Privacy & Tech

Knowledge Base | Privacy & Tech | Can synthetic data reveal information about real people?

Can synthetic data reveal information about real people?

Yes. Synthetic data consists of artificially generated records, but those records may be created using patterns learned from real personal information. Depending on the method, they can reproduce sensitive details or allow inferences about people in the source dataset.

A business might use synthetic customer records to test a checkout system without giving developers access to its customer database. That reduces exposure only if the generated records are sufficiently protected against revealing the original information.

Useful checks include:

  • Whether generated records closely reproduce real records.

  • Whether rare combinations of characteristics expose individuals.

  • Whether someone could infer that a person appeared in the source data.

  • Whether the generation process includes additional privacy protections.

The ICO’s guidance on synthetic data explains why synthetic does not necessarily mean anonymous.

Assess the source data, generation method and intended release together. Anonymization and pseudonymization remain distinct outcomes, regardless of whether the resulting records look artificial.