CIPP-E · Question #86
What must a data controller do in order to make personal data pseudonymous?
The correct answer is A. Separately hold any information that would allow linking the data to the data subject. Pseudonymisation is a method that allows you to switch the original data set (for example, e-mail or a name) with an alias or pseudonym, or, in other words, a value which does not allow the individual to be directly identified. It is a reversible process that de-identifies data…
Question
What must a data controller do in order to make personal data pseudonymous?
Options
- ASeparately hold any information that would allow linking the data to the data subject.
- BEncrypt the data in order to prevent any unauthorized access or modification.
- CRemove all indirect data identifiers and dispose of them securely.
- DUse the data only in aggregated form for research purposes.
How the community answered
(20 responses)- A90% (18)
- B5% (1)
- D5% (1)
Explanation
Pseudonymisation is a method that allows you to switch the original data set (for example, e-mail or a name) with an alias or pseudonym, or, in other words, a value which does not allow the individual to be directly identified. It is a reversible process that de-identifies data but allows the re- identification later on if necessary. This is a well-known data management technique highly recommended by the General Data Protection Regulation (GDPR) as one of the data protection methods. To make personal data pseudonymous, a data controller must separately hold any information that would allow linking the data to the data subject, such as a key or a code, and ensure that this information is kept securely and subject to technical and organisational measures to prevent unauthorised access or re-identification.
Topics
Community Discussion
No community discussion yet for this question.