Privacy & Data Protection
De-identification
De-identification is the umbrella practice of stripping identifying elements from data — spanning redaction, pseudonymization, and anonymization, each with different legal weight.
De-identification covers the family of techniques that remove or obscure identifying information: masking direct identifiers, generalizing quasi-identifiers, tokenizing, and suppressing rare records. HIPAA formalizes two routes — Safe Harbor's checklist of 18 identifier types, and expert determination.
The term's breadth is its trap: "de-identified" ranges from lightly-masked to truly anonymous, and AI vendors' promises to train only on "de-identified" data mean little without the method. The question to ask is always: could a motivated party re-identify this?
Where this shows up
Related terms
See it in your own organization.
Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.