Properties of Effective Information Anonymity Regulations

Aloni Cohen,Micah Altman,Francesca Falzon,Evangelina Anna Markatou,Kobbi Nissim
2024-08-27
Abstract:A firm seeks to analyze a dataset and to release the results. The dataset contains information about individual people, and the firm is subject to some regulation that forbids the release of the dataset itself. The regulation also imposes conditions on the release of the results. What properties should the regulation satisfy? We restrict our attention to regulations tailored to controlling the downstream effects of the release specifically on the individuals to whom the data relate. A particular example of interest is an anonymization rule, where a data protection regulation limiting the disclosure of personally identifiable information does not restrict the distribution of data that has been sufficiently anonymized. In this paper, we develop a set of technical requirements for anonymization rules and related regulations. The requirements are derived by situating within a simple abstract model of data processing a set of guiding general principles put forth in prior work. We describe an approach to evaluating such regulations using these requirements -- thus enabling the application of the general principles for the design of mechanisms. As an exemplar, we evaluate competing interpretations of regulatory requirements from the EU's General Data Protection Regulation.
Computers and Society
What problem does this paper attempt to address?
### What problems does this paper attempt to solve? This paper aims to explore and define the properties that effective information anonymization regulations should possess. Specifically, it focuses on how to control the impact on personal privacy during data processing and publication through formulating reasonable regulations. The following are the core problems that the paper attempts to solve: 1. **Objectives of the regulations**: - How to ensure that the regulations can effectively control the specific impact of data publication on individuals (i.e., downstream effects), especially when this data involves personal information. 2. **Technical requirements for anonymization rules**: - Develop a set of technical requirements for evaluating and designing anonymization rules and other subject effect regulations. These requirements are based on the general principles proposed in previous work and are applied to a simple abstract data - processing model. 3. **Applicability and evaluation of the regulations**: - Propose a method to evaluate whether the proposed subject effect regulations meet the above - mentioned technical requirements, thereby providing guidance for the design of regulations. In particular, taking the EU General Data Protection Regulation (GDPR) as an example, the paper analyzes the effectiveness and consistency of different interpretations. 4. **Application of the six principles**: - The paper elaborately describes six key principles: Process Protection, Format Neutrality, Inclusion - Based Protection, Composition Awareness, Transparency, and Protective Assumptions. These principles are the basis for evaluating and designing anonymization regulations. 5. **Application of GDPR anonymization**: - Apply these six principles to analyze the anonymization requirements in GDPR, especially for three types of privacy attacks: linkability, singling out, and inference. In this way, the paper shows how to use these principles to improve the interpretation and application of existing regulations. ### Summary In general, this paper attempts to evaluate and design anonymization regulations by establishing a rigorous technical framework, ensuring that these regulations can protect personal privacy while allowing reasonable data use and publication. The paper not only proposes a theoretical framework but also demonstrates the practical application value of these frameworks through specific cases (such as GDPR).