Skip to content
Conference Open access

From Privacy-Utility Trade-Offs to Policies: Optimized Anonymization Recommendations for Data Trustees in Data Spaces

2026 · Proceedings of the 15th International Conference on Data Science, Technology and Applications · pp. 1097-1108 · 0 citations · 42 references

TL;DR

By mapping spatial transformation algorithms to ODRL constraints, this research provides data trustees with an approach to automatically enforce spatial privacy and sovereignty within data spaces.

Abstract

: As data spaces emerge to facilitate sovereign data exchange, geospatial data has become a critical resource across various domains. However, sharing sensitive geodata, such as cadastral property records, presents a privacy-utility trade-off. While the European Data Governance Act (DGA) establishes data trustees as the technical intermediaries authorized to perform necessary anonymization, a gap remains between theoretical spatial privacy algorithms and their practical, policy-driven application. This research addresses this gap by presenting an empirical evaluation of 11 spatial anonymization methods applied to complex polygon geometries. Using a dataset of 2,147 forested cadastral parcels, we quantify the trade-offs using privacy metrics ( k -anonymity, differential privacy ε ) and utility measures (Hausdorff distance, area deviation, centroid shift). Our results identify algorithmic failure modes, such as the “sparse forest” phenomenon, and demonstrate the improved performance of combined hybrid approaches. To operationalize these findings, we integrate our results into the architecture of data trustees operating within various domain-specific data spaces. We demonstrate how the empirically derived, use-case-specific anonymization guidelines can be translated into machine-interpretable Open Digital Rights Language (ODRL) policies. By mapping spatial transformation algorithms to ODRL constraints, this research provides data trustees with an approach to automatically enforce spatial privacy and sovereignty within data spaces.

Read PDF

Similar papers

Preprint Aug 2026

Dependency Triad: A Metric to Quantify the Dependencies Between Attributes for Local Differential Privacy

A novel metric, ``Dependency Triad''(DT), is proposed, which summarizes the pairwise dependency information relevant to CPL using three parameters and yields a conservative estimator of pairwise CPL, which is particularly suitable for high-cardinality attributes.

Sandaru Jayawardana, S. Ulukus, Ming Ding et al. · 0 citations
Open access Jul 2026

A New Multidimensional Data Anonymization Algorithm for Privacy-Preserving Data Publishing

Developing a privacy-preserving data publishing algorithm that prevents individuals’ identity information from being disclosed without ignoring the utility of the data is still an important goal to be achieved. Finding the optimal balance between data utility and data privacy is an NP-hard problem. In this study, a new k-anonymization-based data anonymization algorithm is proposed. The proposed algorithm partitions the data space with a new efficient partitioning strategy based on the k-dimensional tree (KD-tree), resolves the boundary problem while maintaining the trade-off balance, and introduces a new mechanism to address the problems caused by outliers. Moreover, it can be applied to both numerical and categorical data. The experimental results indicate that the proposed algorithm achieves competitive or improved performance compared with the baseline algorithms across seven commonly used evaluation metrics. Overall, the findings suggest that the proposed framework can improve the utility–privacy trade-off in multidimensional k-anonymization.

Burak Cem Kara, Can Eyüpoğlu, Oktay Karakuş · 0 citations
Open access Jul 2026

Privacy Preservation in Data Streams: An Efficient Query Algorithm Based on CGP

A lightweight collaborative geographic privacy preservation mechanism for dynamic data streams called Pruning-CGP, which has blocked side-channel cardinality leakage and can be applied to address the demand for a high-performance, low-resource algorithm in the context of edge computing.

Shiwen Xu · 0 citations
Book Open access Jul 2026

Unequal Cover: Measuring Privacy Disparities in Proxy Infrastructure

Privacy-focused proxy systems (e.g., multi-party relays, VPNs, etc.) are now standard Internet infrastructure, yet little is known about potential disparities in the privacy they provide across different populations. In this work, we investigate disparities in proxy crowd sizes, measuring how mappings between users and infrastructure can produce unequal geolocation anonymity across communities. We combine infrastructure deployment data with demographic information and apply our framework to Apple's iCloud Private Relay, analyzing 83,609 U.S. census tracts, and find significant disparities: rural users receive crowd sizes over 9× smaller than urban users, and income moderately correlates with privacy outcomes in rural areas (r=0.39) while showing negligible correlation in cities. We then explore, through simulation, strategies for improving privacy equity, demonstrating that operators can enhance privacy for the worst-protected populations by up to 2.5× using simple consolidation strategies while introducing manageable potential geolocation error.

Jess Alencaster, Rishan Baweja, Leticia Leon-Rodriguez et al. · 0 citations
Open access Oct 2026

SoK: Mapping the Privacy Landscape of Geolocation Ecosystems

Modern geolocation ecosystems rely on diverse technical solutions and architectures, often proprietary, making it difficult to develop a global understanding of the privacy implications of location data production. This challenge is particularly critical given the ubiquity of geolocation in modern digital infrastructures and the central role of location data in privacy concerns. Yet, existing work largely focuses on isolated case studies, resulting in a fragmented understanding of the privacy risks associated with location data production. In this work, we introduce an abstract model of geolocation ecosystems together with a systematic methodology for analyzing their privacy implications, which we apply to nine representative case studies spanning a broad range of architectures, from OS-level geolocation services to object-tracking platforms. This comparative analysis identifies structural design choices that significantly impact users' privacy and reveals common structural privacy risks across heterogeneous ecosystems, which reflect architectural design decisions rather than security vulnerabilities or poor system design. These findings, together with gaps identified in existing defense mechanisms, motivate research directions aimed at strengthening privacy in future geolocation architectures.

Augustin Laouar, P. Lachat, Loïc Desgeorges et al. · 0 citations
Open access 2026

A Serverless Client-Side Privacy Index for Sensitive Data Processing

The Privacy Index is introduced, a unified metric designed to aggregate multiple privacy-related factors into a single, interpretable score that integrates the validation of established privacy models, detection of anonymization techniques, and estimation of re-identification risk under different attacker assumptions.

José A. Gameiro, J. Oliveira, João Rafael Almeida · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.