How Syndata AB worked with Mimer AI Factory to rigorously evaluate the privacy properties of synthetic data, and build the tools to keep doing it
| Organization | Syndata AB |
| Industry | Synthetic data/Privacy technology |
| Challenge | Formally validating the privacy properties of synthetic data against GDPR and AI Act requirements |
| Support from | Nishat Mowla, Henrik Forsgren, Michael Popoff, Kabir Fahria, Susanne Stenberg |
| Type of support | Technical and privacy evaluation; policy and regulation expertise |
| Outcome | Verified evaluation results, repeatable testing methodology, and increased regulatory readiness |
The promise of synthetic data
Synthetic data holds real promise for organisations that need to share, test, or analyse data without exposing personal information. Instead of working with real records, they work with artificially generated datasets that mirror the statistical properties of the original, but without the identifiable details.
Syndata AB has built its business on this idea. The Swedish company provides synthetic data generation solutions to organisations looking to unlock the value of their data while managing privacy risk. But offering synthetic data as a privacy-preserving tool is not the same as proving it is one.
GDPR and the EU AI Act both demand rigorous accountability. Synthetic data reduces privacy risk; it does not eliminate it. Re-identification attacks, membership inference, and attribute disclosure are real threats that any serious provider must be able to evaluate and quantify. The challenge for Syndata was not just meeting regulatory requirements, but building a credible, structured way to measure privacy risk and communicate it to customers.
Without that foundation, customer trust is hard to establish and adoption is slow. The field of synthetic data evaluation is still maturing, and standardised methods are not yet settled. Syndata needed both the technical capability and the regulatory grounding to do this work properly.
Testing and translating solve the rigor problem
Syndata approached Mimer AI Factory for both technical depth and regulatory expertise, two things that are rarely found together. The Mimer team brought specialists across privacy evaluation, machine learning, and GDPR and AI Act policy to bear on the problem.
The work combined structured evaluation with exploratory method development. Established privacy risk techniques were tested alongside emerging approaches, with the team working to quantify specific risks, including re-identification and privacy leakage, using both conventional and novel evaluation tools. Because the field lacks agreed standards, part of the value was in developing and validating practical approaches that could be applied consistently.
Alongside the technical work, Mimer’s policy and regulation experts helped translate the requirements of GDPR and the AI Act into concrete, measurable technical criteria. This meant the evaluation was not just technically rigorous; it was directly aligned with what the regulatory landscape demands.
The result was both a set of verified evaluation results for Syndata’s existing solution, and a repeatable methodology that Syndata can apply independently in future deployments, with Mimer support available when needed.
Without this project, we wouldn’t have been able to run this sort of pilot at all, due to all insecurities. The economic impact is large. The value comes from reducing uncertainty and risk, enabling more efficient customer dialogues, and providing a credible way to verify and demonstrate the properties of synthetic datasets. – Statement from Syndata AB Leadership
From uncertainty to evidence
The collaboration has strengthened the trustworthiness of Syndata’s products in a tangible, demonstrable way. Being able to quantify privacy risk and show the numbers to customers changes the nature of the sales conversation. It reduces uncertainty on both sides, and it gives buyers a concrete basis for their own compliance decisions.
For a company operating in a market where trust is everything and regulation is tightening, this kind of credibility is not just a competitive advantage. It is becoming a prerequisite. The project has positioned Syndata as a more mature, accountable provider, better prepared for GDPR and AI Act requirements, and better equipped for scalable growth.
It has also contributed something more durable: Syndata now has the internal capability to run this kind of evaluation independently, building on the methods developed during the collaboration. The knowledge transfer was part of the design.