Test re-identification and residual disclosure risks: What is the most defensible response?
Synthetic generation does not automatically make data anonymous; residual disclosure and re-identification require explicit assessment.
The question
A software procurement team receives a vendor dataset described as synthetic. The vendor provides no generation method, similarity analysis, or evidence about whether sensitive source patterns remain. The purchasing team asks whether privacy review can be skipped. What is the most defensible response?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Test re-identification and residual disclosure risks ✓Synthetic data may preserve identifiable patterns or leak information, so privacy properties require evidence rather than an automatic assumption.
- Accept the vendor’s synthetic-data label as sufficient privacy evidenceA label does not establish anonymity, especially when generation and similarity evidence are unavailable.
- Use the dataset only for accuracy testing without further privacy analysisAccuracy testing does not determine whether sensitive patterns remain or whether the dataset creates disclosure risks.
- Require consent from every person represented in the original source dataConsent may be relevant in some circumstances, but the evidence does not establish it as the sole or necessary response.
The trap
Ask what privacy evidence supports a synthetic-data claim; the word “synthetic” alone does not establish non-identifiability. How to remember it
Synthetic generation does not automatically make data anonymous; residual disclosure and re-identification require explicit assessment.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Development questions
- Conduct targeted security and privacy testing: What evidence gap is decisive? →
- Clarify criteria: What evidence should it prioritize before interpreting model performance? →
- Link model, dataset, transformation, and test versions: What control most directly resolves the uncertainty? →
- All 426 Understanding How to Govern AI Development questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Development ·
Every answer, right and wrong, comes with its own explanation.