07/13/2026
We’ve been solving privacy with a black marker. But the ink was never enough.
Every time a company promises your data is “safe” because they removed your name and email, they’re treating privacy like a game of hide-and-seek - where only your face is covered, but your shadow, your gait, and the company you keep are all still visible.
The truth is: names were never the dangerous part.
It’s the pattern of when you log in. The combination of your zip code, birth date, and gender. The sequence of websites you visited before you got there.
Researchers have shown that 87% of the U.S. population can be re-identified from just three data points: birth date, gender, and zip code.
For Canadian context: Research from the University of Ottawa found the numbers here are actually starker. Because Canadian postal codes are far more granular than U.S. ZIP codes. The average postal code covers about 19 people, not 2,700 — roughly 97% of Canadians can be re-identified from their full postal code, birth date, and gender alone. Even if you strip it back to just the first three characters of a postal code, that figure still sits near 80%. So the “anonymous” dataset you’re trusting? For most Canadians, it was never anonymous to begin with.
Remove the name, and the person is still unmistakably there.
We’ve built a culture of “compliance theatre”, where redacting a field feels like security, but it’s often just cosmetic. Real anonymization requires thinking about context, correlation, and time. It means asking not “Did we remove the obvious labels?” but “Could someone still recognize this person if they tried?”
So here’s what I keep coming back to: If perfect anonymization is nearly impossible, and pseudonymization is fragile, what standard should we actually hold companies to? Is informed consent even meaningful when the risks are this technical and this opaque?
We want to hear your take!
Where do you land on this? Do you think companies should be required to prove data can’t be re-identified before they call it ‘anonymized’? Or is the whole concept of anonymous data becoming obsolete?
Drop your thoughts below. The best answers might end up in part two.