問題文
A data set has direct identifiers replaced with random values. In the first variant the mapping is kept in a vault; in the second the mapping was destroyed; in the third the values are encrypted with a key the company holds. Which classification of the three variants is correct?
選択肢
- The first and third are pseudonymized personal data because the company can reverse them; the second is anonymous only if the remaining attributes cannot single anyone out.
- Every one of the three is pseudonymized because the transformation was applied to the identifiers rather than removing them, and a data set that once carried identifiers keeps that status for good.
- All three are anonymized because the direct identifiers no longer appear in the data set, and the presence of a mapping or a key elsewhere in the organization concerns the security of that separate store rather than the classification of the data set itself, which is determined by what the data set contains.
- Only the first is pseudonymized and the other two are anonymous, because encryption is a stronger protection than a mapping table and the destroyed mapping removes the link altogether.