Skip to content

Re-identification Risk

What is Re-identification Risk?

The possibility that anonymized or pseudonymized data could be linked back to specific individuals through additional data or techniques.

Privacy and Data Protection

Each of these is named in at least one of the same controls as re-identification risk. The number is how many controls name both.

What the standards actually require on re-identification risk

Requirements naming re-identification risk across 5 standards, quoted from the control text.

Define when research data is anonymised (irreversibly non-identifiable) and therefore outside GDPR, with a robust re-identification-risk assessment.

RDCOC-ANO-01 · Anonymisation Criteria

Synthetic data generation produces artificial datasets that preserve statistical properties of the original data without containing real personal data, supporting model training and testing while reducing personal-data exposure;

ENISA-DPE-4.5 · Synthetic data
HITECH Act1 control

HITECH Subtitle D - Breach Notification + Business Associate (BA) direct liability. BREACH NOTIFICATION RULE (Section 17932; 45 CFR Part 164 Subpart D, Sections 164.400-414): covered entities + BAs must provide notification following discovery of a breach of U...

HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability · HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors
Turkey KVKK1 control

Anonymisation must render data permanently and irreversibly non-identifiable, considering means reasonably likely to be used. KVKK Board Anonymisation Guidelines (2018) cover techniques (generalisation, masking, perturbation, k-anonymity) and re-identification...

KVKK-Anonymisation · Anonymisation Standards

Questions people ask about re-identification risk

What is Re-identification Risk?
The possibility that anonymized or pseudonymized data could be linked back to specific individuals through additional data or techniques.
Why is Re-identification Risk important for compliance?
Re-identification Risk is a key concept in Privacy and Data Protection. Understanding re-identification risk helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Re-identification Risk?
Re-identification Risk appears in the requirement text of Code of Conduct on Data Protection for Research (GDPR Article 40), ENISA Data Protection Engineering - From Theory to Practice, HITECH Act, Jamaica Data Protection Act 2020, Turkey KVKK. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Re-identification Risk?
Explore our compliance framework pages to see how re-identification risk applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Re-identification Risk applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.