An international financial services company is preparing to share historical transaction records with an external research consortium. The privacy officer mandates that the dataset must be modified so that individual data subjects can no longer be identified by any direct or indirect means, even if the records are combined with outside data sources. Once applied, this technical transformation must render the dataset completely exempt from privacy regulation requirements (such as GDPR), permitting long-term retention for analytical study. Which of the following data protection controls should the security team implement to satisfy this mandate?
- Data anonymizationCevap
- BPseudonymization
- CDynamic data masking
- DTokenization
Cevap
Data anonymization is the correct control because it irreversibly transforms personal data so that re-identification is impossible, removing the dataset from the scope of privacy regulations.
Data anonymization irreversibly alters personal data so that the individual can no longer be identified directly or indirectly by any means reasonably likely to be used. Because anonymized data is no longer considered personal data, it falls entirely outside the scope of privacy regulations such as GDPR, allowing organizations to retain and process the dataset indefinitely without regulatory restrictions.
Adım Adım Çözüm
Anahtar Kavram
Data Anonymization vs. Pseudonymization and Privacy Controls