Skip to content

ACCA Strategic Professional · Strategic Business Leader · Big data and data analytics

Brennan Health, a hospital group, plans to share patient records with a university for research. The data protection officer proposes removing names and identifiers and replacing them with codes, while the group retains a separate key allowing re-identification. A director says the data is then 'anonymous' and outside data protection rules. Which response is most accurate?

The director is wrong because coded data that the hospital can re-identify with a retained key is pseudonymised, not anonymous, so it remains personal data subject to protection rules. Pseudonymisation lowers risk but true anonymisation requires that individuals cannot reasonably be re-identified.

  1. ACorrect, because removing names always takes data outside data protection rules
  2. BIncorrect, because only encrypted data is protected, and coded data is not encrypted
  3. CCorrect, provided the university signs a confidentiality agreement
  4. DIncorrect, because data that can be re-identified using a retained key is pseudonymised, not anonymous, and remains personal dataCorrect

Explanation

Pseudonymisation replaces identifiers with codes but the data can be linked back using the key, so it remains personal data and governance obligations still apply. It reduces risk but is not anonymisation. A confidentiality agreement does not change the data's status, and protection does not depend on encryption alone.

Did you get it right without looking?

One question tells you little. A timed set on Big data and data analytics shows your real accuracy, how long you take and where you lose marks.

More Big data and data analytics questions