Saved in:
Bibliographic Details
Main Authors: Cohen, Aloni, Altman, Micah, Falzon, Francesca, Markatou, Evangelina Anna, Nissim, Kobbi
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2408.14740
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914924950716416
author Cohen, Aloni
Altman, Micah
Falzon, Francesca
Markatou, Evangelina Anna
Nissim, Kobbi
author_facet Cohen, Aloni
Altman, Micah
Falzon, Francesca
Markatou, Evangelina Anna
Nissim, Kobbi
contents A firm seeks to analyze a dataset and to release the results. The dataset contains information about individual people, and the firm is subject to some regulation that forbids the release of the dataset itself. The regulation also imposes conditions on the release of the results. What properties should the regulation satisfy? We restrict our attention to regulations tailored to controlling the downstream effects of the release specifically on the individuals to whom the data relate. A particular example of interest is an anonymization rule, where a data protection regulation limiting the disclosure of personally identifiable information does not restrict the distribution of data that has been sufficiently anonymized. In this paper, we develop a set of technical requirements for anonymization rules and related regulations. The requirements are derived by situating within a simple abstract model of data processing a set of guiding general principles put forth in prior work. We describe an approach to evaluating such regulations using these requirements -- thus enabling the application of the general principles for the design of mechanisms. As an exemplar, we evaluate competing interpretations of regulatory requirements from the EU's General Data Protection Regulation.
format Preprint
id arxiv_https___arxiv_org_abs_2408_14740
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Properties of Effective Information Anonymity Regulations
Cohen, Aloni
Altman, Micah
Falzon, Francesca
Markatou, Evangelina Anna
Nissim, Kobbi
Computers and Society
A firm seeks to analyze a dataset and to release the results. The dataset contains information about individual people, and the firm is subject to some regulation that forbids the release of the dataset itself. The regulation also imposes conditions on the release of the results. What properties should the regulation satisfy? We restrict our attention to regulations tailored to controlling the downstream effects of the release specifically on the individuals to whom the data relate. A particular example of interest is an anonymization rule, where a data protection regulation limiting the disclosure of personally identifiable information does not restrict the distribution of data that has been sufficiently anonymized. In this paper, we develop a set of technical requirements for anonymization rules and related regulations. The requirements are derived by situating within a simple abstract model of data processing a set of guiding general principles put forth in prior work. We describe an approach to evaluating such regulations using these requirements -- thus enabling the application of the general principles for the design of mechanisms. As an exemplar, we evaluate competing interpretations of regulatory requirements from the EU's General Data Protection Regulation.
title Properties of Effective Information Anonymity Regulations
topic Computers and Society
url https://arxiv.org/abs/2408.14740