<?xml version="1.0" encoding="UTF-8"?>
<mods xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.1" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-1.xsd">
  <titleInfo>
    <title>Recommendations on shaping technology according to GDPR provisions</title>
    <subTitle>An overview on data pseudonymisation</subTitle>
  </titleInfo>
  <name type="corporate">
    <namePart>European Union Agency for Network and Information Security</namePart>
    <role>
      <roleTerm authority="marcrelator" type="text">creator</roleTerm>
    </role>
  </name>
  <typeOfResource>text</typeOfResource>
  <genre authority="marc">technical report</genre>
  <originInfo>
    <place>
      <placeTerm type="text">Attiki, Greece</placeTerm>
    </place>
    <publisher>ENISA</publisher>
    <dateIssued>november 2018</dateIssued>
    <dateIssued encoding="marc">2019</dateIssued>
    <issuance>monographic</issuance>
  </originInfo>
  <language>
    <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
  </language>
  <physicalDescription>
    <extent>43 p.</extent>
  </physicalDescription>
  <abstract>Pseudonymisation is an established and accepted de-identification process that has gained additional attention following the adoption of the General Data Protection Regulation (GDPR), where it is referenced as both a security and data protection by design mechanism. As a result, in the GDPR context, pseudonymisation can motivate the relaxation to a certain degree of data controllers’ legal obligations if properly applied. In this report, we present an overview of the notion and main techniques of pseudonymisation in correlation with its new role under GDPR. In particular, starting from the definition of pseudonymisation (as well as its differences from other key techniques, such as anonymization and encryption), the report first discusses its core data protection benefits. Following this analysis, the report then addresses some techniques that may be utilised for pseudonymisation, such as hashing, hashing with key or salt, encryption and other cryptographic mechanisms, tokenization, as well as other relevant approaches. Last, certain pseudonymisation use cases and best practices are discussed, focusing especially on the area of mobile apps and revisiting some of the earlier discussed techniques. Although the report does not seek to conduct a detailed analysis of the different aspects related to specific pseudonymisation methods and implementations, it touches upon some of the key issues in this regard. However, further research is needed, as well as practical experience, involving all stakeholders in the field</abstract>
  <targetAudience authority="marctarget">specialized</targetAudience>
  <note type="statement of responsibility">enisa</note>
  <note>Contiene bibliografía</note>
  <subject authority="lcsh">
    <topic>Tecnologías habilitadoras digitales</topic>
  </subject>
  <subject>
    <topic>computer network  </topic>
  </subject>
  <subject>
    <topic>data protection</topic>
  </subject>
  <subject>
    <topic>data-processing law </topic>
  </subject>
  <subject>
    <topic>digital technology</topic>
  </subject>
  <subject>
    <topic>information storage</topic>
  </subject>
  <subject>
    <topic>information technology</topic>
  </subject>
  <subject>
    <topic>Internet access provider</topic>
  </subject>
  <subject>
    <topic>mobile phone </topic>
  </subject>
  <subject>
    <topic>protection of privacy</topic>
  </subject>
  <subject>
    <topic>regulation of telecommunications</topic>
  </subject>
  <subject>
    <topic>software</topic>
  </subject>
  <identifier type="isbn">978-92-9204-281-3	</identifier>
  <identifier type="uri">https://publications.europa.eu/en/publication-detail/-/publication/0e1ca64f-29c7-11e9-8d04-01aa75ed71a1/language-en/format-PDF/source-86095141</identifier>
  <location>
    <url displayLabel="Acceso a la publicación">https://publications.europa.eu/en/publication-detail/-/publication/0e1ca64f-29c7-11e9-8d04-01aa75ed71a1/language-en/format-PDF/source-86095141</url>
  </location>
  <recordInfo>
    <recordContentSource authority="marcorg"/>
    <recordCreationDate encoding="marc">190206</recordCreationDate>
    <recordChangeDate encoding="iso8601">20220119165422.0</recordChangeDate>
    <recordIdentifier source="ES-MaONT">00004894</recordIdentifier>
  </recordInfo>
</mods>
