggregation or suppression.
Output: field map, schema and transformation recordPersons, actors and recipient context
Identify whom the data concerns, who holds relevant information, the recipient’s role, access, purpose, auxiliary data and realistic capacity to distinguish or treat a person differently.
Output: actor, perspective and responsibility mapThreat model
Assess singling out, linkage, inference, membership, active attacks, recipient-held data and AI-assisted extraction, reconstruction or re-identification.
Output: attack tree and residual-risk registerTechnical measures and calibration
Record the reasoning, evidence and test results behind thresholds, cohorts, bins, allowlists, location cells, session rules, suppression classes and privacy parameters.
Output: parameter, calibration and test recordTask-specific utility
Measure what the transformed artefact can still achieve for the stated task, identify unacceptable degradation and compare the minimum information needed to preserve the function.
Output: benchmark and degradation reportRecipient controls and access architecture
Record what the recipient may access, join, train, derive, store, share and delete, together with roles, logging, lineage, output checks, retention and onward-transfer boundaries.
Output: access and control architectureRed-team evidence and lifecycle
Test realistic adversaries, record failures and remediation, define approval conditions, and set dates and events that renew, narrow, suspend or revoke reliance.
Output: red-team log, decision and review scheduleOutcomes
Five practical routes. No black-box score.
The AUIA records a route, the evidence supporting it and the conditions that limit it.
Anonymity not demonstrated
Do not release the artefact as anonymous through the proposed route. Assess any continued use under the applicable personal-data framework.
Further treatment required
Change the artefact, parameters or evidence before retesting Gate 1.
Use a safer route
Move to aggregation, a more restricted dataset, controlled access or privacy-tested output.
Bounded release
Approve the defined artefact for the named recipient, task, modality and period.
Reassessment triggered
Pause reliance after a material change, control failure, misuse or new technical capability.
An artefact may pass the anonymity gate but fail the utility test. The answer is to redesign the artefact or access route, not to weaken anonymity.
Outputs
One dossier. Evidence another team can inspect.
The AUIA creates a connected record rather than a generic dashboard. A reader can trace the conclusion back to the asset, recipient, threat assumptions, transformations, technical tests, utility evidence and controls.
Confidential AUIA dossier — the full seven-module evidence record, assumptions, gaps, tests and decision.
Executive decision record — the route, reasons, conditions, owners and unresolved work.
Non-confidential summary — a controlled explanation for recipients, auditors, regulators or governance bodies.
TRACE Passport export — an optional bounded summary that travels with the approved artefact.
What the dossier contains
- Field and transformation map
- Actor and recipient-context map
- Attack tree and residual-risk register
- Technical calibration and test evidence
What the decision layer contains
- Utility benchmark and degradation analysis
- Access and control architecture
- Red-team findings and remediation
- Approval, expiry and reassessment triggers
Users and use cases
Built for teams that must release value without inventing a privacy fiction.
The method joins expertise that organisations often keep in separate files. Legal and data-protection teams define the threshold and actors. Privacy engineers and data scientists supply transformation and attack evidence. Product, research and competition teams define the task. Security, audit and governance teams test the controls and lifecycle.
Competition and statutory sharing
Assess record-level data, aggregates, APIs and controlled-access models under a defined recipient and purpose.
Scientific and public-interest collaboration
Document privacy threats and task utility for research data, secure environments and cross-organisational projects.
Models, embeddings and outputs
Attach the assessment to the actual artefact and interface, then test extraction, membership, memorisation and reconstruction risks.
Data spaces and PET programmes
Compare transformations and access modalities so privacy-enhancing technology preserves a useful and reviewable function.
Technical details
Simple to use. Inspectable underneath.
The first release is being designed as a local-first browser application. It will structure the assessment and evidence without requiring an organisation to send confidential project material to DigiData.
No assessment back end required for the core workflow.
The dossier records test evidence and references rather than ingesting the source dataset.
Versioned branching rules, gates and conclusion language.
Planned browser storage, file references and SHA-256 evidence hashes.
Local project export, print-ready report and optional Passport summary.
No generative model determines the outcome or substitutes for evidence.
The AUIA is an assessment and evidence system, not a transformation engine. Version 1 will not anonymise a dataset, run every privacy attack automatically or prove anonymity from a file upload. Technical teams must perform the relevant tests and supply the evidence. The AUIA structures, challenges and records that evidence.
Proposed launch model
Explore it. Use it once. Build it into the programme.
The AUIA remains in development. Online purchasing is not open. The proposed licence fees position the product above generic templates and below broad enterprise privacy platforms.
Public demonstration
Explore a complete fictional data-access scenario and see how the two gates and seven modules connect.
- Pre-loaded sample facts
- Interactive evidence pathway
- Watermarked sample report
- No real organisational decision
Single assessment
Complete one AUIA for one named organisation and one bounded assessment object.
- One versioned artefact
- One recipient or recipient class
- One defined task and up to three candidate access modalities
- Local save, JSON and full report
- Optional TRACE Passport export
- 180-day completion period
Organisation licence
Use the AUIA repeatedly within one named legal entity across an ongoing data-sharing or assurance programme.
- Unlimited internal users and assessments
- Method and rule-pack updates
- Standard use-case and sector profiles
- Version comparison and reassessment
- Priority product support
- Internal governance and audit use
Professional review remains separate. An expert review of a completed AUIA would start from £3,500 + VAT. Group-company, adviser, consultancy, external-client, white-label and regulator licences require separate terms.
These prices remain proposed until DigiData finalises the workflow, security model, support scope and licence terms.
Origin and legal context
Born in Article 6(11). Built to travel.
Dr M.R. Leiser developed the AUIA through DigiData’s intervention on Google Search data sharing under Article 6(11) of the Digital Markets Act. The submission proposed a formal evidence pack that demonstrates anonymity in the recipient context before explaining the utility retained for concrete search tasks.
The European Commission adopted binding Google Search data-sharing specification measures on 16 July 2026. The final regime combines significant technical alteration with complementary contractual and organisational safeguards, pre-access verification, annual independent audits and biennial review. The Commission describes that package as ensuring anonymisation. The AUIA preserves the distinction between what changes the artefact and what constrains the recipient, and records both. It remains an independent DigiData method; the Commission did not adopt or mandate it by name.
The pre-release rule pack also takes account of the EDPB’s draft Guidelines 02/2026 on Anonymisation. DigiData will version the methodology against final guidance and later legal developments before commercial reliance.
Evidence baseline for this page: 14 August 2026.
Relationship with TRACE
AUIA holds the evidence. TRACE carries the result.
The AUIA is the complete assessment and decision dossier. TRACE is the portable, versioned summary that can travel with the approved artefact and state the scope, actors, controls, evidence, review date and trigger events.
Explore the TRACE PassportFrequently asked questions
The boundaries are part of the product.
A credible assurance method must explain what it cannot establish as clearly as what it can record.
Does the AUIA certify that data is anonymous?
No. It structures and records the evidence supporting a bounded conclusion. It does not bind a regulator, court, auditor or recipient, and it cannot make weak evidence conclusive.
Does the AUIA anonymise or redact data?
No. It is not a transformation engine. The organisation’s technical team or specialist provider must apply and test the relevant transformations. The AUIA records the methods, parameters, results, limitations and residual risk.
Can strong utility justify a lower anonymity standard?
No. The anonymity gate comes first. Utility helps the organisation choose among artefacts or access arrangements that have already met the applicable threshold.
Is a clean room or controlled API enough?
No. A controlled environment may reduce operational, combination or output risks and may form part of the recipient context. It does not make still-identifying data anonymous merely by restricting access.
Does the AUIA replace a DPIA?
No. A DPIA addresses high-risk processing of personal data. An AUIA examines the evidence for anonymity and retained utility. A project may require both, particularly while personal data remains in the source or transformation process.
What exactly does one assessment cover?
One defined and versioned artefact, one recipient or recipient class, one stated task and one release decision. The standard single licence may compare up to three candidate access modalities, but the final conclusion attaches to the selected modality and decision context. A material change to any of those elements may require reassessment.
Can the method assess models, embeddings and outputs?
Yes, provided that the assessment attaches to a defined version and interface and uses form-specific tests such as membership, extraction, memorisation, inversion, reconstruction and prompt-based disclosure.
What information leaves the browser?
The planned core workflow processes assessment content locally. Standard web hosting may still generate ordinary server logs when the page loads. Users should not enter real confidential information into the public demonstration.
When should an AUIA be reassessed?
After material changes to fields, transformations, recipient classes, purposes, auxiliary information, access modalities, AI capabilities, attack methods, control performance, evidence of misuse or the utility benchmark.
Is the AUIA only for Article 6(11) DMA?
No. Article 6(11) supplied the original problem and discipline. The same two-gate structure can support research, data spaces, PET programmes, competition remedies, analytics and model or output release where anonymity and useful function both require evidence.
Legal and methodological boundary
No badge. No legal fiction. No false certainty.
The AUIA provides structured decision support. It does not provide legal advice, certification, an audit opinion or a universal determination of data status. Any result remains conditional on the facts, evidence, recipient context, technology, law and method version recorded at the assessment date.
Organisations remain responsible for selecting qualified assessors, performing adequate technical testing, meeting applicable legal duties and deciding whether independent review or regulatory engagement is required.
Coming soon
Start with one real data-access decision.
Identify the artefact, intended recipient, lawful task, proposed access route and decision timetable. DigiData can then assess whether an early pilot, sector profile or organisational licence fits the problem.