Glossary
/
Re-identification

Re-identification

It can occur through direct access to a mapping key, unique combinations of attributes, linkage with external datasets, or inference. Risk changes as new data sources and techniques become available, so de-identification should be assessed in context and monitored over time. Controls include minimization, aggregation, generalization, access restrictions, contractual limits, testing, and secure separation of mapping information.

What is Re-identification?

Re-identification is the process of linking de-identified, anonymized, or pseudonymized data back to a specific person or entity.

Why it matters

It can occur through direct access to a mapping key, unique combinations of attributes, linkage with external datasets, or inference. Risk changes as new data sources and techniques become available, so de-identification should be assessed in context and monitored over time. Controls include minimization, aggregation, generalization, access restrictions, contractual limits, testing, and secure separation of mapping information.

Example

Exact timestamps, rare locations, and public social posts are combined to infer which person generated a supposedly anonymous activity record.

Related terms