Read The Times Australia

Daily Bulletin

Ten questions you should ask before sharing data about your customers

  • Written by: Christine O'Keefe, Research Director · Digital Productivity, CSIRO

In 2016, a group of University of Melbourne researchers managed to decrypt some data that should have been anonymous.

Using publicly available information, the team pulled service provider numbers out of a sample of Pharmaceutical Benefits and Medicare Benefits Schedule data published online by the Australian government.

Needless to say, people were worried. But while the official response was swift, the exercise showed the potential vulnerability of some datasets that have ostensibly been anonymised to protect privacy.

Read More: Our healthcare records outlive us – it’s time to decide what happens to the data once we’re gone

Still, there are many reasons why it might be useful to share or release data.

A government health department may choose to make data available for medical research. A supermarket may share customer data with a local petrol station to launch a loyalty scheme.

When data is shared, de-identification can provide one way to do it while protecting privacy. That is, transforming data so that the risk of re-identifying an individual or revealing personal information about someone is low.

But de-identification is a complex process. Along with the Office of the Australian Information Commissioner, CSIRO Data61 has developed a De-Identification Decision-Making Framework to help data holders identify, evaluate and manage the relevant risks.

One potential solution

Any government, business or organisation that handles information about people – whether purchases or preferences, location, phone numbers, social media activity, or health services access, for example – needs to think about de-identification.

The technical heart of de-identification typically involves selecting an appropriate data sharing mechanism (such as open data or secure transfer to a single partner). It usually also involves modifying the data so there is a lower risk of re-identification.

Modifications could include removing names, addresses and other identifiers. It could also include removing or reducing detail in sensitive variables, or adding a small amount of random “noise” to obscure the true values.

image In 2017, a journalist found a darknet trader illegally selling the Medicare details of any Australian on request. AAP Image/Mick Tsikas

How should de-identification be carried out?

De-identification is about risk management, because producing safe, useful data means that zero privacy risk is not realistic. Instead, a balance should be found.

Our guide provides a comprehensive look at the issue, but the following ten questions are a place to begin.

  1. What do you know? Understand the nature of your data, as well as the other data, people, infrastructure and governance associated with your data.

  2. What are your legal responsibilities? Know which laws apply to your dataset and what obligations they impose. These may include the Privacy Act among others.

  3. What is your data like? Focus on the data type, features and properties. This involves the data subjects, variables, quality and age. This is important in assessing the re-identification risk.

  4. What is the use case? Know why you want to share your data, which groups will access them, and how those groups might want to use them. This is important in selecting the appropriate data sharing mechanism and modifications like adding a small amount of random “noise”.

  5. What are your ethical obligations? Consider, for example, consent, transparency, stakeholder engagement and governance.

  6. What processes will you need to go through to assess disclosure risk? Establish plausible attack scenarios using risk assessment methods. For example, someone trying to re-identify their neighbour in a local council dataset using characteristics they can easily observe, such as size of family, number of cars, and whether the home has reverse-cycle air-conditioning.

  7. What are the relevant disclosure control processes? This includes selecting the appropriate data sharing mechanism (such as open data or secure transfer to a single partner) and appropriate data modification methods, including possibly reducing the amount of data under consideration.

  8. Who are your stakeholders and how will you communicate with them? Stakeholders could include data subjects, the general public, partner organisations, the media, funders and special interest groups. Trust and credibility must be built.

  9. What happens next, once you have shared or released the data? This includes keeping a register of all the data you have shared or released. It’s being aware of developments such as new data-sharing technologies, changes in the law (like the Notifiable Data Breaches scheme coming into effect in 2018) and keeping track of future related data releases.

  10. What will you do if things go wrong? Have a plan to respond to a disclosure in the event one were to occur. Such measures include having a robust audit trail, a crisis management policy and adequately trained staff.

Read More: Too much information? More than 80% of children have an online presence by the age of two

The De-Identification Decision-Making Framework is not intended to eliminate the need to “call in the experts”. Indeed, expert advice - particularly on the more technical aspects of de-identification - may be crucial.

However, these ten questions will help to start the conversation about what is involved in the de-identification process, and how to begin identifying, evaluating and managing the risks.

Authors: Christine O'Keefe, Research Director · Digital Productivity, CSIRO

Read more http://theconversation.com/ten-questions-you-should-ask-before-sharing-data-about-your-customers-84845

Business News

The strategic rise of Bali as Australia’s next essential healthcare support hub

As Australian healthcare providers grapple with unprecedented operational bottlenecks, a new nearshore model is quietly transforming patient care delivery. Forward-thinking organisations,  including...

Daily Bulletin - avatar Daily Bulletin

Cost Savings and Benefits of Using Used Pallets in Logistics

In today’s competitive logistics and supply chain industry, businesses are constantly looking for ways to reduce operational costs without compromising efficiency and reliability. One of the most prac...

Daily Bulletin - avatar Daily Bulletin

How Fulfilment Services in Australia Help Businesses Scale Efficiently

The growth of e-commerce and modern retail has transformed customer expectations. Consumers now expect fast shipping, accurate order processing, and seamless delivery experiences regardless of where...

Daily Bulletin - avatar Daily Bulletin

Practical Ways Australian Workplaces Can Reduce Operating Costs

Reducing business costs doesn’t always mean cutting staff, shrinking services or making the workplace feel bare-bones. In many cases, the smarter savings are hiding in everyday operations: the light...

Daily Bulletin - avatar Daily Bulletin

Executive Recruitment Solutions That Help Organisations Secure Exceptional Leaders

Leadership has a direct impact on organisational performance, employee engagement, strategic growth, and long-term success. Businesses operating in increasingly competitive environments require experi...

Daily Bulletin - avatar Daily Bulletin

Why A WooCommerce Website Designer Matters For Online Growth

Running an online store today requires more than simply listing products and waiting for customers to arrive. Businesses need a website that is fast, reliable, easy to navigate, and designed to suppor...

Daily Bulletin - avatar Daily Bulletin

Turning Your Empty Tables into Revenue

The rise of AI demand tools in hospitality, the EatClub–CommBank partnership, and seven trends reshaping Australian dining  A growing number of Australian venues are turning to AI-powered demand mana...

Daily Bulletin - avatar Daily Bulletin

High-Impact Dental Marketing Strategies That Are Driving Real Practice Growth Today

The landscape of dental practice growth in Australia has shifted dramatically over recent years. Standard, broad-spectrum advertising campaigns no longer yield the return on investment they once did. ...

Daily Bulletin - avatar Daily Bulletin

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Lighting Shop in Perth: How The Right Lighting Can Transform Your Home And Business

The right lighting can completely change the look, feel, and functionality of any space. Whether it ...

Traffic Light System Solutions For Safer And More Efficient Traffic Management

Modern cities and growing communities rely heavily on effective traffic management to ensure safety...

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...