Define when synthetic data constitutes a privacy claim

Determine when the use of synthetic data constitutes a privacy claim across research, deployment, and governance contexts, and establish uniform definitions that account for differences in the required level of anonymization or privacy protection across data types.

Background

The paper argues that synthetic data is often treated as implicit evidence of privacy even when no threat model, inference-risk analysis, or formal guarantee is provided. It therefore distinguishes using synthetic data as a risk-reduction heuristic from presenting it as evidence supporting a privacy claim.

The authors identify an unresolved definitional issue: organizations and regulators lack a shared understanding of when synthetic-data use amounts to a privacy claim. They argue that uniform definitions are needed before the proposed Minimum Privacy Claim Standard—requiring an explicit threat model, scope, and evidence—can be applied consistently across research, deployment, and governance settings.

References

As synthetic data is increasingly deployed in regulated settings for many different use cases, there is growing uncertainty about when its use constitutes a privacy claim.

Position: Privacy Is a Claim, Not a Property of Synthetic Data  (2609.01273 - Zhao et al., 1 Sep 2026) in Section 6, Call to Action