XIII. The Disclosure Avoidance Crisis
Disclosure avoidance refers to the methods Census uses to prevent published statistics from revealing confidential information about a particular person or household. These protections operate after data collection but before detailed census tables are released.
The challenge is unavoidable. Census publishes information for very small geographic areas and detailed population groups. In some places, a table may describe only a few people with a particular combination of characteristics. When those data are combined with publicly available records, commercial databases, or other government information, an attacker may be able to infer facts about individuals even when names and addresses do not appear in the published table.
For the 2020 Census, the Bureau adopted a disclosure avoidance system based on differential privacy. The system added carefully calibrated statistical noise to published counts while preserving certain totals exactly. Census viewed the approach as a way to provide measurable privacy protection against increasingly powerful reconstruction and linkage techniques.
The controversy that followed was not principally about whether confidentiality matters. It concerned how Census balanced privacy against data usefulness, how errors were distributed, whether the system performed adequately for small populations and geographies, and whether data users had enough opportunity to understand and influence the design before critical decisions were made.
Those concerns remain relevant for 2030, but Census now faces a fundamentally different policy environment. The Commerce Department has prohibited noise infusion as a disclosure avoidance technique. Unless that policy changes or Census receives an exception, the Bureau cannot simply improve and reuse the 2020 approach.
At the same time, eliminating noise does not eliminate disclosure risk. Census must still prevent published tables from revealing confidential responses. Older methods such as suppression and aggregation may avoid visibly altering some published counts, but they impose their own losses. Suppression can remove data entirely. Aggregation can eliminate geographic or demographic detail.
This creates a genuine disclosure avoidance crisis. Census must design a system that addresses modern privacy risks while operating under a policy that may prohibit one of the strongest tools available for measuring and controlling those risks. If the Bureau cannot reconcile those demands, the likely result is not unprotected data. It is a smaller, less detailed, or less transparent public-data program.
The consequences will not be evenly distributed. Large national and state totals can often be protected while remaining highly accurate. The greatest pressure falls on small racial and ethnic populations, rural communities, tribal areas, neighborhoods, and places where only a few people share a particular characteristic. These are often the same communities for which census data provide one of the only reliable sources of information.
The policy also creates legal, scientific integrity, and administrative questions. Census must determine whether Commerce’s prohibition permits an exception for the decennial census, what alternative methods can satisfy Title 13, and whether those alternatives have been tested rigorously enough to support consequential data products. The Bureau must also explain how disclosure avoidance decisions will account for the constitutional and statutory uses of census data.
This chapter examines the conflict between the need for strong confidentiality protection and the need for useful public data. It considers the lessons of 2020, the consequences of prohibiting noise infusion, the limitations of alternative methods, and the decisions advocates should watch as Census develops the 2030 system.
The central principle is that privacy and usefulness must be treated as joint requirements. A disclosure avoidance system fails if it exposes confidential information, but it also fails if the only way to protect confidentiality is to prevent the public from seeing meaningful information about its communities.
A. What the Operational Plan Expected
The Operational Plan anticipated a gradual process of improving the disclosure avoidance system used for the 2020 Census while also evaluating possible alternatives. It did not commit Census to reusing the same system unchanged. Instead, the plan called for research into different methods, testing of their effects on privacy and data quality, and decisions based on the needs of the 2030 data products.
This was a reasonable starting point. The 2020 experience showed that Census needed to improve both the technical design and the process used to develop it. Data users raised concerns about accuracy for small populations and geographic areas, the treatment of particular statistics, and the limited time available to evaluate demonstration data before key decisions were made. Census also gained substantial practical experience operating a formally private system at national scale.
The plan therefore emphasized earlier and more sustained engagement with data users. Rather than presenting a nearly completed system late in the decade, Census intended to involve stakeholders while it was still identifying data needs, comparing methods, and determining how to balance confidentiality with usefulness.
That engagement would ideally address questions such as:
which tables, geographic levels, and population details are most important;
which statistics must be preserved with especially high accuracy;
how alternative methods affect small communities and detailed groups;
how privacy risk and data error will be measured and explained; and
when demonstration products will be available for outside testing.
The Operational Plan also contemplated alternatives to the 2020 system. That is important because differential privacy is a framework for measuring and limiting privacy loss, not a requirement to reproduce every technical choice made in 2020. Census could reconsider the algorithms, privacy-loss allocation, invariants, geographic processing, and product design while retaining a formally measurable approach. It could also compare differential privacy with suppression, aggregation, swapping, or combinations of methods.
The plan’s underlying assumption, however, was that Census would be free to evaluate the available methods scientifically and select the approach that best met its legal and operational responsibilities. It treated disclosure avoidance as a difficult research and design problem, not as a question to be resolved in advance by prohibiting a broad class of techniques.
That distinction matters now. Earlier engagement and alternative-method research remain valuable, but they cannot substitute for genuine methodological choice. If Commerce policy removes noise infusion from consideration before Census completes its research, the Bureau is no longer comparing the full range of approaches anticipated by the Operational Plan.
Original direction
Improve on the 2020 disclosure avoidance system, investigate alternatives, and involve data users earlier in defining priorities and evaluating results.
What has changed
The Commerce prohibition on noise infusion may constrain the research process before Census determines which method provides the strongest combination of confidentiality protection and useful public data.
Why advocates should care
The Operational Plan promised a more open and evidence-based design process. Advocates should press Census to preserve that commitment and explain clearly when a methodological option is rejected because of research findings and when it is excluded because of department policy.
B. What Changed
In 2026, the Department of Commerce issued a Department Administrative Order prohibiting noise infusion in statistical products. The policy removed from consideration the basic mechanism underlying the 2020 Census disclosure avoidance system and the formally private approach Census had initially selected for protecting 2030 block-level population counts.
Census has since added notices to webpages describing its prior disclosure avoidance plans. Those notices state that the information is no longer current and that the Bureau is evaluating alternative approaches to comply with the Department’s prohibition. This includes materials describing both the 2020 differential privacy system and the research program Census announced for 2030.
The practical consequences are becoming clearer. At the 2026 Joint Statistical Meetings in Boston, Census staff affirmed that complying with the DAO would require coarsening and suppression. That statement is important because it moves the discussion beyond the abstract possibility that Census might choose a different technical system. The Bureau now anticipates that some data will need to be published with less detail and that some values may need to be withheld entirely.
Coarsening protects confidentiality by reducing the specificity of published information. Depending on the product, that can include combining categories, aggregating geographic areas, reporting ranges, or rounding values. In the decennial census context, coarsening could mean fewer detailed population categories, less geographic detail, or fewer cross-tabulations showing several characteristics together.
Suppression withholds data that cannot be published safely under the applicable rules. It may protect an individual table cell, but it can also require additional complementary suppressions to prevent users from calculating the hidden value from surrounding totals. Suppression can therefore remove more information than the initially sensitive cell alone.
The Bureau of Economic Analysis’s implementation of the same Department policy illustrates the direction Commerce has established. BEA identifies coarsening as the preferred category of disclosure avoidance methods and permits suppression only as a last resort, when coarsening is legally unavailable or would substantially defeat a product’s accuracy or usefulness. For its June 2026 foreign direct investment release, BEA used aggregation and rounding and reported that it did not use either noise infusion or cell suppression.
BEA’s implementation does not determine the system Census will use for 2030. Economic statistics and decennial population data differ in their legal requirements, product structures, and disclosure risks. But the BEA policy shows the Department’s preferred sequence: reduce detail first and suppress data when coarsening cannot provide adequate protection.
The JSM statement suggests that Census expects the decennial census to require both. Coarsening alone may not resolve every disclosure risk while preserving the totals and products Census is legally or operationally expected to publish. Suppression may therefore be necessary for some small populations, geographic areas, or detailed combinations of characteristics.
This changes the nature of the 2030 disclosure avoidance debate. Under the original research plan, Census expected to compare noise infusion, suppression, aggregation, swapping, and other methods using a common set of scientific principles. The DAO has now excluded noise infusion before that research process is complete. Census must choose among the remaining methods even if its own earlier analysis found that formally private noise infusion best satisfied its principles for protecting block-level population counts.
The likely tradeoff is no longer limited to whether published counts will contain small statistical changes. The more immediate questions are now:
which racial, ethnic, household, and other categories will be combined;
which geographic levels will lose detail;
which cross-tabulations will no longer be produced;
when values will be suppressed;
how much complementary suppression will be required; and
whether some planned data products can be released at all.
Census should promptly replace the general notices on its webpages with a public implementation plan. That plan should explain how the DAO applies to the decennial census, which methods remain under evaluation, what Census staff have already concluded about coarsening and suppression, and how data users will participate in decisions about which information is preserved.
What changed
Commerce prohibited noise infusion, invalidating central assumptions of the 2030 disclosure avoidance research program. Census is evaluating alternatives and has now stated that compliance will require coarsening and suppression.
Credible risk
Census protects confidentiality by reducing geographic and demographic detail and withholding cells, with the greatest losses falling on small populations and small areas.
Why advocates should care
The question is no longer simply how Census will adjust published counts. It is increasingly which communities and characteristics will remain visible in the public data at all.
C. The Remaining Options in Plain Language
Without noise infusion, Census will need to protect confidentiality mainly by publishing less precise or less detailed information. The remaining options include:
Aggregating geographic areas: combining small areas into larger ones so fewer statistics are published for individual blocks or neighborhoods.
Combining population categories: merging detailed racial, ethnic, age, household, or other groups into broader categories.
Rounding: replacing an exact count with a nearby rounded number.
Publishing ranges: reporting that a value falls within a range rather than providing the exact number.
Suppressing values: withholding a number entirely when publishing it could reveal confidential information. Additional values may also need to be suppressed so the missing number cannot be calculated from surrounding totals.
Reducing the number of tables: publishing fewer combinations of characteristics, such as race by age by household type.
Releasing less detailed microdata: limiting the geographic or demographic detail in anonymized person- and household-level files used by researchers.
These methods do not all have the same consequences. Some reduce precision while preserving a general picture. Others remove information altogether. The central question will be how much geographic, demographic, and subject-matter detail Census can preserve while still meeting its confidentiality obligations.
D. Why This Particularly Affects Historically Undercounted Groups
Coarsening and suppression do not affect every population equally. Large groups and large geographic areas can usually retain useful statistics even when some detail is removed. Smaller populations and local communities are more likely to disappear from the published data because their counts are divided among fewer people and smaller places.
For example, Census might continue to publish a total population count for Oglala Lakota County, South Dakota, but combine blocks or tracts until users can no longer see meaningful differences among communities within the Pine Ridge Reservation. The county would remain visible on a map, while the local detail needed for housing, transportation, health, or disaster planning could be lost.
The same problem applies to detailed racial and ethnic groups. A population such as Hmong Americans might remain visible in a national table but be combined into a broader Asian category or suppressed in state and local tables where the number of people is smaller. The published data would still show an Asian population, but officials and community organizations could no longer identify the distinct needs or experiences of Hmong residents.
These effects can compound. A small population living in a small rural area is especially vulnerable because both its geographic and demographic detail may be reduced. Data for a particular tribal community, Pacific Islander group, or immigrant population may disappear even though broader totals for the county or racial category remain available.
This matters because historically undercounted groups often need the most detailed data to identify where census errors occurred and to support civil rights enforcement, program planning, funding requests, and community advocacy. Combining groups can conceal meaningful differences among them. Publishing only larger geographies can hide concentrated needs. Suppression can leave no official number at all.
The loss is therefore not merely statistical. A community may be included somewhere inside a broader total while becoming impossible to see, describe, or advocate for using public census data.
Credible risk
The groups most likely to be undercounted during enumeration are also among the first to lose visibility when Census protects confidentiality by combining categories, enlarging geographies, or suppressing small values.
Why advocates should care
A census data product can appear complete at the national level while providing little usable information about smaller communities. Being counted in a broad total is not the same as remaining visible in the data.
E. Geographic Consequences
The consequences of coarsening and suppression will depend heavily on geography. National and state totals include enough people that Census can often preserve substantial detail. The greatest losses are likely to occur below the state level, where the same population is divided among counties, tracts, block groups, and individual blocks.
A 2021 Census experiment provides a useful illustration, although it should not be treated as a forecast of the 2030 system. Census applied suppression rules modeled on the 1980 Census to 2010 data and examined what would have happened to the P.L. 94-171 redistricting tables. The results showed that traditional suppression could eliminate a large share of the detailed data needed for redistricting, particularly for voting-age populations at small geographic levels. The experiment also counted only the initial suppressions; additional values would have needed to be withheld to prevent users from calculating the suppressed numbers from surrounding totals.
Blocks
Census blocks are the smallest geographic units for which decennial census data are tabulated. They provide the building pieces used to construct voting districts, neighborhoods, and many other local geographies. In urban areas, a block may resemble an ordinary city block. In rural areas, one block may cover many square miles.
Block data are especially vulnerable because many blocks contain comparatively few people. Under the 2021 experiment, cells containing one or two people would have been reported as zero. About 8 percent of block-level race cells and 6 percent of block-level Hispanic-origin-by-race cells would have been changed before accounting for the additional complementary suppressions needed to protect those values.
The consequences would have been much greater for complete tables showing race and Hispanic origin among the voting-age population. The experiment estimated that approximately 84 percent of block-level adult race tables and 88 percent of adult Hispanic-origin-by-race tables would have been suppressed entirely.
This level of loss would make it difficult to determine precisely where small populations live. A community might remain visible at the county or city level while disappearing from the individual blocks needed to draw districts around it.
Block Groups
Block groups combine nearby blocks within a census tract. They are large enough to provide more stable statistics than individual blocks but still small enough to describe parts of a neighborhood or rural community.
The 2021 experiment found particularly severe effects at this level. About 10 percent of race cells and 15 percent of Hispanic-origin-by-race cells would initially have been changed to zero. Under the table-suppression approach, approximately 96 percent of adult race tables and effectively all adult Hispanic-origin-by-race tables would have been withheld.
Coarsening could avoid some of that suppression by combining block groups or publishing fewer categories. But either approach would reduce the ability to identify differences within a tract, such as a small racial or ethnic community concentrated in one part of a neighborhood.
Census Tracts
Census tracts are relatively stable statistical areas designed to support analysis of local communities over time. They are frequently used in research, planning, program targeting, and comparisons of neighborhood conditions.
Tracts contain more people than blocks or block groups, but detailed tables can still produce small cells. In the 2021 experiment, about 6 percent of tract-level race cells and 11 percent of Hispanic-origin-by-race cells would have been changed to zero. When adult population tables were subjected to table suppression, approximately 84 percent of tract-level race tables and nearly 100 percent of tract-level Hispanic-origin-by-race tables would have been withheld.
These losses would affect more than redistricting. Tracts are commonly treated as approximations of neighborhoods in planning and research. If detailed information is published only for combinations of several tracts, important differences among nearby communities may disappear.
Small Counties
County totals are generally more resilient because counties contain more people. But many rural counties have populations smaller than a single urban neighborhood, and detailed cross-tabulations can still contain very small numbers.
The Census experiment estimated that approximately half of county-level adult race tables and 84 percent of county-level adult Hispanic-origin-by-race tables would have been suppressed under the tested rules. Even the less restrictive cell-suppression approach would have altered some county-level values.
This could leave a small county with a reliable total population count but little information about its voting-age racial and ethnic populations. Combining the county with surrounding areas would preserve a regional estimate, but it would no longer describe the county itself.
Tribal Geographies
The P.L. 94-171 data program publishes information for American Indian and Alaska Native areas, Hawaiian homelands, and tribal subdivisions, in addition to conventional state, county, tract, block-group, and block geographies.
Many tribal geographies contain small populations or are divided among several geographically separate communities. Suppression could remove data for particular tribal subdivisions or small population groups. Geographic aggregation could preserve a total for a reservation or broader tribal area while eliminating the information needed to understand differences among its communities.
Combining racial categories could create an additional problem. Data users may need to distinguish people identifying with a particular tribe or detailed American Indian or Alaska Native population from a much broader category. If both geographic and population detail are reduced, a small tribal community could become difficult to identify even within its own lands.
Census should evaluate disclosure avoidance methods specifically for tribal geographies rather than assuming that results for counties or ordinary census tracts describe their effects adequately. Tribal governments should be involved early in determining which geographic and population details are essential.
Neighborhood-Level Redistricting and Planning
P.L. 94-171 requires Census to provide states with the small-area population tabulations needed for legislative redistricting, and block-level data allow states and local governments to assemble districts from the ground up.
If exact block data are unavailable, map drawers may have difficulty determining whether a proposed boundary divides a small racial or ethnic community. Data published only for larger areas may show that a population lives somewhere within a tract or county without showing where it is concentrated.
The effects extend to local redistricting. County commissions, city councils, school boards, and other bodies often draw districts covering relatively small populations. A level of coarsening that leaves congressional redistricting possible may still make neighborhood-scale districts much harder to evaluate.
Local planning faces a similar problem. Communities use small-area data to locate services, understand housing patterns, plan transportation, prepare for emergencies, and document local needs. Combining several neighborhoods may produce a statistically usable number while concealing the particular place where the need is concentrated.
The 2021 estimates do not show exactly what Census will suppress or coarsen in 2030. They used one set of historical suppression rules, older race and ethnicity categories, and 2010 data. But they demonstrate the scale of the underlying problem: conventional suppression can preserve broad totals while eliminating much of the geographic detail that makes census data useful.
Credible risk
Census continues to publish accurate national and state totals but removes large amounts of block-, block-group-, tract-, county-, and tribal-area detail. The data remain technically available while becoming much less useful for local redistricting and planning.
Why advocates should care
Communities exist at smaller scales than states and large counties. When disclosure avoidance removes the ability to see where people live within those areas, it can prevent the public from identifying communities of interest, evaluating district boundaries, and directing resources to the places where they are needed.
F. Worst-Case Scenario
The most severe outcome should be understood as an outer boundary, not a current prediction.
If the Commerce DAO prevents Census from using noise-based methods and the remaining confidentiality standard is applied extremely restrictively, the Bureau may conclude that many detailed tables cannot be published safely. For some subjects, useful data could be limited largely to the state level. For others, county-level or broader geography may be the smallest level available.
Under that scenario, Census might still publish the population totals required for apportionment and some redistricting purposes, but much of the accompanying demographic detail could be coarsened or suppressed. Block- and tract-level data needed to identify small racial and ethnic communities, analyze voting patterns, plan disaster response, or study neighborhood conditions could be severely reduced or unavailable.
The effects would extend beyond the complete disappearance of a table. Census could publish broad totals while withholding the detailed cross-tabulations that make the data useful. A county might retain its total population and broad race categories but lose information about smaller groups, voting-age populations, or how those populations are distributed among neighborhoods.
This is not the most likely outcome under every possible implementation of the DAO. Census may be able to develop methods that preserve substantially more detail. But the scenario illustrates the outer limit of what could happen if the Bureau is required to meet a demanding protection standard with a much narrower set of tools.
There is also an opposite danger. Pressure to preserve every table and geographic level could lead Census to adopt protections that are too weak. Detailed data about very small populations or places may allow users to infer confidential information about individual respondents when combined with outside records.
That risk cannot be dismissed simply because the published tables do not contain names. Census has a legal and ethical obligation to protect the information people provide, particularly when participation is mandatory and respondents cannot control how future technology or outside databases may be used.
The choice is therefore not between useful data and unnecessary privacy rules. Census must avoid two genuine failures:
overprotection, in which communities disappear from public data; and
underprotection, in which confidential respondent information can be reconstructed or inferred.
Worst-case outer boundary
Census preserves only broad state- or county-level information for many subjects, while block-, tract-, tribal-, and neighborhood-level detail is sharply reduced. The resulting products satisfy confidentiality requirements but no longer support many of the local uses for which census data are essential.
Opposite danger
Census preserves detailed products without adequate protection, allowing confidential information about respondents to be inferred from published statistics and outside data.
Why advocates should care
The goal is not to maximize either privacy or detail without limit. It is to require a transparent, evidence-based system that provides meaningful confidentiality protection while preserving the geographic and demographic information the public needs.
G. Time Pressure
The Operational Plan anticipated a multiyear process for developing the 2030 disclosure avoidance system. Census expected to identify user needs, compare alternative methods, publish demonstration products, obtain stakeholder feedback, and select an approach early enough to build it into the final data products.
The Commerce DAO disrupted that schedule by excluding noise infusion after Census had already organized much of its research around improving or replacing the 2020 system. Census must now identify methods that comply with the new policy, determine how much detail they can preserve, and redesign products around their limitations.
Disclosure avoidance cannot be separated from product design. Decisions about suppression or coarsening will affect which tables Census can publish, which geographic levels they can support, and which totals must remain consistent across products. The Bureau also needs time to build production systems, test them at national scale, conduct legal and scientific review, and allow data users to evaluate realistic demonstration files.
As the available time narrows, several risks increase.
Census could adopt a rushed replacement that has not been tested adequately across small populations, local geographies, and major data uses. A method that appears acceptable in national averages may perform poorly for tribal areas, rural communities, or detailed racial and ethnic groups.
The Bureau could also return to an older method because it is familiar and technically available. But older systems were designed for a different data environment and may not provide adequate protection against modern reconstruction and linkage risks. Reuse would still require testing rather than an assumption that a method used in an earlier census remains suitable.
Time pressure could lead Census to release fewer products. When the Bureau cannot establish that a detailed table can be protected safely, the fastest solution may be to eliminate the table, combine categories, or publish only at larger geographic levels. These decisions could become permanent product reductions even if additional research might have identified a better approach.
Data releases could also be delayed. Disclosure avoidance must be applied before Census can publish protected data, and unexpected problems can require repeated processing and review. Late decisions could threaten the schedules for redistricting data, demographic products, detailed race and ethnicity files, and public-use microdata.
Finally, unresolved policy and methodological questions could lead to litigation close to statutory deadlines. States, civil rights organizations, data users, privacy advocates, or other parties could challenge either the loss of necessary data or the adequacy of confidentiality protections. A court dispute shortly before a required release would leave little time to revise the system without delaying the data or disrupting redistricting and other time-sensitive uses.
Census should therefore publish a revised disclosure avoidance schedule as soon as possible. It should identify the dates for selecting candidate methods, releasing demonstration products, obtaining stakeholder feedback, completing legal and scientific review, and making final product decisions. The schedule should also show how much time remains for correction if testing reveals serious problems.
Credible risk
Delay narrows the range of practical choices until Census must select the method that can be implemented fastest rather than the one that best balances confidentiality and data usefulness.
Advocacy priority
Require an updated public timeline, early demonstration data, transparent decision points, and enough time for outside evaluation before methods and products become operationally irreversible.
Why advocates should care
A technically defensible disclosure avoidance system requires years of research and testing. Decisions made under deadline pressure could determine not only how the data are protected, but which public data exist at all.
H. Research Agenda
Census now needs a revised research agenda built around the methods that remain permissible under the Commerce DAO. That work should begin with the data products the public needs, not with an abstract comparison of disclosure avoidance techniques.
1. Map Product and Geographic Requirements
Census should identify every major 2030 data product and the smallest geography at which it is expected to be useful. The analysis should distinguish among products needed for apportionment, redistricting, civil rights enforcement, program administration, local planning, research, and public-use microdata.
This mapping should show where block-level data are essential, where tract- or county-level data may be sufficient, and which products depend on detailed cross-tabulations rather than simple population totals.
2. Model the Effects of Coarsening and Suppression
Census should apply realistic coarsening and suppression rules to prior census data and proposed 2030 tables. The resulting demonstration products should show what information would be combined, rounded, withheld, or eliminated under each approach.
The analysis should include complementary suppression and other secondary effects, not only the first cells identified as sensitive. It should also examine how losses accumulate when geographic and population detail are reduced at the same time.
3. Identify Legally Required Tabulations
Census and Commerce should publish a clear analysis of which tabulations are required by the Constitution, federal statutes, regulations, and binding program commitments. That review should address apportionment, redistricting, the Voting Rights Act, and other civil rights and administrative uses.
The analysis should distinguish legally required outputs from products that are discretionary but still important. Legal minimums should not automatically become the ceiling for the public-data program.
4. Compare Privacy and Usefulness Across Permissible Methods
Census should compare all methods permitted under the DAO using consistent measures of confidentiality risk, statistical error, geographic detail, demographic detail, consistency, and usability.
The comparison should include aggregation, category consolidation, rounding, ranges, suppression, swapping (where permitted), and combinations of methods. It should explain which risks each method addresses and what information it sacrifices.
No method should be described as preferable simply because it avoids visible statistical noise. Coarsening and suppression may leave published values unchanged while removing entire categories, geographies, or tables.
5. Assess Effects on Small Populations
Every candidate system should be evaluated specifically for small racial and ethnic groups, tribal populations, rural communities, small counties, and geographically concentrated populations.
Census should measure how often these communities lose identifiable categories, local geography, cross-tabulations, or all publishable data. National accuracy measures will not reveal whether particular groups disappear from state or local products.
The assessment should include consultation with affected communities about which forms of detail are most important and which kinds of aggregation would be most damaging.
6. Develop a Replacement Research Timeline
Census should publish a revised timeline reflecting the methodological work required after the DAO. It should include dates for:
defining product requirements;
selecting candidate methods;
releasing demonstration data;
obtaining stakeholder feedback;
completing legal and scientific review;
choosing the final approach; and
testing the system at production scale.
The timeline should leave enough time to correct serious problems. A demonstration release issued shortly before final implementation would provide the appearance of consultation without a meaningful opportunity to influence the result.
Advocacy priority
Require Census to replace the disrupted disclosure avoidance research program with a transparent, product-centered agenda that measures both confidentiality protection and the loss of useful information.
Why advocates should care
The central question is not merely which technical method Census adopts. It is which communities, geographies, and public uses the resulting data products will continue to support.
I. Advocacy Priorities
The disclosure avoidance debate should not be left solely to technical staff or postponed until Census releases a nearly final system. Decisions made over the next several years could determine which 2030 data products exist, how much local and demographic detail they contain, and whether the public has enough time to evaluate them.
1. Challenge or Seek Revision of the DAO
Advocates should seek withdrawal, revision, or a decennial-census exception to the Commerce DAO’s prohibition on noise infusion. The objective need not be to require Census to use differential privacy. It should be to restore the Bureau’s ability to compare all scientifically credible methods and select the approach that best meets its confidentiality and data-quality responsibilities.
Legal and policy analysis should examine whether the DAO is consistent with Title 13, the statutory uses of census data, scientific integrity requirements, and ordinary standards for reasoned agency decision-making. Congressional oversight should ask why a department-wide policy displaced the Census Bureau’s existing scientific review before the 2030 research process was complete.
2. Demand a Public Replacement Plan
Census should publish a replacement plan explaining how it will comply with the DAO, which methods remain under consideration, and how the change affects the original research schedule.
The plan should identify:
the candidate disclosure avoidance methods;
the products and geographic levels under review;
the standards Census will use to compare privacy and usefulness;
the dates for major decisions and public releases; and
the process for responding when testing reveals unacceptable data loss.
A notice stating that prior plans are no longer current is not an adequate substitute for a new plan. Census has already acknowledged that it is evaluating alternatives to comply with the prohibition, while BEA’s implementation illustrates the Department’s preference for coarsening and use of suppression only as a last resort.
3. Require Demonstration Products
Census should release realistic demonstration products for every serious candidate method. These files should include the P.L. 94-171 redistricting data and other products important for civil rights analysis, local planning, tribal data, and detailed race and ethnicity research.
Demonstration files should show the combined effects of coarsening, suppression, rounding, product reduction, and consistency requirements. Census should provide enough documentation for data users to determine which categories, geographies, and tables have been changed or removed.
The releases must occur early enough to influence the final decision. Applying the chosen system to the 2028 Dress Rehearsal will provide useful information, but it will be too late if Census treats the basic method and product design as settled by then. The original research plan contemplated demonstration products and stakeholder feedback as inputs into system selection and design.
4. Preserve Independent Scientific Review
The replacement system should be reviewed by experts who are not responsible for defending either the Commerce DAO or the method ultimately selected by Census. Review should address both confidentiality protection and data usefulness.
Census should publish its technical analyses, assumptions, validation measures, and internal recommendations. External reviewers should be able to examine whether the remaining methods protect against realistic disclosure risks and whether Census has accurately measured their effects on small populations and local areas.
Scientific review should not be limited to asking whether a proposed system complies with the DAO. It should also ask whether the policy constraints prevent Census from meeting its broader statistical and legal responsibilities.
5. Establish Explicit Data-Utility Requirements
Census should define minimum utility requirements before selecting the disclosure avoidance method. Otherwise, the Bureau may protect confidentiality first and determine afterward which products survive.
Requirements should identify:
the geographic detail needed for redistricting and local governance;
the racial and ethnic detail needed for civil rights uses;
the minimum products needed for tribal, rural, and small-population analysis;
acceptable levels of suppression or category consolidation; and
the uses for which rounded values or ranges would be inadequate.
These requirements should not guarantee that every requested table can be published. They should make clear when a proposed method fails to support an essential use and require Census to consider another method, product design, or confidentiality strategy.
The Operational Plan itself recognized that disclosure avoidance affects whether census results are fit for use and promised earlier engagement around data needs and products.
6. Build a Joint Data-User Coalition
Redistricting experts, civil rights organizations, tribal and state data centers, local governments, researchers, and privacy experts should engage together rather than presenting Census with isolated requests.
These communities use census data differently, but they share several interests: timely releases, transparent methods, useful local geography, accurate demographic detail, and strong confidentiality protection. A joint coalition can identify a core set of products and standards that should be preserved across uses.
Coordination will also make it harder to dismiss each concern as narrow. The loss of block-level race data is not only a redistricting issue. The disappearance of small populations is not only a research concern. Product reductions can affect civil rights enforcement, emergency planning, government funding, and public understanding at the same time.
The coalition should develop shared requests before Census establishes its replacement plan. Once the Bureau has built a system and redesigned products around it, changing course will become more expensive and less likely.
Advocacy priority
Restore genuine methodological choice, require a public replacement plan and early demonstration products, preserve independent scientific review, and establish minimum data-utility requirements before the system is selected.
Why advocates should care
The central decisions will determine not only how 2030 Census data are protected, but which communities, geographies, and public uses remain visible in the final products.
Where to Look: See section 3.4.1, “Data Products Creation and Dissemination,” pp. 60–62 of the 2030 Census Operational Plan, along with Appendix B’s discussion of disclosure avoidance. The plan called for research into improvements and alternatives to the 2020 system and earlier engagement with data users.
Monitor the Census Bureau’s Decennial Census Disclosure Avoidance webpage and its former 2030 research-agenda materials. Census has marked some earlier plans as no longer current and says it is evaluating alternatives to comply with the Commerce prohibition on noise infusion. BEA’s disclosure avoidance FAQ provides the clearest published example of how another Commerce statistical agency is implementing the policy through coarsening and, when necessary, suppression.
For evidence about the possible consequences of suppression, see Census’s June 2021 presentation on alternatives to the 2020 disclosure avoidance system. Its experimental estimates for the P.L. 94-171 file show how suppression could sharply reduce detailed data below the state level, although the specific results should not be treated as a forecast for 2030.