https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymous-data Skip to main content * About + Contact + Press + People + Opportunities * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers + Podcast + Annual Reports * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Giving Societies + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] --------------------------------------------------------------------- Email updates on news, actions, and events in your area. Join EFF Lists * Copyright (CC BY) * Trademark * Privacy Policy * Thanks Electronic Frontier Foundation Donate Electronic Frontier Foundation * About + Contact + Press + People + Opportunities * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers + Podcast + Annual Reports * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Giving Societies + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] Debunking the Myth of "Anonymous" Data DEEPLINKS BLOG By Paige Collings November 10, 2023 [mobile-pri] Debunking the Myth of "Anonymous" Data Share It Share on Twitter Share on Facebook Copy link [mobile-privacy] Today, almost everything about our lives is digitally recorded and stored somewhere. Each credit card purchase, personal medical diagnosis, and preference about music and books is recorded and then used to predict what we like and dislike, and--ultimately--who we are. This often happens without our knowledge or consent. Personal information that corporations collect from our online behaviors sells for astonishing profits and incentivizes online actors to collect as much as possible. Every mouse click and screen swipe can be tracked and then sold to ad-tech companies and the data brokers that service them. In an attempt to justify this pervasive surveillance ecosystem, corporations often claim to de-identify our data. This supposedly removes all personal information (such as a person's name) from the data point (such as the fact that an unnamed person bought a particular medicine at a particular time and place). Personal data can also be aggregated, whereby data about multiple people is combined with the intention of removing personal identifying information and thereby protecting user privacy. Sometimes companies say our personal data is "anonymized," implying a one-way ratched where it can never be dis-aggregated and re-identified. But this is not possible--anonymous data rarely stays this way. As Professor Matt Blaze, an expert in the field of cryptography and data privacy, succinctly summarized: "something that seems anonymous, more often than not, is not anonymous, even if it's designed with the best intentions." Anonymization...and Re-Identification? Personal data can be considered on a spectrum of identifiability. At the top is data that can directly identify people, such as a name or state identity number, which can be referred to as "direct identifiers." Next is information indirectly linked to individuals, like personal phone numbers and email addresses, which some call "indirect identifiers." After this comes data connected to multiple people, such as a favorite restaurant or movie. The other end of this spectrum is information that cannot be linked to any specific person--such as aggregated census data, and data that is not directly related to individuals at all like weather reports. Data anonymization is often undertaken in two ways. First, some personal identifiers like our names and social security numbers might be deleted. Second, other categories of personal information might be modified--such as obscuring our bank account numbers. For example, the Safe Harbor provision contained with the U.S. Health Insurance Portability and Accountability Act (HIPAA) requires that only the first three digits of a zip code can be reported in scrubbed data. However, in practice, any attempt at de-identification requires removal not only of your identifiable information, but also of information that can identify you when considered in combination with other information known about you. Here's an example: * First, think about the number of people that share your specific ZIP or postal code. * Next, think about how many of those people also share your birthday. * Now, think about how many people share your exact birthday, ZIP code, and gender. According to one landmark study, these three characteristics are enough to uniquely identify 87% of the U.S. population. A different study showed that 63% of the U.S. population can be uniquely identified from these three facts. We cannot trust corporations to self-regulate. The financial benefit and business usefulness of our personal data often outweighs our privacy and anonymity. In re-obtaining the real identity of the person involved (direct identifier) alongside a person's preferences (indirect identifier), corporations are able to continue profiting from our most sensitive information. For instance, a website that asks supposedly "anonymous" users for seemingly trivial information about themselves may be able to use that information to make a unique profile for an individual. Location Surveillance To understand this system in practice, we can look at location data. This includes the data collected by apps on your mobile device about your whereabouts: from the weekly trips to your local supermarket to your last appointment at a health center, an immigration clinic, or a protest planning meeting. The collection of this location data on our devices is sufficiently precise for law enforcement to place suspects at the scene of a crime, and for juries to convict people on the basis of that evidence. What's more, whatever personal data is collected by the government can be misused by its employees, stolen by criminals or foreign governments, and used in unpredictable ways by agency leaders for nefarious new purposes. And all too often, such high tech surveillance disparately burdens people of color. Practically speaking, there is no way to de-identify individual location data since these data points serve as unique personal identifiers of their own. And even when location data is said to have been anonymized, re-identification can be achieved by correlating de-identified data with other publicly available data like voter rolls or information that's sold by data brokers. One study from 2013 found that researchers could uniquely identify 50% of people using only two randomly chosen time and location data points. Done right, aggregating location data can work towards preserving our personal rights to privacy by producing non-individualized counts of behaviors instead of detailed timelines of individual location history. For instance, an aggregation might tell you how many people's phones reported their location as being in a certain city within the last month, but not the exact phone number and other data points that would connect this directly and personally to you. However, there's often pressure on the experts doing the aggregation to generate granular aggregate data sets that might be more meaningful to a particular decision-maker but which simultaneously expose individuals to an erosion of their personal privacy. Moreover, most third-party location tracking is designed to build profiles of real people. This means that every time a tracker collects a piece of information, it needs something to tie that information to a particular person. This can happen indirectly by correlating collected data with a particular device or browser, which might later correlate to one person or a group of people, such as a household. Trackers can also use artificial identifiers, like mobile ad IDs and cookies to reach users with targeted messaging. And "anonymous" profiles of personal information can nearly always be linked back to real people--including where they live, what they read, and what they buy. For data brokers dealing in our personal information, our data can either be useful for their profit-making or truly anonymous, but not both. EFF has long opposed location surveillance programs that can turn our lives into open books for scrutiny by police, surveillance-based advertisers, identity thieves, and stalkers. We've also long blown the whistle on phony anonymization. As a matter of public policy, it is critical that user privacy is not sacrificed in favor of filling the pockets of corporations. And for any data sharing plan, consent is critical: did each person consent to the method of data collection, and did they consent to the particular use? Consent must be specific, informed, opt-in, and voluntary. Related Issues Privacy Locational Privacy Share It Share on Twitter Share on Facebook Copy link Join EFF Lists Discover more. Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Related Updates A swarm of badger bees surrounding the words Privacy Badger SWARM in the center Deeplinks Blog by Alexei Miagkov, Daly Barnett | November 7, 2023 Introducing Badger Swarm: New Project Helps Privacy Badger Block Ever More Trackers Today we are introducing Badger Swarm, a new tool for Privacy Badger that runs distributed Badger Sett scans in the cloud. Badger Swarm helps us continue updating and growing Privacy Badger's tracker knowledge, as well as continue adding new ways of catching trackers. Thanks to continually expanding Badger Swarm-powered training... EU-flag-circuits Deeplinks Blog by Joe Mullin | November 7, 2023 This Month, The EU Parliament Can Take Action To Stop The Attack On Encryption A key European parliamentary committee has taken an important step to defend user privacy, including end-to-end encryption. The Committee on Civil Liberties, Justice and Home Affairs (LIBE) has politically agreed on much-needed amendments to a proposed regulation that, in its original form, would allow for mass-scanning of people's phones and... A wide image with an angry robot on one side. On the other side are the words, Red Flag Machine Press Release | October 31, 2023 EFF Unveils the Red Flag Machine, Exposing Deep Flaws in Student Surveillance Software SAN FRANCISCO--The Electronic Frontier Foundation (EFF) today unveiled the Red Flag Machine: an interactive quiz and report demonstrating the absurd inefficiency--and potential dangers--of student surveillance software that schools across the country use and that routinely invades the privacy of millions of children. The Red Flag Machine... [student-privacy-social] Deeplinks Blog by Jason Kelley | October 30, 2023 Young People May Be The Biggest Target for Online Censorship and Surveillance--and the Strongest Weapon Against Them Over the last year, state and federal legislatures have tried to pass--and in some cases succeeded in passing--legislation that bars young people from digital spaces, censors what they are allowed to see and share online, and monitors and controls when and how they can do it. EFF and many other... [mobile-privacy] Deeplinks Blog by Alexis Hancock | October 18, 2023 Privacy Advocates to TSA: Slow Down Plans for mDLs A digital form of identification should have the same privacy and security protections as physical ones. More so, because the standards governing them are so new and untested. This is at the heart of comments EFF and others submitted recently. Why now? Well, in 2021 the ... Google Spying Deeplinks Blog by Jennifer Lynch, Andrew Crocker | October 16, 2023 Colorado Supreme Court Upholds Keyword Search Warrant Today, the Colorado Supreme Court became the first state supreme court in the country to address the constitutionality of a keyword warrant--a digital dragnet tool that allows law enforcement to identify everyone who searched the internet for a specific term or phrase. In a weak and ultimately confusing opinion,... Bear hugging CA state, with lightning bolts on plum bg Deeplinks Blog by Hayley Tsukayama | October 13, 2023 California Takes Some Big Steps for Digital Rights California often sets the bar for technology legislation across the country. This year, the state enacted several laws that strengthen consumer digital rights.The first big win to celebrate? Californians now enjoy the right to repair. S.B. 244, authored by California Sen. Susan Eggman, makes it easier for individuals and... scales of justice icon + starburst Deeplinks Blog by Mario Trujillo, Adam Schwartz | October 3, 2023 Is Your State's Child Safety Law Unconstitutional? Try Comprehensive Data Privacy Instead Comprehensive data privacy legislation is the best way to hold tech companies accountable in our surveillance age, including for harm they do to children. Well-written privacy legislation has the added benefit of being constitutional--unlike the flurry of laws that restrict content behind age verification requirements that courts have recently blocked... Proposed UN Cybercrime Treaty Deeplinks Blog by Electronic Frontier Foundation | September 29, 2023 The Growing Threat of Cybercrime Law Abuse: LGBTQ+ Rights in MENA and the UN Cybercrime Draft Convention This is Part II of a series examining the proposed UN Cybercrime Treaty in the context of LGBTQ+ communities. Part I looks at the draft Convention's potential implications for LGBTQ+ rights. Part II provides a closer look at how cybercrime laws might specifically impact the LGBTQ+ community and activists... Google Spying Deeplinks Blog by Thorin Klosowski | September 28, 2023 How To Turn Off Google's "Privacy Sandbox" Ad Tracking--and Why You Should Google has rolled out "Privacy Sandbox," a Chrome feature first announced back in 2019 that, among other things, exchanges third-party cookies--the most common form of tracking technology--for what the company is now calling "Topics." Topics is a response to pushback against Google's proposed Federated Learning of Cohorts... Discover more. Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Share It Share on Twitter Share on Facebook Copy link Related Issues Privacy Locational Privacy Back to top EFF Home Follow EFF: * x * facebook * instagram * youtube * flicker * linkedin * mastodon * tiktok Check out our 4-star rating on Charity Navigator. Contact * General * Legal * Security * Membership * Press About * Calendar * Volunteer * Victories * History * Internships * Jobs * Staff * Diversity & Inclusion Issues * Free Speech * Privacy * Creativity & Innovation * Transparency * International * Security Updates * Blog * Press Releases * Events * Legal Cases * Whitepapers * EFFector Newsletter Press * Press Contact Donate * Join or Renew Membership Online * One-Time Donation Online * Giving Societies * Shop * Other Ways to Give * Copyright (CC BY) * Trademark * Privacy Policy * Thanks JavaScript license information *