Pseudonymization and Anonymization

Pseudonymization substitutes direct identifiers while information or relationships may still allow records to be linked to a person. Anonymization aims at an outcome where people are no longer identifiable in the relevant context. The applicable assessment standard and available means of linkage matter.

A hash can still be matched

Replacing an email with a simple deterministic hash does not establish anonymity. Someone with a list of guessed addresses can hash them and compare the results. Removing the email entirely may still leave a rare location-and-time combination that identifies a person.

Separating a lookup table and restricting access can reduce risk, but does not automatically turn pseudonymous records into anonymous data.

Assess the released result

Consider recipients, other available data, specificity, and possible linkage. Aggregation or synthetic generation also needs evaluation: a group of one can reveal information, and a generator can reproduce source details. Choose controls and document residual limits. Neither a transformation name nor the absence of a name column is proof of anonymity.

Reference: NIST SP 800-188.


Discover more from Insightful Data Lab

Subscribe to get the latest posts sent to your email.

Similar Posts

Questions, corrections, or additional insights?

This site uses Akismet to reduce spam. Learn how your comment data is processed.