Skip to content

De-identification

What is De-identification?

The process of removing or obscuring personal identifiers from data to reduce the risk of identifying individuals. De-identified data may still be re-identifiable under certain conditions, unlike fully anonymised data.

Privacy

Each of these is named in at least one of the same controls as de-identification. The number is how many controls name both.

What the standards actually require on de-identification

Requirements naming de-identification across 6 standards, quoted from the control text.

ISO 27701:20193 controls

The organization must delete personal data, or render it into a form that does not permit identification or re-identification of the individual, as soon as the original data is no longer necessary for the identified purposes, having mechanisms to erase data wh...

iso-27701-2019::7.4.5 · PII de-identification and deletion at the end of processing

Inform consumers of their right to have redundant data deleted and delete or de-identify redundant CDR data accordingly.

AUCDR-OB-5 · Deletion or de-identification of redundant data

Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/C...

ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification · Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness

Protect CDR data from misuse, interference, loss and unauthorised access, and destroy or de-identify redundant CDR data.

AUCDR-PS-12 · Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

Recipients must protect CDR data from misuse, interference, loss and unauthorised access per the information-security requirements (Schedule 2), and destroy or de-identify redundant CDR data.

CDR-PS-12 · Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification

HL7 FHIR Resilience + Privacy + SMART Health Cards. RATE LIMITING AND ANTI-ABUSE (FHIR-SEC-14) - API rate limiting + throttling + DDoS protection + abuse detection + IP/Subject + Token-based limits + sliding window + token bucket + sectoral best practices;

HL7-FHIR-Resilience-RateLimit-CORS-AntiAbuse-SmartHealth · HL7 FHIR Resilience - Rate Limiting + Anti-Abuse + CORS + SMART Health Cards + De-identification + Privacy

Questions people ask about de-identification

What is De-identification?
The process of removing or obscuring personal identifiers from data to reduce the risk of identifying individuals. De-identified data may still be re-identifiable under certain conditions, unlike fully anonymised data.
Why is De-identification important for compliance?
De-identification is a key concept in Privacy. Understanding de-identification helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address De-identification?
De-identification appears in the requirement text of ISO 27701:2019, Consumer Data Right Rules 2020 (selected operational obligations), Iowa Consumer Data Protection Act, Australia Consumer Data Right - Banking (CDR), Consumer Data Right (CDR) Framework (Australia). Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about De-identification?
Explore our compliance framework pages to see how de-identification applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how De-identification applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.