The anonymous witness

Research brief, The Morporkian Civil Liberties Union (MCLU). Open file.

Everyone in the room is handed the same dataset. It has been anonymised properly, to the standard that was agreed, by people who did the work carefully.

One person says that is my neighbour. A moment later somebody else says that is my supervisor. Then somebody goes quiet and says that one is me.

Nothing has been re-identified in the sense the standard means. No key was broken and no name appears anywhere. The dataset is still anonymous. The people in the room are not.

What gave them away was not the data. It was knowing them.

  • If a dataset is anonymous only to strangers, what has anonymisation achieved?

  • Who bears the harm when a group is inferred from records and no individual in it can be pointed to?

Whether anonymous survives contact

  • The Article 29 Working Party opinion on anonymisation techniques, for the test actually in use and its stated limits.

  • EU collective redress for inferred groups, on groups built from anonymised data and who may act for them.

  • Re-identification literature where the attacker is an acquaintance rather than a researcher, which is a different threat model and much less studied.

  • Any authority ruling on data that is anonymous in general and identifying within a small community.

  • Whether the AI Act’s treatment of groups offers anything a person in this room could use.

Tell us who you recognised

Last updated: 17 September 2026