Overview
ISO/IEC 20889:2018 - "Privacy enhancing data de-identification terminology and classification of techniques" provides a standardized vocabulary and classification framework for data de-identification. The standard helps organizations describe, select and design de-identification measures consistent with the privacy principles in ISO/IEC 29100. It focuses on reducing the risk of re-identification for datasets containing personally identifiable information (PII) and is applicable to PII controllers and processors across public, private and not‑for‑profit sectors.
Key Topics and Requirements
ISO/IEC 20889:2018 organizes de-identification knowledge into clear technical building blocks and practical guidance:
- Terminology and technical model - standard definitions for terms used in de-identification and a model to describe de-identification processes.
- Re-identification - discussion of re-identification risks and common attack types to inform threat-aware design.
- Classification of de-identification techniques - grouped by characteristics and applicability:
- Statistical tools (sampling, aggregation)
- Cryptographic tools (deterministic, format-preserving, homomorphic techniques)
- Suppression and masking (local and record suppression)
- Pseudonymization (attribute selection and pseudonym creation)
- Anatomization and generalization (rounding, top/bottom coding)
- Randomization (noise addition, permutation, microaggregation)
- Synthetic data generation
- Formal privacy measurement models - overview of models used to quantify privacy guarantees, including k-anonymity (with l-diversity, t-closeness) and differential privacy (server and local models), and other sensitivity-based models.
- Principles for application - guidance on attribute classification, handling direct identifiers, sampling vs. microdata, and integrating privacy guarantee models.
- Organizational and technical controls - access controls, controlled re-identification, and data flow considerations.
Applications and Who Uses This Standard
ISO/IEC 20889 is intended for practitioners and decision-makers who design or oversee data sharing and analytics where privacy is a concern:
- Data protection officers, privacy engineers and data scientists selecting de-identification techniques for research, analytics or publication.
- IT/security teams and architects integrating privacy-enhancing measures into data pipelines and cloud services.
- Healthcare, finance and government organizations publishing or sharing datasets while minimizing re-identification risk.
- Vendors developing de-identification tools, synthetic data platforms and privacy-preserving analytics.
Use cases include secure data sharing, compliance-oriented anonymization, privacy-preserving machine learning, and preparing datasets for research or public release.
Related Standards (if applicable)
- ISO/IEC 29100 - Privacy framework referenced by ISO/IEC 20889 for privacy principles.
- National and regional data-protection laws (e.g., GDPR) provide legal context for de-identification practice.
Keywords: ISO/IEC 20889:2018, privacy enhancing, data de-identification, de-identification techniques, pseudonymization, k-anonymity, differential privacy, re-identification, PII, data anonymization.