Synthetic Data
What is Synthetic Data?
Artificially generated data that mimics the statistical properties of real-world data without containing actual personal information. Synthetic data can be used for AI training and testing while preserving privacy.
Terms that appear alongside synthetic data
Each of these is named in at least one of the same controls as synthetic data. The number is how many controls name both.
- gdpr 4 shared controls
- differential privacy 4 shared controls
- pseudonymisation 3 shared controls
- anonymisation 3 shared controls
- nist 3 shared controls
- federated learning 3 shared controls
- privacy by design 2 shared controls
- data protection 2 shared controls
Frameworks that govern synthetic data
What the standards actually require on synthetic data
Requirements naming synthetic data across 6 standards, quoted from the control text.
Synthetic data generation produces artificial datasets that preserve statistical properties of the original data without containing real personal data, supporting model training and testing while reducing personal-data exposure;
ENISA-DPE-4.5 · Synthetic data →Clauses 6 + 6.1 establish ethical values elicitation and prioritisation. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): elicit values from stakeholders covering categories: human autonomy + beneficence + n...
IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency · IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) →Global CBPR Forum 2024-2025 status + pipeline. UK ACCESSION 2024: United Kingdom acceded April 2024 + first non-APEC member; ICO + DSIT signed accession; first wave of UK-certified Accountability Agents accredited;
CBPR-2024-2025-UK-NewJurisdictions-AI-PEP · Global CBPR Forum: 2024-2025 Update Pipeline - UK 2024, AI Integration, PEP, ASEAN MCC →Personal data must not be used for testing; false or synthetic data must be used instead, and where using personal data for testing is unavoidable the technical and organizational measures of the production environment must be applied, with a risk assessment i...
iso-27701-2019::6.11.3 · Test data →Standard 3 per Section 21 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be adequate + relevant + and necessary in relation to the purposes for which they are processed (Data Minimisation Principle).
JM-DPA2020-Standard3-Adequacy-Relevance-Necessity-Sec21-Data-Minimisation-No-Excess-Processing · Jamaica DPA 2020 Standard 3 - Adequacy + Relevance + Necessity + Section 21 + Data Minimisation + No Excess Processing + Proportionality + Privacy by Default + Field-Level Restraint + Granular Permissions →Apply Section 4.2-4.5 PII minimisation principles: collect only PII necessary + purpose limitation + storage limitation + accuracy + record retention per NARA schedule + secure disposal.
NISTSP122-4 · PII Minimisation, Purpose Limitation, and Pseudonymisation →Questions people ask about synthetic data
What is Synthetic Data?
Why is Synthetic Data important for compliance?
Which compliance frameworks address Synthetic Data?
Where can I learn more about Synthetic Data?
See how Synthetic Data applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.