Absolute anonymization, conceived as an irreversible transformation preventing re-identification and sensitive value disclosure, has proven to be a broken promise. Modern data protection must therefore shift toward a privacy-utility trade-off grounded in risk mitigation. Differential Privacy (DP) offers a rigorous mathematical framework for balancing quantified disclosure risk with analytical usefulness. Nevertheless, widespread adoption remains limited, largely because complex technical concepts, such as privacy-loss parameters, have yet to be translated into forms meaningful to non-technical stakeholders. This difficulty arises from randomization itself: both analysts and adversaries must draw conclusions from uncertain observations rather than deterministic values. In this work, we adopt an interpretation of the privacy-utility trade-off based on hypothesis testing to measure the uncertainty introduced by randomized mechanisms. In particular, we use the concept of relative disclosure risk to quantify the maximum reduction in uncertainty an adversary can obtain from a membership attack on protected outputs, and show this measure relates directly to standard privacy-loss parameters. We further analyze how DP affects analytical validity via its impact on hypothesis tests assessing statistical significance. Building on these results, we provide practical guidance, accessible to non-experts such as data protection authorities, for navigating the trade-off and selecting protection mechanisms and parameter values.
翻译:暂无翻译