- What lower level of anonymity is acceptable? Is 1 in 30 acceptable?
- What about edge cases where it becomes much lower? Say only one person in a small county has an account to a web service because it is largely targeted at people elsewhere?
- What about academic improvements that keep decreasing anonymity by improving understanding of collected data? What time limit would NSA get to update its systems in case of such improvements? What happens if the speed of academic improvements is larger than the speed of updates in NSA systems? Is the system scrapped right away?
I agree that formal definitions seem lucrative. But these aren't simplified mathematical static models that we are talking about.