U.S. flag

An official website of the United States government

Skip Header


A Criterion for Privacy Protection in Data Collection and Its Attainment via Randomized Response Procedures

Author:
RRS2017-07

Abstract

Randomized response (RR) methods have long been suggested for protecting respondents' privacy in statistical surveys. However, how to set and achieve privacy protection goals have received little attention. We give a full development and analysis of the view that a privacy mechanism should ensure that no intruder would gain much new information about any respondent from his response. Formally, we say that a privacy breach occurs when an intruder's prior and posterior probabilities about a property of a respondent, denoted p and p*, respectively, satisfy p* < hl(p) or p*> hu(p), where hl and hu are two given functions. An RR procedure protects privacy if it does not permit any privacy breach. We explore effects of (hl; hu) on the resultant privacy demand, and prove that it is precisely attainable only for certain (hl; hu). This result is used to define a canonical strict privacy protection criterion, and give practical guidance on the choice of (hl; hu). Then, we characterize all privacy satisfying RR procedures and compare their effects on data utility using sufficiency of experiments and identify the class of all admissible procedures. Finally, we establish an optimality property of a commonly used RR method.

Related Information


Page Last Revised - October 28, 2021
Is this page helpful?
Thumbs Up Image Yes Thumbs Down Image No
NO THANKS
255 characters maximum 255 characters maximum reached
Thank you for your feedback.
Comments or suggestions?

Top

Back to Header