Re-identification Risk
What is Re-identification Risk?
The possibility that anonymized or pseudonymized data could be linked back to specific individuals through additional data or techniques.
Terms that appear alongside re-identification risk
Each of these is named in at least one of the same controls as re-identification risk. The number is how many controls name both.
- anonymisation 3 shared controls
- gdpr 2 shared controls
- risk assessment 2 shared controls
Frameworks that govern re-identification risk
What the standards actually require on re-identification risk
Requirements naming re-identification risk across 5 standards, quoted from the control text.
Define when research data is anonymised (irreversibly non-identifiable) and therefore outside GDPR, with a robust re-identification-risk assessment.
RDCOC-ANO-01 · Anonymisation Criteria →Synthetic data generation produces artificial datasets that preserve statistical properties of the original data without containing real personal data, supporting model training and testing while reducing personal-data exposure;
ENISA-DPE-4.5 · Synthetic data →HITECH Subtitle D - Breach Notification + Business Associate (BA) direct liability. BREACH NOTIFICATION RULE (Section 17932; 45 CFR Part 164 Subpart D, Sections 164.400-414): covered entities + BAs must provide notification following discovery of a breach of U...
HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability · HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors →Standard 5 per Section 23 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be kept for no longer than is necessary for the purposes for which they are processed.
JM-DPA2020-Standard5-Retention-Sec23-Time-Limit-No-Longer-Than-Necessary-Erasure-Deletion-Anonymisation · Jamaica DPA 2020 Standard 5 - Retention + Section 23 + Time Limit + No Longer Than Necessary + Erasure + Deletion + Anonymisation + Retention Schedule + Legal Hold + Backup Considerations + Storage Limitation →Anonymisation must render data permanently and irreversibly non-identifiable, considering means reasonably likely to be used. KVKK Board Anonymisation Guidelines (2018) cover techniques (generalisation, masking, perturbation, k-anonymity) and re-identification...
KVKK-Anonymisation · Anonymisation Standards →Questions people ask about re-identification risk
What is Re-identification Risk?
Why is Re-identification Risk important for compliance?
Which compliance frameworks address Re-identification Risk?
Where can I learn more about Re-identification Risk?
See how Re-identification Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.