000 03010nam a22004097a 4500
001 00004894
003 ES-MaONT
005 20220119165422.0
008 190206t2019 ||||frt||| 00| 0 eng d
020 _a978-92-9204-281-3
024 _2doi
_a10.2824/74954
_d.
040 _cCDO
110 2 _aEuropean Union Agency for Network and Information Security
_92344
245 0 0 _aRecommendations on shaping technology according to GDPR provisions
_bAn overview on data pseudonymisation
_cenisa
250 _bProkopios Drogkaris ; Athena Bourka
260 _aAttiki, Greece
_bENISA
_cnovember 2018
300 _a43 p.
_f1 fichero .pdf
336 _atexto (visual)
_2isbdcontent
337 _aelectrónico
_2isbdmedia
338 _arecurso en línea
_2rdacarrier
504 _aContiene bibliografía
520 _aPseudonymisation is an established and accepted de-identification process that has gained additional attention following the adoption of the General Data Protection Regulation (GDPR), where it is referenced as both a security and data protection by design mechanism. As a result, in the GDPR context, pseudonymisation can motivate the relaxation to a certain degree of data controllers’ legal obligations if properly applied. In this report, we present an overview of the notion and main techniques of pseudonymisation in correlation with its new role under GDPR. In particular, starting from the definition of pseudonymisation (as well as its differences from other key techniques, such as anonymization and encryption), the report first discusses its core data protection benefits. Following this analysis, the report then addresses some techniques that may be utilised for pseudonymisation, such as hashing, hashing with key or salt, encryption and other cryptographic mechanisms, tokenization, as well as other relevant approaches. Last, certain pseudonymisation use cases and best practices are discussed, focusing especially on the area of mobile apps and revisiting some of the earlier discussed techniques. Although the report does not seek to conduct a detailed analysis of the different aspects related to specific pseudonymisation methods and implementations, it touches upon some of the key issues in this regard. However, further research is needed, as well as practical experience, involving all stakeholders in the field
650 0 _aTecnologías habilitadoras digitales
_918
653 _acomputer network
653 _adata protection
653 _adata-processing law
653 _adigital technology
653 _ainformation storage
653 _ainformation technology
653 _aInternet access provider
653 _amobile phone
653 _aprotection of privacy
653 _aregulation of telecommunications
653 _asoftware
856 4 _uhttps://publications.europa.eu/en/publication-detail/-/publication/0e1ca64f-29c7-11e9-8d04-01aa75ed71a1/language-en/format-PDF/source-86095141
_x0
_yAcceso a la publicación
942 _2z
_cINF
999 _c4894
_d4894