Skip to content

Aggregation threshold

An aggregation threshold is the minimum number of people a group must contain before a result about that group is shown. Below it, an average or a distribution can reveal an individual, so the cell is suppressed. It is the practical rule that separates a team-level reading from a disguised individual one.

A team average of three people is a statement about each of them, whatever the label on the chart says.

Why it matters when the plan changes

Organisational reporting is full of small groups: a leadership team, a country office, a function of five. Reporting a group score for any of them tells everyone who knows the group something about each member, which is individual data by another route. Recital 26 of the General Data Protection Regulation treats anonymous information as outside data protection principles, but only if the aggregation truly achieves anonymity, not merely a label of 'team'. The threshold is where that leak is stopped, and it has to be set before the first dashboard is built.

The tension is that the groups leaders most want to see are the small ones. A threshold that protects individuals also hides the team the sponsor cares about. Article 5 of the General Data Protection Regulation requires data limited to what is necessary, which supports designing the team-level product around what can be shown at the agreed minimum, since a manager view exists to show appropriate team patterns, not a summary of individuals.

In practice

A manager view shows aggregated behavioural patterns for a team of four. One member is on leave the week of the reforecast and the average moves visibly. Everyone on the team can now read the absent colleague's result from the difference. No individual data was ever displayed, and individual data was disclosed.

Evidence

What it cannot tell you

An aggregation threshold cannot tell you whether a group score is meaningful, only whether it is safe to display. It is silent on the accuracy or relevance of the underlying measure, and a group that clears the minimum size can still mislead if its members are not otherwise comparable, for instance a function assembled from unrelated teams.

Questions

There is no single legal number, but Recital 26 of the General Data Protection Regulation (2016) frames the test as whether information remains anonymous, not whether it sits above an arbitrary count. In practice five or more is common, ten for sensitive results, and small senior groups fail the anonymity test at surprisingly large sizes.

Especially to them. A leadership team is small, its members know each other well, and its results are of intense interest. A team-level reading for such a group has to be designed so that nothing individual can be inferred, which often means reporting patterns and gaps rather than distributions.

Reading an individual from the change between two group results, for example when one person joins or leaves. It defeats a threshold applied to each report separately. Guarding against it means considering what a reader can infer from the sequence of reports, not only from each one alone.

It does not restrict them. Article 5 of the General Data Protection Regulation (2016) requires data to be limited to what is necessary for the purpose; an employee receiving their own results is that purpose fulfilled. The threshold governs what others see about a group, so a person can see themselves in full while a manager sees only the aggregate.

The controller, advised by its data protection officer and, where relevant, agreed with employee representatives. A supplier should propose a default and make the setting visible, but the level is a decision about the employer's population and the employer's risk, not the supplier's.