Reducing identifiability.
WHAT ANONYMISATION ACHIEVES
Data that is no longer personal data, and therefore outside the rules.
WHAT IT REQUIRES
That no person can be identified, by anyone, using any reasonably available means.
WHY THAT BAR IS RARELY MET
Combining datasets re-identifies people surprisingly easily.
WHAT EXAMPLES OF FAILURE LOOK LIKE
Records with names removed but dates, locations and identifiers intact.
WHY THAT FAILS
A small number of attributes uniquely identifies most people.
WHAT PSEUDONYMISATION ACHIEVES
Reduced risk, with data still within scope.
WHAT IT REQUIRES
The key held separately, with restricted access.
WHY IT IS STILL PERSONAL DATA
Re-identification remains possible.
WHERE IT IS USEFUL
Analysis, and limiting access.
WHAT TECHNIQUES EXIST
Removing direct identifiers Generalising values into ranges Aggregating to groups above a minimum size Adding controlled noise
WHY MINIMUM GROUP SIZES MATTER
A group of one is an individual.
WHAT TO CHECK BEFORE CLAIMING ANONYMISATION
Whether any combination of remaining fields identifies someone.
WHAT TO DO IF UNSURE
Treat it as personal data.
WHY
The consequences of being wrong are substantial.
WHAT TO DOCUMENT
The method, and the assessment.