关于假名化的指南_01-2025_46页_1mb
报告摘要
Pseudonymisation as a Data Protection Safeguard
Legal Definition:
Pseudonymisation processes personal data such that attribution requires additional information kept separately and protected by technical measures. It is considered personal data if attribution is possible (Art.4(5) GDPR). Not legally required but may meet obligations like data minimisation or by design (Art.25 GDPR).
Key Benefits:
- Risk Reduction: Used as supplementary justification for lawful processing, compatibility of further processing, or restrictions on third-party data transfers.
- Data Protection Principles: Helps meet requirements for lawfulness, transparency, data minimisation, security, and data subject rights.
- Security & Portability: Supports achieving an appropriate level of security and may reduce notification threshold in case of breaches.
- Third-Party Data Transfers: Serves as a supplementary measure to comply with Art.44/46 GDPR if pseudonymisation significantly limits governmental or third-party attribution capabilities.
- Not Anonymous: Requires confirming anonymity conditions are met post-pseudonymisation.
Implementation Steps:
- Define the pseudonymisation domain and objectives.
- Apply the pseudonymising transformation (replace identifiers), choosing a method (lookup tables or cryptographic algorithms) and generating secrets.
- Secure processing:
- Protect pseudonymisation secrets.
- Define/assess the pseudonymisation domain boundaries.
- Manage data linkage:
- Identify sets for controlled pseudonym consistency (e.g., person, relationship, transaction pseudonyms)
- Select pseudonym type fitting the processing context.
- Set up safeguards against accidental re-attribution.
- Attain the desired pseudonymisation effect through measures tailored to risk and context.
Key Terms:
- Pseudonym: An identifier for a data subject replaceable only with additional information.
- Pseudonymisation Secrets: Information enabling attribution lookup (keys, pseudonym→data crosswalks).
- Pseudonymisation Domain: Context to prevent attribution to specific data subjects.
- Consistent Pseudonymisation: Pseudonymising data processed across multiple stakeholders to avoid re-linkage.
- Context for Analogy Preservation: Handling tokenised identifiers according to domain rules.
Additional Notes:
- GDPR Recitals & Legal Basis: Pseudonymisation supports legitimate interest assessments (Art.6(1)(f)) and determines compatibility of further processing (Art.6(4)).
- Examples: Provided case studies demonstrate application in research, transfers, and custom operations such as securing sensitive data or enhancing portability rights.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载