Simple summary…

The States say most households will be better off under the new tax plan. That claim comes from a computer model that nobody outside the States has ever been allowed to check.

They give two reasons for keeping it hidden: the data behind it is private, and we are also told the model is so clumsy it takes half an hour to run just once.

There has been a standard fix for both problems for over 50 years, and tax offices around the world use it, including in the UK and the US.

The fix works like this:

  • You take the real records, remove anything that could identify a person, keep only a small representative sample, and blur the unusual cases so nobody can be picked out.
  • You then check this smaller, anonymous file against real totals, such as actual tax collected, to prove it still gives the right answers.
  • A file like that can be published safely, because it is about nobody. And because it is small, the model runs in a split second instead of half an hour, so every assumption can be properly tested.

In other words, one piece of work would have solved both problems at once: the privacy problem and the speed problem. The software needed is free.

Guernsey’s data protection law is not a barrier to this. It protects personal data; a properly anonymised file is not personal data, so the law actually shows the way to publish, not a reason to refuse.

So why was it not done? Either the people building the model did not know the basic tools of their own trade, or keeping the data private and the model slow was convenient, because a model nobody can check is a model nobody can challenge. It could be both.

The way out is simple: publish an anonymous version of the data and the model, and let it be tested in the open, the same way we tested their public calculator.

The States say the data behind the tax package is too sensitive to release, and their own model is too slow to test properly. Both problems have had a standard solution for decades. Not using it leaves only two explanations, and neither is flattering.

The claim at the centre of the 2026 Tax Reform Package is distributional: that a majority of households would be better off or no worse off. That claim comes from a household model the public has never seen, built on data the public is told cannot be shared, and run, according to the answers given to Deputy Curgenven, on a spreadsheet that takes the best part of half an hour to recalculate for each cell change. The refusal to release rests on the sensitivity of the data. The absence of any published sensitivity analysis rests, in practice, on the speed of the machine. We wrote in Check their sums about what we found when we tested the one piece of this apparatus that can be tested, the public calculator, and what that implied about the checking of the rest. This article is about the part we cannot test, and about the fact that we should have been able to.

Because here is the thing the debate has missed: the two problems, secrecy and slowness, are one problem, and the profession that builds tax models solved it long ago.

The solution is called a public use file.

It is a reduced, weighted, anonymised extract of the real records, engineered so that it reproduces the population’s tax arithmetic while identifying nobody, and so that it recomputes in moments rather than minutes. Tax administrations have published such files for decades. The United States Internal Revenue Service has issued one since the 1960s, and half a century of American tax analysis has run on it. HMRC releases the Survey of Personal Incomes in public and secure forms. The European Union’s income data underpins EUROMOD, a free tax and benefit model maintained for every member state and adapted by jurisdictions far smaller and poorer than Guernsey; its United Kingdom derivative, UKMOD, is free as well. None of this is exotic. It is the ordinary machinery of the trade.

    A model nobody can check is a model nobody can challenge.

    What would it have looked like here? Six steps, none of them novel.

    First, build the analysis extract and strip identity at source: link the tax records to census household composition through a throwaway key, keep only the dozen or so columns the policy turns on, incomes by type, contributions, housing costs, childcare and health costs, household composition, tenure, ages in bands, and let names, addresses and dates of birth never enter the modelling file at all.

    Second, reduce it by stratified sampling with calibrated weights, which is the disciplined version of thinning the data. Strata are drawn where the policy has edges, around the £24,960 contribution limit, the £28,000 band, the £85,000 taper and the £196,560 ceiling, and the weights are then adjusted so the reduced file reproduces the known totals exactly: taxpayer counts by band, total incomes, pensioner numbers, household counts, and, above all, the actual tax and contribution receipts. A few thousand weighted records built this way will reproduce every distributional statistic in the policy letter’s Appendix 8 to within a few pounds.

    Third, apply disclosure control, which is the step that answers the small-island objection rather than surrendering to it: incomes above a threshold replaced with group averages, money rounded, rare household types merged, ages banded, a fraction of near-identical records swapped so that no row is certainly any one person, and the extreme top of the distribution, where a small island’s identifiable individuals genuinely live, replaced with statistically equivalent simulated records that preserve the revenue arithmetic while severing any link to a person.

    Fourth, attach spending not by linking the small 2018/19 expenditure survey record by record, but by estimating and publishing the spending equations it supports and imputing from those, which converts the weakest dataset into a transparent, criticisable assumption instead of a hidden join.

    Fifth, publish a one-page reconciliation showing that the reduced file matches the census totals, the income distribution and the actual receipts within stated tolerances, because that table is what entitles anyone to trust the file.

    Sixth, release it in tiers: the anonymised file and the model as ordinary, version-controlled code for everyone; supervised access to the full-resolution data for Scrutiny’s advisers under the safeguards British statistics has used for years; and, if even the anonymised file were thought too revealing, a fully synthetic one, artificial records generated to preserve the statistical relationships, against which no privacy objection can survive because no record is anyone.

    And here the two goals converge, which is why the failure is so telling. The same object that makes release safe makes the model fast. A few thousand weighted rows recompute in milliseconds in any scripting language. The half-hour cycle disappears. Testing every threshold one at a time becomes an afternoon; testing the assumptions together, the uplift, the spending patterns, the behavioural response, becomes an overnight run; and the ranges that Appendix 8 conspicuously does not contain become printable. The anonymisation is not a price paid for transparency. Done properly, it is the same operation as making the model fit for the decision it supports. The cost is some weeks of one competent analyst with free software, set against a permanent change to the island’s tax base worth some £59m a year.

    If they did not know the standard way to make a tax model publishable and fast, the island’s biggest fiscal decision was modelled by amateurs.

    The rolling electronic census that the Committee cites as a modelling strength makes all of this easier, not harder, because it is exactly the population register against which the weights are calibrated. And the law points the same way. The Data Protection (Bailiwick of Guernsey) Law, 2017 protects personal data, meaning data from which a living person can be identified; data that has been properly anonymised is not personal data at all and sits outside the Law entirely. Data protection is therefore not an obstacle to publishing the model’s inputs. It is a specification for how to publish them, and the specification is the six steps above.

    Which brings us to the choice of explanations. This is not obscure knowledge. It is taught, documented, free to implement, and practised by every serious tax administration whose work Guernsey’s officials would claim as their peer group. If the people who built this system did not know that a disclosure-controlled, weighted extract was the standard way to make a tax model both publishable and fast, then the island’s largest fiscal decision in a generation has been modelled by people unfamiliar with the basic tooling of their own field, which is consistent, we note, with what the public calculator revealed when we opened it. If, on the other hand, they did know, then the choice to keep the data raw, identifiable and slow had a convenient side effect: it manufactured the very sensitivity now cited as the reason nothing can be released, and it left the model too cumbersome to expose its own uncertainty. We make no claim about anyone’s intent. We simply observe that incompetence and convenience are the only two explanations on the table, that they are not mutually exclusive, and that the incentive ran one way: a model that cannot be checked cannot be challenged.

    There is a straightforward way for the Committee to show that neither explanation is fair, which is to do now what should have been done at the start. Publish a weighted, disclosure-controlled extract of the modelling data with its reconciliation table. Publish the model as code, with its parameters and its spending equations. Offer Scrutiny’s advisers supervised access to the rest. If the extract cannot be produced, publish a synthetic file and say so. Any of these would let the “majority better off” claim be tested the way we tested the calculator, in the open, figure by figure.

    Until one of them happens, “the data is sensitive” should be heard for what it is: not a fact about the data, but a consequence of a decision about how to hold it, made by the people now relying on it.

    The People’s Trust