Assessment of Disclosure Risk

  • George T. DuncanEmail author
  • Mark Elliot
  • Juan-José Salazar-González
Part of the Statistics for Social and Behavioral Sciences book series (SSBS)


Before disseminating a data product for public use, a DSO needs to assess the risk of a data snooper compromising confidentiality. In its original form as the source data, a data product typically has unacceptably high disclosure risk. The data product must therefore be transformed to lower the disclosure risk to an acceptable level. We present a variety of methods for statistical disclosure limitation in Chapters 4 and 5, but first we need to understand disclosure risk and have appropriate tools for its assessment.


Markov Chain Monte Carlo Risk Measure Record Linkage Population Uniqueness Population Unit 
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.


  1. Bacher, J., Brand, R., Bender, S.: Re-identifying register data by survey data using cluster analysis: an empirical study. Int. J. Uncertainty Fuzziness Knowl.-Based Syst. 10(5), 589–608 (2002)CrossRefzbMATHGoogle Scholar
  2. Dale, A.: Confidentiality of official statistics: an excuse for privacy. In: Dorling, D., Simpson, S. (eds.) Statistics in Society, pp. 29–37. Arnold, London (1998)Google Scholar
  3. Dale, A., Marsh, C.: The 1991 Census Users’ Guide. HMSO, London (1993)Google Scholar
  4. Dalenius, T.: Finding a needle in a haystack – or identifying anonymous census records. J. Official Stat. 2(3), 329–336 (1986)Google Scholar
  5. Domingo-Ferrer, J. (ed.): Inference Control in Statistical Databases. Springer, New York, NY (2002)zbMATHGoogle Scholar
  6. Domingo-Ferrer, J., Torra, V.: A quantitative comparison of disclosure control methods for microdata. In: Zayatz, L., Doyle, P., Theeuwes, J., Lane, J. (eds.) Confidentiality, Disclosure and Data Access: Theory and Practical Applications for Statistical Agencies, pp. 111–133. North-Holland, Amsterdam (2001)Google Scholar
  7. Domingo-Ferrer, J., Torra, V.: Validating distance-based record linkage with probabilistic record linkage. Lecture Notes in Computer Science 2504, 207–215 (2002)CrossRefGoogle Scholar
  8. Duncan, G.T., Keller-McNulty, S.A., Stokes, S.L.: Disclosure risk vs. data utility: the R-U confidentiality map. Technical report LA-UR-01-6428, Los Alamos National Laboratory, Los Alamos, NM 2001Google Scholar
  9. Elamir, E., Skinner, C.J.: Record level measures of disclosure risk for survey microdata. J. Official Stat. 22, 525–539 (2006)Google Scholar
  10. Elliot, M.J.: Data intrusion simulation: advances and a vision for the future of disclosure control. Stat. J. United Nations 17, 1–9 (2001)Google Scholar
  11. Elliot, M.J., Dale, A.: Scenarios of attack: a data intruder’s perspective on statistical disclosure risk. Netherlands Official Stat. 14, 6–10 (1999)Google Scholar
  12. Elliot, M.J., Manning, A.M., Ford, R.W.: A computational algorithm for handling the special uniques problem. Int. J. Uncertain. Fuzziness Knowl. Based Syst. 5(10), 493–509 (2002)CrossRefGoogle Scholar
  13. Elliot, M.J., Skinner, C.J., Dale, A.: Special uniques, random uniques and sticky populations: some counterintuitive effects of geographical detail on disclosure risk. Res. Official Stat. 1(2), 53–68 (1998)Google Scholar
  14. Fellegi, I.P., Sunter, A.B.: A theory for record linkage. J. Am. Stat. Assoc. 64, 1183–1210 (1969)CrossRefGoogle Scholar
  15. Garey, M.R., Johnson, D.S.: Computers and Intractability: A Guide to the Theory of NP-Completeness. W.H. Freeman, New York, NY. ISBN 0-7167-1045-5 (1979)zbMATHGoogle Scholar
  16. Gill, L.: Methods for automatic record matching and linking and their use in national statistics. National Statistics Methodology Series, no. 25. Office for National Statistics, London (2001)Google Scholar
  17. Jaro, M.A.: Advances in record-linkage methodology as applied to matching the 1985 census of Tampa, Florida. J. Am. Stat. Assoc. 84(406), 414–420 (1989)CrossRefGoogle Scholar
  18. McCullagh, K.: Data sensitivity: proposals for resolving the conundrum. J. Int. Commer. Law Technol. 2(4), 190–201 (2007)Google Scholar
  19. Müller, W., Blien, U., Wirth, H.: Identification risks of micro data. Evidence from experimental studies. Sociol. Methods Res. 24, 131–157 (1995)CrossRefGoogle Scholar
  20. Paass, G.: Disclosure risk and disclosure avoidance for microdata. J. Bus. Econ. Stat. 6(4), 487–500 (1988)CrossRefGoogle Scholar
  21. Polettini, S., Stander, J.: A Bayesian hierarchical model approach to risk estimation in statistical disclosure limitation. In Domingo-Ferrer, J., Torra, V. (eds.) Privacy in Statistical Databases, pp. 247–261. Springer, Berlin (2004)CrossRefGoogle Scholar
  22. Skinner, C.J., Elliot, M.J.: A measure of disclosure risk for microdata. J. R. Stat. Soc. Ser. B 64(4), 855–867 (2002)CrossRefzbMATHMathSciNetGoogle Scholar
  23. Skinner, C.J., Holmes, D.J.: Estimating the re-identification risk per record in microdata. J. Off. Stat. 14, 361–372 (1998)Google Scholar
  24. Smith, D., Elliot, M.J.: An experiment in Naive Bayesian record linkage. Proceedings of Conference of the International Statistical Institute, Sydney, April 2005Google Scholar
  25. Smith, D., Elliot, M.J.: A measure of disclosure risk for tables of counts. Trans. Data Priv. 1(1), 34–52 With Smith, D. (2008)MathSciNetGoogle Scholar
  26. Torra, V., Abowd, J., Domingo-Ferrer, J.: Using Mahalanobis distance-based record linkage for disclosure risk assessment. Lect. Notes in Comput. Sci. 4302, 233–242 (2006)CrossRefGoogle Scholar
  27. Winkler, W.E.: Matching and record linkage. In: Cox, B.G. et al. (ed.) Business Survey Methods, pp. 355–384. Wiley, New York, NY (1995a)Google Scholar
  28. Yancey, W.E., Winkler, W.E., Creecy, R.H.: Disclosure risk assessment in perturbative microdata protection. In: Domingo-Ferrer, J. (ed.) Inference Control in Statistical Databases. Lecture Notes in Computer Science, vol. 2316, pp. 135–152. Springer, Berlin, Heidelberg (2002)Google Scholar
  29. Skinner, C.J., Shlomo, N.: Assessing identification risk in survey micro-data. J. Am. Stat. Assoc. 103(483), 989–1001 (2008)CrossRefzbMATHMathSciNetGoogle Scholar
  30. Elliot, M.J.: DIS: a new approach to the measurement of statistical disclosure risk. Risk Manage. Int. J. 2(4), 39–48 (2000)CrossRefGoogle Scholar
  31. Marsh, C., Skinner, C., Arber, S., Penhale, B., Openshaw, S., Hobcraft, J., Lievesley, D., Walford, N.: The case for samples of anonymized records from the 1991 census. J. R. Stat. Soc. Ser. A 154, 305–340 (1991)CrossRefGoogle Scholar
  32. Greenberg, B.V.: Disclosure avoidance research at the census Bureau. Proceedings of the Bureau of the Census Sixth Annual Research Conference, Bureau of the Census, Washington, DC, pp. 144–166 1990Google Scholar
  33. Benedetti, R., Franconi, L., Capobianchi, A.: Individual risk of disclosure using sampling design information. Istat Contributi n. 14/2003. Available at (2003)
  34. Federal Committee on Statistical Methodology: Statistical Policy Working Paper 22: Report on Statistical Disclosure Limitation Methodology, U.S. Office of Management and Budget, Washington, DC 1994Google Scholar
  35. Elliot, M.J.: Data Citizenship: a 21st century solution to a 20th Century problem. Keynote speech to Exploiting Existing Data for Health Research, St Andrews September (2007)Google Scholar
  36. Domingo-Ferrer, J., Torra, V.: Disclosure risk assessment in statistical microdata protection via advanced record linkage. Stat. Comput. 13, 343–354 (2003)CrossRefMathSciNetGoogle Scholar
  37. Pagliuca, D., Seri, G.: Some Results of Individual Ranking Method on the System of Enterprise Accounts Annual Survey, Esprit SDC Project, Deliverable MI-3/D2 (1999)Google Scholar
  38. Domingo-Ferrer, J., Torra, V. Mateo-Sanz, J.M., Sebé, F.: Empirical disclosure risk assessment of the ipso synthetic data generators. In: Santos, M.J., Bujnowska, A. (eds.) Monographs in Official Statistics-Work Session on Statistical Data Confidentiality, pp. 227–238. Eurostat, Luxemburg (2006)Google Scholar
  39. Robert, C.P., Casella, G.: Monte Carlo Statistical Methods (second edition). Springer, New York, NY (2004)zbMATHGoogle Scholar
  40. Duncan, G.T., Lambert, D.: The risk of disclosure for microdata. J. Bus. Econ. Stat. 7, 207–217 (1989)CrossRefGoogle Scholar

Copyright information

© Springer New York 2011

Authors and Affiliations

  • George T. Duncan
    • 1
    Email author
  • Mark Elliot
    • 2
  • Juan-José Salazar-González
    • 3
  1. 1.Carnegie Mellon UniversitySanta FeUSA
  2. 2.University of ManchesterManchesterUK
  3. 3.University of La LagunaLa LagunaSpain

Personalised recommendations