CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard

A healthcare organization replaces patient names in a research dataset with randomly generated unique codes. The organization retains a separately secured mapping table linking each code back to the original patient identity for authorized re-identification if needed later. Which de-identification technique does this represent?

  1. AAggregation
  2. BPseudonymization
  3. CAnonymization
  4. DData masking
Show answer & explanation

Correct answer: B. Pseudonymization

Pseudonymization replaces identifying fields with artificial identifiers (codes) while retaining a separate, securely stored mapping table that allows re-identification, unlike true anonymization, which permanently removes the ability to re-identify individuals.

Why the other options are wrong

  • A. Aggregation combines data into summary groups, not individual-level code substitution.
  • C. Anonymization irreversibly removes identifying information so re-identification is not possible.
  • D. Data masking obscures values (e.g., partial characters) typically for display, not full replacement with a reversible code.

Pseudonymization

A reversible de-identification technique that replaces identifying data fields with artificial identifiers (pseudonyms), while a separately secured mapping table allows authorized re-identification.

  • Reversible, unlike anonymization
  • Mapping table must be securely stored separately
  • Still considered personal data under regulations like GDPR

Memory trick: Pseudonymization wears a 'mask' that can be removed with the right key.

More Data Governance, Quality and Controls questions