Sanción al Sescam por una comunicación mal anonimizada

A public health organization was reprimanded for sharing a disciplinary resolution that failed to fully anonymize a worker’s identity. The data protection authority determined that indirect references, such as a unique residential location and specific work details, allowed colleagues to identify the individual. This highlights that merely omitting direct identifiers like names is insufficient; any information enabling re-identification violates privacy standards under current regulations. The agency criticized the organization’s internal verification process, noting that relying on a small review team revealed a fundamental lack of expertise in data anonymization. This procedural gap created a high risk of errors, demonstrating that informal checks are inadequate for ensuring compliance with strict data protection principles. Such negligence underscores the necessity for specialized training and robust technical measures within public sector entities handling sensitive employee information. This case is relevant to open data because it illustrates the critical balance between transparency and privacy. While organizational accountability is vital, releasing information without rigorous anonymization compromises individual rights. It serves as a cautionary tale for anyone managing public records, emphasizing that true openness requires sophisticated data handling to protect personal identities while maintaining institutional integrity.

Source: expansion.com
Published on 2023-04-29