Privacy enhancing data de-identification terminology and classification of techniques

Privacy enhancing data de-identification terminology and classification of techniques

Regular price
£322.00
Sale price
£322.00
Regular price
£161.00
Sold out
Unit price
per 

What is ISO/IEC 20889 about?  

ISO/IEC 20889 provides a description of privacy-enhancing data de-identification techniques, to be used to describe and design de-identification measures in accordance with the privacy principles in ISO/IEC 29100. In particular, ISO/IEC 20889 specifies terminology, classification of de-identification techniques according to their characteristics, and their applicability for reducing the risk of re-identification.  

Note: ISO/IEC 20889 is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations that are PII controllers or PII processors acting on a controller’s behalf implementing data de-identification processes for privacy enhancing purposes. 

Who is ISO/IEC 20889 for? 

ISO/IEC 20889 on data de-identification terminology is useful for: 

  • Public and private companies 
  • Government organization 
  • Not-for-profit organizations 

Why should you use ISO/IEC 20889 

It is well-established that major benefits can be derived from processing electronically stored data, including so-called “big data”. However, where this data includes personally identifiable information (PII), as is often the case, processing this data needs to comply with applicable personal data protection principles. ISO/IEC 20889 provides appropriate use of de-identification techniques is an important component of measures to enable the exploitation of the benefits of data processing while maintaining compliance with the relevant ISO/IEC 29100 privacy principles. The immediate relevance of ISO/IEC 20889 is to the personal data protection of natural persons (i.e. PII principals), but the term “data principal”, defined and used in this document, is broader than “PII principal” and, for example, includes organizations and computers. ISO/IEC 20889 focuses on commonly used techniques for de-identification of structured datasets as well as on datasets containing information about data principals that can be represented logically in the form of a table. In particular, the techniques are applicable to datasets that can be converted to having the form of a table (e.g. data held in key-value databases). It is possible that the techniques described in this document do not apply to more complex datasets, e.g. containing free-form text, images, audio, or video. The use of de-identification techniques is good practice to mitigate re-identification risk but does not always guarantee the desired result. ISO/IEC 20889 establishes the notion of a formal privacy measurement model as an approach to the application of data de-identification techniques.