header-logo header-logo

Data, disclosure & de-identification

19 January 2018 / Stewart Duffy
Issue: 7777 / Categories: Features , Data protection , Criminal
printer mail-detail
nlj_7777_duffy

Will proposed offences in the Data Protection Bill make criminals of us all? Stewart Duffy investigates

  • De-identified data may subsequently be re-identified, often through context.
  • Clause 162, Data Protection Bill makes re-identification a criminal offence.
  • Defences may centre on the ‘purpose’ of the re-identification or the ‘reasonable beliefs’ of the accused.

De-identification of personal data is an important and widely used strategy deployed to mitigate the risk of unauthorised disclosure or access. The techniques that are deployed are varied. They do not necessarily render the data ‘anonymous’ as defined by the General Data Protection Regulation (GDPR). That is often not their intention. Deliberate, and sometimes technically sophisticated, efforts to subvert those security measures are a legitimate cause for concern. There can be little principled objection to outlawing such steps by individuals who have no legitimate reason to possess the de-identified data, less still ‘re-identify’ it.

The criminalisation of ‘re-identification’ proposed in cl 162 of the Data Protection Bill is not an entirely novel innovation. Such a measure has been under active consideration

If you are not a subscriber, subscribe now to read this content
If you are already a subscriber sign in
...or Register for two weeks' free access to subscriber content

MOVERS & SHAKERS

Quinn Emanuel Urquhart & Sullivan—Andrew Savage

Quinn Emanuel Urquhart & Sullivan—Andrew Savage

Firm expands London disputes practice with senior partner hire

Druces—Lisa Cardy

Druces—Lisa Cardy

Senior associate promotion strengthens real estate offering

Charles Russell Speechlys—Robert Lundie Smith

Charles Russell Speechlys—Robert Lundie Smith

Leading patent litigator joins intellectual property team

NEWS
The government’s plan to introduce a Single Professional Services Supervisor could erode vital legal-sector expertise, warns Mark Evans, president of the Law Society of England and Wales, in NLJ this week
Writing in NLJ this week, Jonathan Fisher KC of Red Lion Chambers argues that the ‘failure to prevent’ model of corporate criminal responsibility—covering bribery, tax evasion, and fraud—should be embraced, not resisted
Professor Graham Zellick KC argues in NLJ this week that, despite Buckingham Palace’s statement stripping Andrew Mountbatten Windsor of his styles, titles and honours, he remains legally a duke
Writing in NLJ this week, Sophie Ashcroft and Miranda Joseph of Stevens & Bolton dissect the Privy Council’s landmark ruling in Jardine Strategic Ltd v Oasis Investments II Master Fund Ltd (No 2), which abolishes the long-standing 'shareholder rule'
In NLJ this week, Sailesh Mehta and Theo Burges of Red Lion Chambers examine the government’s first-ever 'Afghan leak' super-injunction—used to block reporting of data exposing Afghans who aided UK forces and over 100 British officials. Unlike celebrity privacy cases, this injunction centred on national security. Its use, the authors argue, signals the rise of a vast new body of national security law spanning civil, criminal, and media domains
back-to-top-scroll