Anonymization and Risk

Anonymization and Risk
复制标题

匿名化和风险

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
Woodrow Hartzog
Woodrow Hartzog
中科院分区:
--
文献类型:
--
作者:
I. Rubinstein;Woodrow Hartzog

文献摘要

被引文献

相似文献

包含个人信息的数据集的完美匿名化失败了。但保护共享信息中的数据主体的过程仍然是隐私实践和政策不可或缺的一部分。尽管关于身份识别的辩论一直很激烈和富有成效,但政策没有明确的方向。因此,当数据集被发布给其他人时,法律在采用整体方法来保护数据主体方面进展缓慢。目前,法律的重点是是否可以在给定的集合中识别个人。我们认为,将数据发布政策从所谓的匿名化失败中转移出来的最佳方式是专注于将重新识别和敏感属性披露的风险降至最低的过程,而不是防止伤害。基于过程的数据发布策略类似于数据安全定律,它将帮助我们克服专注于数据集是否已被“匿名”的限制。它利用不同的策略来保护数据主体的隐私,包括准确的身份识别修辞,禁止重新身份识别和敏感属性披露的合同,数据飞地,以及将所需保护与风险水平相匹配的基于查询的策略。通过关注过程,数据发布政策可以更好地平衡隐私和效用,而几乎所有的数据交换都带有一定的风险。
Perfect anonymization of data sets that contain personal information has failed. But the process of protecting data subjects in shared information remains integral to privacy practice and policy. While the deidentification debate has been vigorous and productive, there is no clear direction for policy. As a result, the law has been slow to adapt a holistic approach to protecting data subjects when data sets are released to others. Currently, the law is focused on whether an individual can be identified within a given set. We argue that the best way to move data release policy past the alleged failures of anonymization is to focus on the process of minimizing risk of reidentification and sensitive attribute disclosure, not preventing harm. Process-based data release policy, which resembles the law of data security, will help us move past the limitations of focusing on whether data sets have been “anonymized.” It draws upon different tactics to protect the privacy of data subjects, including accurate deidentification rhetoric, contracts prohibiting reidentification and sensitive attribute disclosure, data enclaves, and query-based strategies to match required protections with the level of risk. By focusing on process, data release policy can better balance privacy and utility where nearly all data exchanges carry some risk.