{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-12","description":"Apply masking, pseudonymization, or de-identification when full identifiers are not required, following policy and the applicable legal standard (e.g., expert determination or safe-harbor methods, limited data sets under agreement). Protect the keys and mappings that could re-identify data, and prohibit re-identification attempts.","details":{"control_category":"technical","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"A.8.11","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"HIPAA-164.514","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"SI-19","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A006","coverage":"partial","delta":"personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Apply masking, pseudonymization, or de-identification when full identifiers are not required, following policy and the applicable legal standard (e.g., expert determination or safe-harbor methods, limited data sets under agreement). Protect the keys and mappings that could re-identify data, and prohibit re-identification attempts.","title":"De-identify, mask, or pseudonymize personal data","unified_id":"UC-DATA-12"},"id":"uc:UC-DATA-12","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-12","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-DATA-12 — De-identify, mask, or pseudonymize personal data","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0059f91f380a53e6d32b3a6fba91ea68eaa30bd7f98e807c5ab6d096b6d51c86","properties":{},"sourceDetailPath":"/data/v1/records/wf-r10-bc8bf886.json","sourceId":"wf:R10","targetDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","targetId":"uc:UC-DATA-12","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ca6ad3a9b99abd2f429684fcb0b5b76a0361388deec0baee43c30a3a30ea729","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","targetId":"uc:UC-DATA-12","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:47cc01fbac20185035f09875fdc49f3b3e2d1f6a738b8ed24034b96703d09ae7","properties":{"rationale":"Masked/pseudonymized data lowers the impact of any disclosure by limiting identifiability of exposed data.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:910ecea2df45bd97d6d8e48d6a91183ff8a82ca6e1a502943fa5a9bb9230d579","properties":{"rationale":"Applying pseudonymization when full identifiers aren't required is a core privacy-by-design/default technique.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/risk-privacy-no-privacy-by-design-c9472484.json","targetId":"risk:privacy-no-privacy-by-design","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a61f37f0d822a0d2f0f83a8f144cc7c10b3d99b4fed6473e86dbae2100efe744","properties":{"control_id":"HIPAA-164.514","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-514-ccac89ca.json","targetId":"ctrl:hipaa:HIPAA-164.514","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c783b550d3306227ac7538c829191604618ac82bd4c07c50f23ebdf9d0ceb7bf","properties":{"control_id":"A006","coverage":"partial","delta":"personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a006-846858b8.json","targetId":"ctrl:aiuc-1:A006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d03de70994cf6ae42ed65883aeba4e7b4c30f2e8f3aba91d450e253570833ce3","properties":{"rationale":"Masking/pseudonymization/de-identification plus protecting re-identification keys and prohibiting re-identification directly counters linkage/inference attacks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/risk-data-reidentification-inference-d4b31f45.json","targetId":"risk:data-reidentification-inference","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e7d290409635aa443f48ca96873b8ede955e7a22cdf34121a8acf404b37c3ceb","properties":{"control_id":"A.8.11","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-11-bb2940ca.json","targetId":"ctrl:iso-27001:A.8.11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea0857f1471c448528c386dedf7737383f16319ad8aa316a3aa3f3e4ae295328","properties":{"rationale":"Robust de-identification reduces AI inference re-identifying anonymized data and inferring sensitive attributes.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/risk-ai-privacy-leakage-9aa8d83c.json","targetId":"risk:ai-privacy-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd350d03603f04f7a3ac48b4f70b0e90d28108b93d0221aa497e8bd80a96fcb9","properties":{"control_id":"SI-19","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-19-cbae8fe7.json","targetId":"ctrl:nist-800-53:SI-19","type":"maps_to"}],"schemaVersion":1}
