Re-identification Risk Determinations (RRDs) are assessments where an expert applies generally accepted statistical methods to determine how identifiable individuals are in a dataset. The expert will recommend necessary changes to de-identify or anonymize the data and may act as a Trusted Third Party (TTP) to apply those changes.
RRDs are aligned with the Expert Determination method under the Health Insurance Portability and Accountability Act (HIPAA) and assessments of identifiability under the General Data Protection Regulation (GDPR).
Experts performing these assessments pay a lot of attention to the statistical methods used. However, several non-technical factors can increase (or decrease!) the likelihood that a data privacy initiative is successful.
Privacy Analytics has been supporting clients and partners with RRDs since 2007. In that time, we’ve discovered several factors that can significantly impact your organization’s ability to reach its desired outcomes. Drawing from those, here is a summary of 10 best practices for RRDs:
These best practices can enable you to streamline the Re-identification Risk Determination process, reducing costs, increasing efficiency, and improving your return on investment in data privacy.
Contact an expert at Privacy Analytics to discuss Re-identification Risk Determinations and how the right approach can provide a smoother, higher-value experience for your organization.