GB/T 42460-2023Information security technology - Guide for evaluating the effectiveness of personal information de-identification (English PDF)
信息安全技术 个人信息去标识化效果评估指南
Open the GB/T 42460-2023 preview as PDF
This is a limited preview
Buy now to download the full PDF (25 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
March 17, 2023
Implementation date
October 1, 2023
Scope
GB/T 42460-2023 is the English-translated version of 信息安全技术 个人信息去标识化效果评估指南.
GB/T 42460-2023 covers how far a set of personal data has actually been de-identified and how that is proved - a grading of identifiability into four levels, the process an evaluation follows, and the work itself: preparation, a qualitative pass, a quantitative pass, the forming of conclusions, the communication and negotiation that follows, and the documentation kept of the whole process. Stripping names and identity numbers out of a dataset feels as though it settles the matter, and it does not: dates, locations, job titles and similar quasi-identifiers combine to single out individuals in data that looks anonymous, and a release judged safe on its own can be re-identified once someone joins it to something else. The annexes work on exactly that difficulty, with examples of direct identifiers, examples of quasi-identifiers, a method for deciding which fields in a real dataset behave as quasi-identifiers, and a worked evaluation using the K-anonymity model. Written for organisations that publish, share or sell datasets derived from personal information, for the teams inside them who have to sign a release off, and for assessors and regulators checking whether a de-identification claim holds up.
Document preview — GB/T 42460-2023
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- Foreword3
- Introduction4
- 1 Scope5
- 2 Normative references5
- 3 Terms and definitions5
- 4 Grading of personal information de-identification effectiveness7
- 5 Evaluation process for effectiveness of personal information de-identification8
- 6 Evaluation implementation9
- 6.1 Evaluation preparation9
- 6.2 Qualitative evaluation10
- 6.3 Quantitative evaluation10
- 6.4 Formation of evaluation conclusions11
- 6.5 Communication and negotiation11
- 6.6 Evaluation process documentation management11
- Annex A (informative) Examples for direct identifiers13
- Annex B (informative) Examples for quasi-identifiers14
- Annex C (informative) Identification of quasi-identifier15
- Annex D (informative) Examples for de-identification effectiveness evaluation based on K-anonymity model17
- Bibliography25
Foreword
This document was issued on 17 March 2023 by the State Administration for Market Regulation; Standardization Administration of the PRC and takes effect on 1 October 2023.
It is a GB/T standard: recommended rather than compulsory, but it is the text a Chinese reviewer applies when assessing a submission.
1 Scope
GB/T 42460-2023 covers how far a set of personal data has actually been de-identified and how that is proved - a grading of identifiability into four levels, the process an evaluation follows, and the work itself: preparation, a qualitative pass, a quantitative pass, the forming of conclusions, the communication and negotiation that follows, and the documentation kept of the whole process. Stripping names and identity numbers out of a dataset feels as though it settles the matter, and it does not: dates, locations, job titles and similar quasi-identifiers combine to single out individuals in data that looks anonymous, and a release judged safe on its own can be re-identified once someone joins it to something else. The annexes work on exactly that difficulty, with examples of direct identifiers, examples of quasi-identifiers, a method for deciding which fields in a real dataset behave as quasi-identifiers, and a worked evaluation using the K-anonymity model. Written for organisations that publish, share or sell datasets derived from personal information, for the teams inside them who have to sign a release off, and for assessors and regulators checking whether a de-identification claim holds up.
This document provides guidelines for grading and evaluating the effectiveness of
personal information de-identification.
This document applies to personal information de-identification activities. It is also
applicable to personal information security management, supervision and evaluation.
2 Normative references
The following referenced documents are indispensable for the application of this
document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
GB/T 25069-2022, Information security techniques -- Terminology
GB/T 35273-2020, Information security technology -- Personal information security
specification
GB/T 37964-2019, Information security technology -- Guide for de-identifying
personal information
3 Terms and definitions
For the purposes of this document, the terms and definitions defined in GB/T 25069-
2022, GB/T 35273-2020, GB/T 37964-2019 as well as the followings apply.
3.1 personal information
Various information related to identified or identifiable natural persons recorded
electronically or otherwise.
NOTE: Anonymized information is not included.
[Source: GB/T 35273-2020, 3.1, modified]
3.2 personal information subject
The natural person identified or associated with the personal information.
3.9 completely public sharing
Once the data is released, it is difficult to recall, and it is generally released directly
through the Internet.
[Source: GB/T 37964-2019, 3.12]
3.10 controlled public sharing
The use of data is constrained by the data use protocol.
[Source: GB/T 37964-2019, 3.13]
3.11 enclave public sharing
Share within physical or virtual jurisdictions. Data cannot be exported outside the
territory.
[Source: GB/T 37964-2019, 3.14]
3.12 re-identification risk; identifiability
The probability that the subject of personal information can be identified from the data.
3.13 equivalence class
A collection of rows in microdata where all quasi-identifier attribute values have the
same value.
3.14 acceptable risk threshold
The set re-identification risk threshold value.
NOTE: When the re-identification risk is greater than this value, mitigation measures (including
de-identification processing) and emergency measures need to be taken to keep the risk within a
controllable range.
4 Grading of personal information de-identification effectiveness
Based on whether the data can directly identify the subject of personal information, or
how likely it is to identify the subject of personal information, the identifiability of
personal information is graded into four levels, see Table 1, used to distinguish the
effectiveness of de-identification of personal information.
Table 1 -- 4 levels of personal information identifiability
Grading Grading basis
c) Form an evaluation team, including personal information protection compliance
experts, de-identification technical experts, and relevant business experts.
d) Carry out preliminary research, including detailed research on the data usage
environment.
e) Determine the evaluation basis, including relevant laws, regulations and standards.
f) Determine the re-identification risk calculation scheme and acceptable risk
threshold:
1) The re-identification risk calculation scheme considers both the dataset and the
context in which it is used. It can be based on K anonymous model or
differential privacy model, etc.
2) The acceptable risk threshold meets the corresponding safety requirements and
meets the application needs.
g) Develop an evaluation plan.
6.2 Qualitative evaluation
Qualitative evaluation includes:
a) Identify the identifier according to 5.3 in GB/T 37964-2019. Form a list of
identifiers (including direct identifiers and quasi-identifiers).
b) Determine whether the dataset contains identifiers in the identifier list. If it does
not contain any identifiers, it is rated as level 4 and the evaluation ends; otherwise
continue.
c) Determine whether the dataset has eliminated direct identifiers from the identifier
list. If it contains the direct identifiers in the list, it is rated as level 1, and the
evaluation ends; otherwise, further quantitative evaluation is carried out.
6.3 Quantitative evaluation
Quantitative evaluation includes:
a) Quantitatively calculate the re-identification risk. Carry out re-identification risk
calculation according to the re-identification risk calculation scheme determined
in 6.1f).
b) Compare the calculated re-identification risk results with acceptable risk
thresholds. If the re-identification risk result is less than the acceptable risk
threshold, it is rated as level 3; otherwise, it is rated as level 2, and the evaluation
ends.
See Annex D for the re-identification risk calculation scheme and evaluation example
based on the K-anonymity model.
6.4 Formation of evaluation conclusions
The formation of evaluation conclusions includes:
a) Combining the results of qualitative and quantitative evaluations, a grading
conclusion for de-identification effectiveness is formed.
b) The conclusion is approved by management officials.
6.5 Communication and negotiation
During the evaluation process, maintain communication with relevant parties
(including data providers, data receivers, etc.) and record the communication content,
including:
a) Confirmation of understanding of data sharing purpose and data sharing
environment;
b) Establishment of notification mechanism for major data environment changes;
c) Mutual exchange of information and views on re-identification risk metrics;
d) Opinions expressed by interested parties on the risk of re-identification;
e) Plan for regular/irregular reassessment.
6.6 Evaluation process documentation management
Evaluation process documentation management includes the following.
a) Evaluation process documents include the basis, reference and generated process
documents and result documents during the evaluation process, including but not
limited to:
1) Evaluation plan: including the data set to be evaluated, the environment for
data use, evaluators, evaluation methods, formation of evaluation results and
implementation progress, etc.;
2) Identifier identification report: the process and results of identifier
identification;
3) Re-identification risk calculation scheme: the re-identification risk calculation
scheme and the determination process and results of the acceptable threshold
Remaining clauses in the full document
- 5 Evaluation process for effectiveness of personal information de-identification
- 6 Evaluation implementation
- Annex A
- Annex C
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 25 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 25069-2022, Information security techniques -- TerminologyInformation security techniques—Terminology
- GB/T 35273-2020, Information security technology -- Personal information securityInformation security technology—Personal information security specification
- GB/T 37964-2019, Information security technology -- Guide for de-identifyingInformation security technology—Guide for de-identifying personal information
Similar standards
How to Buy GB/T 42460-2023
- 1Add to cart. Click the "Buy GB/T 42460-2023" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 42460-2023
$275.00