De-identification
What is De-identification?
The process of removing or obscuring personal identifiers from data to reduce the risk of identifying individuals. De-identified data may still be re-identifiable under certain conditions, unlike fully anonymised data.
Terms that appear alongside de-identification
Each of these is named in at least one of the same controls as de-identification. The number is how many controls name both.
- pseudonymisation 11 shared controls
- gdpr 10 shared controls
- consent 7 shared controls
- nist 7 shared controls
- hipaa 7 shared controls
- audit 6 shared controls
- confidentiality 6 shared controls
- encryption 6 shared controls
Frameworks that govern de-identification
What the standards actually require on de-identification
Requirements naming de-identification across 6 standards, quoted from the control text.
The organization must delete personal data, or render it into a form that does not permit identification or re-identification of the individual, as soon as the original data is no longer necessary for the identified purposes, having mechanisms to erase data wh...
iso-27701-2019::7.4.5 · PII de-identification and deletion at the end of processing →Inform consumers of their right to have redundant data deleted and delete or de-identify redundant CDR data accordingly.
AUCDR-OB-5 · Deletion or de-identification of redundant data →Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/C...
ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification · Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness →Protect CDR data from misuse, interference, loss and unauthorised access, and destroy or de-identify redundant CDR data.
AUCDR-PS-12 · Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data →Recipients must protect CDR data from misuse, interference, loss and unauthorised access per the information-security requirements (Schedule 2), and destroy or de-identify redundant CDR data.
CDR-PS-12 · Privacy Safeguard 12: Security of CDR Data, and Destruction or De-identification →HL7 FHIR Resilience + Privacy + SMART Health Cards. RATE LIMITING AND ANTI-ABUSE (FHIR-SEC-14) - API rate limiting + throttling + DDoS protection + abuse detection + IP/Subject + Token-based limits + sliding window + token bucket + sectoral best practices;
HL7-FHIR-Resilience-RateLimit-CORS-AntiAbuse-SmartHealth · HL7 FHIR Resilience - Rate Limiting + Anti-Abuse + CORS + SMART Health Cards + De-identification + Privacy →Questions people ask about de-identification
What is De-identification?
Why is De-identification important for compliance?
Which compliance frameworks address De-identification?
Where can I learn more about De-identification?
See how De-identification applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.