Care · research january 2026 · published 2026-08-03 · v1 · 3 min read
The parameter is a policy
Some decisions are made once, numerically, by an engineer, and then govern everyone the system touches
How a privacy budget, a classification threshold, or a decay constant becomes an unreviewed ruling about people, and the disclosure that converts it back into a decision someone can be held to. The canonical treatment of a parameter as policy.
Somewhere in a configuration file there is a number that decides how much of one person’s exposure buys how much of everyone else’s accuracy, and it was set once, by whoever was closest to the code. The received view is that this is tuning. Parameters are engineering detail, chosen by the people who understand the mathematics, adjusted when the output looks wrong, and not the sort of thing a governance conversation has any purchase on. For most parameters that is exactly right. For one class it is a category error, and the cleanest instance of that class is a Greek letter.
On June 9, 2021, the United States Census Bureau’s Data Stewardship Executive Policy Committee announced the settings for the system protecting the 2020 census redistricting file, and the headline setting was a privacy-loss budget of epsilon equal to 19.61, split as 17.14 for the persons file and 2.47 for housing units. The committee had raised the figure after data users objected that the earlier demonstration products distorted counts for small places, tribal areas, and race and ethnicity statistics. Alabama had already sued in March to stop the method, and a three-judge court denied its request for a preliminary injunction on June 29 before the case was dropped that September. A number in a statistical pipeline had become a federal lawsuit, and nobody involved was confused about why.
Epsilon is unusual only in making the trade explicit. In the formulation Cynthia Dwork, Frank McSherry, Kobbi Nissim and Adam Smith published in 2006, epsilon bounds how much any single person’s record can change what the released statistics say, and the bound is purchased with noise. A smaller epsilon means more noise, a stronger guarantee for the individual, and worse numbers for everyone who uses the results to draw a district or fund a school. Whoever picks the value is therefore ruling on a trade between two parties’ interests, both real and neither of them in the room, and the ruling arrives as a decimal rather than as a sentence somebody could disagree with.
That is the shape to look for elsewhere, because the same structure is everywhere and almost never labeled. A retention window is a ruling about whose past stays recoverable. A classification threshold is a ruling about how many false accusations buy how many catches, issued by whoever set the cutoff. A decay constant decides how long a judgment about a person keeps its force. Each is chosen once, numerically, and then governs everyone the system touches, and each looks from inside the codebase like a knob. Our corpus already has a position on constraints that nothing enforces and on the scope a claim quietly leaves out. This is a third thing and it is the opposite failure. The decision was genuinely made and is genuinely binding, and it was never written anywhere a person subject to it could read it.
The remedy has already been drafted by the people closest to the mathematics. Dwork, with Nitin Kohli and Deirdre Mulligan, argued in 2019 under a title that is itself the whole instruction, expose your epsilons, for a public registry of the values that real deployments actually use, on the grounds that a guarantee whose parameter is secret is not a guarantee anyone outside can evaluate. Generalize it past differential privacy and it becomes an ordinary disclosure test. For every number in a system that trades one group’s interest against another’s, name who gains, who pays, who chose, and where the choice is recorded. Most parameters fail the test by being boring, which is the point, because the handful that survive it were governing people all along, and a team that can name them out loud has turned an unreviewed default back into a decision it can be held to.
Evidence and lineage
Research trail
Follow the sources, inspect how the claims are graded, or propose a correction at the exact record it concerns.
Sources 4
-
Cynthia Dwork, Frank McSherry, Kobbi Nissim, Adam Smith (2006). Calibrating Noise to Sensitivity in Private Data Analysis (Theory of Cryptography Conference)
The origin of the epsilon formulation. Privacy is preserved by adding noise calibrated to a query's sensitivity, and epsilon is the parameter bounding how much any one record may influence the released answer.
Comment on this source -
United States Census Bureau, Data Stewardship Executive Policy Committee (2021). Census Bureau Sets Key Parameters to Protect Privacy in 2020 Census Results
The public parameter decision. A named committee set the privacy-loss budget for the redistricting file at epsilon 19.61, raising it from the demonstration level after data users objected to accuracy losses for small places, tribal areas, and race and ethnicity statistics.
Comment on this source -
State of Alabama and others v. United States Department of Commerce (2021). Three-judge federal panel, Middle District of Alabama, challenge to the 2020 census disclosure avoidance system
The litigation. Filed March 2021, preliminary injunction denied June 29, 2021, dismissed without prejudice in September 2021. Evidence that the parameter choice was contested as policy rather than as engineering.
Comment on this source -
Cynthia Dwork, Nitin Kohli, Deirdre Mulligan (2019). Differential Privacy in Practice: Expose your Epsilons! (Journal of Privacy and Confidentiality 9(2))
The remedy the brick generalizes. A proposed public Epsilon Registry recording the values real deployments use, on the argument that an undisclosed parameter makes a guarantee unevaluable from outside.
Comment on this source
Claims and confidence 4
- verified
The Census Bureau's Data Stewardship Executive Policy Committee announced on June 9, 2021 a privacy-loss budget of epsilon 19.61 for the 2020 census redistricting file, split as 17.14 for the persons file and 2.47 for housing units.
Census Bureau press release of June 9, 2021 and the accompanying disclosure avoidance system production parameter documentation; verified against census.gov during the spiritual-harvest wave, 2026-08-03.
Respond to this claim - verified
Epsilon bounds how much any single person's record can change a released statistic, so a smaller value buys a stronger individual guarantee with more noise and less accurate results.
Dwork, McSherry, Nissim and Smith (TCC 2006) and the standard differential privacy literature; the direction of the trade is definitional rather than empirical.
Respond to this claim - verified
Alabama sued to stop the Census Bureau's use of differential privacy in March 2021, a three-judge court denied its motion for a preliminary injunction on June 29, 2021, and the case was dismissed without prejudice that September.
Case dockets and contemporaneous coverage; verified during the spiritual-harvest wave, 2026-08-03.
Respond to this claim - verified
Dwork, Kohli and Mulligan proposed a public Epsilon Registry in 2019, recording the epsilon values real deployments use.
Differential Privacy in Practice: Expose your Epsilons!, Journal of Privacy and Confidentiality 9(2), 2019.
Respond to this claim