Official databases fail to protect personal data

Organisations face challenge in protecting confidential records

Written by Robert Jaques

Official organisations that maintain databases containing personal information need to devise better ways to protect individuals' privacy while preserving the value of the information to researchers, academics argue.

A report by Carnegie Mellon University statistics professor George Duncan in the journal Science claimed that traditional methods of 'de-identifying' records, such as stripping away Social Security numbers or birthdates, are inadequate to safeguard privacy.

Professor Duncan warned that a person who knows enough about the data pool could use other characteristics to identify individuals.

The academic pointed out that he is the only person who holds a Ph.D. in statistics and teaches in Carnegie Mellon's H. John Heinz III School of Public Policy and Management, so any data set that included that information, even with Duncan's name removed, could be used to determine his identity.

This could have serious consequences when it comes to data that includes information about a person's medical history or sexual behaviour, such as that collected by the National Center for Health Statistics.

Unfortunately, the characteristics that can be used to 're-identify' records are often the very information that makes the data useful to legitimate researchers.

"The question is how data can be made useful for research purposes without compromising the confidentiality of those who provided the data," said Professor Duncan.

Possible solutions to this dilemma include administrative procedures that limit data access to approved users who must abide by restrictions on the use of information, and statistical methods that 'de-identify' records in such a way that the user cannot readily reconstruct personal identities.

In order to be effective, these statistical transformations must be tailored to how the data will be used so that researchers can see the information that interests them while other characteristics remain veiled.

"Achieving 'adequate' privacy will require engineering innovation, managerial commitment, information cooperation of data subjects and social controls (legislation, regulation, codes of conduct by professional associations and response to reactions of the public)," Professor Duncan concluded.

Tags:

Further reading

Related articles

Carnegie Mellon floats anti-phishing game

Game on for Anti-Phishing Phil   More...

Virus and phishing attacks soar in September

Second surge of email attacks targeted at executives   More...

Digital library hits 1.5 million volumes

Project exceeds all expectations   More...

Phishing victims learn online security lesson

Once bitten twice shy   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement