Soru

Zorluk: ZorData Governance, Classification, and Privacy Controls

An international financial services company is preparing to share historical transaction records with an external research consortium. The privacy officer mandates that the dataset must be modified so that individual data subjects can no longer be identified by any direct or indirect means, even if the records are combined with outside data sources. Once applied, this technical transformation must render the dataset completely exempt from privacy regulation requirements (such as GDPR), permitting long-term retention for analytical study. Which of the following data protection controls should the security team implement to satisfy this mandate?

  1. Data anonymizationCevap
  2. B
    Pseudonymization
  3. C
    Dynamic data masking
  4. D
    Tokenization

Cevap

Data anonymization is the correct control because it irreversibly transforms personal data so that re-identification is impossible, removing the dataset from the scope of privacy regulations.
Data anonymization irreversibly alters personal data so that the individual can no longer be identified directly or indirectly by any means reasonably likely to be used. Because anonymized data is no longer considered personal data, it falls entirely outside the scope of privacy regulations such as GDPR, allowing organizations to retain and process the dataset indefinitely without regulatory restrictions.

Adım Adım Çözüm

1
Analyze the regulatory compliance requirements for the research dataset.
The requirement specifies permanently removing the dataset from the scope of privacy regulations by ensuring re-identification is impossible by any reasonable means.
Regulations like GDPR exempt datasets only when the data can no longer be linked to an identifiable natural person.
2
Evaluate the available privacy-enhancing technologies against the requirement of non-reversibility.
Controls such as pseudonymization, tokenization, and dynamic data masking leave data linkable or reversible via additional information, vault lookups, or underlying storage.
Reversible or display-only obfuscation techniques leave the data subject to privacy regulations.
3
Select the control that achieves permanent, non-reversible identity removal.
Data anonymization irreversibly removes all direct and indirect identifiers, converting personal data into anonymous information.
Anonymized data is completely exempt from privacy laws and can be retained indefinitely without ongoing consent or regulatory burden.

Anahtar Kavram

Data Anonymization vs. Pseudonymization and Privacy Controls
Bu soruyu puanla