Does fair anonymization exist?
Zoltán Alexin · International Review of Law Computers & Technology · 2014
Anonymization is viewed as an instrument by which personal data can be rendered so that it can be processed further without harming data subjects' private lives, for purposes that are beneficial to the public good. The anonymization is fair if the possibility of re-identification can be practically excluded. The data processor does all that he or she can to ensure this. For a fair anonymization, simply removing the primary personal identification data, such as the name, resident address, phone number and email address, is not enough, as many papers have warned. Therefore, new guidance documents, and even legal rulings such as the HIPAA Privacy Rule on de-identification, may improve the security of anonymization. Researchers are continuously testing the efficiency of the methods and simulating re-identification attacks. Since the US and Canada do not have a population registry, re-identification experiments were carried out with the help of other publicly available databases, such as census data or the voters' database. Unfortunately, neither of these is complete and sufficiently detailed, so the computed risk was only an estimate. The author obtained the zip code, gender, date of birth distribution data from the Hungarian population registry and computed re-identification risks in several simulated cases. This paper also gives an insight into the legal environment of Hungarian personal medical data protection legislation.