TL;DR:
- The Department of Commerce has ordered the Census Bureau and the Bureau of Economic Analysis to stop using "noise infusion" in their statistical products. The order was issued last week, surfaced publicly on June 11, 2026, and hit the front page of Hacker News on June 13 with 800 points and 503 comments. [1][2]
- "Noise infusion" is the technique differential privacy uses to protect individual records. The 2020 Census adopted it because the swapping method used in 1990, 2000, and 2010 had been mathematically broken: researchers could reconstruct individual census forms from the published tables. [1]
- The order is written carefully to avoid claiming it overrides confidentiality law. It says it "shall not be interpreted to conflict with any constitutional, statutory, regulatory, or other legal provision." That phrasing leaves the Bureau legally required to keep individual records confidential, with the only safe tool for doing so explicitly banned. [1]
- Desfontaines, ex-Google differential-privacy researcher, is blunt about the result. "Future statistical releases will either be useless compared to past ones, or they will be incredibly unsafe." He has not seen a major U.S. outlet pick up the story yet. [1]
- You cannot opt out of the Census. The legal response is the only lever. Researchers, demographers, and the privacy community can submit comments during any public-comment window the Bureau opens, and they can push the agency to use its existing legal authority to push back against the Commerce order.
What the order does
The Trump administration's Department of Commerce has issued an order to the Census Bureau and the Bureau of Economic Analysis declaring that "noise infusion" is no longer an acceptable disclosure-avoidance technique for any of their statistical products. The order was signed last week. Privacy researcher Damien Desfontaines published the analysis that surfaced it on June 11, 2026. Hacker News put the story on the front page on June 13. By the time you read this, the post has 800 points and 503 comments, the largest privacy-researcher community reaction of the week. [1][2]
The order's language targets differential privacy by name and goes further. It also pushes the agencies toward coarsening (less precise categories) and suppression (removing any statistic that fails a threshold), and it tells them to use those tools "first" and "as a last resort" respectively. The Bureau's only remaining options for protecting the identities behind its tables are blunt instruments. [1]
The order carefully says it "shall not be interpreted to conflict with any constitutional, statutory, regulatory, or other legal provision." That is the contradiction at the heart of the document. The Bureau is required by federal law to keep individual census responses confidential. The 2020 Census adopted differential privacy specifically because the previous technique, swapping, had been mathematically proven to leak individual records. Banning noise infusion leaves the Bureau legally bound to keep records confidential and procedurally forbidden from using the only tool that can keep them confidential at the granularity it currently publishes. [1]
Why this is a privacy story, not a statistics story
The Census is the most complete dataset the U.S. government collects on its residents. Every ten years, every household is required by law to answer, with fines for refusal. The answers cover race, ethnicity, household composition, income, housing costs, citizenship status for some questions, and granular geography down to the block. It is the dataset that underpins congressional apportionment, the allocation of hundreds of billions of dollars in federal funding, the Voting Rights Act enforcement, and almost every piece of public health, education, and housing research in the country. [1]
Publishing that data is the whole point. The Bureau is not collecting it for fun. The privacy problem is that publishing fine-grained statistics about small groups (a block, a specific demographic combination, a specific age bracket) can be turned into a system of equations that lets an attacker reconstruct the original records. Researchers demonstrated this against the 2010 Census published tables. It was not a theoretical flaw. It worked. [1]
That is what "disclosure avoidance" is for. The Bureau needs to publish useful statistics about populations, but it also needs to make sure no one can use those statistics to figure out what an individual household reported. The 2020 Census adopted a system built on differential privacy because the privacy research community concluded, after a multi-year evaluation, that it was the technique that gave the most useful data while still protecting confidentiality. The privacy parameters were not chosen to be mathematically elegant. They were chosen to squeeze the most utility out of the data while reaching an acceptable level of protection. [1]
What differential privacy actually does, in plain English
Differential privacy works by adding carefully calibrated random noise to the statistics the Bureau publishes. If the published count of households in a census tract is 1,247, the actual count might have been 1,243, or 1,251. The amount of noise is chosen so that no matter what an attacker already knows, the published numbers cannot be used to learn anything specific about any individual household with high confidence. [1]
The noise is not random in the sense of "unpredictable" or "sloppy." The amount of noise added is calculated from a privacy budget, a mathematical quantity that limits how much any individual record can affect the published statistics. Get the budget right and you can publish rich, useful data. Get the budget wrong and either the data is too noisy to be useful, or the noise is too thin to protect privacy. The 2020 Census, imperfect as it was, got this right in a way the previous swapping approach had not. [1]
Desfontaines is the right person to explain the trade-off. He was on Google's differential privacy team. He built Tumult Analytics, a company whose core product is differential privacy tooling for government and corporate datasets. He is not writing this as an opponent of the Bureau. He is writing it as someone who knows what the Bureau just gave up. [1]
What banning it actually breaks
Desfontaines's summary is the cleanest version: "Future statistical releases will either be useless compared to past ones, or they will be incredibly unsafe." [1] That is not a partisan framing. It is the math.
The reason is that the remaining disclosure-avoidance tools are not equivalent. Suppression removes statistics that fail a threshold, which destroys utility for small populations. Coarsening makes data less precise, which destroys utility for any analysis that depends on fine-grained geography or demographic combinations. Both tools are essentially the disclosure-avoidance equivalent of locking the filing cabinet and throwing away the key. The data is safe because it is gone. [1]
The data tools the order is banning are not just differential privacy. They include any technique that injects randomness into the published statistics. The Cell Key method used at statistical agencies in other countries adds noise. The swapping used by the U.S. Census from 1990 to 2010 added randomness. Random sampling adds noise. Even statistical imputation, the technique statisticians use to fill in missing values, adds noise. The order is written broadly enough to potentially affect all of these. The Desfontaines post flags this explicitly. [1]
The structural problem is that privacy attacks on statistical releases are a system-of-equations problem. They get a lot easier when the attacker knows the published statistics are exactly right. Noise is what forces the attacker to compute probabilities, quantify uncertainty, and reason about baselines. Take the noise away and the attacks become trivial. [1]
Why it matters to you, even if you are not a demographer
The Census does not collect your name. It does not collect your Social Security number. It does not collect your income, your immigration status, or anything you would normally think of as "private" in the data-broker sense. What it does collect is the most complete picture of who lives where in the United States, and it is the dataset that every other federal data product is anchored to. [1]
If the 2030 Census publishes tables that can be reverse-engineered to individual records, the privacy loss compounds. Those tables feed the American Community Survey. They feed the Current Population Survey. They feed the funding formulas for Medicaid, SNAP, highway planning, school district budgets, disaster relief, and rural hospital reimbursement. Researchers use them to document housing discrimination, environmental justice, voting rights violations, and the demographic impact of policy. The data is not a spreadsheet on a shelf. It is the substrate. [1]
The order's critics on the Hacker News thread include former census enumerators who walked door to door for the 2020 count. One of them wrote: "Trust in my community was already not high and I had lots of interesting encounters. I really believed the rather invasive data I was collecting with a friendly face would be used and handled responsibly. I feel for the poor souls that'll sign up to go door to door for 2030 now that the firewalls against weaponizing and monetizing all of our sensitive government data has been torn down." [2] That is not a privacy researcher talking. That is the person whose job is to convince strangers to answer the door. If the enumerators cannot promise confidentiality, the response rate drops, and a Census that undercounts is the privacy problem that follows from the privacy solution being banned. [2]
What the order says, and what it does not say
The Department of Commerce has not published a public explainer for the order. Desfontaines is working from the order text itself and from a Bureau of Economic Analysis announcement. The post does not quote the order directly in full, but the structural reading is consistent: the order lists noise infusion as a banned technique, names coarsening and suppression as the preferred alternatives, and includes the "shall not be interpreted to conflict with any legal provision" carve-out. [1]
What the order does not say is why. The Hacker News thread is full of speculation, much of it pointed: that the goal is to force the Census to publish data that enables reidentification (useful for gerrymandering), or that the goal is to suppress useful demographic data entirely, or that the order is just administrative convenience that nobody thought through. Desfontaines's preferred explanation is Hanlon's razor: the privacy/utility trade-off is annoying, differential privacy makes it explicit, and banning the technique is a way of pretending the problem does not exist. [1][2]
None of those explanations are reassuring. The political-economy point is that an administration that wanted to use Census-derived data for reidentification now has the legal tool to force the Bureau to publish tables that can be reidentified. An administration that wanted to suppress useful demographic data now has the legal tool to force the Bureau to publish less. Either way, the Bureau loses, and the public loses, and the only winner is the agency that gets to define what "useful" means going forward. [1]
What you can do
You cannot opt out of the Census. You can opt into the response.
The larger pattern
The Census order lands the same week as the Department of Commerce's other data decisions, including the export-control directive that suspended Anthropic's Fable 5 and Mythos 5 models for foreign nationals and the Amazon-AWS pressure that drove it. [3][4] The two stories are not the same story, but they are part of the same pattern: a Commerce Department that is now setting the rules on what kinds of data the United States publishes, what kinds of inference the United States runs, and what kinds of tools the United States allows its federal statistical agencies to use. The diffusion of authority is the story. The Census order is one piece of it.
There is also a FISA 702 piece to the story, and a state-of-surveillance piece. Federal statistical products are part of the surveillance state the same way wiretap records are, in the sense that the data the government collects about you is the data the government can use to make decisions about you. The 2030 Census, published with the protection the order is banning, becomes a tool that lets a future administration match your block, your household composition, and your demographic profile to anything else in the federal data stack. The privacy researchers who are sounding the alarm about this are not worried about an academic exercise. They are worried about a Census product that becomes a key in a much larger reidentification database. [1][2]
The Bottom Line
The Department of Commerce has ordered the Census Bureau and the Bureau of Economic Analysis to stop using the noise-infusion techniques that differential privacy is built on. The order is written to avoid claiming it overrides the Bureau's confidentiality obligations, which is the legally interesting part: it leaves the Bureau bound to keep records confidential with the only safe tool for doing so explicitly off the table. The 2020 Census adopted differential privacy because researchers had mathematically broken the previous swapping approach. Going back to the pre-2020 techniques is not a return to a working system. It is a return to a system that has been proven to leak. [1]
Desfontaines's framing is the right one. The choice the Bureau now faces is between less useful data and unsafe data. That is not a privacy-research community opinion. It is the math. The 800-point Hacker News thread, the 503 comments, the alarmed former census enumerators writing in are symptoms of a much larger problem: a federal statistical agency being told, quietly, to publish data that is easier to reidentify. [1][2]
The story is two days old. There is no major U.S. outlet coverage yet. There will be. The question is whether the public-comment window and the congressional pressure come before the Bureau commits to a methodology for 2030.
Sources
- Damien Desfontaines: "Banning noise will be a disaster for statistical data products" (June 11, 2026; ex-Google differential-privacy researcher; primary analysis of the Commerce order)
- Hacker News: "Noise infusion banned from statistical products published by Census Bureau" (June 13, 2026, 800 points, 503 comments, top story of the day for the privacy research community)
- State of Surveillance: "Anthropic Pulled Fable 5 and Mythos 5. The US Government Made Them Do It." (June 12, 2026; the export-control directive from the same Department of Commerce, covering the Fable 5 and Mythos 5 access suspension for foreign nationals)
- The Verge: "Amazon security research reportedly led to the White House's Anthropic Fable ban" (June 13, 2026; the Amazon-originated pressure behind the Fable 5 and Mythos 5 export-control action)