2025-W04 Navigating the Pseudonymisation Guidelines episode artwork

EPISODE · May 22, 2025 · 13 MIN

2025-W04 Navigating the Pseudonymisation Guidelines

from Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance · host Elislav Atanasov

Pseudonymisation is a multifunctional tool helping us comply with many GDPR provisions and principles. Pseudonymisation should always be considered in the context of ROPAs. It’s not something that is simply stated in some document. “We are protecting data by using pseudonymisation” is definetly not enough.Lastly, the framework below is the result of me summarising the examples from the Annex of the Guidelines. It’s not something I came up with on my own.Context and Purpose of ProcessingStart by understanding the purpose of processing and documenting it in your Record of Processing Activities (ROPA).Example Context: A hospital conducts a clinical study involving patient health records to analyze treatment efficacy.Purpose of Processing: The hospital needs to process sensitive health data while ensuring compliance with GDPR and minimizing privacy risks to participants.What Problem is to Be Solved?Define your goal for pseudonymisation. Are you aiming to rely on legitimate interests for processing, meet the privacy by design/default principle, or both?Objective: Protect patient privacy by pseudonymising health records to reduce re-identification risks while enabling researchers to use the data for analysis.Compliance Goal: Fulfill the privacy by default principle while maintaining the utility of the data.Original DataDescribe the personal data you are starting with before applying pseudonymisation.Example Original Data:Patient namesAddressesDate of birthHealth conditionsTreatment historyPseudonymised DomainDefine who will process the pseudonymised data and in what capacity.Example: Researchers analyzing the dataset. They will work with pseudonymised data and will not have access to the additional information required for re-identification.Pseudonymised DataDescribe the data after pseudonymisation.Example Pseudonymised Data:Names are replaced with random identifiers (e.g., “Patient_001”).Addresses and dates of birth are generalized (e.g., replacing “01/21/1980” with “1980”).Health conditions and treatment history remain unchanged for research purposes but are no longer directly linked to individuals.Additional InformationExplain how you will implement pseudonymisation, detailing the method used.Method: Use a lookup table to replace names with pseudonyms.Example: Store the mapping of “Patient_001” = “John Doe” in a secure, access-controlled database.Optionally, encrypt sensitive fields (e.g., addresses) using AES encryption.Storage: Keep the lookup table and encryption keys in a physically and logically separate system, accessible only to authorized personnel.Processing of Pseudonymised DataDescribe how the pseudonymised data will be used.Example Use Case: Researchers access pseudonymised health data for statistical analysis. The pseudonyms (e.g., “Patient_001”) are sufficient for their work and do not allow them to identify specific individuals.Pseudonymisation ProcessDetail the steps taken to pseudonymise the data.Step 1: Extract relevant data fields from the original dataset.Step 2: Replace direct identifiers (e.g., names) with pseudoyms using a secure, randomized algorithm.Step 3: Encrypt sensitive indirect identifiers (e.g., addresses) using crptographic methods.Step 4: Store the mapping of original identifiers to pseudonyms (lookup table) and encryption keys in separate secure locations.Step 5: Provide the pseudonymised dataset to researchers for processing.Additional SafeguardsIdentify safeguards specific to this scenario to further protect the pseudonymised data.Access Controls: Strictly limit access to the lookup table and encryption keys.Separation of Duties: Ensure that only administrative staff can access the lookup table, while researchers handle only pseudonymised data.Auditing: Regularly monitor and log access to both the lookup table and the pseudonymised dataset.Minimization: Only share the minimum data necessary for the research objective.

NOW PLAYING

2025-W04 Navigating the Pseudonymisation Guidelines

0:00 13:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

MG Show MG Show The MG Show, hosted by Jeffrey Pedersen and Shannon Townsend, is a leading alternative media platform dedicated to uncovering the truth behind today’s most pressing political issues. Launched in 2019, the show has grown exponentially, offering unfiltered insights, comprehensive research, and real-time analysis. With a commitment to independent journalism and factual integrity, the MG Show empowers its audience with knowledge and encourages active participation in the political discourse. Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world?

Frequently Asked Questions

How long is this episode of Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance?

This episode is 13 minutes long.

When was this Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance episode published?

This episode was published on May 22, 2025.

What is this episode about?

Pseudonymisation is a multifunctional tool helping us comply with many GDPR provisions and principles. Pseudonymisation should always be considered in the context of ROPAs. It’s not something that is simply stated in some document. “We are...

Can I download this Privacy Navigator: Weekly Insights on Privacy, AI, and Compliance episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!