Insights on Crypto Payments, Infrastructure, and Operations

Re-identification Risk

Pronunciation: ree-eye-den-tih-fih-KAY-shun risk

Also known as: De-anonymization risk, Identity linkage risk

Definition

Re-identification risk is the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations. Pseudonymization usually reduces direct identification but does not automatically remove data from privacy obligations because linkage may remain reasonably possible. Operationally, teams should assess motivated intruders and available auxiliary data, minimize quasi-identifiers, aggregate or perturb outputs, and control access.

Overview

Re-identification risk is the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations.

Re-identification Risk is closely connected to Privacy-Preserving Analytics, Privacy Risk Assessment, and Homomorphic Encryption. Pseudonymization usually reduces direct identification but does not automatically remove data from privacy obligations because linkage may remain reasonably possible.

Operational implementation should assess motivated intruders and available auxiliary data, minimize quasi-identifiers, aggregate or perturb outputs, control access, limit repeated queries, test linkage, monitor data releases, and reconsider risk as external data changes.

The principal failure modes include unique combinations, small groups, location trails, longitudinal records, public-data linkage, model memorization, overly detailed dashboards, and assumptions that removing names is sufficient.

Useful measures include re-identification test success, minimum group sizes, high-risk releases, linkage findings, query controls, and reassessments after new datasets become available.

Operationally, teams should assess motivated intruders and available auxiliary data, minimize quasi-identifiers, aggregate or perturb outputs, and control access. Key risks include unique combinations, small groups, location trails, and longitudinal records.

For Re-identification Risk, the assessment should evaluate the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations. The assessment record should separate observed evidence supporting the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations have changed enough to require a new rating, treatment, or approval.

Key Takeaway

Re-identification risk is the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person using available information, auxiliary datasets, or repeated observations.

Sources

  1. Anonymisation and Pseudonymisation Guidance — Information Commissioner’s Office (2026-08-03)
  2. NIST Privacy Framework — NIST (2026-08-03)
  3. Regulation (EU) 2016/679, General Data Protection Regulation — European Union (2026-08-03)