unified
UC-DATA-12 — De-identify, mask, or pseudonymize personal data
Apply masking, pseudonymization, or de-identification when full identifiers are not required, following policy and the applicable legal standard (e.g., expert determination or safe-harbor methods, limited data sets under agreement). Protect the keys and mappings that could re-identify data, and prohibit re-identification attempts.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- technical
Details
- unified_id
- UC-DATA-12
- title
- De-identify, mask, or pseudonymize personal data
- statement
- Apply masking, pseudonymization, or de-identification when full identifiers are not required, following policy and the applicable legal standard (e.g., expert determination or safe-harbor methods, limited data sets under agreement). Protect the keys and mappings that could re-identify data, and prohibit re-identification attempts.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- technical
- members
- framework
- iso-27001
- control_id
- A.8.11
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.514
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SI-19
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- A006
- coverage
- partial
- delta
- personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Personal Data Quality & De-identification operates UC-DATA-12 — De-identify, mask, or pseudonymize personal data
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-12 — De-identify, mask, or pseudonymize personal data
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Masked/pseudonymized data lowers the impact of any disclosure by limiting identifiability of exposed data.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates Absence of privacy-by-design and default
- strength
- related
- rationale
- Applying pseudonymization when full identifiers aren't required is a core privacy-by-design/default technique.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data maps_to HIPAA-164.514 — De-identification of PHI and limited data sets
- framework
- hipaa
- control_id
- HIPAA-164.514
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data maps_to A006 — Prevent PII leakage
- framework
- aiuc-1
- control_id
- A006
- coverage
- partial
- delta
- personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates Re-identification and unanticipated revelation from data
- strength
- primary
- rationale
- Masking/pseudonymization/de-identification plus protecting re-identification keys and prohibiting re-identification directly counters linkage/inference attacks.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data maps_to A.8.11 — Data masking
- framework
- iso-27001
- control_id
- A.8.11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Robust de-identification reduces AI inference re-identifying anonymized data and inferring sensitive attributes.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data maps_to SI-19 — De-identification
- framework
- nist-800-53
- control_id
- SI-19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.