問題文
A data set has direct identifiers removed and internal identifiers replaced with random values, with the mapping kept in a separate vault. How should the result be treated?
選択肢
- As personal data only if the random values were derived from the original identifiers, because a value drawn at random cannot lead back.
- As pseudonymized personal data, because the mapping makes re-identification possible for the organization that holds it.
- As anonymized data, because the identifiers in the data set itself no longer refer to any individual and the vault is subject to separate access controls that prevent routine linkage back to the original records.
- As non-personal data for internal analytics but as personal data if it is disclosed externally, since the recipient decides the classification.