QuestionQ143

Compliance with European Data Protection Law and Regulation

What must a data controller do to render personal data pseudonymous?

  • A Separately hold any information that would allow linking the data to the data subject.
  • B Encrypt the data in order to prevent any unauthorized access or modification.
  • C Remove all indirect data identifiers and dispose of them securely.
  • D Use the data only in aggregated form for research purposes.
Explanation

Pseudonymisation requires that any additional information capable of linking the data back to a data subject is retained separately and subject to safeguards, so the data cannot be attributed to that person without it.

Community Discussion

No comments yet. Be the first to start the discussion!