[{"data":1,"prerenderedAt":16},["ShallowReactive",2],{"news-anonymisation-20-sharemind-as-a-tool-for-de-identifying-personal-data-part-2-sharemind-and-anonymisation":3},{"articles":4},[5],{"documentId":6,"title":7,"slug":8,"createdAt":9,"publishingDate":10,"description":11,"content":12,"quote":11,"postAuthor":11,"thumbnail":11,"relatedProducts":11,"industry":11,"relatedPosts":13,"metaData":14},"lorjerubqe704fo7rq5ogclo","Sharemind as a tool for de-identifying personal data (Part 2: Sharemind and anonymisation)","anonymisation-20-sharemind-as-a-tool-for-de-identifying-personal-data-part-2-sharemind-and-anonymisation","2021-07-07T13:59:55.000Z","2018-09-04",null,"In this two-part series, we answer a question we're often asked: is Sharemind anonymisation? Or is it something better?  Having established what [anonymisation and de-identification](https:\u002F\u002Fcyber.ee\u002Fresources\u002Fnews\u002Fanonymisation-20-sharemind-as-a-tool-for-de-identifying-personal-data-part-1-definitions\u002F) actually mean, both technically and legally, we'll now turn to Sharemind itself, and ask the more fundamental question: is this comparison even valid in the first place?\n\n## How does Sharemind work with anonymisation?\n\n[Sharemind](https:\u002F\u002Fcyber.ee\u002Fsolutions\u002Fprivacy-enhancement) is a platform for privacy-enhancing data analytics. Depending on its set-up and configuration, there are many ways in which Sharemind can be used to analyse de-identified information. When implemented in its maximum privacy mode, Sharemind enables anonymised processing of personal data. How does Sharemind achieve that?\n\n### Anonymous data vs anonymous processing\n\nIn the first article we acknowledged that there are two well-known techniques to anonymisation: noise addition at the **input level** (anonymised database) and at the **output level** (anonymised query result).\n\nIt is less known that in addition to anonymous databases and anonymous query results, anonymisation can also be achieved by means of anonymous processing. In that case, there is no suppression or noise needed - the underlying data remains intact and the anonymisation principle is applied at the processing level, not only to the data.\n\nThere's a common technology we can use as an analogy. Secure channels on the internet provide end-to-end confidentiality and integrity. TLS (stands for Transport Layer Security) is a popular standard for such communications. When done properly, the content of the data exchanged through a secure channel can not be manipulated and data subjects cannot be identified. The sender can be sure that only the intended recipient can read the messages. However, secure communication is static - the data cannot be modified.\n\nWhat if we could go a step further and also process data with end-to-end encryption?\n\n## Quick recap of Sharemind\n\nSo how does Sharemind actually achieve anonymous processing? Here's a quick recap of the mechanism.\n\nData owners encrypt the data and provide it to Sharemind without giving the Sharemind host access to the decryption key. This takes the reidentification capability out of the hands of the host. The unique selling point of Sharemind is the transformation of encrypted inputs into encrypted results without making the data available to Sharemind.\n\nThis is true end-to-end security. From data owners to users with no middlemen seeing the values. Think of it like TLS for analytics. Or we could say that Sharemind provides PLS - Process Layer Security.\n\nSharemind also provides remote audit and control capabilities that the Sharemind host cannot turn off. This is great for enforcing privacy policies and ensuring that only legitimate processing takes place.\n\n## Is Sharemind anonymisation?\n\nYes and no.\n\nFrom a regulatory standpoint, Sharemind provides anonymisation guarantees (for example, in the meaning of the GDPR). Sharemind's use of encryption technology achieves de-identification throughout the data flow.\n\nFrom a technical standpoint, Sharemind has properties that other anonymisation technologies cannot achieve. Let's return to the service provider example from the first part of the series, where a service provider collects identifiable data from multiple sources and processes it to offer insights or statistics to customers.\n\nIf that service is built using Sharemind's secure application servers, the service provider will not have access to the data at all. Re-identification becomes nearly impossible, while linking, aggregation, statistical analysis, AI and other functions remain entirely possible. From a security analysis standpoint, the main avenue for re-identification in this setup is the exploitation of side channels. In applications where that risk is realistic, special care should be taken to counter side-channel attacks during application preparation.\n\nFor the data user, our approach of choice is to apply minimisation. That is, to show the user the absolute minimum amount of data to deliver the value from the data. This requires careful analysis during application preparation and a change in the way data analysts are used to working. But the prize is that the results will be accurate, with no added noise that noise-based anonymisation techniques would require.\n\nThat said, Sharemind is also compatible with other anonymisation techniques, for example, differential privacy. In this case, the service provider will build anonymisation into the Sharemind application so that anonymised results are calculated just as normal ones would be. The difference is that instead of minimisation and accuracy, the results will be less limited, but with noise added.\n\n## Conclusion\n\nThe goal of this two-part series was to answer the popular question on how is Sharemind related to the concept of anonymisation and anonymisation technologies.\n\nWhile Sharemind does not perform anonymisation according to the popular definitions, it may well be offering the best possible anonymisation in the meaning of the law. This is because Sharemind helps to lower the risk of identifying a person by any data processor to the minimum, while maintaining the accuracy of the underlying data and enabling making adequate conclusions from it.\n\n**Recommendations**\n\nWhen building a data-driven service, choose the anonymisation approach that best fits the value at stake in re-identifying the data.\n\n- For the most accurate results, we recommend anonymous processing with Sharemind, combined with minimisation of query interfaces.\n- If minimisation proves difficult to implement, anonymous processing with Sharemind combined with result anonymisation through randomisation is another strong option.",[],{"metaTitle":7,"metaDescription":15,"shareImage":11},"Is Sharemind anonymisation, or something better? Part 2 explores how Sharemind achieves GDPR-compliant anonymous data processing through encryption.",1788355408814]